This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware Defender 2009

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi What the Tech Team!! :wavey: I have Windows XP and the other day Malware Defender 2009 somehow showed up and tries to run constantly! It also has a fake "windows security center" window that pops up and says i need to activate the Malware Defender. I know the Program is Fake i just cant seem to get rid of it!! Since its been on my computer I have pop ups galore when im on Firefox and my computer is running really really slow!! My friend told me to come here you've helped her with her computer on more than one occasion! Any who…heres my log!! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:34:02 AM, on 3/31/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\WINDOWS\Explorer.EXE C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe c:\windows\system32\hkcmd.exe c:\windows\system32\igfxpers.exe c:\windows\system32\dla\dlactrlw.exe c:\program files\hp\hp software update\hpwuschd2.exe c:\program files\dell support center\bin\sprtcmd.exe c:\progra~1\mcafee\spamki~1\mskagent.exe c:\windows\system32\rundll32.exe c:\program files\itunes\ituneshelper.exe c:\program files\common files\installshield\updateservice\issch.exe c:\program files\dell\media experience\dmxlauncher.exe c:\program files\java\jre6\bin\jusched.exe c:\program files\dellsupport\dsagnt.exe c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe c:\program files\cyberdefender\antispyware\cdasc9.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\WINDOWS\system32\igfxsrvc.exe c:\program files\mozilla firefox\firefox.exe C:\Program Files\Malware Defender 2009\malwaredef.exe C:\WINDOWS\system32\wcenter.exe c:\program files\trend micro\hijackthis\hijackthis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) R3 - URLSearchHook: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll O2 - BHO: McAfee Anti-Phishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll O2 - BHO: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Adobe PDF Reader Link Helper - {B782EDE4-CCB3-4E3E-981F-96C68116F38C} - C:\WINDOWS\system32\AcroIEHelpe.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O3 - Toolbar: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter O4 - HKLM\..\Run: [MSKAGENTEXE] c:\progra~1\mcafee\spamki~1\mskagent.exe O4 - HKLM\..\Run: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime O4 - HKLM\..\Run: [CPM53824205] Rundll32.exe "c:\windows\system32\zazofose.dll",a O4 - HKLM\..\Run: [50b17199] rundll32.exe "C:\WINDOWS\system32\sazisuhi.dll",b O4 - HKLM\..\Run: [hitejabofu] Rundll32.exe "C:\WINDOWS\system32\wapetose.dll",s O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe" O4 - HKLM\..\Run: [malwaredef] C:\Program Files\Malware Defender 2009\malwaredef.exe O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0 O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\cdasc9.exe" /minimize O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee.com\shredder\SHRED32.EXE" /q C:\WINDOWS\Prefetch\MALWAR~1.SH! C:\WINDOWS\Prefetch\WCENTE~1.SH! O4 - HKUS\S-1-5-19\..\Run: [hitejabofu] Rundll32.exe "C:\WINDOWS\system32\wapetose.dll",s (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [hitejabofu] Rundll32.exe "C:\WINDOWS\system32\wapetose.dll",s (User 'NETWORK SERVICE') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://*.mcafee.com O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O20 - AppInit_DLLs: C:\WINDOWS\system32\kuyukiza.dll c:\windows\system32\zazofose.dll O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zazofose.dll O21 - SSODL: HardwareDrivers - {2EA7E4D0-622A-479D-A00F-C1529665D5F6} - C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll O21 - SSODL: DriversLoad - {52745E8B-F4E4-4C0C-963F-2CB9675B4F1F} - C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\egdieexaru.dll O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zazofose.dll O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\Dell Game Console\GameConsoleService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe – End of file - 12566 bytes Thanks so much for all you do!!! Mary.
Hi and :welcome:

Please do the following



Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

  • Notes:
  • Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi CB thank you for your time.. I tried unsuccessfully to run Combo fix.. I got to the "agreement" window and when i clicked yes it shut down? Idea's?
Try this:

Click the Windows 'Start' button > Select 'Run' - then copy/paste the following into the open run box & click OK:

"%userprofile%\desktop\combofix.exe"
UGGHH… Same result.. :( I'm sorry I'm being so difficult when it opens that Malware Defender 2009 pops up with its "scan" do you think this is affecting the ComboFix? Mary.
Yes it could be an issue,

Lets try another tactic…

Please do this


Follow these steps to uninstall Combofix
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK.
  • Note the space between the ..X and the /U, it needs to be there.
[external image: Posted Image]

Then do the following



Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
Ok CB, Here's whats going on… I disabled all my virus ect. protection and made sure my script blocking was disabled as well. I redownloaded ComboFix and saved it just as instructed and still no go… The Malware Defender Pops up as soon as I open Combo fix, then the security window opens and thats when it shuts down. I have tried to uninstall the malware defender, no luck it just reinstalls itself instantly. I also ended the process tree for "wcenter.exe" which is directly related to the program and tried to run ComboFix while it was trying to restart to no avail… Thanks again for your patience! Mary.
Lets try a different tool then

please do the following

Download and Run SmitfraudFix

Please download SmitfraudFix
Run the file, it will extract SmitfraudFix to its own folder and run.

Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
ok so thats not working either..which reminds me, sorry i didnt think of this earlier, I downloaded a game from Dell the other day when the malware defender was popping up and it wouldnt ever open that program either? it downloaded it just like it is these but wouldnt open… Mary.
Im may be overthinking this all but i cant open the conficker debugger link that i found in the "what the heck" forum on here, it says "timed out" and when i try to reload it says the same thing?!…do you think thats whats wrong with my computer? would it kind of explain why i cant open any of the programs you are asking me to?
Hi maryloulea,

I have consulted with my colleagues and we have come up with several things for you to try

Have you tried running any of these programs in safe mode?

If not try that first:

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY repeatedly,
  • this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
  • go into your usual account

Try the Combo-fix program first…if no go, try the Smitfraudfix

If that works - skip the next steps and post back the logs:

if not - carry on:

Nest I would like you to try is this: NOTE: I know the program will probably not run, but please check your private messages first in your user control panel before running it.

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



If it simply will not run then please do the following:

If the above program runs - then please skip this next step and post back the log from MBAM

Thanks:


As we are going to be making some changes to the registry,
we need to first back it up in case we encounter some unforeseen problems.

To do this:

Please go to Start > Run
Paste in the following line:regedit /e c:\registrybackup.reg
Click OK.
It won't appear to be doing anything, that's normal.
Your mouse pointer may turn to an hour glass for a minute.
Please continue when it no longer has the hour glass.

NEXT

Open Notepad

Click Start >Run type notepad into the run box click OK
Click Format and make certain that Word Wrap is NOT checked.

Copy the text inside of the code box, put your mouse cursor at the very beginning of the text and then hold down the left button and drag your mouse so that all of the text is highlighted. Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Now paste the copied text into the open notepad. To do this click in the blank page so that your cursor is flashing there and press CTRL+V (or right click and choose 'paste')

Note: There must be NO blank lines in front of the pasted text, but ensure that there is a blank line at the end of the text, otherwise the registry merge will not work.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B782EDE4-CCB3-4E3E-981F-96C68116F38C}]

[-HKEY_CLASSES_ROOT\CLSID\{B782EDE4-CCB3-4E3E-981F-96C68116F38C}]

[-HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}]

[-HKEY_CLASSES_ROOT\CLSID\{2EA7E4D0-622A-479D-A00F-C1529665D5F6}]

[-HKEY_CLASSES_ROOT\CLSID\{52745E8B-F4E4-4C0C-963F-2CB9675B4F1F}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"="localhost"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
@="{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CPM53824205"=-
"50b17199"=-
"hitejabofu"=-
"malwaredef"=-

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "hitejabofu"=- 

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "hitejabofu"=- 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"=-

Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in fixme.reg as the file name, then choose All Files as the save as file type.
Then click the save button.
Once you have clicked the save button, close Notepad.

You should now see a file on your desktop that looks like this:

[external image: Posted Image]

Locate the fixme.reg icon on your desktop and double click it, an information box will pop up asking if you want to merge the information in the file into the registry, click YES.

Once the file has run, the information will have merged with your registry so you can delete fixme.reg from your desktop as you won't be needing it any more.

NEXT

Please Open Notepad
Click Start >Run type notepad into the run box click OK
Click Format and make certain that Word Wrap is NOT checked.

Copy
all the text inside of the code box, put your mouse cursor at the very beginning of the text and then hold down the left button and drag your mouse so that all of the text is highlighted. Press Ctrl+C (or right click on the highlighted section and choose 'copy')

@echo off
attrib -s -h -r "C:\Program Files\Malware Defender 2009"
del /f /q "C:\Program Files\Malware Defender 2009"
attrib -s -h -r C:\WINDOWS\system32\wcenter.exe
del /f /q C:\WINDOWS\system32\wcenter.exe
attrib -s -h -r C:\WINDOWS\system32\AcroIEHelpe.dll
del /f /q C:\WINDOWS\system32\AcroIEHelpe.dll
attrib -s -h -r c:\windows\system32\zazofose.dll
del /f /q c:\windows\system32\zazofose.dll
attrib -s -h -r C:\WINDOWS\system32\sazisuhi.dll
del /f /q C:\WINDOWS\system32\sazisuhi.dll
attrib -s -h -r C:\WINDOWS\system32\wapetose.dll
del /f /q C:\WINDOWS\system32\wapetose.dll
attrib -s -h -r "C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll"
del /f /q  "C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll"
attrib -s -h -r "C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\egdieexaru.dll"
del /f /q "C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\Drivers\egdieexaru.dll"
del %0

Now paste the copied text into the open notepad. To do this click in the blank page so that your cursor is flashing there and press CTRL+V (or right click and choose 'paste')

Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in runme.bat as the file name, then choose All Files as the save as file type.
Then click the save button.

Once you have clicked the save button, close Notepad.

You will now have a file on your desktop that looks like this

[external image: Posted Image]

Locate runme.bat on your Desktop and double-click it

A black window will flash up and disappear again, and runme.bat will be deleted.

This is normal.
Good Morning CB!!

Finally some good news, I was in fact able to run ComboFix in Safe Mode..
It wasnt able to install the Recovery Tool, i tried to cancel the scan but it ran anyway, it said it was unable to install it.
Here is the Log from the scan.. my machine seems to be running better it feels so good to know we are starting to make some progress!! I still have a few pop ups but no where near what it was!! I am also having some program crashes on my antivirus programs..not sure if its due to this or not! I will also rerun HJT and post its log next…

Mary!





ComboFix 09-03-31.01 - Lea Family 2009-04-01 7:21:00.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.809 [GMT -5:00]
Running from: c:\documents and settings\[removed]\desktop\combofix.exe
AV: CyberDefender Internet Security *On-access scanning enabled* (Updated)
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers
c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\c.cgm
c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\egdieexaru.dll
c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll
c:\documents and settings\Lea Family\Start Menu\Programs\Malware Defender 2009
c:\documents and settings\Lea Family\Start Menu\Programs\Malware Defender 2009\Malware Defender 2009.lnk
c:\documents and settings\Lea Family\Start Menu\Programs\Malware Defender 2009\Uninstall.lnk
c:\program files\Malware Defender 2009
c:\program files\Malware Defender 2009\conf.cfg
c:\program files\Malware Defender 2009\malwaredef.exe
c:\program files\Malware Defender 2009\mbase.vdb
c:\program files\Malware Defender 2009\quarantine.vdb
c:\program files\Malware Defender 2009\queue.vdb
c:\program files\Malware Defender 2009\uninstall.exe
c:\program files\Malware Defender 2009\vbase.vdb
c:\windows\IE4 Error Log.txt
c:\windows\system32\AccessibleMarshal.dll
c:\windows\system32\AcroIEHelpe.dll
c:\windows\system32\cks
c:\windows\system32\cks\lea [removed][1].txt
c:\windows\system32\cks\lea [removed][2].txt
c:\windows\system32\cks\lea family@adbrite[1].txt
c:\windows\system32\cks\lea family@apmebf[1].txt
c:\windows\system32\cks\lea family@atdmt[1].txt
c:\windows\system32\cks\lea family@doubleclick[1].txt
c:\windows\system32\cks\lea family@doubleclick[2].txt
c:\windows\system32\cks\lea [removed][1].txt
c:\windows\system32\cks\lea family@hitbox[1].txt
c:\windows\system32\cks\lea [removed][1].txt
c:\windows\system32\cks\lea family@tribalfusion[1].txt
c:\windows\system32\cks\lea family@tribalfusion[2].txt
c:\windows\system32\cks\lea family@zedo[1].txt
c:\windows\system32\cks\lea family@zedo[2].txt
c:\windows\system32\components
c:\windows\system32\components\aboutRights.js
c:\windows\system32\components\aboutRobots.js
c:\windows\system32\components\browser.xpt
c:\windows\system32\components\browserdirprovider.dll
c:\windows\system32\components\brwsrcmp.dll
c:\windows\system32\components\FeedConverter.js
c:\windows\system32\components\FeedProcessor.js
c:\windows\system32\components\FeedWriter.js
c:\windows\system32\components\fuelApplication.js
c:\windows\system32\components\jsconsole-clhandler.js
c:\windows\system32\components\nsAddonRepository.js
c:\windows\system32\components\nsBadCertHandler.js
c:\windows\system32\components\nsBlocklistService.js
c:\windows\system32\components\nsBrowserContentHandler.js
c:\windows\system32\components\nsBrowserGlue.js
c:\windows\system32\components\nsContentDispatchChooser.js
c:\windows\system32\components\nsContentPrefService.js
c:\windows\system32\components\nsDefaultCLH.js
c:\windows\system32\components\nsDownloadManagerUI.js
c:\windows\system32\components\nsExtensionManager.js
c:\windows\system32\components\nsHandlerService.js
c:\windows\system32\components\nsHelperAppDlg.js
c:\windows\system32\components\nsLivemarkService.js
c:\windows\system32\components\nsLoginInfo.js
c:\windows\system32\components\nsLoginManager.js
c:\windows\system32\components\nsLoginManagerPrompter.js
c:\windows\system32\components\nsMicrosummaryService.js
c:\windows\system32\components\nsPlacesTransactionsService.js
c:\windows\system32\components\nsPostUpdateWin.js
c:\windows\system32\components\nsProxyAutoConfig.js
c:\windows\system32\components\nsSafebrowsingApplication.js
c:\windows\system32\components\nsSearchService.js
c:\windows\system32\components\nsSearchSuggestions.js
c:\windows\system32\components\nsSessionStartup.js
c:\windows\system32\components\nsSessionStore.js
c:\windows\system32\components\nsSetDefaultBrowser.js
c:\windows\system32\components\nsSidebar.js
c:\windows\system32\components\nsTaggingService.js
c:\windows\system32\components\nsTryToClose.js
c:\windows\system32\components\nsUpdateService.js
c:\windows\system32\components\nsUrlClassifierLib.js
c:\windows\system32\components\nsUrlClassifierListManager.js
c:\windows\system32\components\nsURLFormatter.js
c:\windows\system32\components\nsWebHandlerApp.js
c:\windows\system32\components\pluginGlue.js
c:\windows\system32\components\storage-Legacy.js
c:\windows\system32\components\txEXSLTRegExFunctions.js
c:\windows\system32\components\WebContentConverter.js
c:\windows\system32\dtw5d
c:\windows\system32\dtw5d\1396_0000000001.key
c:\windows\system32\dtw5d\1396_0000000002.clb
c:\windows\system32\dtw5d\1396_0000000003.htm
c:\windows\system32\dtw5d\1420_0000000041.clb
c:\windows\system32\dtw5d\1420_0000000042.htm
c:\windows\system32\dtw5d\1420_0000000043.frm
c:\windows\system32\dtw5d\1420_0000000044.pst
c:\windows\system32\dtw5d\1420_0000000046.clb
c:\windows\system32\dtw5d\1420_0000000047.htm
c:\windows\system32\dtw5d\188_0000000007.key
c:\windows\system32\dtw5d\188_0000000008.clb
c:\windows\system32\dtw5d\188_0000000009.htm
c:\windows\system32\dtw5d\252_0000000010.key
c:\windows\system32\dtw5d\252_0000000011.clb
c:\windows\system32\dtw5d\252_0000000012.htm
c:\windows\system32\dtw5d\2696_0000000029.clb
c:\windows\system32\dtw5d\2696_0000000030.htm
c:\windows\system32\dtw5d\2996_0000000013.key
c:\windows\system32\dtw5d\2996_0000000014.clb
c:\windows\system32\dtw5d\2996_0000000015.htm
c:\windows\system32\dtw5d\3688_0000000004.key
c:\windows\system32\dtw5d\3688_0000000005.clb
c:\windows\system32\dtw5d\3688_0000000006.htm
c:\windows\system32\dtw5d\3724_0000000032.clb
c:\windows\system32\dtw5d\3724_0000000033.htm
c:\windows\system32\dtw5d\3788_0000000017.clb
c:\windows\system32\dtw5d\3788_0000000018.htm
c:\windows\system32\dtw5d\4440_0000000026.clb
c:\windows\system32\dtw5d\4440_0000000027.htm
c:\windows\system32\dtw5d\4592_0000000048.key
c:\windows\system32\dtw5d\4592_0000000049.clb
c:\windows\system32\dtw5d\4592_0000000050.htm
c:\windows\system32\dtw5d\4592_0000000051.frm
c:\windows\system32\dtw5d\4592_0000000052.frm
c:\windows\system32\dtw5d\4592_0000000053.frm
c:\windows\system32\dtw5d\4592_0000000054.pst
c:\windows\system32\dtw5d\4592_0000000055.pst
c:\windows\system32\dtw5d\4592_0000000056.key
c:\windows\system32\dtw5d\4592_0000000057.clb
c:\windows\system32\dtw5d\4592_0000000058.htm
c:\windows\system32\dtw5d\4592_0000000059.frm
c:\windows\system32\dtw5d\4592_0000000060.key
c:\windows\system32\dtw5d\4592_0000000061.htm
c:\windows\system32\dtw5d\4592_0000000062_ifrm.htm
c:\windows\system32\dtw5d\4592_0000000063_ifrm.htm
c:\windows\system32\dtw5d\4592_0000000064.frm
c:\windows\system32\dtw5d\5276_0000000022.key
c:\windows\system32\dtw5d\5276_0000000023.clb
c:\windows\system32\dtw5d\5276_0000000024.htm
c:\windows\system32\dtw5d\5280_0000000034.key
c:\windows\system32\dtw5d\5280_0000000035.clb
c:\windows\system32\dtw5d\5280_0000000036.htm
c:\windows\system32\dtw5d\5280_0000000037_ifrm.htm
c:\windows\system32\dtw5d\5280_0000000038_ifrm.htm
c:\windows\system32\dtw5d\5280_0000000039.pst
c:\windows\system32\dtw5d\6136_0000000019.key
c:\windows\system32\dtw5d\6136_0000000020.clb
c:\windows\system32\dtw5d\6136_0000000021.htm
c:\windows\system32\dtw5d\AcroRd32_UAs001.dat
c:\windows\system32\dtw5d\AcroRd32_UAs002.dat
c:\windows\system32\dtw5d\buildintime-wt_UAs001.dat
c:\windows\system32\dtw5d\buildintime-wt_UAs002.dat
c:\windows\system32\dtw5d\cdasc9_UAs001.dat
c:\windows\system32\dtw5d\cdasc9_UAs002.dat
c:\windows\system32\dtw5d\cdasc9_UAs003.dat
c:\windows\system32\dtw5d\cdasc9_UAs004.dat
c:\windows\system32\dtw5d\cdasc9_UAs005.dat
c:\windows\system32\dtw5d\cdasc9_UAs006.dat
c:\windows\system32\dtw5d\cdasc9_UAs007.dat
c:\windows\system32\dtw5d\cdasc9_UAs008.dat
c:\windows\system32\dtw5d\cdasc9_UAs009.dat
c:\windows\system32\dtw5d\cdasc9_UAs010.dat
c:\windows\system32\dtw5d\cdinstx_UAs001.dat
c:\windows\system32\dtw5d\cdinstx_UAs002.dat
c:\windows\system32\dtw5d\countyfair-wt_UAs001.dat
c:\windows\system32\dtw5d\countyfair-wt_UAs002.dat
c:\windows\system32\dtw5d\daisy-wt_UAs001.dat
c:\windows\system32\dtw5d\download_snm-2.67_swpl_UAs001.dat
c:\windows\system32\dtw5d\dw20_UAs001.dat
c:\windows\system32\dtw5d\dwwin_UAs001.dat
c:\windows\system32\dtw5d\explorer_UAs004.dat
c:\windows\system32\dtw5d\farm2-wt_UAs001.dat
c:\windows\system32\dtw5d\farm2-wt_UAs002.dat
c:\windows\system32\dtw5d\farm2_UAs001.dat
c:\windows\system32\dtw5d\gameconsole-wt_UAs001.dat
c:\windows\system32\dtw5d\gameconsole-wt_UAs002.dat
c:\windows\system32\dtw5d\helpctr_UAs001.dat
c:\windows\system32\dtw5d\HelpHost_UAs001.dat
c:\windows\system32\dtw5d\HelpHost_UAs002.dat
c:\windows\system32\dtw5d\hprbupdate_UAs001.dat
c:\windows\system32\dtw5d\iexplore_UAs005.dat
c:\windows\system32\dtw5d\javaw_UAs001.dat
c:\windows\system32\dtw5d\jre-6u12-windows-i586-p-iftw_UAs001.dat
c:\windows\system32\dtw5d\jre-6u12-windows-i586-p-iftw_UAs002.dat
c:\windows\system32\dtw5d\jusched_UAs001.dat
c:\windows\system32\dtw5d\malwaredefender2009[1]_UAs001.dat
c:\windows\system32\dtw5d\malwaredefender2009[2]_UAs001.dat
c:\windows\system32\dtw5d\MsiExec_UAs001.dat
c:\windows\system32\dtw5d\mvtapp_UAs001.dat
c:\windows\system32\dtw5d\netbanke_2009.03.11.041751_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041751_lea family@atdmt[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041751_lea family@doubleclick[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041751_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041751_lea family@hitbox[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041752_lea family@adbrite[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041752_lea family@apmebf[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041752_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041752_lea family@tribalfusion[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041752_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.070953_lea family@apmebf[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.070953_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.070953_lea family@fastclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071003_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071446_lea family@atdmt[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071446_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071446_lea family@hitbox[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071457_lea family@atdmt[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071623_lea family@fastclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071936_lea family@fastclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071951_lea family@apmebf[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075436_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075436_lea family@hitbox[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075442_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075442_lea family@hitbox[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075447_lea family@hitbox[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075642_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075642_lea family@realmedia[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075648_lea family@fastclick[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.14.110537_lea family@fastclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.15.082844_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.15.082844_lea family@hitbox[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.15.083424_lea family@adbrite[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.16.092026_lea family@adbrite[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.085050_lea family@tribalfusion[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.085055_lea family@tribalfusion[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.085110_lea family@tribalfusion[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.094846_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101154_lea family@apmebf[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101154_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101154_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101154_lea family@hitbox[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101204_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101807_lea family@casalemedia[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124043_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124049_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124054_lea family@advertising[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124054_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124059_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124105_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124105_lea family@advertising[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124105_lea family@atdmt[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124110_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124115_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124120_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124125_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124131_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124136_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124141_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124141_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124146_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124146_lea family@atdmt[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124147_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124152_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124157_lea family@atdmt[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124157_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124203_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124208_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124213_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124218_lea family@atdmt[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124218_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124224_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.22.051346_lea family@advertising[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.23.055751_lea family@casalemedia[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.23.070251_lea family@casalemedia[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.24.102742_lea family@advertising[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.24.105303_lea family@tribalfusion[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.062112_lea family@fastclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.062118_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.062138_lea family@microsoftwindows.112.2o7[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.082940_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083015_lea family@advertising[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083021_lea family@advertising[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083026_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083031_lea family@advertising[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083552_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083659_lea family@fastclick[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083700_lea family@apmebf[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083705_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104213_lea family@casalemedia[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104219_lea family@casalemedia[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104401_lea family@tribalfusion[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104406_lea family@tribalfusion[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104412_lea family@doubleclick[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104412_lea family@tribalfusion[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.105030_lea family@advertising[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.114144_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.114144_lea family@hitbox[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.26.052414_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.26.052521_lea family@tribalfusion[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.062431_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.062437_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.062954_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.064149_lea family@trafficmp[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.064206_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.065039_lea family@trafficmp[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.065732_lea family@trafficmp[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.070332_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.074336_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.30.064004_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.30.064009_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.30.070812_lea family@casalemedia[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.055300_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.055306_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062059_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062109_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062220_lea family@2o7[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062220_lea family@msnportal.112.2o7[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062225_lea family@msnservices.112.2o7[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062942_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062952_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062958_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.063008_lea family@doubleclick[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.095208_lea family@atdmt[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.095615_lea family@atdmt[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.101945_lea family@apmebf[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.101945_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\ranchrush-wt_UAs001.dat
c:\windows\system32\dtw5d\ranchrush-wt_UAs002.dat
c:\windows\system32\dtw5d\SNM_UAs001.dat
c:\windows\system32\dtw5d\sprtcmd_UAs001.dat
c:\windows\system32\dtw5d\VRM2009_UAs001.dat
c:\windows\system32\dtw5d\win_UAs001.dat
c:\windows\system32\firefox.exe
c:\windows\system32\freebl3.dll
c:\windows\system32\korlg.ini
c:\windows\system32\ldshyr.old
c:\windows\system32\mozcrt19.dll
c:\windows\system32\nspr4.dll
c:\windows\system32\nss3.dll
c:\windows\system32\nssckbi.dll
c:\windows\system32\nssdbm3.dll
c:\windows\system32\nssutil3.dll
c:\windows\system32\nwklr.ini
c:\windows\system32\nwpp.ini
c:\windows\system32\nwwlnt.ini
c:\windows\system32\plc4.dll
c:\windows\system32\plds4.dll
c:\windows\system32\Plugins
c:\windows\system32\Plugins\npnul32.dll
c:\windows\system32\ppdnp.ini
c:\windows\system32\pporlg.ini
c:\windows\system32\smime3.dll
c:\windows\system32\softokn3.dll
c:\windows\system32\srvblck.tmp
c:\windows\system32\ssl3.dll
c:\windows\system32\UAs
c:\windows\system32\UAs\AcroRd32_UAs001.dat
c:\windows\system32\UAs\AcroRd32_UAs002.dat
c:\windows\system32\UAs\bb2_UAs001.dat
c:\windows\system32\UAs\buildintime-wt_UAs001.dat
c:\windows\system32\UAs\buildintime-wt_UAs002.dat
c:\windows\system32\UAs\cdasc9_UAs001.dat
c:\windows\system32\UAs\cdasc9_UAs002.dat
c:\windows\system32\UAs\cdasc9_UAs003.dat
c:\windows\system32\UAs\cdasc9_UAs004.dat
c:\windows\system32\UAs\cdasc9_UAs005.dat
c:\windows\system32\UAs\cdasc9_UAs006.dat
c:\windows\system32\UAs\cdasc9_UAs007.dat
c:\windows\system32\UAs\cdasc9_UAs008.dat
c:\windows\system32\UAs\cdasc9_UAs009.dat
c:\windows\system32\UAs\cdasc9_UAs010.dat
c:\windows\system32\UAs\cdinstx_UAs001.dat
c:\windows\system32\UAs\cdinstx_UAs002.dat
c:\windows\system32\UAs\countyfair-wt_UAs001.dat
c:\windows\system32\UAs\countyfair-wt_UAs002.dat
c:\windows\system32\UAs\crashreporter_UAs001.dat
c:\windows\system32\UAs\daisy-wt_UAs001.dat
c:\windows\system32\UAs\download_snm-2.67_swpl_UAs001.dat
c:\windows\system32\UAs\dsagnt_UAs001.dat
c:\windows\system32\UAs\dw20_UAs001.dat
c:\windows\system32\UAs\dwwin_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs002.dat
c:\windows\system32\UAs\Explorer_UAs003.dat
c:\windows\system32\UAs\explorer_UAs004.dat
c:\windows\system32\UAs\farm2-wt_UAs001.dat
c:\windows\system32\UAs\farm2-wt_UAs002.dat
c:\windows\system32\UAs\farm2_UAs001.dat
c:\windows\system32\UAs\firefox_UAs001.dat
c:\windows\system32\UAs\firefox_UAs002.dat
c:\windows\system32\UAs\firefox_UAs003.dat
c:\windows\system32\UAs\gameconsole-wt_UAs001.dat
c:\windows\system32\UAs\gameconsole-wt_UAs002.dat
c:\windows\system32\UAs\googletoolbarnotifier_UAs001.dat
c:\windows\system32\UAs\googletoolbarnotifier_UAs002.dat
c:\windows\system32\UAs\helpctr_UAs001.dat
c:\windows\system32\UAs\HelpHost_UAs001.dat
c:\windows\system32\UAs\HelpHost_UAs002.dat
c:\windows\system32\UAs\hprbupdate_UAs001.dat
c:\windows\system32\UAs\iexplore_UAs001.dat
c:\windows\system32\UAs\iexplore_UAs002.dat
c:\windows\system32\UAs\iexplore_UAs003.dat
c:\windows\system32\UAs\iexplore_UAs004.dat
c:\windows\system32\UAs\iexplore_UAs005.dat
c:\windows\system32\UAs\javaw_UAs001.dat
c:\windows\system32\UAs\jre-6u12-windows-i586-p-iftw_UAs001.dat
c:\windows\system32\UAs\jre-6u12-windows-i586-p-iftw_UAs002.dat
c:\windows\system32\UAs\jucheck_UAs001.dat
c:\windows\system32\UAs\jusched_UAs001.dat
c:\windows\system32\UAs\malwaredefender2009[1]_UAs001.dat
c:\windows\system32\UAs\malwaredefender2009[2]_UAs001.dat
c:\windows\system32\UAs\mcshell_UAs001.dat
c:\windows\system32\UAs\mcsvrcnt_UAs001.dat
c:\windows\system32\UAs\McSync_UAs001.dat
c:\windows\system32\UAs\mcupdmgr_UAs001.dat
c:\windows\system32\UAs\mcvsmap_UAs001.dat
c:\windows\system32\UAs\MsiExec_UAs001.dat
c:\windows\system32\UAs\msimn_UAs001.dat
c:\windows\system32\UAs\msimn_UAs002.dat
c:\windows\system32\UAs\mvtapp_UAs001.dat
c:\windows\system32\UAs\npswf32_flashutil_UAs001.dat
c:\windows\system32\UAs\ranchrush-wt_UAs001.dat
c:\windows\system32\UAs\ranchrush-wt_UAs002.dat
c:\windows\system32\UAs\SNM_UAs001.dat
c:\windows\system32\UAs\softwareupdate_UAs001.dat
c:\windows\system32\UAs\sprtcmd_UAs001.dat
c:\windows\system32\UAs\sprtsvc_UAs001.dat
c:\windows\system32\UAs\VRM2009_UAs001.dat
c:\windows\system32\UAs\win_UAs001.dat
c:\windows\system32\UAs\winlogon_UAs001.dat
c:\windows\system32\UAs\wmplayer_UAs001.dat
c:\windows\system32\updater.exe
c:\windows\system32\windmlp.ini
c:\windows\system32\worlg.ini
c:\windows\system32\xpcom.dll

.
((((((((((((((((((((((((( Files Created from 2009-03-01 to 2009-04-01 )))))))))))))))))))))))))))))))
.

2009-04-01 07:29 . 2009-04-01 07:30 d——– c:\windows\system32\UAs
2009-04-01 07:28 . 2009-04-01 07:30 d——– c:\windows\system32\Dtw5d
2009-04-01 07:18 . 2009-04-01 07:18 552 –a—— c:\windows\system32\d3d8caps.dat
2009-04-01 07:02 . 2006-07-17 11:48 d——– c:\documents and settings\Administrator\Application Data\Symantec
2009-04-01 07:02 . 2009-04-01 07:02 d——– c:\documents and settings\Administrator
2009-03-31 14:19 . 2008-12-12 00:45 d——– c:\windows\system32\SmitfraudFix
2009-03-31 14:11 . 2009-03-31 14:12 d—-c— C:\Combo-Fix
2009-03-31 13:17 . 2009-03-31 13:17 d—-c— C:\ComboFix1
2009-03-31 10:33 . 2009-03-31 10:33 d——– c:\program files\Trend Micro
2009-03-29 23:14 . 2009-03-29 23:14 381,440 –a—— c:\windows\system32\wcenter.exe
2009-03-29 22:23 . 2009-03-29 22:23 1,152 –a—— c:\windows\system32\windrv.sys
2009-03-29 22:17 . 2009-03-29 22:23 d——– c:\documents and settings\Lea Family\Application Data\GetRightToGo
2009-03-29 21:35 . 2009-03-29 21:35 d——– c:\documents and settings\Lea Family\Application Data\CyberDefender
2009-03-29 09:31 . 2009-03-29 09:31 73 –a—— c:\windows\st_affiliate.ini
2009-03-29 09:23 . 2009-03-29 09:23 63 –a—— c:\windows\av_affiliate.ini
2009-03-29 09:23 . 2009-03-29 09:23 63 –a—— c:\windows\as_affiliate.ini
2009-03-29 09:19 . 2009-03-29 21:31 d——– c:\program files\CyberDefender
2009-03-29 09:19 . 2009-03-29 09:16 67,424 –a—— c:\windows\system32\drivers\CDAVFS.sys
2009-03-28 10:32 . 2009-03-28 10:32 d——– c:\windows\system32\config\systemprofile\Application Data\SACore
2009-03-11 16:17 . 2009-03-31 18:22 d——– c:\windows\system32\cock
2009-03-10 18:43 . 2009-03-10 18:43 41,168 –a—— c:\windows\system32\ldshyf.old
2009-03-04 09:09 . 2009-03-04 09:07 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2009-03-04 09:05 . 2009-03-04 09:24 d——– c:\documents and settings\Lea Family\.housecall6.6
2009-03-04 09:00 . 2009-03-23 16:15 d——– c:\program files\Panda Security
2009-03-04 01:33 . 2009-04-01 06:02 1,546 –a—— c:\windows\system32\urhtps.dat
2009-03-03 21:14 . 2009-03-10 18:46 997,888 –a—— c:\windows\system32\dllcache\kernel32.dll
2009-03-03 21:14 . 2009-03-10 18:46 21,504 –a—— c:\windows\system32\dllcache\powrprof.dll
2009-03-01 20:03 . 2009-03-01 20:03 d——– c:\documents and settings\Lea Family\Application Data\ViquaSoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-31 23:09 ——— d—–w c:\program files\LimeWire
2009-03-27 12:36 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2009-03-27 12:35 ——— d—–w c:\documents and settings\Lea Family\Application Data\McAfee
2009-03-25 02:13 ——— d—–w c:\program files\McAfee
2009-03-24 00:01 ——— d—–w c:\program files\WildTangent
2009-03-23 22:56 ——— d—–w c:\program files\Dell Games
2009-03-22 22:26 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-03-17 14:46 5,018 –sha-w c:\windows\system32\KGyGaAvL.sys
2009-03-11 21:14 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-11 12:59 84,992 ——w c:\windows\system32\zazofose.dll
2009-03-11 12:59 79,872 ——w c:\windows\system32\sazisuhi.dll
2009-03-10 23:46 690,688 —-a-w c:\windows\system32\wininet.dll
2009-03-10 23:46 21,504 —-a-w c:\windows\system32\powrprof.dll
2009-03-10 15:23 ——— d—–w c:\documents and settings\Lea Family\Application Data\SPORE Creature Creator
2009-03-09 12:58 79,872 ——w c:\windows\system32\melunule.dll
2009-03-06 02:59 9,742,840 —-a-w c:\windows\system32\xul.dll
2009-03-06 02:59 696,312 —-a-w c:\windows\system32\js3250.dll
2009-03-06 02:59 395,768 —-a-w c:\windows\system32\sqlite3.dll
2009-03-06 02:59 185,848 —-a-w c:\windows\system32\crashreporter.exe
2009-03-02 02:42 ——— d—–w c:\documents and settings\All Users\Application Data\WildTangent
2009-03-02 00:57 ——— d—–w c:\program files\FinePixViewer
2009-03-02 00:50 ——— d—–w c:\program files\Oberon Media
2009-02-24 18:26 ——— d—–w c:\documents and settings\All Users\Application Data\FarmFrenzy-PizzaParty
2009-02-20 22:02 ——— d—–w c:\documents and settings\Lea Family\Application Data\Apple Computer
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2009-02-09 11:13 1,846,784 ——w c:\windows\system32\dllcache\win32k.sys
2008-12-11 05:23 88 –sh–r c:\windows\system32\CF87502B0D.sys
.

——- Sigcheck ——-

2006-01-09 13:02 662016 dde9597a3311748c1519444e2bc147bd c:\windows\$hf_mig$\KB912945\SP2QFE\wininet.dll
2006-05-10 00:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
2008-04-21 01:44 666112 2b0c24aa747a93a28987b6d65a4a74bc c:\windows\$hf_mig$\KB950759\SP3GDR\wininet.dll
2008-04-21 01:24 666624 26f240c250e5b4b395cb4b178ba75437 c:\windows\$hf_mig$\KB950759\SP3QFE\wininet.dll
2008-06-23 10:09 666112 f12fbb673de9cc802c5dc518fe99aa2f c:\windows\$hf_mig$\KB953838\SP3GDR\wininet.dll
2008-06-23 09:54 666624 972299b7241ec325d8c7e5638c884925 c:\windows\$hf_mig$\KB953838\SP3QFE\wininet.dll
2008-08-19 23:58 666624 94418f53d2612c26dbadc04dafbc197c c:\windows\$hf_mig$\KB956390\SP3QFE\wininet.dll
2008-10-15 20:04 667136 e8fce58a470999350f64c591557f9e42 c:\windows\$hf_mig$\KB958215\SP3QFE\wininet.dll
2008-06-23 11:12 667136 611ace3f4201e9610af8452f7c268995 c:\windows\$NtServicePackUninstall$\wininet.dll
2006-05-10 00:23 658432 38ab7a56f566d9aaad31812494944824 c:\windows\$NtUninstallKB916281$\wininet.dll
2006-05-10 00:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$NtUninstallKB942615$\wininet.dll
2007-10-11 00:57 666112 80d660a49e0d118144423099b2a9f5da c:\windows\$NtUninstallKB944533$\wininet.dll
2007-12-06 19:44 666112 085a7c37f9c6ede1ba870b7dbec06399 c:\windows\$NtUninstallKB947864$\wininet.dll
2008-04-13 19:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\$NtUninstallKB950759$\wininet.dll
2008-02-16 04:32 666112 bb1eacd6ab47e78ebca02eb781550d55 c:\windows\$NtUninstallKB950759_0$\wininet.dll
2008-04-21 01:44 666112 2b0c24aa747a93a28987b6d65a4a74bc c:\windows\$NtUninstallKB953838$\wininet.dll
2008-04-21 01:56 666624 2e7de1bf9418b071799eb53de8cc22f5 c:\windows\$NtUninstallKB953838_0$\wininet.dll
2008-06-23 10:09 666112 f12fbb673de9cc802c5dc518fe99aa2f c:\windows\$NtUninstallKB956390$\wininet.dll
2008-08-20 00:30 666112 9af5f25124fbdc36e2b510729cba2674 c:\windows\$NtUninstallKB958215$\wininet.dll
2008-04-13 19:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\ServicePackFiles\i386\wininet.dll
2009-03-10 18:46 690688 a4c471050b3c631b42951d7e32237987 c:\windows\system32\wininet.dll
2009-03-10 18:46 690688 a4c471050b3c631b42951d7e32237987 c:\windows\system32\dllcache\wininet.dll

2007-04-16 11:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
2007-04-16 10:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\$NtServicePackUninstall$\kernel32.dll
2004-08-04 05:00 983552 888190e31455fad793312f8d087146eb c:\windows\$NtUninstallKB935839$\kernel32.dll
2008-04-13 19:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\ServicePackFiles\i386\kernel32.dll
2009-03-10 18:46 997888 ac26a98dbbd5b924d53efe4b50c451a5 c:\windows\system32\kernel32.dll
2009-03-10 18:46 997888 ac26a98dbbd5b924d53efe4b50c451a5 c:\windows\system32\dllcache\kernel32.dll

2004-08-04 05:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\$NtServicePackUninstall$\powrprof.dll
2008-04-13 19:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\ServicePackFiles\i386\powrprof.dll
2009-03-10 18:46 21504 84797238ddd10b9990701398f3c879d0 c:\windows\system32\powrprof.dll
2009-03-10 18:46 21504 84797238ddd10b9990701398f3c879d0 c:\windows\system32\dllcache\powrprof.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}"= "c:\documents and settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2009-03-29 3851592]

[HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}]
2009-03-29 09:15 3851592 –a—— c:\documents and settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}"= "c:\documents and settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2009-03-29 3851592]

[HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}"= "c:\documents and settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2009-03-29 3851592]

[HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-31 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"CyberDefender Early Detection Center"="c:\program files\CyberDefender\AntiSpyware\cdasc9.exe" [2009-03-29 664904]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DelayShred"="c:\program files\mcafee.com\shredder\SHRED32.EXE" [2005-07-15 57344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-07-12 1117184]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-08 645328]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"MSKAGENTEXE"="c:\progra~1\mcafee\spamki~1\mskagent.exe" [2005-07-12 110592]
"QuickTime Task"="c:\program files\quicktime\qttask.exe" [2008-11-04 413696]
"CPM53824205"="c:\windows\system32\zazofose.dll" [2009-03-11 84992]
"50b17199"="c:\windows\system32\sazisuhi.dll" [2009-03-11 79872]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-22 148888]
"CyberDefender Early Detection Center"="c:\program files\CyberDefender\AntiSpyware\ISSIntro.exe" [2009-03-29 570696]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\zazofose.dll" [2009-03-11 84992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zazofose.dll [2009-03-11 84992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\zazofose.dll
"LoadAppInit_DLLs"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Turbosurf\\PxClient.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\WINDOWS\\system32\\DLA\\DLACTRLW.EXE"=
"c:\\Program Files\\CyberDefender\\AntiSpyware\\cdasc9.exe"=

S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-09-29 210216]
S3 CDAVFS;CDAVFS;c:\windows\system32\drivers\CDAVFS.sys [2009-03-29 67424]
.
Contents of the 'Scheduled Tasks' folder

2009-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]

2009-03-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-09 11:53]

2009-04-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-09 11:53]
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
HKLM-Run-hitejabofu - c:\windows\system32\wapetose.dll
SSODL-HardwareDrivers-{2EA7E4D0-622A-479D-A00F-C1529665D5F6} - c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll
SSODL-DriversLoad-{52745E8B-F4E4-4C0C-963F-2CB9675B4F1F} - c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\egdieexaru.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Lea Family\Application Data\Mozilla\Firefox\Profiles\kdlamel2.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-01 07:29:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-77453670-2768504289-846323367-1006\Software\SecuROM\License information*]
"datasecu"=hex:e7,e9,83,ea,9b,c5,c3,aa,a7,2a,74,c7,37,10,0f,00,2c,ae,c0,cb,24,
1d,4c,b0,e2,34,2e,02,76,2e,a3,32,f0,ba,6b,ff,1a,aa,bf,8b,35,e5,27,28,9c,9c,\
"rkeysecu"=hex:e2,12,2a,1c,07,b2,61,76,3d,83,d3,aa,3e,e6,b1,38
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\rundll32.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MSK\msksrver.exe
c:\progra~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\program files\FinePixViewer\QuickDCF2.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\wdfmgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Java\jre6\bin\jucheck.exe
c:\progra~1\McAfee\MSC\mcupdui.exe
c:\windows\system32\wscript.exe
.
**************************************************************************
.
Completion time: 2009-04-01 7:36:51 - machine was rebooted [Lea Family]
ComboFix-quarantined-files.txt 2009-04-01 12:35:50

Pre-Run: 37,034,020,864 bytes free
Post-Run: 36,888,227,840 bytes free

697 — E O F — 2009-03-29 08:04:11
HiJackThis report from this morning…





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:52:36, on 4/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
c:\windows\system32\hkcmd.exe
c:\windows\system32\igfxpers.exe
c:\windows\system32\dla\dlactrlw.exe
c:\program files\hp\hp software update\hpwuschd2.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\program files\dell support center\bin\sprtcmd.exe
c:\progra~1\mcafee\spamki~1\mskagent.exe
c:\windows\system32\rundll32.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\itunes\ituneshelper.exe
c:\program files\common files\installshield\updateservice\issch.exe
c:\program files\dell\media experience\dmxlauncher.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\program files\java\jre6\bin\jusched.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\program files\dellsupport\dsagnt.exe
c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
c:\program files\finepixviewer\quickdcf2.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
c:\program files\java\jre6\bin\jucheck.exe
C:\WINDOWS\explorer.exe
c:\program files\mozilla firefox\firefox.exe
c:\program files\trend micro\hijackthis\hijackthis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: McAfee Anti-Phishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [MSKAGENTEXE] c:\progra~1\mcafee\spamki~1\mskagent.exe
O4 - HKLM\..\Run: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CPM53824205] Rundll32.exe "c:\windows\system32\zazofose.dll",a
O4 - HKLM\..\Run: [50b17199] rundll32.exe "C:\WINDOWS\system32\sazisuhi.dll",b
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\cdasc9.exe" /minimize
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee.com\shredder\SHRED32.EXE" /q C:\WINDOWS\Prefetch\MALWAR~1.SH! C:\WINDOWS\Prefetch\WCENTE~1.SH!
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1238540058968
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: c:\windows\system32\zazofose.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zazofose.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zazofose.dll
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\Dell Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

–
End of file - 11911 bytes
Hi,

That is very good news, but we still have a little work to do.

Please do the following

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text inside the codebox below into it: (starting with

Collect::
c:\windows\system32\ldshyf.old
c:\windows\system32\urhtps.dat
c:\windows\system32\zazofose.dll
c:\windows\system32\sazisuhi.dll
c:\windows\system32\melunule.dll

Folder::
c:\windows\system32\cock

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CPM53824205"=-
"50b17199"=-
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
"LoadAppInit_DLLs"=-

FCopy:: 
c:\windows\ServicePackFiles\i386\kernel32.dll | c:\windows\system32\kernel32.dll 
c:\windows\ServicePackFiles\i386\wininet.dll | c:\windows\system32\wininet.dll 
c:\windows\ServicePackFiles\i386\powrprof.dll | c:\windows\system32\powrprof.dll 

Driver::

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


NEXT

Please run the MalwareBytes AntiMalware program (in the normal fashion - NOT as per the PM)

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.

In your next response please include

  • Combofix log
  • MBAM log
also advise how your computer is running now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI