Due to the large numbers of HJT logs being posted, there are four things that you need to be aware of.
1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.
2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time, I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!
3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.
4) Back-ups can get lost or damaged, so make two if the files are that important to you!
Assuming you don't already have it installed, download a copy of HJTInstall.exe from here and save it to your Desktop
Double click HJTInstall.exe to begin installation.
Accept the installation location, which by default is C:\Program Files\Trend Micro\HijackThis or click the Browse… button if you want to chose somewhere else and then click Install
Once HJT has installed, a shortcut will be created on your Desktop and HJT will run automatically.
You will need to accept the EULA, if it appears, to be able to use the tool.
When HJT opens, click on the Do a system scan and save a log file button.
When HJT has finished scanning, a window entitled "hijackthis.log" will open - when you close this window the log will be saved into the Hijackthis folder.
1. I have only posted here and will continue to monitor this posting.
2. Here is the log:
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:45:04, on 3/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Take a trip to this webpage for download links and instructions for running Combofix by sUBs: http://www.bleepingcomputer.com/combofix/how-to-use-combofix *
Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start.
When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply.
Post a fresh HJT log as well.
Let me know how the PC is behaving.
* There are two points to note from the instructions page:
1) The Recovery Console.
It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete it's removal tasks without the installation of the Console, so you are free to choose whether you want to complete this step, but it is in your interests to do so.
2) Disabling your Anti-Virus.
CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for!
Loaded Combofix and did the recovery console. Ran for a bit then rebooted to my normal screen, but without the windows start button or quick start tool bar, so no way to control the computer. The mouse works, and the virus remover 2009 popups continue. There has been no log displayed and it has been running an hour.
Virus Remover 2009 is still poping up
Combo log:
ComboFix 09-03-10.03 - Gregg 2009-03-11 16:31:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2637 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
255 — E O F — 2009-03-11 07:02:26
New HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:52:35, on 3/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Log.txt:
Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-03-12 16:11:32
Microsoft Windows XP Professional Service Pack 3
System drive C: has 170 GB (60%) free of 286 GB
Total RAM: 3071 MB (84% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:11:37, on 3/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
nfo.txt logfile of random's system information tool 1.05 2009-03-12 16:11:39
======Uninstall list======
–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 10 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Amazon Unbox Video–>C:\Program Files\InstallShield Installation Information\{54A4839E-87F8-4BD1-9682-A349E9943F0A}\setup.exe -runfromtemp -l0x0409
Apple Mobile Device Support–>MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Avanquest update–>C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\setup.exe -runfromtemp -l0x0009 -removeonly
AviSynth 2.5–>"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Belarc Advisor 7.2–>C:\PROGRA~1\Belarc\Advisor\Uninstall.exe C:\PROGRA~1\Belarc\Advisor\INSTALL.LOG
Canon iP1600–>C:\WINDOWS\system32\CNMCP75.exe "-PRINTERNAMECanon iP1600" "-HELPERDLLC:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600 Installer\Inst2\cnmis.dll" "-RCDLLcnmi0409.dll"
Compel Adaptec WinASPI–>"C:\Program Files\WinASPI\unins000.exe"
Critical Update for Windows Media Player 11 (KB959772)–>"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
DivX Codec–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter–>C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player–>C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters–>C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player–>C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Google Toolbar for Internet Explorer–>"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)–>C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)–>C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB961118)–>"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
IDT Audio–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe" -l0x9 -remove -removeonly
iolo technologies' System Mechanic Professional–>"C:\Program Files\iolo\System Mechanic Professional\unins000.exe"
iTunes–>MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
LG USB Modem Drivers–>MsiExec.exe /I{FA02ACAC-9E14-4878-A257-92A22A647C2C}
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Maxtor MaxBlast–>MsiExec.exe /X{81A60A13-224D-4637-8203-3EAC03B121A4}
McAfee SecurityCenter–>C:\Program Files\McAfee\MSC\mcuninst.exe
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2–>MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2–>MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1–>C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1–>MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
NVIDIA Drivers–>C:\WINDOWS\System32\nvudisp.exe UninstallGUI
Picasa 3–>"C:\Program Files\Google\Picasa3\Uninstall.exe"
PowerDVD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PrimoPDF–>"C:\WINDOWS\PrimoPDF4\uninstall.exe" "/U:C:\Program Files\activePDF\PrimoPDF\Uninstall\uninstallPrimoPDF4.xml"
QuickTime–>MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
Security Update for Windows Internet Explorer 7 (KB938127-v2)–>"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)–>"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)–>"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)–>"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)–>"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958215)–>"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)–>"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)–>"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)–>"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960714)–>"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)–>"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
TransferMy DVD–>C:\Program Files\InstallShield Installation Information\{7913F011-1CB8-45F4-B4F4-C31AADFD21FB}\setup.exe -runfromtemp -l0x0009 -removeonly
TuneRanger–>MsiExec.exe /X{3E56BE35-E61F-48B1-AF09-7099ABA91CD0}
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)–>"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
VC80CRTRedist - 8.0.50727.762–>MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
Visual C++ 2008 x86 Runtime - (v9.0.30729)–>MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01–>C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
Windows Defender–>MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
Windows Internet Explorer 7–>"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live OneCare safety scanner–>RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
======Security center information======
AV: McAfee VirusScan
FW: McAfee Personal Firewall
System event log
Computer Name: GREGG-G
Event Code: 7
Message: The device, \Device\CdRom0, has a bad block.
Record Number: 2904
Source Name: Cdrom
Time Written: 20090202131400.000000-360
Event Type: error
User:
Computer Name: GREGG-G
Event Code: 7
Message: The device, \Device\CdRom0, has a bad block.
Record Number: 2903
Source Name: Cdrom
Time Written: 20090202131357.000000-360
Event Type: error
User:
Computer Name: GREGG-G
Event Code: 7
Message: The device, \Device\CdRom0, has a bad block.
Record Number: 2902
Source Name: Cdrom
Time Written: 20090202131354.000000-360
Event Type: error
User:
Computer Name: GREGG-G
Event Code: 7
Message: The device, \Device\CdRom0, has a bad block.
Record Number: 2901
Source Name: Cdrom
Time Written: 20090202131351.000000-360
Event Type: error
User:
Computer Name: GREGG-G
Event Code: 7
Message: The device, \Device\CdRom0, has a bad block.
Record Number: 2900
Source Name: Cdrom
Time Written: 20090202131349.000000-360
Event Type: error
User:
Application event log
Computer Name: GREGG-G
Event Code: 1000
Message: Performance counters for the MSDTC (MSDTC) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.
Record Number: 5
Source Name: LoadPerf
Time Written: 20090110125417.000000-360
Event Type: information
User:
Computer Name: GREGG-G
Event Code: 1000
Message: Performance counters for the TermService (Terminal Services) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.
Record Number: 4
Source Name: LoadPerf
Time Written: 20090110125415.000000-360
Event Type: information
User:
Computer Name: GREGG-G
Event Code: 1000
Message: Performance counters for the RemoteAccess (Routing and Remote Access) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.
Record Number: 3
Source Name: LoadPerf
Time Written: 20090110125244.000000-360
Event Type: information
User:
Computer Name: GREGG-G
Event Code: 1000
Message: Performance counters for the PSched (PSched) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.
Record Number: 2
Source Name: LoadPerf
Time Written: 20090110125233.000000-360
Event Type: information
User:
Computer Name: GREGG-G
Event Code: 1000
Message: Performance counters for the RSVP (QoS RSVP) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.
Record Number: 1
Source Name: LoadPerf
Time Written: 20090110125232.000000-360
Event Type: information
User:
Pay a visit to the Kaspersky Online Scanner 7 - I.E. is preferred for this scan.
Read the Information panel and then click Accept.
Allow the ActiveX download if necessary.
Both the anti-virus engine and database will need to be downloaded, which may take a little time.
Once this has been completed, select My Computer from the Scan section on the left hand side.
Put the kettle on!
Although it is recommended by Kaspersky that you should disable your anti-virus scanner before starting this scan, it should work OK with it still active - it does on my PC.
Although you may find the scan speed increases if you carry out this step, I never like to disable my resident scanner while online, so I don't.
When the scan has completed, click View scan report at the bottom.
Click Save Report As…
Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
Click Save and pick a location for the file - the Desktop is always handy.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, March 12, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, March 12, 2009 23:56:50
Records in database: 1892884
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Files scanned: 71719
Threat name: 1
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 00:54:58
File name / Threat name / Threats count
C:\WINDOWS\system32\userinit.exe/C:\WINDOWS\system32\userinit.exe Infected: Trojan-Downloader.Win32.FraudLoad.dst 1
C:\WINDOWS\system32\userinit.exe Infected: Trojan-Downloader.Win32.FraudLoad.dst 1
The selected area was scanned.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:10:29, on 3/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
I keep having to run explorer to get anything up on my screen. How do I fix that?
One of the files on your computer appears to be infected or has been replaced with a malicious version, and this may be the cause of the issue. We'll deal with that first and see if it solves the problem. Can you tell me how long this has been happening?
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.
Preparation
1) Download SDFix by AndyManchesta from here and save it to your Desktop.
Double click SDFix.exe and it will extract the files to a folder on the drive that contains the Windows Directory - typically C:\SDFix.
2) Log off from the internet and disconnect your modem cable for the duration of the fix.
Removal
1) Boot into Safe Mode:
If the computer is running, shut down Windows, and then turn off the power.
Wait 30 seconds, and then turn the computer on.
Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
Ensure that the Safe Mode option is selected.
Press Enter. The computer then begins to start in Safe mode.
Login on your usual account.
2) Navigate to and open the SDFix folder and double click RunThis.bat to begin the fix.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process then display Finished - press any key to end the script and load your desktop icons.
Once the desktop icons load, the SDFix report will open on screen and a copy will be saved into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Post a new HJT log, Report.txtAND a description of how your PC is running.
Sat 17 Jan 2009 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sun 11 Jan 2009 9,934,392 A..H. — "C:\Program Files\Google\Picasa3\setup.exe"
Wed 11 Mar 2009 20,487 A.SHR — "C:\Program Files\McAfee\MQC\MRU.bak"
Wed 11 Mar 2009 265 A.SHR — "C:\Program Files\McAfee\MQC\qcconf.bak"
Sat 17 Jan 2009 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sat 17 Jan 2009 4,348 …H. — "C:\Documents and Settings\Gregg\Application Data\Real\rhapsody\wmlicbackup\drmv1key.bak"
Sat 17 Jan 2009 20 A..H. — "C:\Documents and Settings\Gregg\Application Data\Real\rhapsody\wmlicbackup\drmv1lic.bak"
Sat 17 Jan 2009 312 …H. — "C:\Documents and Settings\Gregg\Application Data\Real\rhapsody\wmlicbackup\drmv2key.bak"
Sat 17 Jan 2009 1,536 A..H. — "C:\Documents and Settings\Gregg\Application Data\Real\rhapsody\wmlicbackup\drmv2lic.bak"
Sun 28 Jul 2002 31,744 A..H. — "C:\Documents and Settings\Gregg\My Documents\My Documents\Data files\New Job Stuff\~WRL0005.tmp"
Sun 28 Jul 2002 32,768 A..H. — "C:\Documents and Settings\Gregg\My Documents\My Documents\Data files\New Job Stuff\~WRL0205.tmp"
Sun 28 Jul 2002 32,256 A..H. — "C:\Documents and Settings\Gregg\My Documents\My Documents\Data files\New Job Stuff\~WRL1668.tmp"
Sun 7 Jan 2001 45,056 A..H. — "C:\Documents and Settings\Gregg\My Documents\My Documents\Old Data\Karen's work\~WRL1200.tmp"
Finished!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34:34, on 3/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal