This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Spyware Remover 2009

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I followed the directions that are posted: (cleared "hide file extensions for known file types" etc. etc.) * Downloaded ATF cleaner and ran as instructed. * Downloaded Malwarebytes Anti-Malware and ran as instructed. Below is a copy of the results. Do I go back to My Computer and undo the changes? (hide file extensions, etc. etc.) Malwarebytes' Anti-Malware 1.36 Database version: 1962 Windows 5.1.2600 Service Pack 2 4/10/2009 10:58:43 AM mbam-log-2009-04-10 (10-58-43).txt Scan type: Quick Scan Objects scanned: 92701 Time elapsed: 3 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 3 Registry Keys Infected: 8 Registry Values Infected: 5 Registry Data Items Infected: 1 Folders Infected: 1 Files Infected: 22 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\ati3duag(3.dll (Trojan.Downloader) -> Delete on reboot. C:\WINDOWS\system32\__c003B018.dat (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\__c00E9790.dat (Trojan.Agent) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{fd01d5d4-e056-4d72-a908-910f8bdbf58d} (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fd01d5d4-e056-4d72-a908-910f8bdbf58d} (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fd01d5d4-e056-4d72-a908-910f8bdbf58d} (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c00e9790 (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\dlp.dlpobj.1 (Adware.WebDir) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\ati3duag(3.dll (Trojan.Downloader) -> Delete on reboot. C:\WINDOWS\system32\apcup.dll (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\appmg.dll (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ati2dvag(3.dll (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\atikvmag(.dll (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\atiok3x2(4.dll (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ati2evxx(.dll (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ati2evxx(4.dll (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c00E9790.dat (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\__c003B018.dat (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\__c0012541.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c0019424.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c00240D8.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c003DD44.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c004980C.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c0070CDA.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c0098A5C.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c00A8D7C.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c00C84FD.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c00C8590.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c00EA617.exe (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\__c00FB6A4.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
Hi and :welcome:

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
I am not able to logon to my yahoo mail now. When I click sign in to yahoo mail all that happens is a blank screen appears. So now I cannot check my yahoo mail.


ComboFix 09-04-04.01 - Online College class 2009-04-10 13:35:23.2 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jackie\Application Data\IUpd721
c:\documents and settings\Jackie\Application Data\IUpd721\Logs\scns.log
c:\temp\PRE45
c:\temp\PRE45\pG8.log
c:\windows\system32\sX3i19
C:\xcrashdump.dat

.
((((((((((((((((((((((((( Files Created from 2009-03-10 to 2009-04-10 )))))))))))))))))))))))))))))))
.

2009-04-10 12:47 . 2009-04-10 12:47 d——– c:\windows\LastGood
2009-04-09 10:58 . 2009-04-10 10:28 d——– c:\documents and settings\All Users\Application Data\SITEguard
2009-04-09 10:57 . 2009-04-09 10:57 d——– c:\program files\Common Files\iS3
2009-04-09 10:57 . 2009-04-10 10:29 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2009-04-09 10:45 . 2009-04-09 10:46 d——– c:\documents and settings\Online College class\Application Data\FUJIFILM
2009-04-08 11:37 . 2009-04-08 11:37 d——– c:\program files\CCleaner
2009-04-08 11:29 . 2009-04-08 11:29 d——– c:\documents and settings\Online College class\Application Data\ATI
2009-04-08 11:19 . 2009-04-08 11:18 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-03-26 12:30 . 2009-03-26 12:31 d——– c:\program files\iTunes
2009-03-26 12:30 . 2009-03-26 12:30 d——– c:\program files\iPod
2009-03-26 12:30 . 2009-03-26 12:31 d——– c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-22 19:40 . 2009-04-09 10:37 d——– c:\program files\Pando Networks
2009-03-20 18:25 . 2009-03-20 18:25 41,808 –a—— c:\windows\system32\xfcodec.dll
2009-03-13 10:27 . 2009-04-08 14:12 d——– c:\documents and settings\Online College class\Application Data\teamspeak2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-10 17:33 ——— d—–w c:\program files\Google
2009-04-10 16:51 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-10 15:04 ——— d—–w c:\documents and settings\Jackie\Application Data\Xfire
2009-04-10 14:53 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-10 04:23 ——— d-s—w c:\program files\Xfire
2009-04-10 04:23 ——— d—–w c:\documents and settings\Online College class\Application Data\Xfire
2009-04-09 23:29 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-09 14:45 ——— d—–w c:\program files\FinePixViewer
2009-04-09 14:36 ——— d—–w c:\program files\Panda Security
2009-04-08 15:18 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-04-08 15:04 ——— d—–w c:\program files\Viewpoint
2009-04-08 15:04 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-04-08 15:00 ——— d–h–w c:\program files\InstallShield Installation Information
2009-04-08 14:57 ——— d—–w c:\program files\Logitech
2009-04-08 14:55 ——— d—–w c:\program files\BenefitBarIE
2009-04-07 23:17 34 —-a-w c:\documents and settings\Online College class\jagex_runescape_preferences.dat
2009-04-07 15:37 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-06 19:32 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 19:32 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-03-26 16:30 ——— d—–w c:\program files\Common Files\Apple
2009-03-26 16:27 ——— d—–w c:\program files\QuickTime
2009-03-26 16:15 ——— d—–w c:\program files\Safari
2009-03-26 16:14 ——— d—–w c:\program files\Bonjour
2009-03-13 14:27 ——— d—–w c:\program files\Teamspeak2_RC2
2009-03-07 20:45 ——— d—–w c:\documents and settings\Online College class\Application Data\Apple Computer
2009-03-07 20:41 ——— d—–w c:\program files\Java
2009-02-27 19:26 ——— d—–w c:\program files\Microsoft Silverlight
2009-02-16 15:34 ——— d—–w c:\program files\Imikimi
2009-02-09 10:19 1,846,272 —-a-w c:\windows\system32\win32k.sys
2009-02-07 17:48 34 —-a-w c:\documents and settings\Jackie\jagex_runescape_preferences.dat
2009-01-27 18:07 34 —-a-w c:\documents and settings\Dallas.STEIGER-908F50B\jagex_runescape_preferences.dat
2008-11-18 00:01 165 —-a-w c:\documents and settings\All Users\Application Data\service.dat
2008-04-10 23:06 47,360 —-a-w c:\documents and settings\Dallas.STEIGER-908F50B\Application Data\pcouffin.sys
2007-11-28 05:26 22,328 —-a-w c:\documents and settings\Dallas.STEIGER-908F50B\Application Data\PnkBstrK.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-16 2356088]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Lexmark X5100 Series"="c:\program files\Lexmark X5100 Series\lxbabmgr.exe" [2002-12-03 86102]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-08 148888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"GeelixHUDDesktop"="c:\program files\Geelix.4.0.6.0\GeelixHUDDesktop.exe" [2008-02-14 2146304]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 c:\windows\soundman.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
"vidc.3IV2"= 3ivxVfWCodec.dll
"vidc.SEDG"= SamsungVfWCodec.dll
"vidc.DX50"= DivXVfWCodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Reminder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk
backup=c:\windows\pss\Event Reminder.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Documents and Settings\\Dallas.STEIGER-908F50B\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"d:\\Azureus\\Azureus\\Azureus.exe"=
"d:\\cyberlink\\PowerDirector\\PDR.exe"=
"d:\\Ghost Recon\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
"d:\\Ghost Recon\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe"=
"d:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Tams11\\Games\\Farkle\\farkle.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"d:\\CoD2MP_s.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2006-02-23 11264]
S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2008-12-08 55136]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2007-08-24 21920]


— Other Services/Drivers In Memory —

*Deregistered* - a347bus
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - Apple Mobile Device
*Deregistered* - Ati HotKey Poller
*Deregistered* - ATI Smart
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - bgsvcgen
*Deregistered* - BITS
*Deregistered* - Bonjour Service
*Deregistered* - Browser
*Deregistered* - Capture Device Service
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - fssfltr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - gusvc
*Deregistered* - helpsvc
*Deregistered* - HidServ
*Deregistered* - HTTP
*Deregistered* - ImapiService
*Deregistered* - IpFilterDriver
*Deregistered* - IpNat
*Deregistered* - iPod Service
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - Kbdclass
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LexBceS
*Deregistered* - LmHosts
*Deregistered* - mcmscsvc
*Deregistered* - McNASvc
*Deregistered* - McProxy
*Deregistered* - McShield
*Deregistered* - McSysmon
*Deregistered* - mfeavfk
*Deregistered* - mfebopk
*Deregistered* - mfehidk
*Deregistered* - mfesmfk
*Deregistered* - mnmdd
*Deregistered* - Modem
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - MPFP
*Deregistered* - MpfService
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - MSIServer
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - ParVdm
*Deregistered* - pcouffin
*Deregistered* - PnkBstrA
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RDPWD
*Deregistered* - RichVideo
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - SCREAMINGBDRIVER
*Deregistered* - SeaPort
*Deregistered* - Secdrv
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sprtsvc_ddoctorv2
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TDTCP
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - UleadBurningHelper
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - Wdf01000
*Deregistered* - WebClient
*Deregistered* - WinDefend
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder

2009-04-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-04-10 c:\windows\Tasks\ErrorSmart Scheduled Scan.job
- c:\program files\ErrorSmart\ErrorSmart.exe []

2009-04-10 c:\windows\Tasks\ErrorSmart Scheduled Scan.job
- c:\program files\ErrorSmart []

2009-04-10 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-25 18:06]

2009-03-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 14:32]

2009-04-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 14:32]

2009-04-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 20:20]

2009-04-10 c:\windows\Tasks\rpc.job
- c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
.
- - - - ORPHANS REMOVED - - - -

Toolbar-SITEguard - (no file)
HKCU-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
HKLM-Run-eBayToolbar - c:\program files\eBay\eBay Toolbar2\eBayTBDaemon.exe
HKLM-Run- - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = https://angel.lcc.edu/default.asp
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Jackie\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
FF - ProfilePath - c:\documents and settings\Online College class\Application Data\Mozilla\Firefox\Profiles\8w94w70x.default\
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npkimi.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-10 13:39:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-602162358-1035525444-725345543-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_%C*å*]
@Class="Shell"

[HKEY_USERS\S-1-5-21-602162358-1035525444-725345543-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*_%C*å*\OpenWithList]
@Class="Shell"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ •€|ù•A~ *]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
Completion time: 2009-04-10 13:42:42
ComboFix-quarantined-files.txt 2009-04-10 17:42:37

Pre-Run: 5,940,846,592 bytes free
Post-Run: 6,178,381,824 bytes free

342 — E O F — 2009-04-06 15:05:28


Hi and :welcome:

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Hi,

Did the problem occur with your mail after MBAM removed the vundo files or after Combofix?

Please reboot your computer, that will often resolve the issue.

You don't say whether you downloaded and ran HJT before MBAM, if you didn't, please do so now and post a log

Download the latest version of Trendmicro's Hijackthis to your desktop.

Double click the downloaded program icon to install it [external image: Posted Image]
Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe

Open HJT

Click on Scan and Save a Log File, it will open in Notepad
Go to Format and make sure Wordwrap is Unchecked
Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread by using the Add Reply button.
Hi,
I can access my yahoo email through Mozilla Firefox, but I cannot access it through Internet Explorer which is what I like to use. The problem with my blank screen with yahoo mail happened after I did the combofix.

Also I never received a reply from you if I was to reset my computer back to its normal settings (I am talking about the hide file extensions etc. etc.) So I reset them back to the defaults. I figured that would be the safest thing to do. I will run a hijack this log and post it for you. Thank you so much for your quick response and all your help!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:24:07 AM, on 4/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Geelix.4.0.6.0\GeelixHUDDesktop.exe
C:\WINDOWS\system32\lexpps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\Restore\rstrui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [GeelixHUDDesktop] C:\Program Files\Geelix.4.0.6.0\GeelixHUDDesktop.exe -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jackie\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase9563.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1165543934470
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1183046861468
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…436/mcfscan.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LWWLicenseService - WoltersKluwerLWW - C:\Program Files\Common Files\WoltersKluwerLWW Shared\Service\LWWLicenseService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 14077 bytes
Hi,

(yes, resetting hide was correct)

There isn't an obvious reason why ComboFix altered your IE access to your email


Try resetting I.E. web settings

To Reset Web settings


1. Open Internet Explorer.
2. On the Tools menu, click Internet Options.
3. Click the Programs tab, and then click the Reset Web Settings button.
4. Under Internet programs, verify that the correct e-mail program is selected.
5. Click to select the Internet Explorer should check to see whether it is the default browser check box.
6. Click Apply, and then click OK.

Note : If you receive a message when Internet Explorer starts telling you that IE is not currently your default browser, click Yes to make it your default.

NEXT


ReRun MalwareBytes

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Hi, when going to tools, then internet options, then programs, there is no option "to click the Reset Web Settings button. "
Sorry, my mistake you have IE7

do this to reset IE instead

click Start, and then click Run.
Type the following command in the Open runbox, and then press ENTER:


inetcpl.cpl

That did not work. Did I say that I could see other pages with yahoo? Such as my yahoo address book, contacts, etc. I just get a blank page with yahoo email. Does it have anything to do with activeX controls?
Hi,

It could very well be active x, but I think it might be security settings in IE blocking Yahoo mail…

sorry I don't use IE myself but I found this resolution:

right-click the menu bar and check 'Web assistant'. the Web assistant should now be showing on the tool bar. click on it and uncheck 'Block ads on this site'. this works for yahoo mail and other web mail accounts.


continue on with the remaining instructions for now and I'll look into this further….
thanks

CB
Hi, I followed the instructions and after right clicking on menu bar "Web Assistant" is not a choice on my menu bar. I will continue on with the remaining instructions while we try and figure out how to resolve this issue. Thank you.
Try this for the active X settings:

Tools>Internet Options>Security>Advanced>Custom Level> change each of the
ActiveX Controls setting respectively down the list to the following:

Change the following in order:
Prompt
Disable
Disable
Prompt
Prompt

For the security settings - try this

Open up Internet Explore, click Tools, Internet Options, click on the tab Security and underneath 'Security Level for this Zone' put it on Medium.
Then click on the tab Privacy and under 'settings' put it on Medium. Click Apply then Ok.

If that doesn't work reset them to Med High

It may also be a java script issue as well.


here is a link for how to reset IE7 back to default:

http://blogs.msdn.com/ie/archive/2006/06/12/628499.aspx
Hi, none of the above helped I am still unable to view my yahoo mail in internet explorer. I can view all other pages though. I am also not able to see my system restore box (it is blank when I open it). At the end of the msn blog it mentioned this: "If one or more of RIES tasks fail (identified by an X against the task in Progress dialog), the details of failed actions are logged. The logs files, ried.log and brndlog.txt, can be found in %USERPROFILE%\Local Settings\Application Data\Microsoft\Internet Explorer\. " so I went and opened this file (brndlog.bak) (the brndlog.txt was from today) but here is the log from the brndlog.bak: Maybe the mistake is in here somewhere: I will post my other scans in another reply 04/10/2009 14:24:49 COM initialized with S_OK success code. 04/10/2009 14:24:49 Branding Internet Explorer… 04/10/2009 14:24:49 Command line is "/mode:isp /peruser". 04/10/2009 14:24:49 Global branding settings are: 04/10/2009 14:24:49 Context is (0x01C00008) "Internet Content Providers, running from per-user stub"; 04/10/2009 14:24:49 Settings file is "C:\Program Files\Internet Explorer\Signup\install.ins"; 04/10/2009 14:24:49 Target folder path is "C:\Program Files\Internet Explorer\Signup". 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 About to clear previous branding… 04/10/2009 14:24:49 Removing customizations… 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing migration of old settings… 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing wininet setup… 04/10/2009 14:24:49 There are no connection settings to process! 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing deletion of connection settings… 04/10/2009 14:24:49 Existing connection settings weren't specified to be deleted! 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing zones HKCU settings… 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing local machine policies and restrictions… 04/10/2009 14:24:49 There are no local machine *.inf files to process! 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing current user policies and restrictions… 04/10/2009 14:24:49 There are no current user *.inf files to process! 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing legacy policies and restrictions… 04/10/2009 14:24:49 There are no local machine *.inf files to process! 04/10/2009 14:24:49 There are no current user *.inf files to process! 04/10/2009 14:24:49 There are no legacy *.inf files to process! 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing general customizations… 04/10/2009 14:24:49 Browser title is set to "Windows Internet Explorer provided by Yahoo!". 04/10/2009 14:24:49 Home page is set to "http://www.yahoo.com/?fr=fp-yie8". 04/10/2009 14:24:49 User agent string is set to "yie8" in HKLM. 04/10/2009 14:24:49 User agent string is set to "yie8" in HKCU. 04/10/2009 14:24:49 First Home Page is set to "http://downloads.yahoo.com/internetexplorer/welcome". 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing Help->About customization… 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing browser toolbar buttons… 04/10/2009 14:24:49 There are no toolbar buttons to process! 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing root certificates… 04/10/2009 14:24:49 This feature is for ISPs only! 04/10/2009 14:24:49 Done. 04/10/2009 14:24:49 Processing default favorites and/or quick links… 04/10/2009 14:24:49 Creating separate thread for processing default favorites… 04/10/2009 14:24:49 COM initialized with S_OK success code. 04/10/2009 14:24:50 Determining favorites attributes… 04/10/2009 14:24:50 folder location is "C:\Documents and Settings\Online College class\Favorites". 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Microsoft Websites\Welcome to IE7", 04/10/2009 14:24:51 URL - "http://go.microsoft.com/fwlink/?linkid=68919", 04/10/2009 14:24:51 with a default icon, 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Microsoft Websites\IE site on Microsoft.com.url", 04/10/2009 14:24:51 URL - "http://go.microsoft.com/fwlink/?linkid=44661", 04/10/2009 14:24:51 with a default icon, 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Microsoft Websites\IE Add-on site", 04/10/2009 14:24:51 URL - "http://go.microsoft.com/fwlink/?LinkId=50893", 04/10/2009 14:24:51 with a default icon, 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Microsoft Websites\Microsoft At Home", 04/10/2009 14:24:51 URL - "http://go.microsoft.com/fwlink/?linkid=55424", 04/10/2009 14:24:51 with a default icon, 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Microsoft Websites\Microsoft At Work", 04/10/2009 14:24:51 URL - "http://go.microsoft.com/fwlink/?linkid=68920", 04/10/2009 14:24:51 with a default icon, 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Microsoft Websites\Marketplace", 04/10/2009 14:24:51 URL - "http://go.microsoft.com/fwlink/?linkid=69151", 04/10/2009 14:24:51 with a default icon, 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Links\Customize Links", 04/10/2009 14:24:51 URL - "http://go.microsoft.com/fwlink/?LinkId=53540", 04/10/2009 14:24:51 with a default icon, 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Processing deletion of favorites and/or quick links… 04/10/2009 14:24:51 None of the favorites folders were specified to be deleted! 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Processing favorites… 04/10/2009 14:24:51 Creating separate thread for processing favorites… 04/10/2009 14:24:51 COM initialized with S_OK success code. 04/10/2009 14:24:51 Using [FavoritesEx] section… 04/10/2009 14:24:51 Preprocessing "Title1" title key… 04/10/2009 14:24:51 Preprocessing "URL1" URL key… 04/10/2009 14:24:51 Adding this favorite: 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Yahoo! Websites\Yahoo!.url", 04/10/2009 14:24:51 URL - "http://www.yahoo.com/?fr=fp-yie8", 04/10/2009 14:24:51 Icon file - "C:\Program Files\Internet Explorer\Signup\yahoo.ico", 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Preprocessing "Title2" title key… 04/10/2009 14:24:51 Preprocessing "URL2" URL key… 04/10/2009 14:24:51 Adding this favorite: 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Yahoo! Websites\Answers.url", 04/10/2009 14:24:51 URL - "http://answers.yahoo.com", 04/10/2009 14:24:51 Icon file - "C:\Program Files\Internet Explorer\Signup\answers_favicon.ico", 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Preprocessing "Title3" title key… 04/10/2009 14:24:51 Preprocessing "URL3" URL key… 04/10/2009 14:24:51 Adding this favorite: 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Yahoo! Websites\Finance.url", 04/10/2009 14:24:51 URL - "http://rd.software.yahoo.com/yie8/finance", 04/10/2009 14:24:51 Icon file - "C:\Program Files\Internet Explorer\Signup\finance.ico", 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Preprocessing "Title4" title key… 04/10/2009 14:24:51 Preprocessing "URL4" URL key… 04/10/2009 14:24:51 Adding this favorite: 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Yahoo! Websites\Flickr.url", 04/10/2009 14:24:51 URL - "http://www.flickr.com", 04/10/2009 14:24:51 Icon file - "C:\Program Files\Internet Explorer\Signup\flickr.ico", 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Preprocessing "Title5" title key… 04/10/2009 14:24:51 Preprocessing "URL5" URL key… 04/10/2009 14:24:51 Adding this favorite: 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Yahoo! Websites\Mail.url", 04/10/2009 14:24:51 URL - "http://mail.yahoo.com", 04/10/2009 14:24:51 Icon file - "C:\Program Files\Internet Explorer\Signup\mail.ico", 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Preprocessing "Title6" title key… 04/10/2009 14:24:51 Preprocessing "URL6" URL key… 04/10/2009 14:24:51 Adding this favorite: 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Yahoo! Websites\My Yahoo!.url", 04/10/2009 14:24:51 URL - "http://my.yahoo.com", 04/10/2009 14:24:51 Icon file - "C:\Program Files\Internet Explorer\Signup\yahoo.ico", 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Preprocessing "Title7" title key… 04/10/2009 14:24:51 Preprocessing "URL7" URL key… 04/10/2009 14:24:51 Adding this favorite: 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Yahoo! Websites\News.url", 04/10/2009 14:24:51 URL - "http://rd.software.yahoo.com/yie8/news", 04/10/2009 14:24:51 Icon file - "C:\Program Files\Internet Explorer\Signup\news.ico", 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Preprocessing "Title8" title key… 04/10/2009 14:24:51 Preprocessing "URL8" URL key… 04/10/2009 14:24:51 Adding this favorite: 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Yahoo! Websites\Shopping.url", 04/10/2009 14:24:51 URL - "http://rd.software.yahoo.com/yie8/shopping", 04/10/2009 14:24:51 Icon file - "C:\Program Files\Internet Explorer\Signup\shopping2.ico", 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Preprocessing "Title9" title key… 04/10/2009 14:24:51 Preprocessing "URL9" URL key… 04/10/2009 14:24:51 Adding this favorite: 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Yahoo! Websites\Sports.url", 04/10/2009 14:24:51 URL - "http://rd.software.yahoo.com/yie8/sports", 04/10/2009 14:24:51 Icon file - "C:\Program Files\Internet Explorer\Signup\sports.ico", 04/10/2009 14:24:51 not marked IEAK created, 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Done. 04/10/2009 14:24:51 Preprocessing "Title10" title key… 04/10/2009 14:24:51 Preprocessing "URL10" URL key… 04/10/2009 14:24:51 Adding this favorite: 04/10/2009 14:24:51 Determining favorites attributes… 04/10/2009 14:24:51 marked as Low Integrity, 04/10/2009 14:24:51 Title - "Microsoft Websites\Welcome to IE8.url", 04/10/2009 14:24:52 URL - "http://go.microsoft.com/fwlink/?LinkId=68919", 04/10/2009 14:24:52 with a default icon, 04/10/2009 14:24:52 not marked IEAK created, 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Preprocessing "Title11" title key… 04/10/2009 14:24:52 Preprocessing "URL11" URL key… 04/10/2009 14:24:52 Adding this favorite: 04/10/2009 14:24:52 Determining favorites attributes… 04/10/2009 14:24:52 marked as Low Integrity, 04/10/2009 14:24:52 Title - "Microsoft Websites\IE site on Microsoft.com.url", 04/10/2009 14:24:52 URL - "http://go.microsoft.com/fwlink/?LinkId=44661", 04/10/2009 14:24:52 with a default icon, 04/10/2009 14:24:52 not marked IEAK created, 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Preprocessing "Title12" title key… 04/10/2009 14:24:52 Preprocessing "URL12" URL key… 04/10/2009 14:24:52 Adding this favorite: 04/10/2009 14:24:52 Determining favorites attributes… 04/10/2009 14:24:52 marked as Low Integrity, 04/10/2009 14:24:52 Title - "Microsoft Websites\IE Add-on site.url", 04/10/2009 14:24:52 URL - "http://go.microsoft.com/fwlink/?LinkId=50893", 04/10/2009 14:24:52 with a default icon, 04/10/2009 14:24:52 not marked IEAK created, 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Preprocessing "Title13" title key… 04/10/2009 14:24:52 Preprocessing "URL13" URL key… 04/10/2009 14:24:52 Adding this favorite: 04/10/2009 14:24:52 Determining favorites attributes… 04/10/2009 14:24:52 marked as Low Integrity, 04/10/2009 14:24:52 Title - "Microsoft Websites\Microsoft At Home.url", 04/10/2009 14:24:52 URL - "http://go.microsoft.com/fwlink/?LinkId=55424", 04/10/2009 14:24:52 with a default icon, 04/10/2009 14:24:52 not marked IEAK created, 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Preprocessing "Title14" title key… 04/10/2009 14:24:52 Preprocessing "URL14" URL key… 04/10/2009 14:24:52 Adding this favorite: 04/10/2009 14:24:52 Determining favorites attributes… 04/10/2009 14:24:52 marked as Low Integrity, 04/10/2009 14:24:52 Title - "Microsoft Websites\Microsoft At Work.url", 04/10/2009 14:24:52 URL - "http://go.microsoft.com/fwlink/?LinkId=68920", 04/10/2009 14:24:52 with a default icon, 04/10/2009 14:24:52 not marked IEAK created, 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Preprocessing "Title15" title key… 04/10/2009 14:24:52 Preprocessing "URL15" URL key… 04/10/2009 14:24:52 Adding this favorite: 04/10/2009 14:24:52 Determining favorites attributes… 04/10/2009 14:24:52 marked as Low Integrity, 04/10/2009 14:24:52 Title - "Microsoft Websites\Marketplace.url", 04/10/2009 14:24:52 URL - "http://go.microsoft.com/fwlink/?LinkId=69151", 04/10/2009 14:24:52 with a default icon, 04/10/2009 14:24:52 not marked IEAK created, 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Preprocessing "Title16" title key… 04/10/2009 14:24:52 This key doesn't exist indicating that there are no more favorites. 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Processing ordering of favorites… 04/10/2009 14:24:52 Yahoo! Websites\ folder has been ordered successfully! 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Processing quick links… 04/10/2009 14:24:52 Creating separate thread for processing quick links… 04/10/2009 14:24:52 COM initialized with S_OK success code. 04/10/2009 14:24:52 Preprocessing "Quick_Link_1_Name" quick link title key… 04/10/2009 14:24:52 Preprocessing "Quick_Link_1" quick link URL key… 04/10/2009 14:24:52 Adding this quick link: 04/10/2009 14:24:52 Determining favorites attributes… 04/10/2009 14:24:52 marked as Low Integrity, 04/10/2009 14:24:52 Title - "Links\eBay.url", 04/10/2009 14:24:52 URL - "http://www.ebay.com/", 04/10/2009 14:24:52 with a default icon, 04/10/2009 14:24:52 not marked IEAK created, 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Preprocessing "Quick_Link_2_Name" quick link title key… 04/10/2009 14:24:52 Preprocessing "Quick_Link_2" quick link URL key… 04/10/2009 14:24:52 Adding this quick link: 04/10/2009 14:24:52 Determining favorites attributes… 04/10/2009 14:24:52 marked as Low Integrity, 04/10/2009 14:24:52 Title - "Links\Customize Links.url", 04/10/2009 14:24:52 URL - "http://go.microsoft.com/fwlink/?LinkId=53540", 04/10/2009 14:24:52 with a default icon, 04/10/2009 14:24:52 not marked IEAK created, 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Preprocessing "Quick_Link_3_Name" quick link title key… 04/10/2009 14:24:52 This key doesn't exist indicating that there are no more quick links. 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Processing ordering of quick links… 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Processing connection settings… 04/10/2009 14:24:52 There are no connection settings to process! 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Processing TrustedPublisherLockdown restriction… 04/10/2009 14:24:52 This restriction is not set! 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Registering download URLs as safe for updating IE… 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Deleting links… 04/10/2009 14:24:52 No links to delete! 04/10/2009 14:24:52 Done. 04/10/2009 14:24:52 Creating feeds… 04/10/2009 14:24:53 Processing [Feeds] section… 04/10/2009 14:24:53 Creating feed "Microsoft Feeds\Microsoft at Home" 04/10/2009 14:24:53 Creating feed "Microsoft Feeds\Microsoft at Work" 04/10/2009 14:24:53 Done. 04/10/2009 14:24:53 Creating start pages… 04/10/2009 14:24:53 There are no start pages to add! 04/10/2009 14:24:53 Done. 04/10/2009 14:24:53 Creating search providers… 04/10/2009 14:24:53 Processing [SearchProviders] section… 04/10/2009 14:24:53 Processing [SearchProviders] GetExisitingProviderList :: ENTER 04/10/2009 14:24:53 Processing [SearchProviders] GetExisitingProviderList :: EXIT 04/10/2009 14:24:53 Processing [SearchProviders] AddSearchProvider :: ENTER 04/10/2009 14:24:53 Processing [SearchProviders] AddSearchProvider :: EXIT 04/10/2009 14:24:53 Processing [SearchProviders] AddSearchProvider :: ENTER 04/10/2009 14:24:53 Processing [SearchProviders] AddSearchProvider :: EXIT 04/10/2009 14:24:53 Processing [SearchProviders] AddSearchProvider :: ENTER 04/10/2009 14:24:53 Processing [SearchProviders] AddSearchProvider :: EXIT 04/10/2009 14:24:53 Processing [SearchProviders] AddSearchProvider :: ENTER 04/10/2009 14:24:53 Processing [SearchProviders] AddSearchProvider :: EXIT 04/10/2009 14:24:53 Processing [SearchProviders] section EXIT 04/10/2009 14:24:53 Done. 04/10/2009 14:24:53 Processing active desktop customizations… 04/10/2009 14:24:53 No desktop customizations to process! 04/10/2009 14:24:53 Done. 04/10/2009 14:24:53 Processing channels and their categories (if any)… 04/10/2009 14:24:53 There are no channels to process! 04/10/2009 14:24:53 Done. 04/10/2009 14:24:53 Processing software update channels… 04/10/2009 14:24:53 folder location is "C:\WINDOWS\Web". 04/10/2009 14:24:53 There are no software update channels to add! 04/10/2009 14:24:53 Done. 04/10/2009 14:24:53 Actual processing of channels by calling webcheck.dll "DllInstall" API… 04/10/2009 14:24:53 There is no webcheck processing necessary! 04/10/2009 14:24:53 Done. 04/10/2009 14:24:53 Showing channel bar on the desktop… 04/10/2009 14:24:53 Done. 04/10/2009 14:24:53 Processing subscriptions… 04/10/2009 14:24:53 There are no subscriptions to process! 04/10/2009 14:24:53 Done. 04/10/2009 14:24:53 Refreshing browser settings… 04/10/2009 14:24:53 Broadcasting "Windows settings change" to all top level windows… 04/10/2009 14:25:16 Done. 04/10/2009 14:25:16 Done. 04/10/2009 14:25:16 Done.
Below is malwarebytes scan and Kaspersky scan: Malwarebytes' Anti-Malware 1.36 Database version: 1970 Windows 5.1.2600 Service Pack 2 4/12/2009 12:39:06 PM mbam-log-2009-04-12 (12-39-06).txt Scan type: Quick Scan Objects scanned: 93143 Time elapsed: 5 minute(s), 10 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\dlp.dlpobj.1 (Adware.WebDir) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Monday, April 13, 2009 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Sunday, April 12, 2009 21:18:35 Records in database: 2038527 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ Scan statistics: Files scanned: 236969 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 10:10:36 File name / Threat name / Threats count C:\WINDOWS\system32\drivers\nVIDIA\DLL\regedit Infected: Trojan.WinREG.RunKeys.e 1 The selected area was scanned.
Hi

the list of quarantined files from Combofix can be found at this location:

C:\Qoobox\ComboFix-quarantined-files.txt


please copy paste that list here.

If you say this only occurred after using ComboFix, then we should restore those files from quarantine and see if the problem is corrected

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI