InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1651. |
Solve : AVG 8.0? |
|
Answer» I downloaded the latest version of AVG at home, brought my LAPTOP to work, ran it and everything seemed fine. I can on occasion get a wireless connection at work so I tried to get on the internet and in my search bar no matter what I type in it says , http://search.yahoo.com/search?fr=ffds1&p=search.yahoo.com and I also noticed avg added a toolbar to my page and a yahoo toolbar? This is what you've done (should be similar to latest version although it's a version that's a little older)? See screenshots on link below. When I last tried with AVG, no yahoo toolbar was installed Well heres what I wound up doing. I went into view , tool bars and unchecked yahoo and AVG. I can see tomorrow I will be uninstalling and custom installing AVG again. Thanks much, MP.Sure, let us know how it goes Yes, hiding the toolbar is a temporary fix for having the toolbars not show up, but it wont' get rid of it off your machine so we'll see how you do tomorrow.Removed 1st install of 8.5 reinstalled and no toolbar. Thanks much, MP.Glad that everything worked out for you Thank you for the time and effort. |
|
| 1652. |
Solve : XEROX - NWWIA? |
|
Answer» Hai, i am gopinath - please solve my problem in the given below. |
|
| 1653. |
Solve : Vundo? |
|
Answer» Just so I don't HIJACK that other THREAD anymore |
|
| 1654. |
Solve : What are the top free antivirus and spyware programs for my computer? |
|
Answer» I have a reconditioned hp computer with windows xp and i would like to know what the best antivirus programs are to install to KEEP my computer clean and how many i need to install. Thank You. System: Microsoft Windows XP Professional Version 2002 Service Pack 3. Intel(R) Pentium(R) 4 CPU 3.20GHz 3.19Ghz, .099 GB of Ram.1. for antivirus -- get AVAST, AVG, or AVIRA (all three are free, get the one you like best ... only one antivirus is needed, DO NOT GET MORE THAN ONE!!) |
|
| 1655. |
Solve : Computer is not working right?? |
|
Answer» My computer is not working right. I'm not exactly sure of what is GOING on with it but I know that there is something wrong. I really need help. I know I have not posted my logs yet but I will asap.Nobody is going to be ABLE to provide any help at all until you tell US exactly what the specific problems are. |
|
| 1656. |
Solve : Windows Security Alert problems...? |
|
Answer» Well im pretty ure i have malware problems, I did the malware tutorial steps. |
|
| 1657. |
Solve : Orange Email problem? |
|
Answer» Hi, I can log into my Orange home page no prob, I then click the link to my Email account then a full page SECURITY mess comes up and tells me There is a problem with this websites security cert. The security cert presented by this website has expired or is not yet valid, Ive never had this prob before with Orange I've tried changing the time on my computer clock and system restore but nothing has helped any ideas please More info would be helpful. Does Orange mean http://www.orange.co.uk/? Do you use always ACCESS your email VIA their webmail logon, in other words, via your web browser? There is a problem with this websites security cert. The security cert presented by this website has expired or is not yet valid, Ive never had this prob before with Orange ...Does the message actually pertain to Orange or to the website which is being opened from a hyperlink in an email message in your Orange account? Hi everyone problem solved went to start search typed inetcpl.cpl hit ENTER opened advanced tab and clicked reset, re downloaded INTERNET explorer 8 and everything is now working fine. yipee OK. |
|
| 1658. |
Solve : Possible Malware/Virus Problem? |
|
Answer» Hi, i've been having regular PROBLEMS with my computer which I suspect is a virus/spyware/malware problem. Every time i try to open an application it says "Application cannot be executed. The file _______ is infected. Do you want to activate your antivirus software now?" Any help would be greaty appreciated.Try all of these please. |
|
| 1659. |
Solve : Autorun Infections on USB Drives? |
|
Answer» Yes that would be best.When I tried to drag the CFScript.txt onto the ComboFix icon I think it asked to Run and I think I said O.K. then I realised my browser was still OPEN and so I tried to delay the ComboFix program while I closed it. Will I be able to shut them from the icons on the TaskBar while the warning boxes are still visible ? Yes shut them down now and then let CF continue.I've closed Avast and BOClean and the ComboFix Blue area has appeared. It has given a message that there is a new version of ComboFix available and is asking if I want to download it. Should I update now or proceed with the scan ?Yes update it before continuing.In case it is important, I thought I had better mention that both times after ComboFix re-booted the Lenovo it has briefly displayed a text line saying that it couldn't find combofix.sys. I have attached the ComboFix Report generated after starting it with the CFScript. I have run the Temp File Cleaner. It removed 68.00MB. [Saving space, attachment deleted by admin]That looks good now. I'm confident that the computer is clean and it should perform a little better with all of the Norton stuff gone. Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done. * Click START then RUN * Now type Combofix /Uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter. The above procedure will: * Delete: ComboFix and its associated files and folders. * Reset the CLOCK settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Here are some more suggestions to help tighten up your computers security. Use the Secunia Software Inspector to check for out of date software. * Click Start Now * Check the box next to Enable thorough system inspection. * Click Start * Allow the scan to finish and scroll down to see if any updates are needed. * Update anything listed. ---------- Go to Microsoft Windows Update and get all critical updates. ---------- If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page. ---------- I recommend you keep SUPERANTISPYWARE and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online SCAMS, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hi. Thank you for your help. I am trying to uninstall ComboFix. I have typed the command in the RUN box. BOClean hs produced this message : RSK-HIDE.SAA MALWARE STOPPED by BOCLEAN Location of startup : FILE C:\32788R22FW\HIDEC.EXE This trojan horse was found on your machine. It has been shut down, but the FILE from which it started still remains and can be started up again. Do you want the file removed also ? YES/NO Please advise.Disable BOClean before uninstalling ComboFix.I closed down BOClean and Avast so that the unistallation would continue. I have an "Info" Box on screen that says "ComboFix is ininstalled". It appeared really quickly, there were no other screens and the computer did not re-boot. Is that O.K?Yes it's gone. It happens very fast. You should be good to go on cleaning the other drives now. Nothing on the computer will spread to them. Just don't let the drives auto launch before you are sure they're cleaned. In the process of using a 250GB Iomega Hard Drive, that has not had contact with the Lenovo, to transport Flash Disinfector, Panda USB Vaccine and Avira Anti-Virus to my Toshiba laptop, I discovered that I had not been following your TWEAK UI Auto-Run instructions properly. What I have found is that if you --> Open Tweak UI Expand My Computer Expand AutoPlay Click Types UNcheck "Enable Autoplay for removable drives" Click Apply Click O.K. your external hard drive will STILL Autoplay, even after a re-boot. I suppose the Tweak Tool is divided up so that the section I looked at and modified is geared towards ENABLING a function - whereas the LIST I *should* have looked at is about SWITCHING THINGS OFF. I'm posting my mistake so that hopefully other people will avoid it. I do find it confusing that IMY WRONG Tweak appears to have no effect. Is AutoPlay ever actually really necessary for anything ? If you have a CD or a DVD, could you not always CHOOSE to make it start by clicking the optical drive's icon ? Thanks again for all the help that you have provided. This site is brilliant. The direct links to the relevant pages for program downloads cut through so much time searching at Google or just trying to navigate through a software company's site. ADDITION : I just went to manually modify the AutoPlay settings on the Lenovo and this Systemax and can see that ALL of the drives - even the optical drives - have been deselected. So I take it that's what Panda Vaccine does when it "Vaccinates a Computer" rather than an external drive. There are some more solutions for disabling autoruns here. http://support.microsoft.com/kb/967715 |
|
| 1660. |
Solve : Please review- Help !!! 3 Different problems !? |
|
Answer» - I have tried to download the NEW 9.0 AVG - and it will not load - gets to the end and says it can't be installed. ( I have 8.5 running) - I TRIED to load the SuperAntispyware - Website is temporarily unavailable..... I did run the hijack This - log attached I ran MalwareBytes -Log attached I ran AVG in safe mode and got a bunch of problems .. -Log attached So far the 3 main issues i have found are - Packed.DelfCrypt Vundo.JP and Fake Alert.OQ I don't even know where to start as everytime I try run the scan it just freezes and shuts down - however I did run AVG in safe mode Any help would be greatly appreciated ! Thanks , M3lani3 [Saving space, attachment deleted by admin]Welcome to CH Spicegirl. Open HijackThis and select Do a system scan only Place a check mark next to the following entries: (if there)
Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. NOTE: Realtek AC97 Audio - Event Monitor. "Sypware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers ---------- Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger or Windows Live Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply. Exit out of MessengerDisable then delete the two files that were put on the desktop. ---------- If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFix Thank You Evil - I have done as instructed and then did a new log from combo fix... I did run the Malware bytes again last night and got it down to 4 infections- still need to upgrade my AVG - My IE still hangs - wont move off of the front page .... Only Firefox running at this point- can you help me with that too?? Is it all still connected to the Viruses/ spyware? Greatly Appreciate all your help ~! M3L [Saving space, attachment deleted by admin]Let me know how things are after this. 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: File:: i:\program files\Save\Save.exe Registry:: [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] "BootExecute"=hex(7):61,75,74,6f,63,68,65,63,6b,20,61,75,74,6f,63,68,6b,20,2a,00,00 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "WhenUSave"=- 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in CASE it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeThanks again Evil .. I have done as instructed again , and attaching the log ... STILL no IE - brings up yahoo homepage , then just sits .. Can't do anything .. Thankfully Firefox , still ok.. Anymore suggestions to fix the IE ? Thanks again ! M3L ! [Saving space, attachment deleted by admin]Download the Fix IE Utility to your desktop. Before running the utility, make sure that all your Internet Explorer windows are closed! * Extract the contents of the .zip file to your desktop. * Double click the Fix IE Utility button to run the tool. * Click Run Utility * Click OK when you see 'Re-registered all files' * Open Internet Explorer and see how it works. Let me know how things are now. THANK YOU, THANK YOU, THANK YOU !!!!! I **THINK** it is all back to normal now ... I am writing to you again through IE this time (YAY!!) I have run AVG and nothing comes up - will run the Malware Bytes again this evening , but seems to be running alot better ... Thanks soooo much for all your help Evil! I have applied to learn to fight malware(@ GeekPolice Acadamy) to assist others like you have done for me ! Do I need to delete the combofix , hijack this and various other things from my computer now ? Or shall I keep them just in case?? ( suppose I could always just re-install them all ..) Once again , THANK YOU !!!!! (I'd hug ya if I knew ya better !!!) * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /Uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then HIT Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- ESET Online Scan Scan your computer with the ESET FREE Online Virus Scan * Click the ESET Online Scanner button. * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop * Double click on the esetsmartinstaller_enu.exe icon on your desktop. * Place a check mark next to YES, I accept the Terms of Use. * Click the Start button. * Accept any security warnings from your browser. * Leave the check mark next to Remove found threats and place a check next to Scan archives. * Click the Start button. * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time. * When the scan completes, click List of found threats. * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply. * Click the <<Back button then click Finish. In your next reply please include the ESET Online Scan LogWell, it all SEEMED good ! hhahah ! The ESET found 2 infected files .. Log Attached .. Thanks Evil... [Saving space, attachment deleted by admin]Those were nothing to worry about. Disable/Enable the System Restore Utility to flush old infected restore points 1) Right click the My Computer icon on the Desktop and click on Properties. 2) Click on the System Restore tab. 3) Put a check mark next to Turn off System Restore on All Drives 4) Click the OK button. 5) You will be prompted to restart the computer. Click the Yes button. Now re-enable System Restore To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'. 1) Right click the My Computer icon on the Desktop and click on Properties. 2) Click on the System Restore tab. 3) Remove the check mark next to Turn off System Restore on All Drives 4) Click the OK button. ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. Use only trusted security software like the programs listed on this page. Trusted security tools & resourcesThank You for your help Evil - I have done as you instructed above - did have to update the Java , and have now added the WOT , so hopefully it helps me out ! I really appreciate all the help ! Mel Your welcome. Safe surfing... |
|
| 1661. |
Solve : spyware/malware?? |
|
Answer» Thanks DMJ... |
|
| 1662. |
Solve : New AV? |
|
Answer» Hi guy's you could try sophos AV it's not normally used for home computers and seems to be more aimed at distributed platforms such as in college servers where many different computers/OS's (MAC,Windows,Linux,Unix etc) could be connecting to get on the net. I ran it for 2 years and never had a problem. It was almost like using an industrial chemical for home cleaning purposes...needlessly excessive!!! and more than a safe bet for home computing. Yeah one reason to move from Norton would be the fact that Norton is a massive 'resource hog'. How is sophos when it comes to background stuff? Thanks for the reply. I, myself, prefer MicroSoft Security Essentials. With a 98% EFFIENCY rating and not being a resource hog sure gets my vote. Remember to only install one antivirus! 1) Avast! Home Edition 2) AVG Free Edition 3) AVIRA AntiVir Personal 4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download 4-a) Microsoft Security Essentials for Windows XP 5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one) 6) PC Tools AntiVirus Free Edition It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.Quote from: SuperDave on February 11, 2010, 08:58:52 AM I, myself, prefer MicroSoft Security Essentials. With a 98% effiency rating and not being a resource hog sure gets my vote. Very helpful SuperDave, thanks for the links. Thinking I may give MS security essentials a run. |
|
| 1663. |
Solve : ??? Web-Protection ???? |
|
Answer» While downloading somthing else Mc-Afee got installed on my computer.I just ran 1 scan with it and it says I have no internet protection,what do they mean with that ? I do have Avast.(I don`t run the 2 at the same time,I was curious and thought;Let`s see if it "can spot something Avast has missed).As I see it Avast is I-Net protection.Or do they mean there is no childrens lock installed ? |
|
| 1664. |
Solve : help! cannot open any programs. keep getting virus alerts? |
|
Answer» out of nowhere today my computer kept getting popups telling me i have a virus. it won't let me open any programs other than firefox. i've been reading posts with other people who had this problem but nothing seems to work. it's called antivirus soft. please help me.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
here's the log ComboFix 10-02-01.02 - User Account 02/02/2010 6:29.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.479.91 [GMT -4:00] Running from: c:\documents and settings\User Account\desktop\commy.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Start Menu\HP Image Zone .lnk c:\documents and settings\User Account\Application Data\inst.exe C:\Install.exe c:\program files\INSTALL.LOG c:\recycler\S-1-5-21-299502267-1715567821-839522115-1003 c:\windows\EventSystem.log c:\windows\system32\Thumbs.db c:\windows\system32\trial icon - .ico . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_SSHNAS ((((((((((((((((((((((((( Files Created from 2010-01-02 to 2010-02-02 ))))))))))))))))))))))))))))))) . 2010-02-02 04:20 . 2010-02-02 04:20--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2010-02-02 04:16 . 2010-02-02 04:16--------d-----w-c:\program files\SUPERAntiSpyware 2010-02-02 04:16 . 2010-02-02 04:16--------d-----w-c:\documents and settings\User Account\Application Data\SUPERAntiSpyware.com 2010-02-02 03:24 . 2010-02-02 03:24--------d-sh--w-c:\documents and settings\Administrator\PrivacIE 2010-02-02 00:15 . 2010-02-02 00:15--------d-----w-c:\windows\LMI5C.tmp 2010-02-02 00:05 . 2010-02-02 00:05--------d-----w-c:\program files\LogMeIn Rescue 2010-02-01 21:22 . 2010-02-01 21:22--------d-----w-c:\program files\Trend Micro 2010-02-01 21:15 . 2010-02-01 21:15--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2010-02-01 20:34 . 2010-02-01 20:34--------d-----w-c:\documents and settings\User Account\Application Data\Malwarebytes 2010-02-01 20:33 . 2010-01-07 20:0738224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-01 20:33 . 2010-02-01 20:33--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2010-02-01 20:33 . 2010-02-02 04:01--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2010-02-01 20:33 . 2010-01-07 20:0719160----a-w-c:\windows\system32\drivers\mbam.sys 2010-02-01 18:29 . 2010-02-02 10:20--------d-----w-c:\documents and settings\User Account\Local Settings\Application Data\fngmom 2010-01-23 13:53 . 2007-03-19 00:3765602----a-w-c:\windows\system32\cook3260.dll 2010-01-19 14:37 . 2010-01-31 01:30--------d-----w-c:\documents and settings\User Account\Application Data\Vso 2010-01-19 14:36 . 2010-01-23 13:53--------d-----w-c:\program files\VSO 2010-01-19 14:24 . 2010-01-19 14:24--------d-----w-c:\program files\Haali . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-02 10:06 . 2010-02-02 04:21117760----a-w-c:\documents and settings\User Account\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-02-02 04:21 . 2010-02-02 04:2152224----a-w-c:\documents and settings\User Account\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-02-01 19:52 . 2008-05-12 01:43--------d-----w-c:\documents and settings\User Account\Application Data\Azureus 2010-01-23 13:53 . 2010-01-19 14:3747360----a-w-c:\windows\system32\drivers\pcouffin.sys 2010-01-23 13:53 . 2010-01-19 14:3747360----a-w-c:\documents and settings\User Account\Application Data\pcouffin.sys 2010-01-23 13:53 . 2010-01-19 14:3747360----a-w-c:\documents and settings\User Account\Application Data\pcouffin.sys 2010-01-23 13:44 . 2010-01-23 12:58--------d-----w-c:\program files\Common Files\AVSMedia 2010-01-23 13:44 . 2010-01-23 12:58--------d-----w-c:\program files\AVS4YOU 2010-01-23 13:01 . 2010-01-23 13:01--------d-----w-c:\documents and settings\User Account\Application Data\AVS4YOU 2010-01-23 13:01 . 2010-01-23 13:01--------d-----w-c:\documents and settings\All Users\Application Data\AVS4YOU 2010-01-22 19:34 . 2010-02-02 00:04177568----a-w-c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\extensions\[emailprotected]\platform\WINNT\plugins\rahook.dll 2010-01-22 19:34 . 2010-02-02 00:056116752----a-w-c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\extensions\[emailprotected]\platform\WINNT\plugins\npRescue.dll 2010-01-22 19:34 . 2010-02-02 00:05959904----a-w-c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\extensions\[emailprotected]\platform\WINNT\components\npRescuePostInstallProcedure.exe 2010-01-22 19:34 . 2010-02-02 00:051803680----a-w-c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\extensions\[emailprotected]\platform\WINNT\plugins\LMIRSrv.dll 2010-01-20 13:00 . 2009-10-03 16:06--------d-----w-c:\program files\Microsoft Silverlight 2010-01-19 23:29 . 2010-01-19 15:55--------d-----w-c:\documents and settings\All Users\Application Data\vsosdk 2010-01-19 14:24 . 2009-11-17 04:35--------d-----w-c:\program files\AviSynth 2.5 2010-01-18 13:07 . 2010-01-26 15:451260800----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe 2010-01-18 13:07 . 2010-01-26 15:453777280----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe 2010-01-07 01:11 . 2008-10-26 22:41--------d-----w-c:\program files\Vuze 2009-12-21 19:14 . 2004-08-10 21:51916480----a-w-c:\windows\system32\wininet.dll 2009-12-17 01:20 . 2009-12-17 01:19--------d-----w-c:\documents and settings\All Users\Application Data\AVG Security Toolbar 2009-12-17 01:19 . 2009-12-17 01:19360584----a-w-c:\windows\system32\drivers\avgtdix.sys 2009-12-17 01:19 . 2009-12-17 01:1912464----a-w-c:\windows\system32\avgrsstx.dll 2009-12-17 01:19 . 2009-12-17 01:19333192----a-w-c:\windows\system32\drivers\avgldx86.sys 2009-12-17 01:19 . 2009-12-17 01:1928424----a-w-c:\windows\system32\drivers\avgmfx86.sys 2009-12-17 01:18 . 2009-12-17 01:18--------d-----w-c:\documents and settings\All Users\Application Data\avg9 2009-12-17 01:18 . 2009-06-21 18:01--------d-----w-c:\program files\AVG 2009-11-27 16:54 . 2009-07-16 23:4561664-c-ha-w-c:\windows\system32\mlfcache.dat 2009-11-21 15:51 . 2004-08-10 21:49471552----a-w-c:\windows\AppPatch\aclayers.dll 2009-11-10 03:20 . 2009-11-10 03:2015884----a-w-c:\documents and settings\User Account\Application Data\Azureus\plugins\azitunes\libProcessAccess.dll 2009-11-10 03:20 . 2009-11-10 03:20102400----a-w-c:\documents and settings\User Account\Application Data\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll 2009-11-10 03:20 . 2009-11-10 03:204141117----a-w-c:\documents and settings\User Account\Application Data\Azureus\plugins\vuzexcode\mediainfo.exe 2009-11-10 03:20 . 2009-11-10 03:206516755----a-w-c:\documents and settings\User Account\Application Data\Azureus\plugins\vuzexcode\ffmpeg.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080] [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152] "QuickTime TASK"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600] "D-Link Wireless G WUA-1340"="c:\program files\D-Link\Wireless G WUA-1340\AirGCFG.exe" [2007-08-27 1662976] "ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472] MBCameraMonitor.lnk - c:\program files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe [2009-9-5 541976] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 18:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-12-17 01:1912464----a-w-c:\windows\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2008-10-15 05:0439792----a-w-c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-14 00:1215360------w-c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2006-02-19 05:4149152----a-w-c:\program files\HP\HP Software Update\hpwuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2009-10-29 00:21141600----a-w-c:\program files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Location Finder] 2005-08-25 02:25101080-c--a-w-c:\program files\Microsoft Location Finder\LocationFinder.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr] 2009-07-26 19:443883856----a-w-c:\program files\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] 2001-07-09 19:50155648-c--a-w-c:\windows\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] 2005-04-27 19:035898240----a-w-c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] 2005-04-27 19:0386016-c--a-w-c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] 2005-04-27 19:031519616-c--a-w-c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2009-09-05 04:54417792----a-w-c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] 2005-01-21 04:0477824-c--a-w-c:\windows\SOUNDMAN.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2008-02-22 07:25144784-c--a-w-c:\program files\Java\jre1.6.0_05\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\StubInstaller.exe"= "c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Ares\\Ares.exe"= "c:\\Program Files\\Vuze\\Azureus.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\AVG\\AVG9\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26/05/2008 1:10 AM 715248] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [16/12/2009 9:19 PM 333192] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [16/12/2009 9:19 PM 360584] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/01/2010 7:56 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 7:56 AM 74480] R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [03/10/2009 8:25 AM 464264] R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [03/10/2009 8:25 AM 234888] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [16/12/2009 9:18 PM 906520] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [16/12/2009 9:18 PM 285392] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 7:56 AM 7408] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [21/09/2009 11:15 AM 133104] . Contents of the 'Scheduled Tasks' folder 2010-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 15:34] 2010-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-21 15:15] 2010-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-21 15:15] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.ca/ uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000 DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {8F4213B4-A970-4B3C-820D-343C693D5BF0} - hxxp://dsp02.eastlink.ca/SelfProvisioning.cab FF - ProfilePath - c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo! Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ FF - prefs.js: keyword.URL - hxxp://ca.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_ca&p= FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\[emailprotected]\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\[emailprotected]\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\[emailprotected]\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\[emailprotected]\components\xpavgtbapi.dll FF - plugin: c:\documents and settings\User Account\Application Data\Mozilla\Firefox\Profiles\h9aemmb4.default\extensions\[emailprotected]\platform\WINNT\plugins\npRescue.dll FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - ORPHANS REMOVED - - - - URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) MSConfigStartUp-!AVG Anti-Spyware - c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe MSConfigStartUp-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe MSConfigStartUp-avast! - c:\progra~1\ALWILS~1\Avast4\ashDisp.exe MSConfigStartUp-DbWinEn - c:\windows\system32\ypgfqvuz.exe MSConfigStartUp-IMprocess - c:\program files\Instant Messenger Names\IM-svr.EXE MSConfigStartUp-MSFox - c:\docume~1\USERAC~1\LOCALS~1\Temp\a.exe MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-02 06:42 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys spvw.sys hal.dll >>UNKNOWN [0x8598F944]<< kernel: MBR read successfully detected MBR rootkit HOOKS: \Driver\Disk -> CLASSPNP.SYS @ 0xf75b9f28 \Driver\ACPI -> ACPI.sys @ 0xf7326cb8 \Driver\atapi -> atapi.sys @ 0xf72e1b40 IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8 ParseProcedure -> ntkrnlpa.exe @ 0x805827e8 \Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8 ParseProcedure -> ntkrnlpa.exe @ 0x805827e8 NDIS: SiS 900-Based PCI Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xf71ecb0a PacketIndicateHandler -> NDIS.sys @ 0xf71f7a21 SendHandler -> NDIS.sys @ 0xf71ec949 user & kernel MBR OK ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] @DACL=(02 0000) "Installed"="1" @="" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] @DACL=(02 0000) "NoChange"="1" "Installed"="1" @="" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] @DACL=(02 0000) "Installed"="1" @="" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(532) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(856) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\slserv.exe c:\program files\AVG\AVG9\avgnsx.exe c:\program files\Windows Media Player\WMPNetwk.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\iPod\bin\iPodService.exe c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe . ************************************************************************** . Completion time: 2010-02-02 06:52:15 - machine was rebooted ComboFix-quarantined-files.txt 2010-02-02 10:52 Pre-Run: 33,711,702,016 bytes free Post-Run: 33,722,482,688 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect - - End Of File - - E8010BFE5BE0C42DCE93EBC246EAED95 Hi again. Please do these steps in order. 1. Please download TFC by OldTimer to your desktop
Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. 3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer: http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial Post the log from SUPERAntiSpyware when you've accomplished that. 4. Please run a free online scan with the ESET Online Scanner
5. Post the following in your next reply:
MALWARE BYTES Malwarebytes' Anti-Malware 1.43 Database version: 3458 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 8.0.6001.18702 01/02/2010 4:57:20 PM mbam-log-2010-02-01 (16-57-20).txt Scan type: Quick Scan Objects scanned: 118882 Time elapsed: 13 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 37 Registry Values Infected: 5 Registry Data Items Infected: 0 Folders Infected: 3 Files Infected: 62 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\xml.xml (Worm.Allaple) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\xml.xml.1 (Worm.Allaple) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{9233c3c0-1472-4091-a505-5580a23bb4ac} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\applications\accessdiver.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\dpcproxy (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\fwbd (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\HolLol (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\IMAdvertiser (Adware.SearchTwo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mslAgent (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\System\CurrentControlSet\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\System\CurrentControlSet\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{0656a137-b161-cadd-9777-e37a75727e78} (Fake.Dropped.Malware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\turbonet (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\systemcheck2 (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\akl (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\system32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\mslagent (Adware.EGDAccess) -> Quarantined and deleted successfully. Files Infected: C:\Program Files\akl\akl.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\Program Files\akl\akl.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\Program Files\akl\uninstall.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\Program Files\akl\unsetup.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\system32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\mslagent\2_mslagent.dll (Adware.EGDAccess) -> Quarantined and deleted successfully. C:\WINDOWS\mslagent\mslagent.exe (Adware.EGDAccess) -> Quarantined and deleted successfully. C:\WINDOWS\mslagent\uninstall.exe (Adware.EGDAccess) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\RECYCLER\ADAPT_Installer.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\awtoolb.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\bsva-egihsg52.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\[emailprotected]k.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vbsys2.dll (Trojan.Clicker) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\Winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\winSystem.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\a.bat (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\base64.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\FVProtect.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\iTunesMusic.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\userconfig9x.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\winSystem.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\zip1.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\zip2.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\zip3.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\zipped.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.SUPERANTI SPYWARE SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 02/02/2010 at 05:58 PM Application Version : 4.33.1000 Core Rules Database Version : 4548 Trace Rules Database Version: 2360 Scan type : Quick Scan Total Scan Time : 00:27:28 Memory items scanned : 541 Memory threats detected : 0 Registry items scanned : 554 Registry threats detected : 0 File items scanned : 16130 File threats detected : 12 Adware.Tracking Cookie C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][1].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][1].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][1].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][1].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][1].txt C:\Documents and Settings\User Account\Cookies\[emailprotected][2].txt ESET [emailprotected] as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=dfe16a8708cf9d489892f4e80efe9c4b # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-02-02 11:07:46 # local_time=2010-02-02 07:07:46 (-0400, Atlantic Standard Time) # country="Canada" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 6861 6861 0 0 # compatibility_mode=768 16777215 100 0 41122462 41122462 0 0 # compatibility_mode=1024 16777175 100 0 3218276 3218276 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=78970 # found=0 # cleaned=0 # scan_time=3071 Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
|
|
| 1665. |
Solve : Trojan caused Win Vista problems? |
|
Answer» I'm new to this site, but I've been told it's the best place to go for help. I had AVG on my HP notebook for a very long time, however a trojan snuck past it and now I'm getting errors left and right. When I would double click on AVG, Mozilla, or any other program, I would get a box that said "Open With - Choose the program you want to USE to open this file: " and my only choices were Adobe Reader 8.1 or Firefox. By chosing Firefox (to open a web page) another box would pop up that says "Opening firefox.exe - You have chosen to open firefox.exe which is a: Application from C:\Program Files\Mozilla Firefox - Would you like to save this file?" and I would have the option to Save or Cancel. I had no option to "Always use the selected file to open this program" or I would have just checked that box and solved that problem... Going hand in hand with this minor inconvenience is a problem with my Windows program (the actual part I'm worried about). When I try to open things in my Control Panel I get the message "C:\Windows\system32\rundll32.exe Application not found ". Therefore, I am unable to navigate through several areas of my control panel (to my ability anyway). |
|
| 1666. |
Solve : avast help? |
|
Answer» I use Avast Virus program and it is FREE |
|
| 1667. |
Solve : Recomended Antivirus and Firewall.? |
|
Answer» As I recall there was a page somewhere here that listed the latest and greatest antivirus and firwalls. I cannot seem to find it, if it still exists. |
|
| 1668. |
Solve : How can I get a back trace to catch a hacker? |
|
Answer» Last night a hacker got into my MAIN computer and changed all my SETTINGS and DISABLED my devices and is now trying to communicate with me thru yahoo messenger. He disabled his username he says was for my protection. I had Zone Alarm FIREWALL, AVG antivirus, and Threat fire antivirus but he was still able to get into my computer. My ZoneAlarm doesn't have the back trace feature and I can't find any info who to CONTACT to do a back trace if he attempts to contact me thru messenger again. Any help appreciated. THANKSPlease go to this link and follow the directions and post the required logs. |
|
| 1669. |
Solve : anti-virus question? |
|
Answer» If I'm using AVG Free version, and I've got RESIDENT Shield enabled, should it be disabled before I run a scan with say, Malwarebytes?I don't disable mine. |
|
| 1670. |
Solve : Internet Explorer very hard to open? |
|
Answer» For some time we have suffered from redirects when browsing. This problem was becoming more persistent. We also had a recurring message about a threat on a WIN file which AVG was patching but could not remove.
Important: Close all open windows EXCEPT for HijackThis and then click Fix checked. Once completed, exit HijackThis. ---------- If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop DO NOT run it yet! Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: File:: C:\WINDOWS\system32\kdpjv.exe C:\WINDOWS\system32\lphcafoj0e7er.exe 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while DRAGGING the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze Thanks for the help. I'll go with trying to clean the system. I've DONE everything described however when combofix began to execute it asked me to disable the AVG antivirus scanner or risk damage to the machine. Is it possible to disable this? If so how? Quote from: moreagh on February 03, 2010, 10:04:17 AM Is it possible to disable this? If so how? See here. http://www.bleepingcomputer.com/forums/topic114351.htmlThese are the Combofix logs. I have noticed that Windows Firewall is not active and the system will not let me turn it on. Is this because this is the base computer for a wireless network [Saving space, attachment deleted by admin]Quote AV: Windows Live OneCare *On-access scanning disabled* (Updated) {427ADFC3-B354-4A51-BE34-A9D4218E45C4} You can't turn it on because OneCare is still there. I suggest uninstalling both Windows Live OneCare and Windows Live OneCare firewall. Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger or Windows Live Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply. Exit out of MessengerDisable then delete the two files that were put on the desktop. ---------- Go to Start > Run and type notepad.exe then click OK Copy the text in the Code box below and paste it into Notepad. Code: [Select]REGEDIT4 [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] In Notepad go to File > Save as... Next to File name: type fixme.reg Use the dropdown box next to Save as type: and select All files. Save it to the Desktop. There should now be a file on the Desktop that looks like this Double-click fixme.reg it and ALLOW it to merge with the Registry. You may not see anything happen but give it a few seconds or so to finish. Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Now delete the fixme.reg file from the Desktop. ---------- * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /Uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * RESET the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- ESET Online Scan Scan your computer with the ESET FREE Online Virus Scan * Click the ESET Online Scanner button. * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop * Double click on the esetsmartinstaller_enu.exe icon on your desktop. * Place a check mark next to YES, I accept the Terms of Use. * Click the Start button. * Accept any security warnings from your browser. * Leave the check mark next to Remove found threats and place a check next to Scan archives. * Click the Start button. * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time. * When the scan completes, click List of found threats. * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply. * Click the <<Back button then click Finish. In your next reply please include the ESET Online Scan Log Merging with the registry was a success. I also have Windows Firewall again. ESETScan file attached [Saving space, attachment deleted by admin]Looks good. How is the computer running now? For a good free firewall. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo HopSurf..", Ask.com search provider" and "Make Comodo HopSurf.com Search my homepage" 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus Computer running very well. Good connections Sharp response No virus alerts No redirects I am really grateful for your help. The steps have been extremely clear, accurate and easy to follow. Are there any of the programs I should now delete or any that I should now use on a regular basis in case of recurring problems? Thanks again RobertYour welcome. Final suggestions. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page. ---------- I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 1671. |
Solve : here are my logs as requested? |
|
Answer» 16:31:37:218 3128TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25
Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
so i went thru all my files in outlook and deleted them.....will that be sufficient? did everthing you asked and here is the request: Results of screen317's Security Check version 0.99.1 Windows XP Service PACK 3 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall ENABLED! Avira AntiVir Personal - Free Antivirus Antivirus up to date! `````````````````````````````` Anti-malware/Other Utilities Check: Spybot - Search & Destroy SUPERAntiSpyware Free Edition CCleaner WISE Disk Cleaner 4.84 Wise Registry Cleaner 4 Free 4.92 Java(TM) 6 Update 17 Adobe Flash Player 10 Adobe Reader 7.0 Out of date Adobe Reader installed! `````````````````````````````` Process Check: objlist.exe by Laurent Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) `````````End of Log``````````` It should be fine. Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. == Please download the newest version of Java from Java.com. Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them. Once old versions are gone, please install the newest version. == Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Firewall
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to MAINTAIN protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
thank you so much for all your help and suggestions! |
|
| 1672. |
Solve : riddled with viruses please help? |
|
Answer» Hi
Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. ---------- Go to Add or Remove Programs and uninstall:
---------- A malicious .DLL file is disrupting the LSP chain on your computer. We need to get rid of it. * Please download LSPFix * Run the LSPFix.exe that you have just finished downloading. * Check the I know what I'm doing box. * In the Keep box you should see one or more instances of winhelper86.dll * Select every instance of winhelper86.dll and move each one to the Remove box by clicking the >> button. * If the winhelper86.dll file only appears on the right side then just click fix checked and close the program. * When you are done click Finish>> Is the connection back? If not continue to the next step. ---------- Download and run WinSockFix This is a two step process that will Back up the Registry and Reset the Winsock Stack.
Note: Resetting the Winsock in SP2 might remove third-party LSPs and restores Winsock to factory default setting. Existing programs that uses their own LSPs may need to be reinstalled. Example: Google Desktop Search. Is the connection back? If not continue to the next step. ---------- Go Start > Run and type in:cmd then click OK In the Command Prompt window type in following commands, and press Enter after each one: Code: [Select]ipconfig /flushdnsCode: [Select]ipconfig /registerdnsCode: [Select]ipconfig /releaseCode: [Select]ipconfig /renew Note the space before the forward slash / Restart the computer. Is the connection back? Continue to the next step if it is or isn't and let me know in the next post. ---------- If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFix Thank you so much for your help. I followed all the instructions and regained access to the internet after the first fix so i did not try the other two and moved straight to the combofix, after the combofix had finished and i had save the log the following error POPPED up in task bar: Windows delayed write failed windows was unable to save all the data fot the file \...\DP(1)0-0+5. The data has been lost. this error may have been caused by a failure of the computer hardware or network connection. please try to save this file elsewhere. I havent touched the laptop since, i will just wait for your reply. i have attached the combofix logs as requested! thank you so much again for your help. Kel [Saving space, attachment deleted by admin]1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Driver:: dhexq 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze ---------- Please go to Start > Run and copy/paste the following blue text, then press Enter: C:\QooBox\Add-Remove Programs.txt A text file should open. Please post the contents of that file in your next reply. ----------All done there didnt seem to be any problems this time, have posted logs as requested! thanks so much again for your help! Kel [Saving space, attachment deleted by admin]Go to Add or Remove Programs and uninstall:
---------- * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /Uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- ESET Online Scan Scan your computer with the ESET FREE Online Virus Scan * Click the ESET Online Scanner button. * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop * Double click on the esetsmartinstaller_enu.exe icon on your desktop. * Place a check mark next to YES, I accept the Terms of Use. * Click the Start button. * Accept any security warnings from your browser. * Leave the check mark next to Remove found threats and place a check next to Scan archives. * Click the Start button. * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time. * When the scan completes, click List of found threats. * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply. * Click the <<Back button then click Finish. In your next reply please include the ESET Online Scan Log Hi, thanks for that, i have completed all the above steps however when the eset antivirus was scanning it threw up serveral boxes of details of the trojans it had deleted (about 10 Id say), but it only gave me an option to delete the messages or close them, i closed them thinking that it would give me a full report at the end but at the end it said no viruses detected and only gave me a finish option?! So i dont kno if i had done something wrong? so i dont have the logs for you sorry, do you want me to run it again? thanks v much Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster JayHello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster JayThanks for you help but I'm trying to fix the laptop for a family member so am hoping to use free software, it's not my place to buy any software for the laptop so if as a last resort evilfantasy says the only way to fix it is to buy some software then I will leave it up to them to deal with that. Thanks Hi. Please disregard any advice given except from me. Did you download ESET or run the online scanner? Try this. Scan your computer with Panda ActiveScan * Once you are on the Panda site click the Scan your PC now button. * A new window will open...click the Scan Now button. * If it wants to install an ActiveX component allow it. * It will start downloading the files it requires for the scan. (Note: It may take a couple of minutes) * You may get a warning from Internet Explorer that Panda is ready to install, please allow it. * The scan will begin. Please be patient as it can take an hour or more to complete. * When the scan completes, if anything malicious is detected, click the Export to: button (looks like a little Notepad). * Save the ActiveScan.txt to a convenient location like your desktop. * Note: You do not need to select any of the Disinfect options. We will remove any threats manually. * Post the contents of the ActiveScan report in your next reply. Thanks I ran the ESET online scanner I have ran the Panda scanner now and attached logs! Thanks V much [Saving space, attachment deleted by admin]Looks good. How is the computer running now? Disable/Enable the System Restore Utility to flush old infected restore points 1) Right click the My Computer icon on the Desktop and click on Properties. 2) Click on the System Restore tab. 3) Put a check mark next to Turn off System Restore on All Drives 4) Click the OK button. 5) You will be prompted to restart the computer. Click the Yes button. Now re-enable System Restore To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'. 1) Right click the My Computer icon on the Desktop and click on Properties. 2) Click on the System Restore tab. 3) Remove the check mark next to Turn off System Restore on All Drives 4) Click the OK button. ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hey, i have completed all of the above! the laptop is running great now, seems to be no more problems! i cant thank you enough for your help! it is really appreciated! Your welcome. Safe surfing... |
|
| 1673. |
Solve : C:\windows\system32\sshnas21.dll infected, Trojan Horse? |
|
Answer» Hello! |
|
| 1674. |
Solve : Application cannot be executed. The file "" is infected. HALPHALPHALP? |
|
Answer» I need help getting rid of this virus/malware/rogue. It's ruining my life.ok a couple of questions to get a clearer IDEA of the problem |
|
| 1675. |
Solve : Virus Concern? |
|
Answer» Hi Jay. I will most certainly update this PC and unload and make sure that the programs that you SUGGESTED are used. I can't thank you enough for your patience ,diligence and expertise in these virus matters. Without your help I don't know where I WOULD have gone or what else I would have done? Sure HOPE that I don't have to bother you again for a long, long time. This was a terrible SITUATION for me but you made it a very LEARNING experience, and I think that you made this whole situation as easy for me as you possibly could have. |
|
| 1676. |
Solve : Malware - Can't open any program or get online...? |
|
Answer» I am running Windows XP service pack 3. I have had AVG free, SuperAntiSpyware, Malwarebytes Anti-malware, and CC Cleaner installed on my computer for over a year. They are up-to-date.
Let me know how it goes.Thank you so very much for your help! So, I took a look at the programs you suggested and then decided that this endeavor was beyond me. Actually, I would have given it a go had there not been data on my computer that I very much did not want to lose. I'll have to start backing up more than twice a month! I took my laptop in to a local place and they were able to save my data by removing my hard drive and doing a voodoo dance, or whatever it is that needs to be done with these things. You would know more than I. The virus has been removed and the laptop restored to factory settings, which in itself is a pain, since the factory settings are now years out-of-date and were glitchy to begin with. So I probably will be back lurking in the different FORUMS trying to figure out how to de-bug and clean-up things like my start-up, etc... But thank you for taking the time to help - it really was a help - I was able to make a decision based on the information, and that in itself, was invaluable. You all are the greatest!!!!!Ok |
|
| 1677. |
Solve : Adware.Zango? |
|
Answer» I can't SEEM to duplicate it. I have MBAM on with IP protection and it's not happening here. STRANGE.I have had no more IP's blocked. I wonder if it had summit to do with the update of MBt's. |
|
| 1678. |
Solve : corrupted exes (control.exe mmc.exe)? |
|
Answer» I don't know what virus I have, but every time I try to open the Add/Remove Programs it tells me that control.exe can't be opened. I ran Malwarebytes, it removed something called cleansweep, and I thought the problem was gone. Later on when I attempted to follow an online guide for modifying Remote Desktop (this took place after I realized something wasn't right with my computer, so its not the catalyst), I tried to open gpedit.msc and it told me that mmc.exe was missing a dll (MRoD.dll). I tested control.exe again, and that is also not working. So, I don't have any issue with pop ups or programs forcing me to buy them, but a whole bunch of essential exes dont seem to work right. Any insight as to what this is?
Database version: 3717 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 2/10/2010 11:43:48 AM mbam-log-2010-02-10 (11-43-47).txt Scan type: Full Scan (C:\|) Objects scanned: 321688 Time elapsed: 3 hour(s), 40 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\cleansweep.exe (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 3/10/2003 10:48:56 AM System Uptime: 2/7/2010 10:56:50 PM (46 hours ago) Motherboard: Compaq | | 07E4h Processor: Intel(R) Pentium(R) 4 CPU 2.66GHz | XU1 PROCESSOR | 2657/533mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 233 GiB total, 118.968 GiB free. E: is CDROM () G: is CDROM () H: is FIXED (NTFS) - 932 GiB total, 670.86 GiB free. ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Intel(R) PRO/100 VM Network Connection Device ID: PCI\VEN_8086&DEV_103B&SUBSYS_00120E11&REV_81\4&25296D99&0&40F0 Manufacturer: Intel Name: Intel(R) PRO/100 VM Network Connection PNP Device ID: PCI\VEN_8086&DEV_103B&SUBSYS_00120E11&REV_81\4&25296D99&0&40F0 Service: E100B ==== System Restore Points =================== No restore point in system. ==== Installed Programs ====================== 7-Zip 4.65 AAC Decoder ACID Pro 7.0 AcronisMigrateEasy Adobe AIR Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Reader 9.2 Adobe Shockwave Player 11.5 Advertising Center AllToAVI v4 r5394 Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft MediaImpression ArcSoft PhotoImpression 5 ArcSoft VideoImpression 2 Ares 2.1.2 Aspell English Dictionary-0.50-2 AutoUpdate AVG 9.0 AviSynth 2.5 BitTyrant Bonjour Calculator Powertoy for Windows XP CamStudio CamStudio Lossless Codec CCleaner Combined Community Codec Pack 2009-09-09 DC++ 0.750 Dev-C++ 5 beta 9 release (4.9.9.2) Digital Camera DivX Codec DivX Plus DirectShow Filters DivX Plus Web Player DivX Version Checker DolbyFiles DVD Flick 1.3.0.7 DVD Shrink 3.2 EA Download Manager EA Download Manager UI Fiesta FreeMind GIMP 2.6.7 GNU Aspell 0.50-3 GTK+ Runtime 2.14.7 rev a (remove only) GUI Design Studio 3.6.95.0 Guifications Plugin (remove only) H.264 Decoder HandBrake 0.9.3 High-Logic FontCreator 6.0 HighMAT Extension to Microsoft Windows XP CD Writing Wizard HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB954550-v5) HP Standard Port Monitor HyperCam 2 Image Resizer Powertoy for Windows XP Intel(R) Extreme Graphics Driver Intel(R) PRO Ethernet Adapter and Software InterVideo DeviceService iPodRip iTunes Java 2 Runtime Environment, SE v1.4.0_01 Java Web Start Java(TM) 6 Update 3 Kazaa Lite K++ v2.4.3 KeyScrambler LogMeIn Hamachi Malwarebytes' Anti-Malware MapleStory MediaCoder 0.6.1 MEGA-DSC Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Office XP Professional with FrontPage Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft WSE 3.0 Runtime Miro MKV Splitter MKVtoolnix 2.9.8 Mozilla Firefox (3.5.7) MUSTEK 1200 UB v2.1 Nero ControlCenter Nero Installer Nero Suite NETGEAR WG111v2 wireless USB 2.0 adapter Notepad++ Orbit PeerGuardian 2.0 Pidgin Pokemon PC 2.0 Project64 1.6 PurgeFox - 4.01 QuickTime RGSS-RTP Standard RPG Maker 2000 1.05 RPG Maker 2003 v1.08 RPG Maker VX 1.02 RPG Maker VX RTP RPG Maker XP - Postality Knights Edition ENHANCED RTP 1.32 Add-On for RM2k RTP de RPG Maker 2003 RTP for RM2K (Png, Wav, Midi, Fonts) save2pc Pro 3.51 Scenario RPGMaker 2003 Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB972270) Smart Install Maker 5.02 SoulSeek 157 NS 13e SoundMAX SUPER © Version 2009.bld.36 (June 10, 2009) SUPERAntiSpyware Professional TES Construction Set The Sims™ 3 Torrent Searcher 9.0 TreeSize Free V2.3.3 TrueCrypt Tweak UI Unlocker 1.8.8 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB975364) Update for Windows Internet Explorer 8 (KB976749) VC80CRTRedist - 8.0.50727.4053 Videora iPod classic Converter 5.03 Videora Trial Version 2.15 VirtualDubMOD 1.5.10.3 US VLC media player 1.0.3 VMware ThinApp VobSub v2.23 (Remove Only) Vuze WebFldrs XP Window Washer Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows Support Tools Windows XP Service Pack 3 WinFF 1.0.4 WinPcap 4.0 Xvid 1.2.2 final uninstall XviD4PSP 5.0 Yahoo! Install Manager Yahoo! Widgets ==== Event Viewer Messages From Past Week ======== 2/9/2010 7:39:08 AM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer MOMLUVSDAD that believes that it is the master browser for the domain on transport NetBT_Tcpip_{5874CD5F-02BD-4F2. The master browser is stopping or an election is being forced. 2/9/2010 1:42:37 PM, information: Windows File Protection [64004] - The protected system file termsrv.dll could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x800b0100 [No signature was present in the subject. ]. 2/7/2010 4:45:01 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 2/7/2010 4:41:57 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 Fips intelppm SASDIFSV SASKUTIL truecrypt 2/7/2010 4:41:41 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 2/7/2010 10:18:22 PM, error: NetDDE [206] - Listen failed: 15: 2/7/2010 10:18:02 PM, error: NetDDE [206] - Listen failed: 23: The ncb_lana_num member did not specify a valid network number. 2/5/2010 7:02:51 AM, error: PSched [14103] - QoS [Adapter {5874CD5F-02BD-4F2C-8B14-55138A3A0C42}]: The netcard driver failed the query for OID_GEN_LINK_SPEED. 2/5/2010 11:57:12 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect. 2/5/2010 11:57:12 PM, error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error: After starting, the service hung in a start-pending state. 2/5/2010 11:57:12 PM, error: Service Control Manager [7001] - The Fast User Switching Compatibility service depends on the Terminal Services service which failed to start because of the following error: After starting, the service hung in a start-pending state. 2/5/2010 11:57:12 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 2/5/2010 11:50:40 PM, error: Service Control Manager [7000] - The npkcrypt service failed to start due to the following error: The system cannot find the path specified. 2/5/2010 1:24:33 PM, error: Service Control Manager [7034] - The Capture Device Service service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:24:32 PM, error: Service Control Manager [7034] - The Window Washer Engine service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:24:30 PM, error: Service Control Manager [7034] - The StarWind iSCSI Service service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:24:29 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:24:27 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:24:25 PM, error: Service Control Manager [7034] - The SoundMAX Agent Service service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:24:20 PM, error: Service Control Manager [7034] - The ArcSoft Connect Daemon service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:24:18 PM, error: Service Control Manager [7034] - The Network DDE service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:24:18 PM, error: Service Control Manager [7034] - The Network DDE DSDM service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:24:18 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:24:16 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective ACTION (Restart the service) after the unexpected termination of the Windows Media Player Network Sharing Service service, but this action failed with the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 2/5/2010 1:23:19 PM, error: Service Control Manager [7034] - The LogMeIn Hamachi 2.0 Tunneling Engine service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:23:19 PM, error: Service Control Manager [7034] - The B's Recorder GOLD Library General Service service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:23:18 PM, error: Service Control Manager [7034] - The WMDM PMSP Service service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:23:15 PM, error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 2/5/2010 1:23:12 PM, error: Service Control Manager [7034] - The AVG E-mail Scanner service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:23:11 PM, error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s). 2/5/2010 1:23:11 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 2/4/2010 11:03:49 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service. 2/4/2010 11:02:52 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 2/3/2010 5:49:46 AM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0023C32129DA. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. 2/3/2010 5:49:09 AM, error: Service Control Manager [7000] - The LogMeIn Hamachi 2.0 Tunneling Engine service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 2/3/2010 5:49:08 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the LogMeIn Hamachi 2.0 Tunneling Engine service to connect. 2/3/2010 1:34:15 PM, error: Srv [2011] - The server's configuration parameter "irpstacksize" is too small for the server to use a local device. Please increase the value of this parameter. ==== End Of File =========================== DDS (Ver_09-12-01.01) - NTFSx86 Run by Alex at 20:24:37.98 on Tue 02/09/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_03 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.66 [GMT -5:00] AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe C:\Program Files\Unlocker\UnlockerAssistant.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINDOWS\system32\ctfmon.exe svchost.exe C:\WINDOWS\system32\netdde.exe C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\AVG\AVG9\avgfws9.exe C:\Program Files\Webroot\Washer\wwDisp.exe C:\Program Files\Orbitdownloader\orbitdm.exe C:\WINDOWS\system32\bgsvcgen.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe C:\Program Files\Orbitdownloader\orbitnet.exe C:\Program Files\LogMeIn Hamachi\hamachi-2.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\AVG\AVG9\avgam.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Webroot\Washer\WasherSvc.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\Documents and Settings\Alex\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = file:///H:/dls/backup/lulz/Anon%20Party%20Hard/anon_partyhard30.swf uInternet Settings,ProxyOverride = 127.0.0.1;*.local uInternet Settings,ProxyServer = 83.133.119.38:8080 BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: CKeyScramblerBHO Object: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File TB: {338B4DFE-2E2C-4338-9E41-E176D497299E} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Window Washer] c:\program files\webroot\washer\wwDisp.exe uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent uRun: [cleansweep.exe] c:\cleansweep.exe\cleansweep.exe mRun: [DrvLsnr] "c:\program files\analog devices\soundmax\DrvLsnr.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe" mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\orbit.lnk - c:\program files\orbitdownloader\orbitdm.exe mPolicies-system: EnableLUA = 0 (0x0) IE: &Download All with FlashGet - c:\documents and settings\Alex\my documents\random junk\programs\flashget\jc_all.htm IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201 IE: &Download with FlashGet - c:\documents and settings\Alex\my documents\random junk\programs\flashget\jc_link.htm IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204 IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203 IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202 IE: Download FLV video content with IDM - c:\documents and settings\Alex\my documents\random junk\programs\internet download manager\IEGetVL.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} - hxxp://office.microsoft.com/productupdates/content/opuc.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37868.274537037 DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_4_0_01-win.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://3dlifeplayer.dl.3dvia.com/player/install/installer.exe Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\Alex\applic~1\mozilla\firefox\profiles\um5wf9ps.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\documents and settings\Alex\application data\mozilla\firefox\profiles\um5wf9ps.default\extensions\{81bf1d23-5f17-408d-ac6b-bd6df7caf670}\components\XpcomOpusConnector.dll FF - component: c:\documents and settings\Alex\application data\mozilla\firefox\profiles\um5wf9ps.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll FF - component: c:\documents and settings\Alex\application data\mozilla\firefox\profiles\um5wf9ps.default\extensions\[emailprotected]\components\KeyScramblerIE.dll FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2009-12-30 25608] R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-12-30 161800] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-12-30 333192] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-12-30 28424] R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-12-30 360584] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 74480] R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-12-30 906520] R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-12-30 285392] R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2009-12-30 2304192] R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2009-12-30 5832712] R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2009-10-29 1074568] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-12-3 236368] R2 StarWindService;StarWind iSCSI Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindService.exe [2005-4-1 217600] R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2009-12-30 30104] R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2009-12-30 122376] R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2009-12-30 30216] R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2009-12-30 25736] R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2007-8-9 113896] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-12-3 19160] R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2009-12-12 272128] R3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [2007-8-8 223128] S0 gxal;gxal;c:\windows\system32\drivers\naaajasa.sys --> c:\windows\system32\drivers\naaajasa.sys [?] S2 PowerManager;Power Manager;c:\windows\svchost.exe --> c:\windows\svchost.exe [?] S3 aic32p;aic32p;\??\c:\windows\system32\drivers\ipfmpo.sys --> c:\windows\system32\drivers\ipfmpo.sys [?] S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2009-12-30 30104] S3 dsreader;MaxDrive Driver (dsreader.sys);c:\windows\system32\drivers\dsreader.sys [2001-1-2 19677] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-1-25 42000] S3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;c:\windows\system32\drivers\usbscan.sys [2007-12-8 15104] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408] S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [2009-11-29 627072] S3 XDva281;XDva281;\??\c:\windows\system32\xdva281.sys --> c:\windows\system32\XDva281.sys [?] =============== Created Last 30 ================ 2010-02-09 19:20:170d-----w-c:\program files\Trend Micro 2010-02-05 18:21:230d-----w-c:\docume~1\Alex\applic~1\Subversion 2010-02-05 18:19:320d-----w-c:\program files\GUI Design Studio 2010-02-03 10:47:380d-----w-c:\program files\LogMeIn Hamachi 2010-01-29 21:12:580d-----w-C:\ProgramData 2010-01-29 21:12:580d-----w-c:\docume~1\alluse~1\applic~1\Electronic Arts 2010-01-29 21:08:44447752----a-r-c:\windows\system32\vp6vfw.dll 2010-01-29 21:08:400d-----w-c:\program files\Microsoft WSE 2010-01-28 04:50:2222297----a-w-c:\documents and settings\Alex\.recently-used.xbel 2010-01-27 01:03:390d-----w-c:\docume~1\alluse~1\applic~1\Kazaa 2010-01-27 00:27:380d-----w-c:\docume~1\Alex\applic~1\Kazaa Lite 2010-01-27 00:27:330d-----w-c:\program files\Kazaa Lite K++ 2010-01-26 23:56:470d-----w-C:\My Shared Folder 2010-01-26 23:56:460d-----w-c:\program files\Torrent Searcher 9.0 2010-01-26 07:27:29766----a-w-c:\windows\DSC.ico 2010-01-26 07:27:297431----a-w-c:\windows\Tw504b.src 2010-01-26 07:27:2965536----a-w-c:\windows\PCCam.exe 2010-01-26 07:27:29515803----a-w-c:\windows\system32\drivers\CA504bv.sys 2010-01-26 07:27:2919456----a-w-c:\windows\system32\Dext504b.ax 2010-01-26 07:27:2914381----a-w-c:\windows\Tw504b.ini 2010-01-26 07:27:29131072----a-w-c:\windows\system32\SP5X_32.DLL 2010-01-26 07:27:2910986----a-w-c:\windows\system32\drivers\Bulk504b.sys 2010-01-26 07:27:290d-----w-c:\windows\MEGA-DSC 2010-01-25 10:58:18479056----a-w-c:\windows\system32\GDIPFONTCACHEV1.DAT 2010-01-24 17:23:470d-----w-c:\program files\Pidgin 2010-01-24 17:23:030d-----w-c:\program files\common files\GTK 2010-01-24 07:39:240d-----w-c:\docume~1\Alex\applic~1\NetMedia Providers 2010-01-24 06:51:350d-----w-c:\program files\Vstplugins 2010-01-24 06:51:040d-----w-c:\program files\Sony 2010-01-24 06:44:500d-----w-c:\program files\Sony Setup 2010-01-14 06:34:290d-----w-c:\program files\Yahoo! 2010-01-12 22:40:560d-----w-c:\docume~1\Alex\applic~1\AVG9 2010-01-11 02:34:120d-----w-c:\docume~1\alluse~1\applic~1\Azureus 2010-01-11 02:33:440d-----w-c:\docume~1\Alex\applic~1\Azureus 2010-01-11 02:28:530d-----w-c:\program files\Vuze ==================== Find3M ==================== 2010-01-07 21:07:1438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 21:07:0419160----a-w-c:\windows\system32\drivers\mbam.sys 2009-12-30 20:51:3425608----a-w-c:\windows\system32\drivers\AVGIDSxx.sys 2009-12-30 20:51:3412464----a-w-c:\windows\system32\avgrsstx.dll 2009-12-30 20:51:33360584----a-w-c:\windows\system32\drivers\avgtdix.sys 2009-12-30 20:51:33161800----a-w-c:\windows\system32\drivers\avgrkx86.sys 2009-12-30 20:51:24333192----a-w-c:\windows\system32\drivers\avgldx86.sys 2009-12-30 20:49:1850968----a-w-c:\windows\system32\avgfwdx.dll 2009-12-30 20:49:1830104----a-w-c:\windows\system32\drivers\avgfwdx.sys 2009-12-30 09:22:29223440----a-w-c:\windows\system32\drivers\truecrypt.sys 2009-12-21 19:14:05916480----a-w-c:\windows\system32\wininet.dll 2009-12-20 06:06:3979416----a-w-c:\windows\fonts\Becker-Bold.ttf 2009-12-20 06:06:3955432----a-w-c:\windows\fonts\Becker_Bold.ttf 2009-12-13 17:02:5992594----a-w-c:\windows\fonts\CCWiccanSansInt-Regular.PFB 2009-12-13 17:01:5848972----a-w-c:\windows\fonts\CCAltogetherOoky-Capitals.ttf 2009-12-13 17:00:5860835----a-w-c:\windows\fonts\CCExterminate-AllOfThem.PFB 2009-12-13 16:59:5845876----a-w-c:\windows\fonts\CCCutthroatInt-Regular.ttf 2009-12-12 22:46:1221035----a-w-c:\windows\system32\drivers\AegisP.sys 2009-12-09 18:57:52306688----a-w-c:\windows\IsUninst.exe 2009-12-08 23:33:172554----a-w-c:\windows\system32\tmp.reg 2009-12-08 20:48:01380928----a-w-c:\windows\SynCor.exe 2009-12-08 20:48:01299520----a-w-c:\windows\uninst.exe 2009-12-05 17:02:3345816----a-w-c:\windows\fonts\euronymous-fo+st.ttf 2009-12-03 01:37:4046504----a-w-c:\windows\fonts\Formal_436_BT.ttf 2009-12-02 11:18:3655324----a-w-c:\windows\fonts\Cooper_Md_BT_Medium.ttf 2009-12-02 11:13:1176000----a-w-c:\windows\fonts\ANNA____.ttf 2009-11-30 01:08:17507392----a-w-c:\windows\system32\AutoPartNt.exe 2009-11-30 00:42:4837888----a-w-c:\windows\system32\setupnt.dll 2009-11-30 00:42:47126976----a-w-c:\windows\system32\snapapi.dll 2009-11-14 00:47:3290112----a-w-c:\windows\system32\dpl100.dll 2009-11-14 00:47:28856064----a-w-c:\windows\system32\divx_xx0c.dll 2009-11-14 00:47:28856064----a-w-c:\windows\system32\divx_xx07.dll 2009-11-14 00:47:28847872----a-w-c:\windows\system32\divx_xx0a.dll 2009-11-14 00:47:28843776----a-w-c:\windows\system32\divx_xx16.dll 2009-11-14 00:47:28839680----a-w-c:\windows\system32\divx_xx11.dll 2009-11-14 00:47:28696320----a-w-c:\windows\system32\DivX.dll 2006-05-03 09:06:54163328--sha-r-c:\windows\system32\flvDX.dll 2009-08-23 00:35:38952--sha-w-c:\windows\system32\KGyGaAvL.sys 2007-02-21 10:47:1631232--sh--r-c:\windows\system32\msfDX.dll 2008-03-16 12:30:52216064--sha-r-c:\windows\system32\nbDX.dll ============= FINISH: 20:27:47.01 =============== Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. First install the new Sun Java Runtime Environment Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close all browser windows before beginning the install. Remove the old version(s) Download JavaRa * Unzip the file and open the JavaRa.exe * Click Remove Older Versions * JavaRa will search for and remove any outdated version of Java and remove any that are found. * Click Additional Tasks * Place a check next to Remove Useless JRE Files and click Go * Exit JavaRa * Delete the JavaRa files from the desktop Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer. ---------- If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop DO NOT run it yet! Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Driver:: gxal aic32p DDS:: TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File TB: {338B4DFE-2E2C-4338-9E41-E176D497299E} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [cleansweep.exe] c:\cleansweep.exe\cleansweep.exe 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeComboFix 10-02-10.01 - Alex 02/10/2010 15:40:14.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.101 [GMT -5:00] Running from: c:\documents and settings\Alex\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Alex\Desktop\CFScript.txt AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\temp c:\program files\temp\Admin.exe c:\program files\temp\Message.ini c:\program files\temp\MSG.INI c:\program files\temp\MSG_CHS.INI c:\program files\temp\MSG_CHT.INI c:\program files\temp\MSG_KOR.INI C:\Thumbs.db c:\windows\patchw.dll c:\windows\system32\404Fix.exe c:\windows\system32\Agent.OMZ.Fix.exe c:\windows\system32\dumphive.exe c:\windows\system32\IEDFix.C.exe c:\windows\system32\IEDFix.exe c:\windows\system32\o4Patch.exe c:\windows\system32\Process.exe c:\windows\system32\SrchSTS.exe c:\windows\system32\tmp.reg c:\windows\system32\VACFix.exe c:\windows\system32\VCCLSID.exe c:\windows\system32\vm.exe c:\windows\system32\WS2Fix.exe Infected copy of c:\windows\system32\Drivers\atapi.sys was found and disinfected Restored copy from - c:\windows\ServicePackFiles\i386\atapi.sys Infected copy of c:\windows\system32\mmc.exe was found and disinfected Restored copy from - c:\windows\system32\dllcache\mmc.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_AIC32P -------\Legacy_POWERMANAGER -------\Service_aic32p -------\Service_gxal -------\Service_PowerManager ((((((((((((((((((((((((( Files Created from 2010-01-10 to 2010-02-10 ))))))))))))))))))))))))))))))) . 2010-02-10 20:13 . 2010-02-10 20:13411368----a-w-c:\windows\system32\deploytk.dll 2010-02-09 19:20 . 2010-02-09 19:20--------d-----w-c:\program files\Trend Micro 2010-02-09 18:50 . 2010-02-10 17:32--------d-----w-c:\documents and settings\Administrator\Application Data\Orbit 2010-02-07 21:47 . 2010-02-07 21:47--------d-----w-c:\documents and settings\Administrator\Application Data\Malwarebytes 2010-02-07 21:41 . 2010-02-07 21:41--------d-sh--w-c:\documents and settings\Administrator\IETldCache 2010-02-06 05:08 . 2010-02-06 05:08--------d-----w-c:\program files\Common Files\Adobe AIR 2010-02-05 18:21 . 2010-02-05 18:21--------d-----w-c:\documents and settings\Alex\Application Data\Subversion 2010-02-05 18:19 . 2010-02-05 18:20--------d-----w-c:\program files\GUI Design Studio 2010-02-03 10:49 . 2010-02-09 22:11--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\LogMeIn Hamachi 2010-02-03 10:49 . 2010-02-10 21:00--------d-----w-c:\documents and settings\NetworkService\Local Settings\Application Data\LogMeIn Hamachi 2010-02-03 10:47 . 2010-02-03 10:47--------d-----w-c:\program files\LogMeIn Hamachi 2010-01-29 21:12 . 2010-02-06 05:10--------d-----w-c:\documents and settings\All Users\Application Data\Electronic Arts 2010-01-29 21:12 . 2010-01-29 21:12--------d-----w-C:\ProgramData 2010-01-29 21:08 . 2008-09-04 20:11447752----a-r-c:\windows\system32\vp6vfw.dll 2010-01-29 21:08 . 2010-01-29 21:08--------d-----w-c:\program files\Microsoft WSE 2010-01-29 20:49 . 2010-01-29 21:09--------d-----w-c:\program files\Electronic Arts 2010-01-27 01:03 . 2010-01-27 01:03--------d-----w-c:\documents and settings\All Users\Application Data\Kazaa 2010-01-27 00:27 . 2010-01-27 00:27--------d-----w-c:\documents and settings\Alex\Application Data\Kazaa Lite 2010-01-27 00:27 . 2010-01-27 00:27--------d-----w-c:\program files\Kazaa Lite K++ 2010-01-26 23:56 . 2010-01-26 23:56--------d-----w-C:\My Shared Folder 2010-01-26 23:56 . 2010-01-26 23:59--------d-----w-c:\program files\Torrent Searcher 9.0 2010-01-26 07:27 . 2010-01-26 07:27--------d-----w-c:\windows\MEGA-DSC 2010-01-26 07:27 . 2002-10-21 16:37515803----a-w-c:\windows\system32\drivers\CA504bv.sys 2010-01-26 07:27 . 2002-09-27 15:3465536----a-w-c:\windows\PCCam.exe 2010-01-26 07:27 . 2002-07-25 16:1910986----a-w-c:\windows\system32\drivers\Bulk504b.sys 2010-01-26 07:27 . 2002-01-19 20:33131072----a-w-c:\windows\system32\SP5X_32.DLL 2010-01-25 10:58 . 2010-01-29 21:11479056----a-w-c:\windows\system32\GDIPFONTCACHEV1.DAT 2010-01-24 17:23 . 2010-02-07 23:32--------d-----w-c:\program files\Pidgin 2010-01-24 17:23 . 2010-01-24 17:23--------d-----w-c:\program files\Common Files\GTK 2010-01-24 07:39 . 2010-01-24 07:39--------d-----w-c:\documents and settings\Alex\Application Data\NetMedia Providers 2010-01-24 07:39 . 2010-01-24 07:39--------d-----w-c:\documents and settings\Alex\Application Data\Publish Providers 2010-01-24 07:38 . 2010-01-24 07:38--------d-----w-c:\documents and settings\Alex\Application Data\Sony 2010-01-24 07:34 . 2010-01-24 07:40--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\Sony 2010-01-24 06:51 . 2010-01-24 06:51--------d-----w-c:\program files\Vstplugins 2010-01-24 06:51 . 2010-01-24 06:51--------d-----w-c:\program files\Sony 2010-01-24 06:44 . 2010-01-24 06:44--------d-----w-c:\program files\Sony Setup 2010-01-14 06:34 . 2010-01-14 06:34--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\Yahoo 2010-01-14 06:34 . 2010-01-14 06:35--------d-----w-c:\program files\Yahoo! 2010-01-12 22:40 . 2010-01-12 22:40--------d-----w-c:\documents and settings\Alex\Application Data\AVG9 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-10 21:03 . 2007-04-29 04:21--------d-----w-c:\documents and settings\Alex\Application Data\Orbit 2010-02-10 20:15 . 2008-01-04 21:35--------d-----w-c:\program files\Common Files\Java 2010-02-10 20:12 . 2003-03-11 14:13--------d-----w-c:\program files\Java 2010-02-10 17:19 . 2009-12-02 00:39--------d-----w-c:\documents and settings\Alex\Application Data\vlc 2010-02-10 16:43 . 2007-11-03 03:03--------d-----w-c:\documents and settings\Alex\Application Data\.purple 2010-02-06 19:29 . 2009-07-17 02:50--------d-----w-c:\documents and settings\Alex\Application Data\dvdcss 2010-02-03 09:30 . 2009-07-20 13:11--------d-----w-c:\documents and settings\All Users\Application Data\DVD Shrink 2010-02-03 09:29 . 2009-07-20 13:11--------d-----w-c:\program files\DVD Shrink 2010-02-03 09:23 . 2007-08-11 15:44--------d-----w-c:\documents and settings\Alex\Application Data\DVD Flick 2010-01-29 20:49 . 2003-03-10 15:01--------d--h--w-c:\program files\InstallShield Installation Information 2010-01-28 03:08 . 2007-11-04 03:13--------d-----w-c:\documents and settings\Alex\Application Data\gtk-2.0 2010-01-25 10:58 . 2007-03-26 02:508224-c--a-w-c:\documents and settings\Alex\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-01-25 10:50 . 2010-01-11 02:33--------d-----w-c:\documents and settings\Alex\Application Data\Azureus 2010-01-23 03:38 . 2009-08-11 01:10--------d-----w-c:\documents and settings\Alex\Application Data\Audacity 2010-01-20 08:21 . 2009-12-15 05:53--------d-----w-c:\documents and settings\Alex\Application Data\BitTyrant 2010-01-12 10:01 . 2009-12-04 02:44--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2010-01-11 02:34 . 2010-01-11 02:34--------d-----w-c:\documents and settings\All Users\Application Data\Azureus 2010-01-11 02:30 . 2010-01-11 02:28--------d-----w-c:\program files\Vuze 2010-01-09 17:06 . 2010-01-09 17:06--------d-----w-c:\program files\VMware 2010-01-07 21:07 . 2009-12-04 02:4438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 21:07 . 2009-12-04 02:4419160----a-w-c:\windows\system32\drivers\mbam.sys 2010-01-03 06:13 . 2010-01-03 06:13--------d-----w-c:\documents and settings\Alex\Application Data\Participatory Culture Foundation 2010-01-03 06:11 . 2010-01-03 06:11--------d-----w-c:\program files\Combined Community Codec Pack 2010-01-03 06:11 . 2010-01-03 06:11--------d-----w-c:\program files\Participatory Culture Foundation 2010-01-03 06:03 . 2009-12-28 04:10--------d-----w-c:\program files\Aegisub 2010-01-03 02:28 . 2010-01-03 02:25--------d-----w-c:\program files\Common Files\ArcSoft 2010-01-03 02:28 . 2010-01-03 02:24--------d-----w-c:\program files\ArcSoft 2010-01-03 02:27 . 2010-01-03 02:26--------d-----w-c:\documents and settings\Alex\Application Data\ArcSoft 2010-01-03 02:27 . 2010-01-03 02:26--------d-----w-c:\documents and settings\All Users\Application Data\ArcSoft 2010-01-02 06:56 . 2009-08-21 20:18--------d-----w-c:\documents and settings\NetworkService\Application Data\gtk-2.0 2010-01-02 03:14 . 2010-01-02 03:14--------d-----w-c:\documents and settings\NetworkService\Application Data\Orbit 2010-01-01 20:34 . 2010-01-01 20:33--------d-----w-c:\program files\P2PChan 2010-01-01 18:34 . 2009-08-10 07:30--------d-----w-c:\program files\Unlocker 2009-12-31 16:50 . 2001-08-23 12:00353792----a-w-c:\windows\system32\drivers\srv.sys 2009-12-31 05:07 . 2008-05-25 15:50--------d-----w-c:\program files\MediaCoder 2009-12-30 21:53 . 2009-12-30 20:17--------d-----w-c:\program files\SUPERAntiSpyware 2009-12-30 20:51 . 2009-12-30 20:5125608----a-w-c:\windows\system32\drivers\AVGIDSxx.sys 2009-12-30 20:51 . 2009-12-30 20:5112464----a-w-c:\windows\system32\avgrsstx.dll 2009-12-30 20:51 . 2009-12-30 20:51360584----a-w-c:\windows\system32\drivers\avgtdix.sys 2009-12-30 20:51 . 2009-12-30 20:51161800----a-w-c:\windows\system32\drivers\avgrkx86.sys 2009-12-30 20:51 . 2009-12-30 20:51333192----a-w-c:\windows\system32\drivers\avgldx86.sys 2009-12-30 20:51 . 2009-12-30 20:5128424----a-w-c:\windows\system32\drivers\avgmfx86.sys 2009-12-30 20:49 . 2009-12-30 20:4950968----a-w-c:\windows\system32\avgfwdx.dll 2009-12-30 20:49 . 2009-12-30 20:4930104----a-w-c:\windows\system32\drivers\avgfwdx.sys 2009-12-30 20:49 . 2009-12-30 20:49--------d-----w-c:\program files\AVG 2009-12-30 20:49 . 2009-12-30 20:49--------d-----w-c:\documents and settings\All Users\Application Data\avg9 2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\documents and settings\Alex\Application Data\SUPERAntiSpyware.com 2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-12-30 19:56 . 2009-11-07 21:11--------d-----w-c:\program files\CCleaner 2009-12-30 19:30 . 2009-11-08 03:46--------d-----w-c:\documents and settings\Alex\Application Data\TrueCrypt 2009-12-30 09:22 . 2009-12-30 09:22--------d-----w-c:\documents and settings\All Users\Application Data\TrueCrypt 2009-12-30 09:22 . 2009-11-07 20:51223440----a-w-c:\windows\system32\drivers\truecrypt.sys 2009-12-30 01:46 . 2007-07-18 20:31--------d-----w-c:\documents and settings\Alex\Application Data\DMCache 2009-12-29 16:41 . 2009-08-25 02:42--------d-----w-c:\documents and settings\Alex\Application Data\WinFF 2009-12-29 14:19 . 2009-12-13 06:29--------d-----w-c:\program files\Xvid 2009-12-29 05:05 . 2009-12-29 05:05--------d-----w-c:\program files\eRightSoft 2009-12-28 07:47 . 2007-08-10 20:32--------d-----w-c:\program files\DVD Flick 2009-12-28 07:36 . 2009-07-20 11:44--------d-----w-c:\program files\Common Files\Webroot Shared 2009-12-28 04:10 . 2009-12-28 04:10--------d-----w-c:\documents and settings\Alex\Application Data\Aegisub 2009-12-28 03:59 . 2007-06-23 18:03--------d-----w-c:\documents and settings\Alex\Application Data\uTorrent 2009-12-27 06:48 . 2009-12-14 11:461620552----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-12-27 05:21 . 2009-12-27 05:21--------d-----w-c:\documents and settings\All Users\Application Data\Speed Soft 2009-12-26 03:13 . 2009-12-26 03:13--------d-----w-c:\documents and settings\Alex\Application Data\JAM Software 2009-12-23 05:59 . 2009-12-23 05:58--------d-----w-c:\program files\VirtualDubMOD 2009-12-22 16:48 . 2009-12-15 22:28--------d-----w-c:\program files\MP3Gain 2009-12-21 19:14 . 2003-03-10 21:03916480----a-w-c:\windows\system32\wininet.dll 2009-12-21 14:20 . 2009-12-21 14:20--------d-----w-c:\documents and settings\Alex\Application Data\Obsidium 2009-12-21 11:31 . 2009-12-21 11:31--------d-----w-c:\program files\FDRLab 2009-12-18 07:01 . 2009-12-18 07:01--------d-----w-c:\program files\Outspark 2009-12-17 05:22 . 2007-04-04 01:57--------d-----w-c:\program files\DivX 2009-12-17 05:22 . 2009-12-17 05:21--------d-----w-c:\program files\Common Files\DivX Shared 2009-12-16 18:43 . 2003-03-10 21:00343040----a-w-c:\windows\system32\mspaint.exe 2009-12-16 02:55 . 2009-12-15 05:53--------d-----w-c:\program files\BitTyrant 2009-12-16 00:03 . 2009-12-16 00:03--------d-----w-c:\program files\JAM Software 2009-12-14 07:08 . 2001-08-23 12:0033280----a-w-c:\windows\system32\csrsrv.dll 2009-12-13 22:44 . 2009-12-13 22:33--------d-----w-c:\program files\Winnydows 2009-12-13 06:41 . 2009-12-13 06:40--------d-----w-c:\program files\StaxRip 2009-12-13 06:28 . 2009-07-19 00:09--------d-----w-c:\program files\AviSynth 2.5 2009-12-13 04:56 . 2009-12-13 04:56--------d-----w-c:\documents and settings\All Users\Application Data\Soulseek 2009-12-13 04:55 . 2009-12-03 02:31--------d-----w-c:\documents and settings\Alex\Application Data\DC++ 2009-12-12 22:46 . 2009-12-12 22:4621035----a-w-c:\windows\system32\drivers\AegisP.sys 2009-12-12 22:46 . 2009-12-12 22:46--------d-----w-c:\program files\NETGEAR 2009-12-09 18:57 . 2009-12-09 18:57306688----a-w-c:\windows\IsUninst.exe 2009-12-08 20:48 . 2009-12-08 20:48299520----a-w-c:\windows\uninst.exe 2009-12-08 20:48 . 2009-12-08 20:48380928----a-w-c:\windows\SynCor.exe 2009-12-08 19:27 . 2001-08-23 12:002189184----a-w-c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43 . 2001-08-17 13:482066048----a-w-c:\windows\system32\ntkrnlpa.exe 2009-12-04 18:22 . 2001-08-23 12:00455424----a-w-c:\windows\system32\drivers\mrxsmb.sys 2009-11-30 01:08 . 2009-11-30 01:08507392----a-w-c:\windows\system32\AutoPartNt.exe 2009-11-30 00:42 . 2009-11-30 00:4237888----a-w-c:\windows\system32\setupnt.dll 2009-11-30 00:42 . 2009-11-30 00:4282464----a-w-c:\windows\system32\drivers\snapman.sys 2009-11-30 00:42 . 2009-11-30 00:42126976----a-w-c:\windows\system32\snapapi.dll 2009-11-27 17:11 . 2003-12-28 19:1717920----a-w-c:\windows\system32\msyuv.dll 2009-11-27 17:11 . 2003-12-28 19:171291776----a-w-c:\windows\system32\quartz.dll 2009-11-27 16:07 . 2001-08-23 12:0028672----a-w-c:\windows\system32\msvidc32.dll 2009-11-27 16:07 . 2001-08-17 22:368704----a-w-c:\windows\system32\tsbyuv.dll 2009-11-27 16:07 . 2003-03-10 21:0011264----a-w-c:\windows\system32\msrle32.dll 2009-11-27 16:07 . 2003-03-10 20:5684992----a-w-c:\windows\system32\avifil32.dll 2009-11-27 16:07 . 2001-08-17 22:3648128----a-w-c:\windows\system32\iyuv_32.dll 2006-05-03 09:06 . 2009-07-20 18:12163328--sha-r-c:\windows\system32\flvDX.dll 2009-08-23 00:35 . 2009-07-18 01:03952--sha-w-c:\windows\system32\KGyGaAvL.sys 2007-02-21 10:47 . 2009-12-29 05:0631232--sh--r-c:\windows\system32\msfDX.dll 2008-03-16 12:30 . 2009-12-28 05:58216064--sha-r-c:\windows\system32\nbDX.dll . ------- Sigcheck ------- [-] 2008-05-18 . 56F4867BAE6FD78E5365A3A7AFA59C82 . 295424 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll [-] 2008-05-18 . 56F4867BAE6FD78E5365A3A7AFA59C82 . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll [7] 2004-08-04 . B60C877D16D9C880B952FDA04ADF16E6 . 295424 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2009-12-28 1201152] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DrvLsnr"="c:\program files\Analog Devices\SoundMAX\DrvLsnr.exe" [2002-04-20 69632] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-09-30 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-09-30 126976] "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2009-10-26 15872] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-01-07 429392] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2007-8-9 1667072] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-12-30 20:32548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-12-30 20:5112464----a-w-c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2009-12-08 20:44136192----a-w-c:\program files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Orbitdownloader\\orbitdm.exe"= "c:\\Program Files\\Orbitdownloader\\orbitnet.exe"= "c:\\Program Files\\Pidgin\\pidgin.exe"= "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"= "c:\\Program Files\\WinPcap\\rpcapd.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "h:\\dls\\romz\\emuz\\VisualBoyAdvance\\VisualBoyAdvance.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Ares\\Ares.exe"= "c:\\Program Files\\DC++\\DCPlusPlus.exe"= "c:\\Program Files\\Ares\\chatServer.exe"= "c:\\Program Files\\Soulseek\\slsk.exe"= "c:\\Program Files\\BitTyrant\\Azureus.exe"= "c:\\Program Files\\Webroot\\Washer\\wwDisp.exe"= "c:\\WINDOWS\\system32\\igfxtray.exe"= "c:\\Program Files\\Analog Devices\\SoundMAX\\DrvLsnr.exe"= "c:\\Program Files\\Malwarebytes' Anti-Malware\\mbamgui.exe"= "c:\\Program Files\\eRightSoft\\SUPER\\SUPER.exe"= "c:\\WINDOWS\\system32\\taskmgr.exe"= "c:\\Program Files\\Unlocker\\UnlockerAssistant.exe"= "c:\\Program Files\\Mozilla Firefox\\crashreporter.exe"= "c:\\Program Files\\iPod\\bin\\iPodService.exe"= "c:\\Program Files\\AVG\\AVG9\\avgam.exe"= "c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"= "c:\\Program Files\\AVG\\AVG9\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 "9420:TCP"= 9420:TCP:Red Swoosh "5000:UDP"= 5000:UDP:Red Swoosh R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [12/30/2009 3:51 PM 25608] R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [12/30/2009 3:51 PM 161800] R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/4/2007 12:29 PM 685816] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/30/2009 3:51 PM 333192] R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/30/2009 3:51 PM 360584] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 74480] R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [12/30/2009 3:50 PM 906520] R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12/30/2009 3:50 PM 285392] R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [12/30/2009 3:50 PM 2304192] R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [12/30/2009 3:50 PM 5832712] R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [10/29/2009 12:27 PM 1074568] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/3/2009 9:44 PM 236368] R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [7/20/2009 6:44 AM 598856] R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [12/30/2009 3:49 PM 30104] R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [12/30/2009 3:50 PM 122376] R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [12/30/2009 3:50 PM 30216] R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [12/30/2009 3:50 PM 25736] R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [8/9/2007 4:43 PM 113896] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/3/2009 9:44 PM 19160] R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [12/12/2009 5:46 PM 272128] R3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [8/8/2007 6:35 AM 223128] S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [12/30/2009 3:49 PM 30104] S3 dsreader;MaxDrive Driver (dsreader.sys);c:\windows\system32\drivers\dsreader.sys [1/2/2001 11:53 PM 19677] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [1/25/2007 12:31 PM 42000] S3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;c:\windows\system32\drivers\usbscan.sys [12/8/2007 12:20 PM 15104] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408] S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [11/29/2009 10:41 AM 627072] S3 XDva281;XDva281;\??\c:\windows\system32\XDva281.sys --> c:\windows\system32\XDva281.sys [?] . Contents of the 'Scheduled Tasks' folder 2010-02-08 c:\windows\Tasks\Malwarebytes' Scheduled Update for Alex.job - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-12-09 21:07] . . ------- Supplementary Scan ------- . uStart Page = file:///H:/dls/backup/lulz/Anon%20Party%20Hard/anon_partyhard30.swf uInternet Settings,ProxyOverride = 127.0.0.1;*.local uInternet Settings,ProxyServer = 83.133.119.38:8080 IE: &Download All with FlashGet - c:\documents and settings\Alex\My Documents\Random Junk\Programs\FlashGet\jc_all.htm IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201 IE: &Download with FlashGet - c:\documents and settings\Alex\My Documents\Random Junk\Programs\FlashGet\jc_link.htm IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204 IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203 IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202 IE: Download FLV video content with IDM - c:\documents and settings\Alex\My Documents\Random Junk\Programs\Internet Download Manager\IEGetVL.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\[emailprotected]\components\KeyScramblerIE.dll FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - ORPHANS REMOVED - - - - HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe AddRemove-HP Standard Port Monitor - c:\program files\Hewlett-Packard\HP Standard Port Monitor\Uninst.isu AddRemove-RTP - c:\program files\ASCII\RPG Maker 2003\RTP2\uninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-10 16:00 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sptd.sys >>UNKNOWN [0x8338C8AC]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0xf886af28 \Driver\ACPI -> ACPI.sys @ 0xf86dbcb8 \Driver\atapi -> atapi.sys @ 0xf8670b40 IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598 ParseProcedure -> ntoskrnl.exe @ 0x8056ea15 \Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598 ParseProcedure -> ntoskrnl.exe @ 0x8056ea15 NDIS: -> SendCompleteHandler -> 0x0 PacketIndicateHandler -> 0x0 SendHandler -> 0x0 user & kernel MBR OK ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*] "AB141C35E9F4BF344B9FC010BB17F68A"="" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1252) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(3796) c:\windows\system32\WININET.dll c:\program files\Unlocker\UnlockerHook.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\program files\SUPERAntiSpyware\SASSEH.DLL c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\windows\system32\netdde.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\windows\system32\bgsvcgen.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe c:\program files\AVG\AVG9\avgnsx.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\program files\Analog Devices\SoundMAX\SMAgent.exe c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe c:\windows\System32\MsPMSPSv.exe c:\program files\Windows Media Player\WMPNetwk.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\Orbitdownloader\orbitnet.exe . ************************************************************************** . COMPLETION time: 2010-02-10 16:19:53 - machine was rebooted ComboFix-quarantined-files.txt 2010-02-10 21:19 Pre-Run: 131,014,467,584 BYTES free Post-Run: 131,102,572,544 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4 - - End Of File - - 8E4CA6C6ECEEAF982CBAD80F99CEB77C control.exe still wont open properlySuspicious file scan Please go to Jotti's malware scan (If more than one file needs scanned they must be done separately and logs posted for each one) * Copy the file path in the below Code box: Code: [Select]c:\windows\system32\termsrv.dll* At the upload site, click once inside the window next to Browse. * Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window. * Next click Submit file * Your file will possibly be entered into a queue which normally takes less than a minute to clear. * This will perform a scan across multiple different virus scanning engines. * Important: Wait for all of the scanning engines to complete. * Once the scan is finished, Copy and then Paste the link in the address bar into your next reply. ---------- Download Rooter.exe to your desktop. * Double click Rooter.exe to start the tool. * A DOS window will appear and show the scan progress. * Once complete a notepad file containing the report will open. * Copy & paste the results in your next reply. * Close notepad and Rooter will close. A log will also save at C:\Rooter.txt ---------- Please download SystemLook from one of the below links and save it to your desktop. Link #1 Link #2 Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. * Double-click SystemLook.exe to run it. * Copy the contents of the following codebox into the main textfield. Code: [Select]:filefind control.exe * Click the Look button to start the scan. * Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer). * When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txthttp://virusscan.jotti.org/en/scanresult/0663266c49f1f2e26f95a158057ef980252cb626/de634f82628724248ed5d969856b86d2ba830f65 Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully ... . Windows XP . (5.1.2600) Service Pack 3 [32_bits] - x86 Family 15 Model 2 Stepping 7, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [SharedAccess] RUNNING (state:4) Windows Firewall -> Disabled ! . Internet Explorer 8.0.6001.18702 Mozilla Firefox 3.5.7 (en-US) . C:\ [Fixed-NTFS] .. ( Total:232 Go - Free:122 Go ) E:\ [CD_Rom] G:\ [CD_Rom] H:\ [Fixed-NTFS] .. ( Total:931 Go - Free:672 Go ) . Scan : 17:30.12 Path : C:\Documents and Settings\Alex\Desktop\Rooter.exe User : Alex ( Administrator -> YES ) . ----------------------\\ Processes . Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (828) ______ \??\C:\WINDOWS\system32\csrss.exe (1228) ______ \??\C:\WINDOWS\system32\winlogon.exe (1252) ______ C:\WINDOWS\system32\services.exe (1296) ______ C:\WINDOWS\system32\lsass.exe (1308) ______ C:\WINDOWS\system32\svchost.exe (1480) ______ C:\WINDOWS\system32\svchost.exe (1548) ______ C:\WINDOWS\System32\svchost.exe (288) ______ C:\WINDOWS\System32\svchost.exe (368) ______ C:\Program Files\AVG\AVG9\avgchsvx.exe (456) ______ C:\Program Files\AVG\AVG9\avgrsx.exe (464) ______ C:\WINDOWS\system32\svchost.exe (544) ______ C:\Program Files\AVG\AVG9\avgcsrvx.exe (764) ______ C:\WINDOWS\system32\spoolsv.exe (1604) Locked AVGIDSAgent.exe (1644) ______ C:\WINDOWS\System32\svchost.exe (1820) ______ C:\WINDOWS\system32\netdde.exe (1860) ______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (796) Locked avgwdsvc.exe (856) Locked avgfws9.exe (668) ______ C:\WINDOWS\system32\bgsvcgen.exe (1040) ______ C:\Program Files\Bonjour\mDNSResponder.exe (1076) ______ C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe (1156) ______ C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (1652) Locked avgam.exe (1132) ______ C:\WINDOWS\System32\svchost.exe (1880) ______ C:\Program Files\Java\jre6\bin\jqs.exe (2036) ______ C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (2252) ______ C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (2968) ______ C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (3364) ______ C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (3804) ______ C:\WINDOWS\System32\svchost.exe (2296) ______ C:\WINDOWS\System32\MsPMSPSv.exe (2348) ______ C:\Program Files\Webroot\Washer\WasherSvc.exe (2392) ______ C:\Program Files\Windows Media Player\WMPNetwk.exe (2988) ______ C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (3420) ______ C:\WINDOWS\system32\hkcmd.exe (2628) ______ C:\Program Files\Unlocker\UnlockerAssistant.exe (2424) ______ C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (4028) ______ C:\Program Files\Common Files\Java\Java Update\jusched.exe (2268) ______ C:\Program Files\Webroot\Washer\wwDisp.exe (3260) ______ C:\Program Files\Orbitdownloader\orbitdm.exe (2896) ______ C:\Program Files\Orbitdownloader\orbitnet.exe (1680) ______ C:\WINDOWS\explorer.exe (3796) ______ C:\Program Files\Mozilla Firefox\firefox.exe (2548) ______ C:\Program Files\AVG\AVG9\avgemc.exe (2064) ______ C:\Program Files\AVG\AVG9\avgcsrvx.exe (2996) ______ C:\Program Files\AVG\AVG9\avgnsx.exe (2508) ______ C:\Program Files\AVG\AVG9\avgcsrvx.exe (1408) ______ C:\WINDOWS\system32\notepad.exe (3772) ______ C:\Documents and Settings\Alex\Desktop\Rooter.exe (2524) . ----------------------\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:250056221184) . ----------------------\\ Scheduled Tasks . C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\Malwarebytes' Scheduled Update for Alex.job C:\WINDOWS\Tasks\SA.DAT . ----------------------\\ Registry . . ----------------------\\ Files & Folders . . ----------------------\\ Scan completed at 17:32.05 . C:\Rooter$\Rooter_1.txt - (10/02/2010 | 17:32.05).c SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 17:34 on 10/02/2010 by Alex (Administrator - Elevation successful) ========== filefind ========== Searching for "control.exe" C:\WINDOWS\system32\control.exe--a--- 77824 bytes[12:00 23/08/2001][12:00 23/08/2001] 1B2DE306FEC245B54340ADEF6AF3A460 C:\WINDOWS\system32\dllcache\control.exe--a--c 8192 bytes[12:00 23/08/2001][12:00 23/08/2001] 4C6785E3D2E45EE87CB995190A0C7737 -=End Of File=-Scan this file at Jotti and post the link to the results. C:\WINDOWS\system32\control.exehttp://virusscan.jotti.org/en/scanresult/d8b344f1308fb523d6e57e18e8116d5db04805a5 Most of the scanners seem to think I have sality or some variant of it (which is strange, considering I got rid of Sality.AA about 4 months ago)You didn't get rid of all of it. Sality is very hard to cure and often takes a complete reformat and reinstall to get rid of it. Let's see if this will work. 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: SkipFix:: FCopy:: C:\WINDOWS\system32\dllcache\control.exe | C:\WINDOWS\system32\control.exe 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeComboFix 10-02-10.01 - Alex 02/10/2010 18:20:38.2.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.127 [GMT -5:00] Running from: c:\documents and settings\Alex\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Alex\Desktop\CFScript.txt AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66} . - REDUCED FUNCTIONALITY MODE - . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . --------------- FCopy --------------- c:\windows\system32\dllcache\control.exe --> c:\windows\system32\control.exe . ((((((((((((((((((((((((( Files Created from 2010-01-10 to 2010-02-10 ))))))))))))))))))))))))))))))) . 2010-02-10 22:30 . 2010-02-10 22:32--------d-----w-C:\Rooter$ 2010-02-10 20:13 . 2010-02-10 20:13411368----a-w-c:\windows\system32\deploytk.dll 2010-02-09 19:20 . 2010-02-09 19:20--------d-----w-c:\program files\Trend Micro 2010-02-09 18:50 . 2010-02-10 17:32--------d-----w-c:\documents and settings\Administrator\Application Data\Orbit 2010-02-07 21:47 . 2010-02-07 21:47--------d-----w-c:\documents and settings\Administrator\Application Data\Malwarebytes 2010-02-07 21:41 . 2010-02-07 21:41--------d-sh--w-c:\documents and settings\Administrator\IETldCache 2010-02-06 05:08 . 2010-02-06 05:08--------d-----w-c:\program files\Common Files\Adobe AIR 2010-02-05 18:21 . 2010-02-05 18:21--------d-----w-c:\documents and settings\Alex\Application Data\Subversion 2010-02-05 18:19 . 2010-02-05 18:20--------d-----w-c:\program files\GUI Design Studio 2010-02-03 10:49 . 2010-02-09 22:11--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\LogMeIn Hamachi 2010-02-03 10:49 . 2010-02-10 23:26--------d-----w-c:\documents and settings\NetworkService\Local Settings\Application Data\LogMeIn Hamachi 2010-02-03 10:47 . 2010-02-03 10:47--------d-----w-c:\program files\LogMeIn Hamachi 2010-01-29 21:12 . 2010-02-06 05:10--------d-----w-c:\documents and settings\All Users\Application Data\Electronic Arts 2010-01-29 21:12 . 2010-01-29 21:12--------d-----w-C:\ProgramData 2010-01-29 21:08 . 2008-09-04 20:11447752----a-r-c:\windows\system32\vp6vfw.dll 2010-01-29 21:08 . 2010-01-29 21:08--------d-----w-c:\program files\Microsoft WSE 2010-01-29 20:49 . 2010-01-29 21:09--------d-----w-c:\program files\Electronic Arts 2010-01-27 01:03 . 2010-01-27 01:03--------d-----w-c:\documents and settings\All Users\Application Data\Kazaa 2010-01-27 00:27 . 2010-01-27 00:27--------d-----w-c:\documents and settings\Alex\Application Data\Kazaa Lite 2010-01-27 00:27 . 2010-01-27 00:27--------d-----w-c:\program files\Kazaa Lite K++ 2010-01-26 23:56 . 2010-01-26 23:56--------d-----w-C:\My Shared Folder 2010-01-26 23:56 . 2010-01-26 23:59--------d-----w-c:\program files\Torrent Searcher 9.0 2010-01-26 07:27 . 2010-01-26 07:27--------d-----w-c:\windows\MEGA-DSC 2010-01-26 07:27 . 2002-10-21 16:37515803----a-w-c:\windows\system32\drivers\CA504bv.sys 2010-01-26 07:27 . 2002-09-27 15:3465536----a-w-c:\windows\PCCam.exe 2010-01-26 07:27 . 2002-07-25 16:1910986----a-w-c:\windows\system32\drivers\Bulk504b.sys 2010-01-26 07:27 . 2002-01-19 20:33131072----a-w-c:\windows\system32\SP5X_32.DLL 2010-01-25 10:58 . 2010-01-29 21:11479056----a-w-c:\windows\system32\GDIPFONTCACHEV1.DAT 2010-01-24 17:23 . 2010-02-07 23:32--------d-----w-c:\program files\Pidgin 2010-01-24 17:23 . 2010-01-24 17:23--------d-----w-c:\program files\Common Files\GTK 2010-01-24 07:39 . 2010-01-24 07:39--------d-----w-c:\documents and settings\Alex\Application Data\NetMedia Providers 2010-01-24 07:39 . 2010-01-24 07:39--------d-----w-c:\documents and settings\Alex\Application Data\Publish Providers 2010-01-24 07:38 . 2010-01-24 07:38--------d-----w-c:\documents and settings\Alex\Application Data\Sony 2010-01-24 07:34 . 2010-01-24 07:40--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\Sony 2010-01-24 06:51 . 2010-01-24 06:51--------d-----w-c:\program files\Vstplugins 2010-01-24 06:51 . 2010-01-24 06:51--------d-----w-c:\program files\Sony 2010-01-24 06:44 . 2010-01-24 06:44--------d-----w-c:\program files\Sony Setup 2010-01-14 06:34 . 2010-01-14 06:34--------d-----w-c:\documents and settings\Alex\Local Settings\Application Data\Yahoo 2010-01-14 06:34 . 2010-01-14 06:35--------d-----w-c:\program files\Yahoo! 2010-01-12 22:40 . 2010-01-12 22:40--------d-----w-c:\documents and settings\Alex\Application Data\AVG9 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-10 23:25 . 2007-04-29 04:21--------d-----w-c:\documents and settings\Alex\Application Data\Orbit 2010-02-10 20:15 . 2008-01-04 21:35--------d-----w-c:\program files\Common Files\Java 2010-02-10 20:14 . 2010-02-10 20:14348160----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-221e8639-n\msvcr71.dll 2010-02-10 20:14 . 2010-02-10 20:14503808----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-221e8639-n\msvcp71.dll 2010-02-10 20:14 . 2010-02-10 20:1461440----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-50e0af3d-n\decora-sse.dll 2010-02-10 20:14 . 2010-02-10 20:14499712----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-221e8639-n\jmc.dll 2010-02-10 20:14 . 2010-02-10 20:1412800----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-50e0af3d-n\decora-d3d.dll 2010-02-10 20:12 . 2003-03-11 14:13--------d-----w-c:\program files\Java 2010-02-10 17:19 . 2009-12-02 00:39--------d-----w-c:\documents and settings\Alex\Application Data\vlc 2010-02-10 16:43 . 2007-11-03 03:03--------d-----w-c:\documents and settings\Alex\Application Data\.purple 2010-02-10 16:41 . 2010-02-10 16:411791----a-w-c:\documents and settings\Alex\Application Data\.purple\certificates\x509\tls_peers\bos.oscar.aol.com 2010-02-10 16:41 . 2010-02-10 16:411505----a-w-c:\documents and settings\Alex\Application Data\.purple\certificates\x509\tls_peers\slogin.oscar.aol.com 2010-02-10 03:42 . 2010-02-10 03:421691----a-w-c:\documents and settings\Alex\Application Data\.purple\certificates\x509\tls_peers\api.screenname.aol.com 2010-02-06 19:29 . 2009-07-17 02:50--------d-----w-c:\documents and settings\Alex\Application Data\dvdcss 2010-02-06 05:00 . 2010-02-06 05:0938784----a-w-c:\documents and settings\Alex\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-02-06 05:00 . 2010-02-06 05:0938784----a-w-c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-02-03 09:30 . 2009-07-20 13:11--------d-----w-c:\documents and settings\All Users\Application Data\DVD Shrink 2010-02-03 09:29 . 2009-07-20 13:11--------d-----w-c:\program files\DVD Shrink 2010-02-03 09:23 . 2007-08-11 15:44--------d-----w-c:\documents and settings\Alex\Application Data\DVD Flick 2010-01-29 21:08 . 2010-01-29 21:0810134----a-r-c:\documents and settings\Alex\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe 2010-01-29 20:49 . 2003-03-10 15:01--------d--h--w-c:\program files\InstallShield Installation Information 2010-01-28 03:08 . 2007-11-04 03:13--------d-----w-c:\documents and settings\Alex\Application Data\gtk-2.0 2010-01-25 19:32 . 2010-02-08 02:57114360----a-w-c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll 2010-01-25 10:58 . 2007-03-26 02:508224-c--a-w-c:\documents and settings\Alex\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-01-25 10:50 . 2010-01-11 02:33--------d-----w-c:\documents and settings\Alex\Application Data\Azureus 2010-01-23 03:38 . 2009-08-11 01:10--------d-----w-c:\documents and settings\Alex\Application Data\Audacity 2010-01-20 08:21 . 2009-12-15 05:53--------d-----w-c:\documents and settings\Alex\Application Data\BitTyrant 2010-01-14 21:28 . 2010-01-27 16:201260800----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe 2010-01-14 21:28 . 2010-01-27 16:203777280----a-w-c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe 2010-01-12 10:01 . 2009-12-04 02:44--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2010-01-12 10:00 . 2009-12-13 10:015115824----a-w-c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2010-01-11 02:34 . 2010-01-11 02:34--------d-----w-c:\documents and settings\All Users\Application Data\Azureus 2010-01-11 02:30 . 2010-01-11 02:28--------d-----w-c:\program files\Vuze 2010-01-09 17:06 . 2010-01-09 17:06--------d-----w-c:\program files\VMware 2010-01-07 21:07 . 2009-12-04 02:4438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 21:07 . 2009-12-04 02:4419160----a-w-c:\windows\system32\drivers\mbam.sys 2010-01-03 06:13 . 2010-01-03 06:13--------d-----w-c:\documents and settings\Alex\Application Data\Participatory Culture Foundation 2010-01-03 06:11 . 2010-01-03 06:11--------d-----w-c:\program files\Combined Community Codec Pack 2010-01-03 06:11 . 2010-01-03 06:11--------d-----w-c:\program files\Participatory Culture Foundation 2010-01-03 06:03 . 2009-12-28 04:10--------d-----w-c:\program files\Aegisub 2010-01-03 02:28 . 2010-01-03 02:25--------d-----w-c:\program files\Common Files\ArcSoft 2010-01-03 02:28 . 2010-01-03 02:24--------d-----w-c:\program files\ArcSoft 2010-01-03 02:27 . 2010-01-03 02:26--------d-----w-c:\documents and settings\Alex\Application Data\ArcSoft 2010-01-03 02:27 . 2010-01-03 02:26--------d-----w-c:\documents and settings\All Users\Application Data\ArcSoft 2010-01-02 06:56 . 2009-08-21 20:18--------d-----w-c:\documents and settings\NetworkService\Application Data\gtk-2.0 2010-01-02 03:14 . 2010-01-02 03:14--------d-----w-c:\documents and settings\NetworkService\Application Data\Orbit 2010-01-01 20:34 . 2010-01-01 20:33--------d-----w-c:\program files\P2PChan 2010-01-01 18:34 . 2009-08-10 07:30--------d-----w-c:\program files\Unlocker 2009-12-31 16:50 . 2001-08-23 12:00353792----a-w-c:\windows\system32\drivers\srv.sys 2009-12-31 08:51 . 2009-12-30 20:3579488----a-w-c:\documents and settings\Alex\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2009-12-31 05:14 . 2009-12-30 20:2852224----a-w-c:\documents and settings\Alex\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2009-12-31 05:14 . 2009-12-30 20:20117760----a-w-c:\documents and settings\Alex\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-12-31 05:07 . 2008-05-25 15:50--------d-----w-c:\program files\MediaCoder 2009-12-30 21:53 . 2009-12-30 20:17--------d-----w-c:\program files\SUPERAntiSpyware 2009-12-30 20:51 . 2009-12-30 20:5125608----a-w-c:\windows\system32\drivers\AVGIDSxx.sys 2009-12-30 20:51 . 2009-12-30 20:5112464----a-w-c:\windows\system32\avgrsstx.dll 2009-12-30 20:51 . 2009-12-30 20:51360584----a-w-c:\windows\system32\drivers\avgtdix.sys 2009-12-30 20:51 . 2009-12-30 20:51161800----a-w-c:\windows\system32\drivers\avgrkx86.sys 2009-12-30 20:51 . 2009-12-30 20:51333192----a-w-c:\windows\system32\drivers\avgldx86.sys 2009-12-30 20:51 . 2009-12-30 20:5128424----a-w-c:\windows\system32\drivers\avgmfx86.sys 2009-12-30 20:49 . 2009-12-30 20:4950968----a-w-c:\windows\system32\avgfwdx.dll 2009-12-30 20:49 . 2009-12-30 20:4930104----a-w-c:\windows\system32\drivers\avgfwdx.sys 2009-12-30 20:49 . 2009-12-30 20:49--------d-----w-c:\program files\AVG 2009-12-30 20:49 . 2009-12-30 20:49--------d-----w-c:\documents and settings\All Users\Application Data\avg9 2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\documents and settings\Alex\Application Data\SUPERAntiSpyware.com 2009-12-30 20:17 . 2009-12-30 20:17--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-12-30 19:56 . 2009-11-07 21:11--------d-----w-c:\program files\CCleaner 2009-12-30 19:30 . 2009-11-08 03:46--------d-----w-c:\documents and settings\Alex\Application Data\TrueCrypt 2009-12-30 09:22 . 2009-12-30 09:22--------d-----w-c:\documents and settings\All Users\Application Data\TrueCrypt 2009-12-30 09:22 . 2009-11-07 20:51223440----a-w-c:\windows\system32\drivers\truecrypt.sys 2009-12-30 01:46 . 2007-07-18 20:31--------d-----w-c:\documents and settings\Alex\Application Data\DMCache 2009-12-29 16:41 . 2009-12-29 16:41464----a-w-c:\documents and settings\Alex\Application Data\WinFF\ff091229114117.bat 2009-12-29 16:41 . 2009-08-25 02:42--------d-----w-c:\documents and settings\Alex\Application Data\WinFF 2009-12-29 14:19 . 2009-12-13 06:29--------d-----w-c:\program files\Xvid 2009-12-29 05:05 . 2009-12-29 05:05--------d-----w-c:\program files\eRightSoft 2009-12-28 07:47 . 2007-08-10 20:32--------d-----w-c:\program files\DVD Flick 2009-12-28 07:36 . 2009-07-20 11:44--------d-----w-c:\program files\Common Files\Webroot Shared 2009-12-28 04:32 . 2009-12-08 20:2060928----a-w-c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\[emailprotected]\installer\setup.exe 2009-12-28 04:10 . 2009-12-28 04:10--------d-----w-c:\documents and settings\Alex\Application Data\Aegisub 2009-12-28 03:59 . 2007-06-23 18:03--------d-----w-c:\documents and settings\Alex\Application Data\uTorrent 2009-12-27 06:48 . 2009-12-14 11:461620552----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-12-27 05:21 . 2009-12-27 05:21--------d-----w-c:\documents and settings\All Users\Application Data\Speed Soft 2009-12-26 03:13 . 2009-12-26 03:13--------d-----w-c:\documents and settings\Alex\Application Data\JAM Software 2009-12-23 05:59 . 2009-12-23 05:58--------d-----w-c:\program files\VirtualDubMOD 2009-12-22 16:48 . 2009-12-15 22:28--------d-----w-c:\program files\MP3Gain 2009-12-22 01:48 . 2009-12-22 01:481201----a-w-c:\documents and settings\Alex\Application Data\.purple\certificates\x509\tls_peers\login.facebook.com 2009-12-21 19:14 . 2003-03-10 21:03916480------w-c:\windows\system32\wininet.dll 2009-12-21 14:20 . 2009-12-21 14:20--------d-----w-c:\documents and settings\Alex\Application Data\Obsidium 2009-12-21 11:31 . 2009-12-21 11:31--------d-----w-c:\program files\FDRLab 2009-12-18 07:01 . 2009-12-18 07:01--------d-----w-c:\program files\Outspark 2009-12-17 05:22 . 2007-04-04 01:57--------d-----w-c:\program files\DivX 2009-12-17 05:22 . 2009-12-17 05:21--------d-----w-c:\program files\Common Files\DivX Shared 2009-12-16 18:43 . 2003-03-10 21:00343040----a-w-c:\windows\system32\mspaint.exe 2009-12-16 02:55 . 2009-12-15 05:53--------d-----w-c:\program files\BitTyrant 2009-12-16 00:03 . 2009-12-16 00:03--------d-----w-c:\program files\JAM Software 2009-12-14 07:08 . 2001-08-23 12:0033280----a-w-c:\windows\system32\csrsrv.dll 2009-12-14 03:19 . 2009-12-14 03:1978336----a-w-c:\documents and settings\Alex\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe 2009-12-13 22:44 . 2009-12-13 22:33--------d-----w-c:\program files\Winnydows 2009-12-13 06:41 . 2009-12-13 06:40--------d-----w-c:\program files\StaxRip 2006-05-03 09:06 . 2009-07-20 18:12163328--sha-r-c:\windows\system32\flvDX.dll 2009-08-23 00:35 . 2009-07-18 01:03952--sha-w-c:\windows\system32\KGyGaAvL.sys 2007-02-21 10:47 . 2009-12-29 05:0631232--sh--r-c:\windows\system32\msfDX.dll 2008-03-16 12:30 . 2009-12-28 05:58216064--sha-r-c:\windows\system32\nbDX.dll . ------- Sigcheck ------- [-] 2008-05-18 . 56F4867BAE6FD78E5365A3A7AFA59C82 . 295424 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll [-] 2008-05-18 . 56F4867BAE6FD78E5365A3A7AFA59C82 . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll [7] 2004-08-04 . B60C877D16D9C880B952FDA04ADF16E6 . 295424 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2009-12-28 1201152] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DrvLsnr"="c:\program files\Analog Devices\SoundMAX\DrvLsnr.exe" [2002-04-20 69632] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-09-30 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-09-30 126976] "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2009-10-26 15872] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-01-07 429392] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2007-8-9 1667072] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-12-30 20:32548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-12-30 20:5112464----a-w-c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2009-12-08 20:44136192----a-w-c:\program files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Orbitdownloader\\orbitdm.exe"= "c:\\Program Files\\Orbitdownloader\\orbitnet.exe"= "c:\\Program Files\\Pidgin\\pidgin.exe"= "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"= "c:\\Program Files\\WinPcap\\rpcapd.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "h:\\dls\\romz\\emuz\\VisualBoyAdvance\\VisualBoyAdvance.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Ares\\Ares.exe"= "c:\\Program Files\\DC++\\DCPlusPlus.exe"= "c:\\Program Files\\Ares\\chatServer.exe"= "c:\\Program Files\\Soulseek\\slsk.exe"= "c:\\Program Files\\BitTyrant\\Azureus.exe"= "c:\\Program Files\\Webroot\\Washer\\wwDisp.exe"= "c:\\WINDOWS\\system32\\igfxtray.exe"= "c:\\Program Files\\Analog Devices\\SoundMAX\\DrvLsnr.exe"= "c:\\Program Files\\Malwarebytes' Anti-Malware\\mbamgui.exe"= "c:\\Program Files\\eRightSoft\\SUPER\\SUPER.exe"= "c:\\WINDOWS\\system32\\taskmgr.exe"= "c:\\Program Files\\Unlocker\\UnlockerAssistant.exe"= "c:\\Program Files\\Mozilla Firefox\\crashreporter.exe"= "c:\\Program Files\\iPod\\bin\\iPodService.exe"= "c:\\Program Files\\AVG\\AVG9\\avgam.exe"= "c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"= "c:\\Program Files\\AVG\\AVG9\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 "9420:TCP"= 9420:TCP:Red Swoosh "5000:UDP"= 5000:UDP:Red Swoosh R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [12/30/2009 3:51 PM 25608] R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [12/30/2009 3:51 PM 161800] R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/4/2007 12:29 PM 685816] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/30/2009 3:51 PM 333192] R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/30/2009 3:51 PM 360584] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 74480] R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [12/30/2009 3:50 PM 906520] R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12/30/2009 3:50 PM 285392] R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [12/30/2009 3:50 PM 2304192] R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [12/30/2009 3:50 PM 5832712] R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [10/29/2009 12:27 PM 1074568] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/3/2009 9:44 PM 236368] R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [7/20/2009 6:44 AM 598856] R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [12/30/2009 3:49 PM 30104] R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [12/30/2009 3:50 PM 122376] R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [12/30/2009 3:50 PM 30216] R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [12/30/2009 3:50 PM 25736] R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [8/9/2007 4:43 PM 113896] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/3/2009 9:44 PM 19160] R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [12/12/2009 5:46 PM 272128] R3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [8/8/2007 6:35 AM 223128] S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [12/30/2009 3:49 PM 30104] S3 dsreader;MaxDrive Driver (dsreader.sys);c:\windows\system32\drivers\dsreader.sys [1/2/2001 11:53 PM 19677] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [1/25/2007 12:31 PM 42000] S3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;c:\windows\system32\drivers\usbscan.sys [12/8/2007 12:20 PM 15104] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408] S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [11/29/2009 10:41 AM 627072] S3 XDva281;XDva281;\??\c:\windows\system32\XDva281.sys --> c:\windows\system32\XDva281.sys [?] . Contents of the 'Scheduled Tasks' folder 2010-02-08 c:\windows\Tasks\Malwarebytes' Scheduled Update for Alex.job - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-12-09 21:07] . . ------- Supplementary Scan ------- . uStart Page = file:///H:/dls/backup/lulz/Anon%20Party%20Hard/anon_partyhard30.swf uInternet Settings,ProxyOverride = 127.0.0.1;*.local uInternet Settings,ProxyServer = 83.133.119.38:8080 IE: &Download All with FlashGet - c:\documents and settings\Alex\My Documents\Random Junk\Programs\FlashGet\jc_all.htm IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201 IE: &Download with FlashGet - c:\documents and settings\Alex\My Documents\Random Junk\Programs\FlashGet\jc_link.htm IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204 IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203 IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202 IE: Download FLV video content with IDM - c:\documents and settings\Alex\My Documents\Random Junk\Programs\Internet Download Manager\IEGetVL.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll FF - component: c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\um5wf9ps.default\extensions\[emailprotected]\components\KeyScramblerIE.dll FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-10 18:28 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sptd.sys >>UNKNOWN [0x8338C8AC]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0xf8845f28 \Driver\ACPI -> ACPI.sys @ 0xf86b6cb8 \Driver\atapi -> atapi.sys @ 0xf864bb40 IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598 ParseProcedure -> ntoskrnl.exe @ 0x8056ea15 \Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598 ParseProcedure -> ntoskrnl.exe @ 0x8056ea15 NDIS: -> SendCompleteHandler -> 0x0 PacketIndicateHandler -> 0x0 SendHandler -> 0x0 user & kernel MBR OK ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*] "AB141C35E9F4BF344B9FC010BB17F68A"="" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1280) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(3024) c:\windows\system32\WININET.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\windows\system32\netdde.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\windows\system32\bgsvcgen.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Orbitdownloader\orbitnet.exe c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\AVG\AVG9\avgnsx.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\program files\Analog Devices\SoundMAX\SMAgent.exe c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\windows\System32\MsPMSPSv.exe c:\program files\AVG\AVG9\avgcsrvx.exe . ************************************************************************** . Completion time: 2010-02-10 18:38:28 - machine was rebooted ComboFix-quarantined-files.txt 2010-02-10 23:38 ComboFix2.txt 2010-02-10 21:19 Pre-Run: 131,112,927,232 bytes free Post-Run: 131,073,851,392 bytes free Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4 - - End Of File - - 245C9D80C4F7FF37AAD040A286EFFD43 it seems to have worked. nothings unexpectedly terminating, control.exe and mmc.exe both work. thanks for the help!The termsrv.dll is also infected so it needs replaced. Enable viewing of hidden system files & folders XP 1. Click Start. 2. Select Control Panel. 3. Select the Tools menu and click Folder Options. 4. Select the View Tab. 5. Under the Hidden files and folders heading select Show hidden files and folders. 6. Uncheck the Hide extensions for known file types option. 7. Uncheck the Hide protected operating system files (recommended) option. 8. Click Apply. 9. Click OK. ---------- Go here and download the termsrv.dll to your desktop. http://www.dlldump.com/download-dll-files_new.php/dllfiles/T/termsrv.dll/5.1.2600.2180/download.html Then find the infected file located in the system32 folder. c:\windows\system32\termsrv.dll Right click it and choose Rename. Rename it to termsrv.old Then immediately go to the desktop and right click on the termsrv.dll and choose Cut. Go back to the system32 folder. At the top of the screen choose Edit > Paste. Let me know when that is done. |
|
| 1679. |
Solve : Re: logon.exe, is it a virus/trojan?? |
|
Answer» It is not a virus, it is a file that helps RUN your computer. I HAPPEN to be missing this file (that's how I found this forum), and it told me for several days that it could not find the file. NOw, it has locked me out of the computer. don't delete it, or you will have the same PROBLEM. a little hint, if your computer says it cannot find a file, immediatly replace it, and instead of SHUTTING your computer down, put it on standby until you can fix it. HOPE this helps! jqsnotify.exe the procedure entry point [emailprotected]@Z Did you get it fixed? |
|
| 1680. |
Solve : Hello I cant use any other search engine but search.com cant remove problem? |
|
Answer» THANK you so much evil my COMPUTER hasnt RUN this well in a very long time AWSOME easy to FALLOW advice thank you againYour welcome. Safe surfing. |
|
| 1681. |
Solve : Help! Removal of Trojan.Packed.NsAnti virus ~ log attached? |
|
Answer» HI My business desktop installted with enterprise version of Symantec antivirus program is infected with Trojan.Packed.NsAnti virus. It is triggering manual scan the entire day, quarantining LOTS of tmp files. Have ATTACHED the log generated using Micro Hijack this. Pls advise asap. [Saving space, attachment deleted by admin]Is this business desktop belonging to an organization or company?Yes, it belongs to an organisation. IT do not support virus removal, I need to reimage my PC to get rid of the virus.I'm sorry to turn down the help, but we help home users for free, but for BUSINESSES we will not help. We are here for home users, sorry. |
|
| 1682. |
Solve : Virus prevents computer from booting normally? |
|
Answer» Just this morning my computer was working fine. All of a sudden I get a message that i have a trojan (AVG free notified me) i click heal and forget about it. Then i get a message saying "fuck3.exe has stopped working". I'm thinking that it's a virus or something so i start a scan. In the first few seconds of the scan i get about 30 trojans that pop up on the AVG free . Try using combofix and delete some of those unwanted entries in your registry editor. Next, download registry mechanic, scan your registry if you see some problems just click repair. Last thing is download an ATF cleaner for windows xp and firefox only, just clean everything. See if this would fix your problem.I gotta thank you man. I think my computer is virus free now. You are a life saver! Bad news. After Doing all that the guy above asked, and after a full virus scan that deleted 3 trojans, my computer seemed to work fine. It restarted a couple times without hiccups. I tried restarting it again and now it won't. It does the same thing, goes to user accounts and then to a black screen. It only goes to the desktop on safemode. Do I have to repeat the steps above or what? hey can u help me 2? i have the same problem but my computer wont even let me go into safe mode it doesnt go to the loggin in screen it juss goes black for 10 secs then restarts n does the same thing over n over againI've got the same issue. Any help is appreciated. |
|
| 1683. |
Solve : Application cannot be executed... My case, pls help? |
|
Answer» Hi, |
|
| 1684. |
Solve : AntiVirus Plus etc? |
|
Answer» Not many options here. To repair a windows xp installation using recovery console, press rok it then says which windows installation would you like to log onto? it only accepts one digit.What do you mean by it only accepts one digit?i TRIED to put that code thing in but after ive typed the "c" it doesnt let me type anything else, so not sure what to do at this stageAre you supposed to type R not C?How many Windows installs is it showing ? ? Have you tried using the up/down arrow to highlight the selection and hit Enter ? ? Sounds like you have a 2nd install of Windows from your repair efforts...nevermind my own stupidity there haha got it loading now and its 60% complete, need to go out just now will be back later, thanks guysCool. Keep us posted.no luck, when i restarted i still cant get on without it logging me straight back off:(with no harm ment. i really suggest this. the os is fine. its just a modified registry key that was hijacked by the infection. Again NO HARM MENT... http://www.ehow.com/how_4527843_onlog-off-loop-windows-xp.htmlThat is a generic article and isn't going to help here. Besides. What they are asking to be done is THE SAME as what we are trying! Only here there is an open dialog here.... @ Alan Rfc1 Can you answer the questions Patio asked please. I'm really thinking you are looking at a reinstall. Quote from: patio on January 27, 2010, 11:41:22 AM How many Windows installs is it showing ? ? |
|
| 1685. |
Solve : I've got a trojan hourse (or two) and can't get shot of it. "psw.generic7.bemv"? |
|
Answer» Quote PS I'm stll geting the ocational website loading up unrequested any ideas ( didn't get this before the malware problem)Which browser are you using?Hi SD, I'm using FireFox v3.6 with add-ons Adblock Plus, AVG Safe Guard ColorfulTabs, NoScript, Personas, Skype, WOT, plus some Java Console This Morning I got this message: see attached:- I've checked Task Manager "Services" and Process ID 816 is PlugPlay and DcomLaunch again! I'm suspecting I'm going to have to go down the clean install route. Is there a good/safe way of partitioning my C: drive with out losing the data and then moving my data across to the new drive without bring the infection across. [Saving space, attachment deleted by admin]Update and run SAS and MBAM again. Just hold off on the re-format. I'm going to check with Evil about this new problem. Do you visit the website 'samdadsupport.com'?Nope I've not clicked on samdadsupport.com. I've tried leaving firefox open and not using the computer for say 45mins and nothing happens but within 5mins of using it I get a new tab load up with various websites (that either NoScript or WOT warns me of danger.) this only happens once a secsion. I know its not the end of the world compared to the mess I was in when I first contacted you guys (thanks again for the help) but I'm still a bit woried that I have a problem. I've not been clicking on anything and websites like this try and open. ___NO_CLICK_____http://www.ukprizedraw.co.uk/default.aspx?campid=105&affid=2741&subid=2284 I have already run SAS but it did not find any thing I will run MBAM again this weekend. Delete ComboFix and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop DO NOT run it yet! Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Temporarily disable your ANTIVIRUS and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: DDS:: DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} Folder:: c:\users\Jamie\AppData\Roaming\lowsec RegLockDel:: [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\5&14c66cf6&0&12345678&02&01\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\5&14c66cf6&0&12345678&02&01\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26CE\4&211ab9e2&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26CE\4&211ab9e2&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\4&211ab9e2&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\4&211ab9e2&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\5&14c66cf6&0&12345678&02&01\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\5&14c66cf6&0&12345678&02&01\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze ---------- Download GooredFix from one of the locations below and save it to your desktop Download Mirror #1 Download Mirror #2 * Ensure all Firefox windows are closed. * To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista). * When prompted to run the scan, click Yes. * GooredFix will check for INFECTIONS, and then a log will appear. Post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt). ---------- Download Rooter.exe to your desktop. * Double click Rooter.exe to start the tool. * A DOS window will appear and show the scan progress. * Once complete a notepad file containing the report will open. * Copy & paste the results in your next reply. * Close notepad and Rooter will close. A log will also save at C:\Rooter.txt ---------- Next post please add:
ComboFix 10-02-07.06 - Jamie 08/02/2010 9:27.4.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2036.1111 [GMT 0:00] Running from: c:\users\Jamie\Desktop\ComboFix.exe Command switches used :: c:\users\Jamie\Desktop\CFScript.txt FW: Sunbelt Personal Firewall *disabled* {82B1150E-9B37-49FC-83EB-D52197D900D0} SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\users\Jamie\AppData\Roaming\lowsec c:\users\Jamie\AppData\Roaming\lowsec\local.ds c:\users\Jamie\AppData\Roaming\lowsec\user.ds Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected Restored copy from - Kitty ate it :p . ((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 ))))))))))))))))))))))))))))))) . 2010-02-08 09:33 . 2010-02-08 09:33--------d-----w-c:\users\Public\AppData\Local\temp 2010-02-08 09:33 . 2010-02-08 09:33--------d-----w-c:\users\IUSR_NMPR\AppData\Local\temp 2010-02-08 09:33 . 2010-02-08 09:33--------d-----w-c:\users\Default\AppData\Local\temp 2010-02-04 16:25 . 2010-02-05 17:48--------d-----w-c:\program files\SpywareBlaster 2010-02-02 15:11 . 2010-02-08 09:53--------d-----w-c:\users\Jamie\AppData\Local\temp 2010-01-29 15:23 . 2010-01-27 17:1915880----a-w-c:\windows\system32\lsdelete.exe 2010-01-28 14:10 . 2010-01-28 14:10--------d-----w-c:\program files\DiskCheckup 2010-01-28 14:10 . 2010-01-28 14:10--------d-----w-c:\windows\Sun 2010-01-27 16:44 . 2009-07-16 13:33157696----a-w-c:\users\Jamie\JavaRa.exe 2010-01-26 15:15 . 2010-02-04 16:28--------d-----w-c:\programdata\Spybot - Search & Destroy 2010-01-26 15:15 . 2010-01-26 15:18--------d-----w-c:\program files\Spybot - Search & Destroy 2010-01-26 10:23 . 2010-01-26 10:28--------d-----w-c:\program files\a-squared Free 2010-01-25 21:08 . 2010-01-25 21:08--------d-----w-c:\users\Jamie\AppData\Roaming\Malwarebytes 2010-01-25 21:08 . 2010-01-07 16:0738224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-25 21:08 . 2010-01-25 21:08--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2010-01-25 21:08 . 2010-01-25 21:08--------d-----w-c:\programdata\Malwarebytes 2010-01-25 21:08 . 2010-01-07 16:0719160----a-w-c:\windows\system32\drivers\mbam.sys 2010-01-25 20:45 . 2010-01-25 20:45--------d-----w-c:\programdata\SUPERAntiSpyware.com 2010-01-25 20:45 . 2010-01-25 20:45--------d-----w-c:\users\Jamie\AppData\Roaming\SUPERAntiSpyware.com 2010-01-25 20:45 . 2010-01-25 20:45--------d-----w-c:\program files\SUPERAntiSpyware 2010-01-25 20:44 . 2010-01-25 20:44--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2010-01-25 17:17 . 2009-12-02 13:1964288----a-w-c:\windows\system32\drivers\Lbd.sys 2010-01-25 16:58 . 2010-01-25 16:59--------dc-h--w-c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9} 2010-01-25 16:58 . 2010-01-25 16:58--------d-----w-c:\program files\Lavasoft 2010-01-21 16:57 . 2010-01-21 16:57--------d-----w-c:\users\Jamie\AppData\Local\HandBrake 2010-01-21 16:57 . 2010-01-21 16:57--------d-----w-c:\users\Jamie\AppData\Roaming\HandBrake 2010-01-20 00:52 . 2010-01-20 00:54--------d-----w-C:\ConverterOutput 2010-01-20 00:52 . 2004-10-12 14:42262144----a-w-c:\windows\system32\TomsMoComp_ff.dll 2010-01-20 00:52 . 2004-10-12 14:402255360----a-w-c:\windows\system32\libavcodec.dll 2010-01-20 00:52 . 2004-10-05 16:16395776----a-w-c:\windows\system32\libmplayer.dll 2010-01-20 00:52 . 2004-10-04 01:50112640----a-w-c:\windows\system32\libmpeg2_ff.dll 2010-01-20 00:52 . 2004-09-10 13:5034820----a-w-c:\windows\system32\ffdshow.reg 2010-01-20 00:52 . 2010-01-20 00:52--------d-----w-c:\program files\Cucusoft 2010-01-19 22:36 . 2010-02-04 17:10--------d-----w-c:\users\Jamie\AppData\Roaming\Auslogics 2010-01-19 22:36 . 2010-02-04 17:09--------d-----w-c:\program files\Auslogics 2010-01-14 16:20 . 2009-10-19 13:38156672----a-w-c:\windows\system32\t2embed.dll 2010-01-14 16:20 . 2009-10-19 13:3572704----a-w-c:\windows\system32\fontsub.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-08 09:55 . 2008-05-15 22:40--------d-----w-c:\programdata\Kontiki 2010-02-06 00:34 . 2009-11-24 16:04--------d-----w-c:\users\Jamie\AppData\Roaming\vlc 2010-02-05 13:55 . 2009-09-24 09:1519944----a-w-c:\windows\system32\drivers\atapi.sys 2010-02-05 09:19 . 2010-01-25 20:45117760----a-w-c:\users\Jamie\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-02-04 17:17 . 2010-01-25 17:16389784----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll 2010-02-04 17:17 . 2010-01-25 17:093803208----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe 2010-02-04 17:17 . 2010-01-25 17:08823928----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe 2010-02-04 17:17 . 2010-01-25 17:061181328----a-w-c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe 2010-02-04 16:11 . 2008-04-29 17:0275912----a-w-c:\users\Jamie\AppData\Local\GDIPFONTCACHEV1.DAT 2010-02-02 14:10 . 2009-06-03 17:06--------d-----w-c:\users\Jamie\AppData\Roaming\uTorrent 2010-01-29 16:22 . 2008-04-10 16:32--------d-----w-c:\program files\Google 2010-01-28 14:03 . 2008-12-15 09:38411368----a-w-c:\windows\system32\deploytk.dll 2010-01-27 16:38 . 2008-04-10 16:26--------d-----w-c:\program files\Java 2010-01-27 16:37 . 2008-04-10 16:26--------d-----w-c:\program files\Common Files\Java 2010-01-25 20:45 . 2010-01-25 20:4552224----a-w-c:\users\Jamie\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-01-25 16:58 . 2009-11-05 09:53--------d-----w-c:\programdata\Lavasoft 2010-01-22 11:28 . 2008-11-10 22:391----a-w-c:\users\Jamie\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2010-01-21 17:38 . 2008-04-29 17:18--------d-----w-c:\program files\Mozilla Thunderbird 2010-01-21 16:57 . 2009-03-05 23:05--------d-----w-c:\program files\HandBrake 2010-01-21 16:01 . 2009-08-12 19:27--------d-----w-c:\program files\Microsoft Silverlight 2010-01-19 23:59 . 2009-07-20 09:22--------d-----w-c:\program files\Common Files\Adobe 2010-01-14 16:57 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail 2010-01-14 11:12 . 2009-10-02 17:01181120------w-c:\windows\system32\MpSigStub.exe 2010-01-12 22:27 . 2009-09-18 11:45--------d-----w-c:\users\Jamie\AppData\Roaming\Skype 2010-01-12 22:20 . 2009-09-18 11:47--------d-----w-c:\users\Jamie\AppData\Roaming\skypePM 2010-01-09 20:12 . 2008-05-05 14:00--------d-----w-c:\users\Jamie\AppData\Roaming\dvdcss 2010-01-02 06:38 . 2010-01-22 11:18916480----a-w-c:\windows\system32\wininet.dll 2010-01-02 06:32 . 2010-01-22 11:1871680----a-w-c:\windows\system32\iesetup.dll 2010-01-02 06:32 . 2010-01-22 11:18109056----a-w-c:\windows\system32\iesysprep.dll 2010-01-02 04:57 . 2010-01-22 11:18133632----a-w-c:\windows\system32\ieUnatt.exe 2009-12-29 13:39 . 2009-12-29 13:39--------d-----w-c:\program files\QuickTime 2009-12-29 13:39 . 2009-12-29 13:39--------d-----w-c:\programdata\Apple Computer 2009-12-29 13:37 . 2009-12-29 13:37--------d-----w-c:\program files\Common Files\Apple 2009-12-29 13:37 . 2009-12-29 13:37--------d-----w-c:\program files\Apple Software Update 2009-12-29 13:37 . 2009-12-29 13:37--------d-----w-c:\programdata\Apple 2009-12-29 13:22 . 2009-09-18 11:44--------d-----r-c:\program files\Skype 2009-12-29 13:14 . 2009-12-29 13:14--------d-----w-c:\program files\Secunia 2009-12-14 20:56 . 2008-06-28 11:05--------d-----w-c:\programdata\Roxio 2009-12-10 17:35 . 2009-12-10 17:35--------d-----w-c:\program files\Stardock 2009-12-10 17:35 . 2009-12-10 17:35--------d-----w-c:\program files\Common Files\Stardock 2009-12-10 17:31 . 2008-04-29 17:18--------d-----w-c:\users\Jamie\AppData\Roaming\Thunderbird 2009-12-07 14:10 . 2010-01-25 16:582953352-c--a-w-c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe 2009-12-04 10:34 . 2009-12-04 10:34784136----a-w-c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2009-11-25 17:42 . 2009-11-25 17:42291696----a-w-c:\users\Jamie\AppData\Roaming\Juniper Networks\Setup Client\x86_Microsoft.VC80.CRTR_8.0.50727.762.exe 2009-11-17 13:33 . 2009-07-28 09:28319456----a-w-c:\windows\DIFxAPI.dll 2009-11-10 10:33 . 2009-06-03 15:51360584----a-w-c:\windows\system32\drivers\avgtdix.sys 2009-12-24 16:07 . 2008-12-22 09:46119808----a-w-c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll 2009-09-25 16:41 . 2009-09-25 16:411044480----a-w-c:\program files\mozilla firefox\plugins\libdivx.dll 2009-09-25 16:41 . 2009-09-25 16:41200704----a-w-c:\program files\mozilla firefox\plugins\ssldivx.dll 2008-04-11 00:11 . 2008-04-10 23:588192--sha-w-c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144] "Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2007-11-26 1206600] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-01-18 17920] "NMSSupport"="c:\program files\Common Files\INTEL\IntelDH\NMS\Support\IntelHCTAgent.exe" [2007-06-27 439512] "CCUTRAYICON"="c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe" [2007-06-27 215256] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-24 30192] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-02-13 16384] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "PivotSoftware"="c:\program files\Portrait Displays\Pivot Software\wpctrl.exe" [2007-02-09 694008] "DT HPW"="c:\program files\Portrait Displays\HP My Display\DTHtml.exe" [2007-04-25 280064] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-04-27 7420448] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-05 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-05 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-05 150552] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2008-04-10 77824] c:\users\Jamie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Broadband Download Monitor.lnk - c:\program files\Broadband Download Monitor\bdm.exe [2008-3-7 688128] Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-12-10 3444008] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Software Director Scheduler.lnk - c:\program files\Common Files\Cloanto\Software Director\softdir.exe [2009-8-11 288328] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableSecureUIAPaths"= 0 (0x0) "EnableVirtualization"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 14:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):78,da,8f,f3,df,3d,ca,01 R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [25/01/2010 17:17 64288] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [03/06/2009 15:51 333192] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [03/06/2009 15:51 360584] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/01/2010 07:56 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 07:56 74480] R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [26/01/2010 10:23 1858144] R2 AERTFilters;Andrea RT FILTERS Service;c:\program files\Realtek\Audio\HDA\AERTSrv.exe [17/11/2009 13:33 81920] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [27/10/2009 16:44 906520] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [27/10/2009 16:43 285392] R2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [12/02/2007 10:46 208896] R2 NMSCore;Intel(R) NMSCore;c:\program files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe [27/06/2007 09:14 317656] R2 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [18/02/2007 19:34 5376] R2 QualityManager;Intel(R) Quality Manager;c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\QualityManager.exe [27/06/2007 09:17 272600] R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [13/11/2009 11:31 92008] R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [28/05/2009 08:12 598856] R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [10/04/2008 16:29 5632] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 07:56 7408] S2 gupdate1c9f354452512a9;Google Update Service (gupdate1c9f354452512a9);c:\program files\Google\Update\GoogleUpdate.exe [22/06/2009 16:12 133104] S3 DHTRACE;Intel(R) DHTrace Controller;c:\program files\Common Files\Intel\IntelDH\bin\DHTraceController.exe [27/06/2007 09:15 39640] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [30/09/2008 07:30 21504] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\System32\drivers\ggflt.sys [09/06/2009 16:58 13224] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [10/04/2008 16:32 30192] S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [02/12/2009 13:19 1181328] S3 PSI;PSI;c:\windows\System32\drivers\psi_mf.sys [17/06/2009 12:20 12648] S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\System32\drivers\s3017bus.sys [09/01/2009 10:42 83880] S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\System32\drivers\s3017mdfl.sys [09/01/2009 10:44 15016] S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\System32\drivers\s3017mdm.sys [09/01/2009 10:44 110632] S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s3017mgmt.sys [09/01/2009 10:50 104616] S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\System32\drivers\s3017nd5.sys [09/01/2009 10:54 25512] S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\System32\drivers\s3017obex.sys [09/01/2009 10:49 100648] S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\System32\drivers\s3017unic.sys [09/01/2009 10:51 110120] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WindowsMobileREG_MULTI_SZ wcescomm rapimgr LocalServiceRestrictedREG_MULTI_SZ WcesComm RapiMgr LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder 2010-02-08 c:\windows\Tasks\AutoSmartDefrag.job - c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-01-19 15:30] 2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-22 16:12] 2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-22 16:12] 2010-02-02 c:\windows\Tasks\SmartDefrag.job - c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-01-19 15:30] 2010-02-08 c:\windows\Tasks\User_Feed_Synchronization-{FA4F8ED9-C3D2-43A5-B120-BB37897806F4}.job - c:\windows\system32\msfeedssync.exe [2010-01-22 04:56] . . ------- Supplementary Scan ------- . uStart Page = hxxp://google.atcomet.com/b/ uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://connect2.pb.com/dana-cached/sc/JuniperSetupClient.cab FF - ProfilePath - c:\users\Jamie\AppData\Roaming\Mozilla\Firefox\Profiles\tga7fkpk.default\ FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: browser.cache.memory.capacity - 65536 FF - user.js: browser.chrome.favicons - fales FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: content.interrupt.parsing - true FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 750000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 750000 FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 0 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut. enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugi n", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); . - - - - ORPHANS REMOVED - - - - SafeBoot-dmboot.sys SafeBoot-dmio.sys SafeBoot-dmload.sys SafeBoot-dmadmin SafeBoot-dmserver SafeBoot-SRService ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-08 09:53 Windows 6.0.6002 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\users\Jamie\AppData\Local\Temp\Cab18FC.tmp 29771 bytes c:\users\Jamie\AppData\Local\Temp\Tar18FD.tmp 77580 bytes scan completed successfully hidden files: 2 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\5&14c66cf6&0&12345678&02&01\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] @DACL=(02 0000) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\Default_Monitor\5&14c66cf6&0&12345678&02&01\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] @DACL=(02 0000) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26CE\4&211ab9e2&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] @DACL=(02 0000) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\HWP26CE\4&211ab9e2&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] @DACL=(02 0000) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\4&211ab9e2&0&UID16843008\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] @DACL=(02 0000) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\4&211ab9e2&0&UID16843008\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] @DACL=(02 0000) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\5&14c66cf6&0&12345678&02&01\Properties\{83da6326-97a6-4088-9453-a1923f573b29}] @DACL=(02 0000) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\TEO6770\5&14c66cf6&0&12345678&02&01\Properties\{a8b865dd-2e3d-4094-ad97-e593a70c75d6}] @DACL=(02 0000) . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'Explorer.exe'(4896) c:\program files\Stardock\ObjectDock\DockShellHook.dll c:\program files\Portrait Displays\Pivot Software\winphook.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Intel\IntelDH\CCU\AlertService.exe c:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe c:\program files\Kontiki\KService.exe c:\program files\AVG\AVG9\avgnsx.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe c:\program files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\windows\system32\conime.exe c:\windows\system32\igfxsrvc.exe c:\program files\Common Files\Portrait Displays\Shared\HookManager.exe c:\windows\ehome\ehmsas.exe c:\program files\Portrait Displays\Pivot Software\floater.exe c:\program files\Intel\IntelDH\CCU\CCU_Engine.exe c:\program files\Secunia\PSI\psi.exe . ************************************************************************** . Completion time: 2010-02-08 09:58:36 - machine was rebooted ComboFix-quarantined-files.txt 2010-02-08 09:58 Pre-Run: 193,404,383,232 bytes free Post-Run: 193,377,882,112 bytes free - - End Of File - - AC84C96F6CA637E54AFB508ABA734AEE GooredFix by jpshortstuff (08.01.10.1) Log created at 10:12 on 08/02/2010 (Jamie) Firefox version 3.6 (en-GB) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [17:15 29/04/2008] {B13721C7-F507-4982-B2E5-502A71474FED} [11:45 18/09/2009] {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} [10:30 05/03/2009] {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [17:21 26/03/2009] {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [07:40 31/08/2009] {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} [14:04 28/01/2010] C:\Users\Jamie\Application Data\Mozilla\Firefox\Profiles\tga7fkpk.default\extensions\ [emailprotected] [08:42 18/01/2010] {0545b830-f0aa-4d7e-8820-50a4629a56fe} [16:47 04/02/2010] {20a82645-c095-46ed-80e3-08825760534b} [07:31 11/07/2009] {73a6fe31-595d-460b-a920-fcc0f8843232} [10:17 05/02/2010] {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [13:13 26/01/2010] {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}-trash [10:22 10/12/2009] {b9db16a4-6edc-47ec-a1f4-b86292ed211d} [08:42 18/01/2010] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [20:12 09/01/2010] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Program Files\Real\RealPlayer\browserrecord" [17:18 09/05/2008] "{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG9\Firefox" [16:43 27/10/2009] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [15:53 09/06/2009] -=E.O.F=- Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully ... . Windows Vista Home Edition (6.0.6002) Service Pack 2 [32_bits] - x86 Family 6 Model 15 Stepping 13, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [MpsSvc] RUNNING (state:4) Windows Firewall -> Enabled Windows Defender -> Disabled ! User Account Control (UAC) -> Enabled . Internet Explorer 8.0.6001.18882 Mozilla Firefox 3.6 (en-GB) . C:\ [Fixed-NTFS] .. ( Total:288 Go - Free:180 Go ) D:\ [Fixed-NTFS] .. ( Total:9 Go - Free:6 Go ) E:\ [CD_Rom] F:\ [Fixed-FAT32] .. ( Total:232 Go - Free:30 Go ) G:\ [CD_Rom] . Scan : 10:13.27 Path : C:\Users\Jamie\Desktop\Rooter.exe User : Jamie ( Administrator -> YES ) . ----------------------\\ Processes . Locked [System Process] (0) Locked System (4) ______ \SystemRoot\System32\smss.exe (424) ______ C:\Windows\system32\csrss.exe (500) ______ C:\Windows\system32\wininit.exe (544) ______ C:\Windows\system32\csrss.exe (556) ______ C:\Windows\system32\services.exe (588) ______ C:\Windows\system32\lsass.exe (604) ______ C:\Windows\system32\lsm.exe (612) ______ C:\Windows\system32\winlogon.exe (656) ______ C:\Windows\system32\svchost.exe (816) ______ C:\Windows\system32\svchost.exe (880) ______ C:\Windows\System32\svchost.exe (1012) ______ C:\Windows\System32\svchost.exe (1044) ______ C:\Windows\system32\svchost.exe (1060) Locked audiodg.exe (1168) ______ C:\Windows\system32\svchost.exe (1192) ______ C:\Windows\system32\SLsvc.exe (1212) ______ C:\Windows\system32\svchost.exe (1244) ______ C:\Windows\system32\svchost.exe (1424) ______ C:\Windows\System32\spoolsv.exe (1628) ______ C:\Windows\system32\svchost.exe (1652) ______ C:\Program Files\a-squared Free\a2service.exe (1804) ______ C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe (1860) ______ C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (1880) ______ C:\Program Files\AVG\AVG9\avgwdsvc.exe (1896) ______ C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe (1920) ______ C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe (1948) ______ C:\Program Files\Kontiki\KService.exe (260) ______ C:\Program Files\AVG\AVG9\avgnsx.exe (1000) ______ C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe (972) ______ C:\Windows\system32\svchost.exe (464) ______ C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe (1732) ______ C:\Program Files\Dell Support Center\bin\sprtsvc.exe (688) ______ C:\Windows\system32\svchost.exe (2060) ______ C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (2088) ______ C:\Windows\System32\svchost.exe (2120) ______ C:\Windows\system32\SearchIndexer.exe (2204) ______ C:\Program Files\Webroot\Washer\WasherSvc.exe (2240) ______ C:\Program Files\AVG\AVG9\avgemc.exe (2316) ______ C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe (2348) ______ C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (2368) ______ C:\Windows\system32\taskeng.exe (2520) ______ C:\Program Files\AVG\AVG9\avgcsrvx.exe (2528) ______ C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe (2852) ______ C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe (2896) ______ C:\Program Files\AVG\AVG9\avgchsvx.exe (2984) ______ C:\Program Files\AVG\AVG9\avgrsx.exe (2992) ______ C:\Program Files\AVG\AVG9\avgcsrvx.exe (3020) ______ C:\Windows\system32\svchost.exe (3756) ______ C:\Windows\system32\Dwm.exe (156) ______ C:\Windows\system32\taskeng.exe (1724) ______ C:\Windows\Explorer.EXE (3904) ______ C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe (732) ______ C:\Windows\system32\taskeng.exe (720) ______ C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe (3388) ______ C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (1980) ______ C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (3700) ______ C:\Windows\WindowsMobile\wmdSync.exe (2232) ______ C:\Program Files\Dell Support Center\bin\sprtcmd.exe (2676) ______ C:\Program Files\Portrait Displays\Pivot Software\wpCtrl.exe (2912) ______ C:\Program Files\Portrait Displays\HP My Display\dthtml.exe (1828) ______ C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (3516) ______ C:\Windows\System32\igfxtray.exe (608) ______ C:\Windows\System32\hkcmd.exe (2592) ______ C:\Windows\System32\igfxpers.exe (3988) ______ C:\Program Files\Java\jre1.6.0\bin\jusched.exe (2804) ______ C:\Windows\ehome\ehtray.exe (476) ______ C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (3964) ______ C:\Program Files\Webroot\Washer\wwDisp.exe (1132) ______ C:\Windows\system32\igfxsrvc.exe (3900) ______ C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (4208) ______ C:\Program Files\Common Files\Cloanto\Software Director\softdir.exe (4216) ______ C:\Program Files\Broadband Download Monitor\bdm.exe (4224) ______ C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (4232) ______ C:\Windows\ehome\ehmsas.exe (4404) ______ C:\Program Files\Portrait Displays\Pivot Software\floater.exe (4620) ______ C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe (4716) ______ C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe (4752) ______ C:\Program Files\Secunia\PSI\psi.exe (5008) ______ C:\Windows\system32\conime.exe (5112) ______ C:\Users\Jamie\Desktop\Rooter.exe (5096) . ----------------------\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:57544704) \Device\Harddisk0\Partition2 (Start_Offset:57671680 | Length:10737418240) \Device\Harddisk0\Partition3 --[ MBR ]-- (Start_Offset:10795089920 | Length:309276442624) . ----------------------\\ Scheduled Tasks . C:\Windows\Tasks\AutoSmartDefrag.job C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job C:\Windows\Tasks\SA.DAT C:\Windows\Tasks\SCHEDLGU.TXT C:\Windows\Tasks\SmartDefrag.job C:\Windows\Tasks\User_Feed_Synchronization-{FA4F8ED9-C3D2-43A5-B120-BB37897806F4}.job . ----------------------\\ Registry . . ----------------------\\ Files & Folders . ----------------------\\ Scan completed at 10:13.36 . C:\Rooter$\Rooter_1.txt - (08/02/2010 | 10:13.36) atapi.sys Please download SystemLook from one of the below links and save it to your desktop. Link #1 Link #2 Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. * Double-click SystemLook.exe to run it. * Copy the contents of the following codebox into the main textfield. Code: [Select]:filefind *atapi* * Click the Look button to start the scan. * Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer). * When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txtDisabled AVG, Spybot, Adaware, and SAS Ran System look as requested. Switch back on AVG, Spybot, Adaware, and SAS SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 11:34 on 09/02/2010 by Jamie (Administrator - Elevation successful) ========== filefind ========== Searching for "*atapi*" C:\Qoobox\Quarantine\C\Windows\System32\drivers\atapi.sys.vir--a--- 19944 bytes[09:15 24/09/2009][13:55 05/02/2010] F0CE0B2BD34E63C0D57139F0AE1C6747 C:\Users\Public\Documents\Amiga Files\System\dir\System\Devs\atapi.device--a--- 13172 bytes[17:29 11/08/2009][04:16 23/09/2003] D0396596015EAC86FB19552FE356F691 C:\Windows\ERDNT\cache\atapi.sys--a--- 19944 bytes[11:04 01/02/2010][13:55 05/02/2010] 1F05B78AB91C9075565A9D8A4B880BC4 C:\Windows\inf\iteatapi.inf--a--- 33660 bytes[10:25 02/11/2006][10:25 02/11/2006] E4EB9FDA7CA1965653EAB8C109CCE546 C:\Windows\inf\iteatapi.PNF--a--- 17916 bytes[10:25 02/11/2006][12:51 02/11/2006] 73DF176A398D10A2338BBD40B56EF72E C:\Windows\System32\DriverStore\en-US\iteatapi.inf_loc--a--- 308 bytes[12:40 02/11/2006][12:40 02/11/2006] DBC002F0F2C65A0519A1BD24D84B22C2 C:\Windows\System32\DriverStore\FileRepository\iteatapi.inf_431397fb\iteatapi.inf--a--- 33660 bytes[10:25 02/11/2006][06:35 02/11/2006] E4EB9FDA7CA1965653EAB8C109CCE546 C:\Windows\System32\DriverStore\FileRepository\iteatapi.inf_431397fb\iteatapi.sys--a--- 35944 bytes[10:25 02/11/2006][09:50 02/11/2006] BCED60D16156E428F8DF8CF27B0DF150 C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5a9555b4\atapi.sys--a--- 21688 bytes[23:58 10/04/2008][23:58 10/04/2008] 9E7E85EC61D1C9C3171CC08427108863 C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5da5d093\atapi.sys--a--- 21688 bytes[00:11 11/04/2008][00:11 11/04/2008] 61CA2C1E145809813C28752298CF9843 C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_64dfd8ea\atapi.sys--a--- 21560 bytes[21:48 30/04/2008][21:48 30/04/2008] E03E8C99D15D0381E02743C36AFC7C6F C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_6c3af7d3\atapi.sys--a--- 21688 bytes[00:11 11/04/2008][00:11 11/04/2008] 7EB55F6BEFB392BD312CD0CD5263305D C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys--a--- 21560 bytes[21:48 30/04/2008][21:48 30/04/2008] B35CFCEF838382AB6490B321C87EDF17 C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys--a--- 19048 bytes[23:58 10/04/2008][23:58 10/04/2008] A779CA2C76DA4FCB595E692C05E8E4EB C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys--a--- 19944 bytes[09:15 24/09/2009][06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4 C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys--a--- 19048 bytes[10:25 02/11/2006][09:49 02/11/2006] 4F4FCB8B6EA06784FB6D475B7EC7300F C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys--a--- 21560 bytes[07:30 30/09/2008][07:41 19/01/2008] 2D9C903DC76A66813D350A562DE40ED9 C:\Windows\System32\drivers\atapi.sys------ 19944 bytes[09:15 24/09/2009][13:55 05/02/2010] 1F05B78AB91C9075565A9D8A4B880BC4 C:\Windows\System32\drivers\iteatapi.sys--a--- 35944 bytes[07:36 02/11/2006][09:50 02/11/2006] BCED60D16156E428F8DF8CF27B0DF150 C:\Windows\System32\en-US\WinSATAPI.dll.mui--a--- 6144 bytes[12:41 02/11/2006][12:41 02/11/2006] 64BDEA749C5954CECAB7EC5E9CC24D39 C:\Windows\System32\WinSATAPI.dll--a--- 383488 bytes[07:31 30/09/2008][07:36 19/01/2008] 3FCB7347D2DE38488C85A31EA7838A3C C:\Windows\winsxs\Manifests\x86_iteatapi.inf.resources_31bf3856ad364e35_6.0.6000.16386_en-us_20cdea2c37532736.manifest--a--- 1913 bytes[12:39 02/11/2006][12:39 02/11/2006] 99D99FA87B40A9FB8F9284AD0D7A71C9 C:\Windows\winsxs\x86_iteatapi.inf.resources_31bf3856ad364e35_6.0.6000.16386_en-us_20cdea2c37532736\iteatapi.inf_loc--a--- 308 bytes[12:40 02/11/2006][12:40 02/11/2006] DBC002F0F2C65A0519A1BD24D84B22C2 C:\Windows\winsxs\x86_microsoft-windows-w..emassessmenttoolapi_31bf3856ad364e35_6.0.6000.16386_none_e167a01dfaaf52f2\WinSATAPI.dll--a--- 382976 bytes[12:34 02/11/2006][12:34 02/11/2006] D5289700FAD39825C8A7BB20B7FC0A0D C:\Windows\winsxs\x86_microsoft-windows-w..emassessmenttoolapi_31bf3856ad364e35_6.0.6001.18000_none_e39e6219f79a63c6\WinSATAPI.dll--a--- 383488 bytes[07:31 30/09/2008][07:36 19/01/2008] 3FCB7347D2DE38488C85A31EA7838A3C C:\Windows\winsxs\x86_microsoft-windows-w..nttoolapi.resources_31bf3856ad364e35_6.0.6000.16386_en-us_86f384ab3e5358a7\WinSATAPI.dll.mui--a--- 6144 bytes[12:41 02/11/2006][12:41 02/11/2006] 64BDEA749C5954CECAB7EC5E9CC24D39 C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys--a--- 19048 bytes[23:58 10/04/2008][23:58 10/04/2008] A779CA2C76DA4FCB595E692C05E8E4EB C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16470_none_db063634249c06f4\atapi.sys--a--- 21688 bytes[00:11 11/04/2008][00:11 11/04/2008] 7EB55F6BEFB392BD312CD0CD5263305D C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys--a--- 21560 bytes[21:48 30/04/2008][21:48 30/04/2008] B35CFCEF838382AB6490B321C87EDF17 C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys--a--- 19048 bytes[23:58 10/04/2008][23:58 10/04/2008] 5653737BAD8C6C10136451C195C19881 C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20509_none_dbe4850d3d78c736\atapi.sys--a--- 21688 bytes[23:58 10/04/2008][23:58 10/04/2008] 9E7E85EC61D1C9C3171CC08427108863 C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20580_none_db8503133dc1c2af\atapi.sys--a--- 21688 bytes[00:11 11/04/2008][00:11 11/04/2008] 61CA2C1E145809813C28752298CF9843 C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys--a--- 21560 bytes[21:48 30/04/2008][21:48 30/04/2008] E03E8C99D15D0381E02743C36AFC7C6F C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys--a--- 21560 bytes[07:30 30/09/2008][07:41 19/01/2008] 2D9C903DC76A66813D350A562DE40ED9 C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys--a--- 19944 bytes[09:15 24/09/2009][06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4 -=End Of File=-* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /Uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- ESET Online Scan Scan your computer with the ESET FREE Online Virus Scan * Click the ESET Online Scanner button. * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop * Double click on the esetsmartinstaller_enu.exe icon on your desktop. * Place a check mark next to YES, I accept the Terms of Use. * Click the Start button. * Accept any security warnings from your browser. * Leave the check mark next to Remove found threats and place a check next to Scan archives. * Click the Start button. * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time. * When the scan completes, click List of found threats. * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply. * Click the <<Back button then click Finish. In your next reply please include the ESET Online Scan Log F:\My docs backup 2008 04 29\Programs\files\click_me_insults.htmlprobably a variant of JS/Seeker.AF trojancleaned by deleting - quarantined F: is my external USB backup drive that was thankfully not connected when all this trouble started.If there are no more malware issues we can finish up now. Use the Secunia Software Inspector to check for out of date software. * Click Start Now * Check the box next to Enable thorough system inspection. * Click Start * Allow the scan to finish and scroll down to see if any updates are needed. * Update anything listed. ---------- Go to Microsoft Windows Update and get all critical updates. ---------- If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page. ---------- I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Cheers for all the help guys.Your welcome. Safe surfing... |
|
| 1686. |
Solve : Virus effect hep with explorer / file manager? |
|
Answer» Hi All
Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. 3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer: http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial Post the log from SUPERAntiSpyware when you've accomplished that. 4. Please run a free online scan with the ESET Online Scanner
5. Post the following in your next reply:
All scans run successfully. Last one found nothing which I presume is good. Computer seems fine now, thanks for your help. Is there any specific scanner I ought to be using to help prevent future problems. I installed Bitdefender as it seemed to have good writeup. Log of scans in next post Cheers JohnMalwarebytes' Anti-Malware 1.44 Database version: 3679 Windows 6.1.7100 Internet Explorer 8.0.7100.0 02/02/2010 20:02:47 mbam-log-2010-02-02 (20-02-47).txt Scan type: Full Scan (C:\|D:\|E:\|) Objects scanned: 351046 Time elapsed: 1 hour(s), 39 minute(s), 23 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: D:\DOWNLOADS\ke find kf151\keyfinder.exe (Application.FindKey) -> Quarantined and deleted successfully. D:\TEMP\SecBku\20080916192916359.tmp (Application.FindKey) -> Quarantined and deleted successfully. C:\Users\John 1\Favorites\Cheap Software from CDRBSoftware.url (Rogue.Link) -> Quarantined and deleted successfully. SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 02/02/2010 at 09:40 PM Application Version : 4.33.1000 Core Rules Database Version : 4548 Trace Rules Database Version: 2360 Scan type : Quick Scan Total Scan Time : 01:00:07 Memory items scanned : 805 Memory threats detected : 0 Registry items scanned : 534 Registry threats detected : 0 File items scanned : 46002 File threats detected : 532 Adware.Tracking Cookie D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][6].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][9].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][7].txt D:\Documents and Settings\John1\Cookies\[emailprotected]somniture[2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][4].txt D:\Documents and Settings\John1\Cookies\[emailprotected][8].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][5].txt D:\Documents and Settings\John1\Cookies\[emailprotected][9].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][4].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][10].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected]gg.adbureau[2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected]yoodjklo.stats.esomniture[2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][4].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected]ts.esomniture[1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][4].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected]2dj6wfmiugczglq.stats.esomniture[2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected]dj6wcmiundjwdp.stats.esomniture[2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected]pdpsfp.stats.esomniture[2].txt D:\Documents and Settings\John1\Cookies\[emailprotected]cl4kmd5gkp.stats.esomniture[2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][10].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][11].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected]iture[2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\john1[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][7].txt D:\Documents and Settings\John1\Cookies\[emailprotected][6].txt D:\Documents and Settings\John1\Cookies\[emailprotected][5].txt D:\Documents and Settings\John1\Cookies\[emailprotected][8].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][4].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][3].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][2].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt D:\Documents and Settings\John1\Cookies\[emailprotected][1].txt Trojan.Agent/Gen-AppX E:\NEW VOLUME\ALLDATA\ALLDATA AUTO DIAGNOSTIC 3.4\ADUTIL\HINSTALL\303\HINSTALL.1.1.1.1.EXE [emailprotected] as CAB hook log: OnlineScanner.ocx - registred OK Note.. Nothing Found by ESETPlease re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.Run again. All Clean !! Malwarebytes' Anti-Malware 1.44 Database version: 3690 Windows 6.1.7100 Internet Explorer 8.0.7100.0 04/02/2010 21:06:32 mbam-log-2010-02-04 (21-06-32).txt Scan type: Quick Scan Objects scanned: 107680 Time elapsed: 7 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) To manually create a new Restore Point
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Results of screen317's Security Check version 0.99.1 Windows 7 (UAC is enabled) `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! ESET Online Scanner v3 BitDefender Antivirus 2010 WMIC entry does not exist for antivirus; attempting automatic update. `````````````````````````````` Anti-malware/Other Utilities Check: SUPERAntiSpyware Free Edition HijackThis 2.0.2 Java(TM) 6 Update 17 Adobe Flash Player 10 Adobe Reader 9.2 `````````````````````````````` Process Check: objlist.exe by Laurent Windows Defender MSMpEng.exe `````````````````````````````` DNS Vulnerability Check: Request Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?) `````````End of Log``````````` Please download the newest version of Java from Java.com. Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still LEAVE you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them. Once old versions are gone, please install the newest version. == Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to STAY safe while browsing, to prevent re-infection. Software recommendations AntiSpyware
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
Best wishes JohnYou're welcome. |
|
| 1687. |
Solve : Someone please help.. :-(? |
|
Answer» I have recently acquired a virus and need some help! Ugh.. the error reading is "Application cannot be executed. The file XXXXX is infected. Do you want to activate your antivirus software now?" then a fake antivirus software alert comes up... I had this same issue a few weeks ago and thought it was gone but it's back again grr!! Any help would be AWESOME! Please download Cheetah-Anti-Rogue, and save to your Desktop.
Cheetah-Anti-Rogue v1.2.17 by DragonMaster Jay Microsoft Windows [Version 6.0.6002] Date: 02/08/2010 - Time: 21:24:00 - Arch.: x86 -- Malware tools check -- Trend Micro HijackThis 2.0.2 Malwarebytes' Anti-Malware SUPERAntiSpyware Please open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Full Scan, and press Scan. Remove selected, and post the log in your next reply.The log from malwarebytes: Malwarebytes' Anti-Malware 1.44 Database version: 3713 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18882 2/9/2010 3:48:03 PM mbam-log-2010-02-09 (15-48-03).txt Scan type: Full Scan (C:\|) Objects scanned: 270324 Time elapsed: 1 hour(s), 57 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 FILES Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I did this scan on the 8th which detected one infected file I thought I should attach it as well: Malwarebytes' Anti-Malware 1.44 Database version: 3640 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18882 2/8/2010 3:41:03 AM mbam-log-2010-02-08 (03-41-03).txt Scan type: Full Scan (C:\|) Objects scanned: 267771 Time elapsed: 3 hour(s), 25 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Users\Zachary\AppData\Local\Temp\e.exe (Trojan.Dropper) -> Quarantined and deleted successfully. To manually create a new Restore Point
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Windows Vista Service Pack 2 (UAC is enabled) `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! SonicStage Mastering Studio Audio Filter Custom Preset Trend Micro AntiVirus Trend Micro AntiVirus Antivirus up to date! `````````````````````````````` Anti-malware/Other Utilities Check: Spyware Doctor 7.0 SUPERAntiSpyware Free Edition HijackThis 2.0.2 Java(TM) 6 Update 17 Java(TM) SE Runtime Environment 6 Java(TM) 6 Update 2 Java(TM) 6 Update 3 Java(TM) 6 Update 5 Out of date Java installed! Adobe Flash Player 10 Adobe Reader 8.1.0 Out of date Adobe Reader installed! `````````````````````````````` Process Check: objlist.exe by Laurent Windows Defender MSASCui.exe `````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) `````````END of Log``````````` Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is IMPORTANT to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. == Please download the newest version of Java from Java.com. Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them. Once old versions are gone, please install the newest version. == Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Firewall
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
|
|
| 1688. |
Solve : UACd.sys Trojan? |
|
Answer» Please open Malwarebytes, click the Scanner TAB, select Perform Quick Scan, and press Scan. Remove selected, and POST the log in your next reply.Hi,
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
I executed according to you instructions. The log is attached. Thanks! [Saving space, attachment deleted by admin]Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. SEARCH in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. == Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Firewall
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware ACTUALLY claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
Thanks for all the advice. I will enhance my PC's protection with the tools you're suggesting. However, I am still stuck with my explorer.exe issue. As I already mentioned, if I log in to my main user account, explorer will die and restart and die and restart and so on. This makes that I can not use this user account. You mentioned earlier that it was no biggie to get rid of that. You did some suggestions which I carried out, in another user account however, since the infected one is rendered useless. Please advice. Thanks!Restore Permissions for explorer.exe Please download Inherit by sUBs
Note: explorer.exe is located in the folder C:\windowsTried to download inherit, but got hit with the following: C:\Users\xbox\AppData\Local\Temp\fgW_siwp.exe.part could not be saved, because the source file could not be read. Try again later, or contact the server administrator. Furthermore AVAST acted up. The WebShield blocked the following threat: Object: ..../://download.bleepingcomputer.com/sUBs/MiniFixes/Inherit.exe| Infection: Win32:Trojan-gen Action: Connection aborted Proces: firefox.exe How to proceed?Disable the antivirus and try again please. That happens all the time, but the actual tool is safe.Hi, Did what you asked, no positive result. Now, thinking about this, I wouldn't expect that something is wrong with explorer.exe anyway. I have 5 user accounts on my computer and on 4 out of them it works as it should. Only one account has this problem. Can it be that there is something wrong in the start-up procedure for this account? Again, I can not do any experiments on this user account, which might make it harder to analyze. Any more ideas would be very much appreciated! Thanks again. Possibly. Log in to another user account to do this method. Save the account files for the account that is giving the problem. Just copy the following folder and save it to a disc, flash drive or somewhere in another username's My Documents folder. C:\Users\{USERNAME} {USERNAME} is the name of the problem account. Copy that folder and save it somewhere. Then go to Control Panel > User Accounts (add or remove user accounts) Delete the problem user account by removing it and all of its files. (Remember that you made a backup of those files) ===== Then, create a new account with the same username, and do the same process in reverse, by going to C:\Users and pasting the backup folder in the folder (Users). Then, restart the computer and let me know if this issue still occurs. == If you get Access Denied messages, let me know and we can Take Ownership of that folder.Hi, sorry for the late reply, work kept me busy (it happens ) Followed your instructions and everything seems to be working ok again. Let me know what I still need to do to declare my PC cured! What ever's next, thanks a lot for all your help. I enjoyed working with you. Couldn't have done it without you! Cheers PeterSeems clean to me. |
|
| 1689. |
Solve : Regarding "Read this before requesting malware removal help"? |
|
Answer» Hi, I have followed everything that you have said to do and can now upload the logs. I can't think of anything that brought the virus on so don't have any additional details for you. When performing the SuperAntiSpyware search, I had to cancel the first search so now have two logs. I have uploaded both of them and the log from the most recent search has been uploaded second. Also, I cannot do a system restore and it asks me to contact the domain administrator. Is there any way of being able to perform a system restore again?
Important: Close all open windows except for HijackThis and then CLICK FIX checked. Once completed, exit HijackThis. ---------- Download Lop S&D by Eric_71 and save it to your desktop. Lop S&D will only run on Windows XP and Windows Vista Disable your antivirus and antimalware programs so they do not interfere with the running of Lop S&D. Double click LopSD.exe - If you are using Windows Vista or Windows 7, right-click on the LopSD icon and select Run as administrator to perform this scan. * Choose the language by typing of the corresponding letter and press Enter * Click OK at the informative window. * Type 2 to choose Option 2 (Delete with Hosts File Restore), then press Enter * Wait until the end of the scan. * A report will be generated, post the contents of it in your next reply, along with a HijackThis log. Hey, here is a copy of he lopR log. Since I only did a system scan with HijackThis, I didn't get another log. Thanks [Saving space, attachment deleted by admin]Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop. Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds to run it. * If your antivirus or firewall try to block DDS then please allow it to run. * When finished DDS will open two (2) logs. 1) DDS.txt 2) Attach.txt * Save both logs to your desktop. * Please copy and paste the entire contents of both logs in your next reply. Note: DDS will instruct you to post the Attach.txt log as an attachment. Please just post it as you would any other log by copy and pasting it into the reply.Hi, here are the next two posts. Thanks [Saving space, attachment deleted by admin]Note: You got this infection from installing the sponsored software with Messenger Plus! Live. Quote C:\DOCUME~1\ALLUSE~1\Documents\Laura K\Desktop\Driver magician V 3.27\How to use keygen.txt Please remove Driver magician V 3.27 and any other cracked software. I can't continue helping if it is not removed. ---------- Go to Add or Remove Programs and uninstall:
Note: You can reinstall Messenger Plus but DO NOT choose to install the sponsored software! ---------- If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop DO NOT run it yet! Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: DDS:: TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File TB: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - No File uRun: [sefjhf98jfoidsfoishgoiusgdgfgd] c:\docume~1\fraser_2\locals~1\temp\zf0qkdnkgh.exe uRun: [smss32.exe] c:\windows\system32\smss32.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe File:: C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job c:\docume~1\fraser_2\locals~1\temp\zf0qkdnkgh.exe c:\windows\system32\smss32.exe c:\windows\system32\IS15.exe c:\windows\system32\helper32.dll c:\windows\system32\winlogon32.exe C:\horj.exe C:\kkalf.exe Folder:: c:\docume~1\fraser_2\applic~1\SystemProc C:\DOCUME~1\ALLUSE~1\Documents\Laura K\Desktop\Driver magician V 3.27 c:\program files\messenger C:\s 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze Hi there, here is the combofix log. Thanks [Saving space, attachment deleted by admin]Download the below attached CFScript.txt and save it to your desktop (click on the Attached File underneath this post) * If you are using Internet Explorer when the "File download" pop up comes click Save and choose desktop in the list of selections in that window and then click Save. * If you are using Firefox choose Save to disk then click OK and choose desktop in the list of selections in that window and then click Save. Close all open Web Browsers! Then drag the CFScript.txt into the ComboFix.exe as shown in the screenshot below. This will start ComboFix. ComboFix may ASK to reboot the computer when it is finished, please allow it to do so. A new log will be created, post the contents of Combofix.txt in your next reply. Note: these instructions and script were created specifically for this user. If you are not this user do NOT follow these instructions or use this script as it could damage the workings of your system. [Saving space, attachment deleted by admin]Here is the latest log. Thanks. I need to go now so I shall continue tomorrow. Thanks for all your help so far. [Saving space, attachment deleted by admin]Quote from: fkmckenzie on February 05, 2010, 05:21:36 PM I need to go now so I shall continue tomorrow. Thanks for all your help so far. No problem. I'll be around. * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /Uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- ESET Online Scan Scan your computer with the ESET FREE Online Virus Scan * Click the ESET Online Scanner button. * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop * Double click on the esetsmartinstaller_enu.exe icon on your desktop. * Place a check mark next to YES, I accept the Terms of Use. * Click the Start button. * Accept any security warnings from your browser. * Leave the check mark next to Remove found threats and place a check next to Scan archives. * Click the Start button. * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time. * When the scan completes, click List of found threats. * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply. * Click the <<Back button then click Finish. In your next reply please include the ESET Online Scan Log Hi, here is the ESETScan log for you. [Saving space, attachment deleted by admin]If there are no other malware issues we can finish up now. Use the Secunia Software Inspector to check for out of date software. * Click Start Now * Check the box next to Enable thorough system inspection. * Click Start * Allow the scan to finish and scroll down to see if any updates are needed. * Update anything listed. ---------- Go to Microsoft Windows Update and get all critical updates. ---------- If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page. ---------- I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thanks a lot. You have been a great help to meYour welcome. |
|
| 1690. |
Solve : PC Infected with 'popup' virus? |
| Answer» AVG will work fine with those. EVERYTHING I suggested in that last post is "PASSIVE protection" and won't interfere with AVG or the performance of your computer. | |
| 1691. |
Solve : need help removing virus? |
|
Answer» Hello, I've recently contracted a virus of some sort that causes the following to happen:
---------- If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixHow do I disable AVG 9.0?See here. http://free.avg.com/ww-en/kb.num-2429ComboFix 10-02-07.08 - Michael Perniciaro 02/08/2010 10:30:22.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1402 [GMT -6:00] Running from: c:\documents and settings\Michael Perniciaro\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Michael Perniciaro\Local Settings\Application Data\xhnsay c:\documents and settings\Michael Perniciaro\Local Settings\Application Data\xhnsay\kfehsftav.exe c:\windows\AegisP.inf c:\windows\system32\AutoRun.inf . ((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 ))))))))))))))))))))))))))))))) . 2010-02-07 09:05 . 2010-02-07 09:05--------d-----w-C:\d29983a7598216d258f242 2010-02-06 21:08 . 2010-02-06 21:23--------d-----w-c:\documents and settings\Michael Perniciaro\.SunDownloadManager 2010-02-06 20:44 . 2010-02-06 20:44503808----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6cd4d373-n\msvcp71.dll 2010-02-06 20:44 . 2010-02-06 20:44499712----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6cd4d373-n\jmc.dll 2010-02-06 20:44 . 2010-02-06 20:44348160----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6cd4d373-n\msvcr71.dll 2010-02-06 20:44 . 2010-02-06 20:4461440----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ffedcc-n\decora-sse.dll 2010-02-06 20:44 . 2010-02-06 20:4412800----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ffedcc-n\decora-d3d.dll 2010-02-06 15:53 . 2010-02-06 15:53--------d-----w-c:\program files\CCleaner 2010-02-06 05:44 . 2010-02-06 05:44--------d-----w-c:\documents and settings\Michael Perniciaro\Application Data\Malwarebytes 2010-02-06 05:43 . 2010-01-07 22:0738224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-06 05:43 . 2010-02-06 05:43--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2010-02-06 05:43 . 2010-02-06 05:46--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2010-02-06 05:43 . 2010-01-07 22:0719160----a-w-c:\windows\system32\drivers\mbam.sys 2010-02-06 02:41 . 2010-02-06 02:4152224----a-w-c:\documents and settings\Michael Perniciaro\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-02-06 02:41 . 2010-02-06 02:41117760----a-w-c:\documents and settings\Michael Perniciaro\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-02-06 02:40 . 2010-02-06 02:40--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2010-02-06 02:40 . 2010-02-06 02:40--------d-----w-c:\program files\SUPERAntiSpyware 2010-02-06 02:40 . 2010-02-06 02:40--------d-----w-c:\documents and settings\Michael Perniciaro\Application Data\SUPERAntiSpyware.com 2010-02-06 02:32 . 2010-02-06 02:32--------d-----w-c:\program files\Trend Micro 2010-02-06 02:09 . 2010-02-06 02:11--------d-----w-c:\documents and settings\Michael Perniciaro\Application Data\QuickScan 2010-02-06 02:09 . 2010-01-11 23:33789320----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Mozilla\Firefox\Profiles\kdecid0k.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll 2010-02-06 02:09 . 2010-01-11 23:32698184----a-w-c:\documents and settings\Michael Perniciaro\Application Data\Mozilla\Firefox\Profiles\kdecid0k.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll 2010-02-05 16:08 . 2010-02-07 09:06--------d-----w-c:\windows\system32\XPSViewer 2010-02-05 16:07 . 2010-02-05 16:07--------d-----w-c:\program files\Reference Assemblies 2010-02-05 16:07 . 2008-07-06 12:0689088----a-w-c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll 2010-02-05 16:07 . 2006-06-29 19:0714048------w-c:\windows\system32\spmsg2.dll 2010-02-05 16:02 . 2010-02-05 16:02--------d-----w-C:\3b84628148cac7604d4a2edb 2010-02-05 16:02 . 2010-02-05 18:27--------d-----w-C:\5838f9b2fb6304ca6b 2010-02-04 15:50 . 2010-02-04 15:50--------d-----w-c:\program files\iPod 2010-02-04 15:50 . 2010-02-04 15:51--------d-----w-c:\program files\iTunes 2010-02-04 15:46 . 2010-02-04 15:47--------d-----w-c:\program files\QuickTime 2010-02-04 15:41 . 2010-02-04 15:4172488----a-w-c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe 2010-01-31 18:30 . 2010-01-31 20:23--------d-----w-c:\program files\Jumi 2010-01-19 22:03 . 2010-01-19 22:03--------d-----w-c:\program files\Garmin GPS Plugin 2010-01-13 19:24 . 2009-11-21 15:51471552------w-c:\windows\system32\dllcache\aclayers.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-08 16:32 . 2008-10-25 15:17--------d-----w-c:\documents and settings\Michael Perniciaro\Application Data\DNA 2010-02-08 16:12 . 2007-04-12 05:04--------d-----w-c:\program files\Google 2010-02-08 15:52 . 2008-10-25 15:17--------d-----w-c:\program files\DNA 2010-02-08 06:11 . 2009-05-04 23:14--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater 2010-02-08 04:33 . 2007-05-01 01:50--------d-----w-c:\documents and settings\All Users\Application Data\Symantec 2010-02-08 04:33 . 2007-05-01 01:48--------d-----w-c:\program files\Common Files\Symantec Shared 2010-02-06 21:23 . 2007-04-12 04:51--------d-----w-c:\program files\Java 2010-02-06 20:53 . 2007-04-12 04:51--------d-----w-c:\program files\Common Files\Java 2010-02-06 14:46 . 2007-05-29 21:10--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2010-02-05 20:43 . 2007-04-12 05:0971616----a-w-c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-02-05 16:08 . 2007-07-11 14:13--------d-----w-c:\program files\MSBuild 2010-02-04 15:50 . 2007-11-22 19:14--------d-----w-c:\program files\Common Files\Apple 2010-01-21 14:25 . 2008-12-23 03:35--------d-----w-c:\program files\Microsoft Silverlight 2010-01-19 16:46 . 2007-04-25 13:49--------d-----w-c:\documents and settings\All Users\Application Data\Microsoft Help 2010-01-15 18:23 . 2007-04-25 00:05--------d-----w-c:\documents and settings\Michael Perniciaro\Application Data\BitTorrent 2010-01-12 13:43 . 2009-04-18 14:43141136----a-w-c:\windows\hpoins14.dat 2009-12-22 05:21 . 2004-08-11 22:00667136----a-w-c:\windows\system32\wininet.dll 2009-12-22 05:20 . 2004-08-11 22:0081920----a-w-c:\windows\system32\ieencode.dll 2009-12-17 23:14 . 2009-12-12 23:15411368----a-w-c:\windows\system32\deploytk.dll 2009-12-12 23:16 . 2009-12-12 23:13--------d-----w-c:\program files\LimeWire 2009-11-21 15:51 . 2004-08-11 22:00471552----a-w-c:\windows\AppPatch\aclayers.dll 2009-11-15 23:37 . 2009-04-21 16:13360584----a-w-c:\windows\system32\drivers\avgtdix.sys 2009-11-15 23:37 . 2009-04-21 16:13333192----a-w-c:\windows\system32\drivers\avgldx86.sys 2009-11-15 23:37 . 2009-04-21 16:1328424----a-w-c:\windows\system32\drivers\avgmfx86.sys 2009-11-15 23:37 . 2009-04-21 16:1312464----a-w-c:\windows\system32\avgrsstx.dll 2008-07-29 13:58 . 2007-05-28 22:08168--sh--r-c:\windows\system32\00D13C0E55.sys 2008-07-29 13:58 . 2007-05-28 22:085642--sha-w-c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392] "ANT Agent"="c:\garmin\ANT Agent\ANT Agent.exe" [2008-09-02 8203352] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-04 39408] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784] "SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 282624] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328] "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-30 185896] "REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152] "SonicWALLNetExtender"="c:\program files\SonicWALL\SSL-VPN\NetExtender\NEGui.exe" [2009-03-02 710480] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608] c:\documents and settings\Michael Perniciaro\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696] OneNote Table Of Contents.onetoc2 [2008-5-18 3656] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 20:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-11-15 23:3712464----a-w-c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\BitTorrent\\bittorrent.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\DNA\\btdna.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/21/2009 10:13 AM 333192] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/21/2009 10:13 AM 360584] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/15/2009 5:37 PM 285392] R3 SSLDrv;SSL-VPN NetExtender Adapter;c:\windows\system32\drivers\SSLDrv.sys [10/23/2007 6:09 PM 20504] S2 gupdate1c9cd0e429dfd3a;Google Update Service (gupdate1c9cd0e429dfd3a);c:\program files\Google\Update\GoogleUpdate.exe [5/4/2009 5:15 PM 133104] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder 2010-02-04 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34] 2010-02-08 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-22 23:14] 2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 23:15] 2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 23:15] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ mStart Page = hxxp://www.dell.com uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6070412 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 DPF: {6EEFD7B1-B26C-440D-B55A-1EC677189F30} - hxxps://vpn.hargrove-associates.com/NELX.cab FF - ProfilePath - c:\documents and settings\Michael Perniciaro\Application Data\Mozilla\Firefox\Profiles\kdecid0k.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\documents and settings\Michael Perniciaro\Application Data\Mozilla\Firefox\Profiles\kdecid0k.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - plugin: c:\documents and settings\Michael Perniciaro\Application Data\Move Networks\plugins\npqmp071505000010.dll FF - plugin: c:\documents and settings\Michael Perniciaro\Application Data\Mozilla\Firefox\Profiles\kdecid0k.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service FF - user.js: yahoo.homepage.dontask - true. - - - - ORPHANS REMOVED - - - - HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe ************************************************************************** scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(916) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\netprovcredman.dll . Completion time: 2010-02-08 10:34:53 ComboFix-quarantined-files.txt 2010-02-08 16:34 Pre-Run: 11,957,153,792 bytes free Post-Run: 11,994,955,776 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - E62948865219CF0183A967E1B913F679 Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger or Windows Live Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply. Exit out of MessengerDisable then delete the two files that were put on the desktop. ---------- Copy and paste the below into Notepad and save as fixme.reg to Your Desktop Code: [Select]REGEDIT4 [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry. Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Delete the fixme.reg from the Desktop. ---------- * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /Uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- ESET Online Scan Scan your computer with the ESET FREE Online Virus Scan * Click the ESET Online Scanner button. * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop * Double click on the esetsmartinstaller_enu.exe icon on your desktop. * Place a check mark next to YES, I accept the Terms of Use. * Click the Start button. * Accept any security warnings from your browser. * Leave the check mark next to Remove found threats and place a check next to Scan archives. * Click the Start button. * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time. * When the scan completes, click List of found threats. * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply. * Click the <<Back button then click Finish. In your next reply please include the ESET Online Scan Log Did get a success message for the fixme.reg. ESET found no threats and went straight to a screen with only a "Finish" button and the option to uninstall upon closing. I will continue to keep this box open until I hear from you. Sounds good. If there are no more malware issues we can finish up now. Use the Secunia Software Inspector to check for out of date software. * Click Start Now * Check the box next to Enable thorough system inspection. * Click Start * Allow the scan to finish and scroll down to see if any updates are needed. * Update anything listed. ---------- Go to Microsoft Windows Update and get all critical updates. ---------- If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page. ---------- I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Everything seems to be working fine. Thank you very much. No, really, THANK YOU!Your welcome. Safe surfing... |
|
| 1692. |
Solve : Need Help Removing Malware? |
|
Answer» Wife said the computer locked up and when she restarted it we are getting numerous alert windows that we are being attacked and do we want to block the attack. One window says "Application cannot be executed. The file avgui.exe is infected. Do you want to activate your antivirus software now?". Previously this window indicated CSC.exe was infected. Different message at each attempt to launch a program.
Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to EITHER and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. 3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer: http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial Post the log from SUPERAntiSpyware when you've accomplished that. 4. Please run a free online scan with the ESET Online Scanner
5. Post the following in your next reply:
MBAM Log: Malwarebytes' Anti-Malware 1.44 Database version: 3691 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 2/4/2010 9:53:41 PM mbam-log-2010-02-04 (21-53-41).txt Scan type: Full Scan (C:\|) Objects scanned: 322964 Time elapsed: 58 minute(s), 51 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{51b15f5a-e98b-4658-b9cb-9307b74773a7} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\webmedia.chl (Trojan.Zlob) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\All Users\Start Menu\Online Antispyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully. SAS Log: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 02/04/2010 at 11:11 PM Application Version : 4.33.1000 Core Rules Database Version : 4558 Trace Rules Database Version: 2370 Scan type : Complete Scan Total Scan Time : 00:39:05 Memory items scanned : 673 Memory threats detected : 0 Registry items scanned : 6721 Registry threats detected : 14 File items scanned : 32144 File threats detected : 133 Adware.ShopAtHomeSelect HKLM\Software\Classes\CLSID\{E8DAAA30-6CAA-4b58-9603-8E54238219E2} HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2} HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2} HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\InprocServer32 HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\InprocServer32#ThreadingModel HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\ProgID HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\Programmable HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\TypeLib HKCR\CLSID\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}\VersionIndependentProgID HKCR\ToolBand.ShopAtHomeIEHelper.1 HKCR\ToolBand.ShopAtHomeIEHelper HKCR\TypeLib\{462E4AEC-DB3B-4e69-AF61-4F300D76255C} C:\PROGRAM FILES\SELECTREBATES\TOOLBAR\SHOPATHOMETOOLBAR.DLL HKU\S-1-5-21-2249627288-277516385-4155468564-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8DAAA30-6CAA-4B58-9603-8E54238219E2} Adware.Tracking Cookie C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][3].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][2].txt C:\Documents and Settings\Jen\Cookies\[emailprotected][1].txt C:\Documents and Settings\Cam\Cookies\[emailprotected][2].txt C:\Documents and Settings\Cam\Cookies\[emailprotected][1].txt C:\Documents and Settings\Cam\Cookies\[emailprotected][1].txt C:\Documents and Settings\Cam\Cookies\[emailprotected][1].txt C:\Documents and Settings\Cam\Cookies\[emailprotected][1].txt C:\Documents and Settings\Cam\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][5].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][3].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][4].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][4].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][4].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][3].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][3].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][2].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][3].txt C:\Documents and Settings\Phil\Cookies\[emailprotected][1].txt Rogue.WebMediaViewer HKU\S-1-5-21-2249627288-277516385-4155468564-1006\Software\WebMediaViewer Malware.Installer-Pkg/Gen C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{3C48F877-A164-45E9-B9DA-26A049FFC207}.EXE C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6293BC00-4EB8-4C65-8548-53E2FC3BF937}.EXE C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6B6A7665-DB48-4762-AB5D-BEEB9E1CD7FA}.EXE C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C2D8F0E2-6978-4409-8351-BA8785DA11EE}.EXE C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{D1A6F3FD-7B40-443F-8767-BADB25A0D222}.EXE C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\WILDTANGENT\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{E0814F95-5380-4892-B8C8-7FA4B349EF46}.EXE ESET Log: [emailprotected] as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=7.00.6000.16981 (vista_gdr.091215-2244) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=b2ca1fda90706a47bad8743498afb32f # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-02-05 06:42:24 # local_time=2010-02-05 12:42:24 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1024 16777191 100 0 38039465 38039465 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=148897 # found=6 # cleaned=6 # scan_time=3468 C:\Qoobox\Quarantine\C\Program Files\SelectRebates\SelectRebates.exe.virprobably a variant of Win32/Genetik trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Qoobox\Quarantine\C\Program Files\SelectRebates\SelectRebatesApi.exe.virprobably a variant of Win32/Adware.SAHAgent application (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Qoobox\Quarantine\C\Program Files\SelectRebates\SelectRebatesUninstall.exe.virprobably a variant of Win32/Genetik trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Qoobox\Quarantine\C\WINDOWS\system32\rtutv.bak1.virWin32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Qoobox\Quarantine\C\WINDOWS\system32\rtutv.bak2.virWin32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Qoobox\Quarantine\C\WINDOWS\system32\rtutv.ini2.virWin32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined)00000000000000000000000000000000C Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.Here is the log. Things seem pretty good now. Malwarebytes' Anti-Malware 1.44 Database version: 3695 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 2/5/2010 6:54:51 PM mbam-log-2010-02-05 (18-54-51).txt Scan type: Quick Scan Objects scanned: 163873 Time elapsed: 8 minute(s), 37 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Windows XP Service Pack 3 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! AVG Free 8.5 ESET Online Scanner v3 Antivirus up to date! (On Access scanning disabled!) `````````````````````````````` Anti-malware/Other Utilities Check: Java(TM) 6 Update 13 Java(TM) SE Runtime Environment 6 Update 1 Java(TM) 6 Update 5 Java(TM) 6 Update 7 Java 2 Runtime Environment, SE v1.4.2_03 Out of date Java installed! Adobe FLASH Player 10 Adobe Reader 9 `````````````````````````````` Process Check: objlist.exe by Laurent AVG avgwdsvc.exe AVG avgtray.exe AVG avgrsx.exe AVG avgnsx.exe AVG avgemc.exe AVG avgemc.exe `````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) `````````End of Log``````````` Please download the newest version of Java from Java.com. Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them. Once old versions are gone, please install the newest version. == Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Firewall
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
I updated the Java as you instructed and I will review the information and install a firewall and antispyware. I have AVG currently installed but I am now on comcast and was wondering if there was any benefit to switch to McAfee that they provide free to customers?I do not like McAfee, but if you stay with AVG, you will have a more secure computer. |
|
| 1693. |
Solve : A few problems with my computer? |
|
Answer» Hi! I'm having a few problems with computer (32-bit vista).
Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. 3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer: http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial Post the log from SUPERAntiSpyware when you've accomplished that. 4. Please run a free online scan with the ESET Online Scanner
5. Post the following in your next reply:
Malwarebytes' Anti-Malware 1.44 Database version: 3691 Windows 6.0.6000 (Safe Mode) Internet Explorer 7.0.6000.16982 04/02/2010 5:59:25 PM mbam-log-2010-02-04 (17-59-05).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 393684 Time elapsed: 1 hour(s), 4 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No MALICIOUS items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a078f691-9c07-4af2-bf43-35e79eecf8b7} (Adware.Softomate) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\ProgramData\sysReserve.ini (Malware.Trace) -> No action taken. SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 02/04/2010 at 09:45 PM Application Version : 4.33.1000 Core Rules Database Version : 4548 Trace Rules Database Version: 2360 Scan type : Complete Scan Total Scan Time : 02:27:50 Memory items scanned : 756 Memory threats detected : 0 Registry items scanned : 8898 Registry threats detected : 0 File items scanned : 56352 File threats detected : 10 Adware.Tracking Cookie C:\Users\Izn\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Izn\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Users\Sian\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][3].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][2].txt C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt [emailprotected] as CAB hook log: OnlineScanner.ocx - registred OK (not sure why the last log is like that, is that normal?) If ESET online scanner produce no results, then yes - that is ok. Let's get a final malware check here: Please download Cheetah-Anti-Rogue, and save to your Desktop.
Heres the log: Cheetah-Anti-Rogue v1.2.17 by DragonMaster Jay Microsoft Windows [Version 6.0.6000] Date: 06/02/2010 - Time: 11:23:38 - Arch.: x86 -- Malware tools check -- CCleaner Trend Micro HijackThis 2.0.2 Malwarebytes' Anti-Malware SUPERAntiSpyware -- Known infection -- Extra message: Detection only. EOF To manually create a new Restore Point
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Results of screen317's Security Check version 0.99.1 Windows Vista (UAC is enabled) Out of date service pack!! `````````````````````````````` Antivirus/Firewall Check: Windows Security Center service is not running! This report may not be accurate! Windows Firewall Disabled! ESET Online Scanner v3 Norton 360 WMIC entry does not exist for antivirus; attempting automatic update. `````````````````````````````` Anti-malware/Other Utilities Check: Ad-Aware SUPERAntiSpyware Free Edition HijackThis 2.0.2 CCleaner Java(TM) 6 Update 18 Java(TM) SE Runtime Environment 6 Update 1 Java Auto Updater Out of date Java installed! Adobe Flash Player 10 Adobe Reader 8.1.3 Out of date Adobe Reader installed! `````````````````````````````` Process Check: objlist.exe by Laurent Norton ccSvcHst.exe Ad-Aware AAWService.exe Ad-Aware AAWTray.exe is disabled! `````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) `````````End of Log``````````` Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. ===== Please consider updating to Windows Vista Service Packs 1 & 2. Windows Vista Service Packs 1 & 2 contain all the updates released since the first release plus support for new types of hardware and emerging hardware standards. It is now available via Windows Update or as a standalone installation here. ===== Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations AntiSpyware
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and BECOME less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a LOT of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
|
|
| 1694. |
Solve : Atapi.sys Google Redirect Problem? |
|
Answer» You're WELCOME. |
|
| 1695. |
Solve : System infected.? |
|
Answer» I have a message on my desktop that my system is infected and spyware activity has been detected. I am also UNABLE to open any pdf FILES. I tried system restore but get a message" Application cannot be executed. the file is infected . please activate antivirus software.Also the computer is running very slow. How can I get rid of the spyware / malware?Quote from: tpayne on February 08, 2010, 10:40:27 AM I have a message on my desktop that my system is infected and spyware activity has been detected. I am also unable to open any pdf files. I tried system restore but get a message" Application cannot be executed. the file is infected . please activate antivirus software.Also the computer is running very slow. How can I get rid of the spyware / malware?system is windows XPPlease download Cheetah-Anti-Rogue, and save to your Desktop.
Here is the log Cheetah-Anti-Rogue v1.2.17 by DragonMaster Jay Microsoft Windows XP [Version 5.1.2600] Date: 02/08/2010 - Time: 17:35:22 - Arch.: x86 -- Malware tools check -- SUPERAntiSpyware -- Known infection -- C:\Program Files\Internet Explorer\msimg32.dll (Adw.MyWebSearch) C:\Documents and Settings\Terry\Application Data\Microsoft\Internet Explorer\Desktop.htt (Trj.FakeAlert) Extra message: Detection only. EOF Please download Malwarebytes Anti-Malware from Malwarebytes.org. Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just FOLLOW the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. |
|
| 1696. |
Solve : Struggling with slow m/c, LONG re-boot and lost HDD space? |
|
Answer» Hi, hope you can help me. |
|
| 1697. |
Solve : Google Redirection and Others? |
|
Answer» Hi, and sorry if I previously posted to another thread. I didn't realize that I wasn't supposed to do that. |
|
| 1698. |
Solve : NvCplDaemon? |
|
Answer» I am running MSI/SpywareBlaster and web of TRUST and I have Comodo registry cleaner after running registry cleaner I clicked on the startup tab and noticed this NvCplDaemon what is it ? |
|
| 1699. |
Solve : HP Pavillion ZD7000 has a virus, trojan?! Help!? |
|
Answer» I was useing my Hp laptop last week and i download a torrent it was windows Chicago which was made in 1993 (so they say) and i used Bit Torrent to fully download it. the next DAY i boot it up and the welcome screen loads longer and the following ERROR shows up: |
|
| 1700. |
Solve : computer slow & hanging up in internet...had a trojan (see below)? |
|
Answer» Hi, not long ago I had a trojan, which supposedly i got rid of...when I start my computer it says that C:\progra1/my WEB not found..My computer has gotten horribly slow within the last 3 wks and when I click on something to look at on the internet it will hang up but after a few minutes it will unhang. I'm a medical transcriptionist and can't be down...Quote I'm a medical transcriptionist and can't be down... Then you have a company computer right? What about tech support? no..I'm self employed.Download TrendMicro HijackThis.exe (HJT) to the desktop. * Double-click on HJTInstall. * Click on the Install button. * It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe. * Upon install, HijackThis should open for you. * Important! If using WINDOWS Vista or Windows 7, close HijackThis. Now right-click HijackThis and Run As Administrator * Click on the Do a system scan and save a log file button * HijackThis will scan and then a log will open in notepad. * Copy and then paste the entire contents of the log in your post. * Do not have HijackThis fix ANYTHING yet. Most of what it finds will be harmless or even required. |
|