This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Download Problem

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi All
From last 2 days iam facing strange problem. My download halts after reaching 70-80% then speed meter shows 0 kb/s. I then uninstalled DAp, then went for flashget, then for leechget and then for firefox addon presently. But the problem was still continuing, I couldnt download anything. I tried Dr Web Cure it, then VLC Player, then CC Cleaner but no success at all

Today i restored the ghost image initially i was adle to download some file(CC cleaner but with difficulty), but within a few hrs the problem surfaced. Then i tried downloading windows installer from microsoft .com after 5 min the pop up box opened and saved the file to E disk but therafter the progress bar didnt moved. Similarly i tried with VLC player and DAP 9, i was not able to download.

Then i checked my ISP speed at www.speedtest.net
http://www.speedtest.net/result/451868138.png
So no problem with the ISP speed.

My configuration Amd Athlon X2 2.5GHZ, 2GB Ram, XP SP2, Browser IE7 and Firefox 3.08.
Security Program KIS 2009 8.0.0.506 (a,B)

I am going :pullhair:

Pls advise

Regards

Sri1979
What type of internet connection do you have with your ISP?

I have a medium ADSL subscription with ATT and get the following
[external image: Posted Image]
You seem to be suspecting Malware as the possible cause of your Internet difficulty.
Malware is one of the high likely cause.

You should NOT run ComboFix or any other advanced Malware Removal Tools without assistance from a specialist.

Let's get you over to the Malware Removal Forum for some assistance.

This will get you started:
http://forums.whatthetech.com/Welcome_New_…ers_t34502.html

Best Regards
Hello Ninja. Malware is known to cause the problems that you state. It is highly likely that you have remnants of the infection that might be the cause of your problem. Please visit the folks in the Malware Forums and let them clean you up. If the problem persists, we can continue our troubleshooting here. ;)

– Mohit
I am not sure whether Malware is the issue. After the persistence of the problem for 2 days i restored the ghost image but didnt format my other drives. For a few moments it worked fine but the problem started again. Also strange thing is there is no disturbance in the normal surfing of sites like mails etc. The download starts but stops after reaching 30 to 40%. From morning iam trying to download hijack this but it stops after reaching 29% but at the same time iam able to download word files(tested 3 docs) from email attachments.

After the persistence of the problem for 2 days i restored the ghost image but didnt format my other drives. For a few moments it worked fine but the problem started again. Also strange thing is there is no disturbance in the normal surfing of sites like mails etc. The download starts but stops after reaching 30 to 40%.

Hello Ninja. There is a possibility that your ghost image might contain the infection too and that is why it resurfaced. The Malware took the "few moments" to copy and reactivate itself and that might explain why you are facing the problem now. Can you boot into Safe Mode With Networking and see if you are able to download anything?

– Mohit
Well i have always restored the same image but this problem iam facing first time. Any way i will check safe mode with networking and will let u know
I was not able to connect to net in safe mode with networking. After restart iam getting the following error(screen dump attahed) 4/15/2009 9:50:11 PM Detected: Intrusion.Win.NETAPI.buffer-overflow.exploit Absent TCP from 172.16.1.74 to local port 445 Its strange before rebooting i scanned with Anti malware bytes which gave clean chit Pls advise

Attachments:

Hello Ninja. It would be in your best interest to visit the Malware Removal Forums as soon as possible and let the experts handle the matter. I am sorry but I cannot advise you further unless you are deemed clean by the specialists. :( – Mohit
Hey Smiling ninja,

You are doing a good job of describing and trying to give us information about your present problem. :thumbup:

Seems like some downloads are relatively smooth, and others hang.
This is sometimes the case with Malware Infection.
And that is the reason why I want this Topic to be handled by one of our trained specialists over in the Malware Removal Forum.

I'm going to move this Thread over to Malware Removal Forum.
Please know that the specialists there are very busy and it may take a while for them to get to your topic.
Please be patient while you wait for your turn.

*** As to SAFE Mode w/ Networking ***

this is very risky and not at all recommended.

In SAFE Mode all of your security programs are turned off, including Firewall.
Therefore you are "wide-open" to attack.
If malware is already ifected into the machine, SAFE Mode w/ Networking gives it a free ride to "call home". Not good.

In some controlled situations, a brief connection to the internet while in SAFE Mode w/ Networking may be a user's only option to, for instance, download a HJT.exe installer or some other needed tool.

However, do not do any general browsing of the internet, until you get the Malware situation resolved with your machine.

I'm moving your thread to Malware Removal now.
Remember, please be patient.

Thanks for deciding to join and learn and work on your machine.
We're delighted to help.

Best Regards
Hi


My Anti Hijack logs

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:47:40 PM, on 4/16/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9EB97B27-D657-4EB9-AD2F-A3058A857197}: NameServer = 203.192.198.7,203.192.195.18
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

–
End of file - 5063 bytes
smiling ninja,

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.

Also, seeing how time has passed. What are you noticing now? At the time you took your log, it looks like windows was trying to update. Did it?
Hi Tomk The problem is still persisting. Iam unable to do windows update getting the error r: 0x8024402F. Pls find the logs. DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 20:57:35.42 on Tue 04/21/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_10 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1790.1237 [GMT 5.5:30] AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) FW: Kaspersky Internet Security *disabled* ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe E:\RRT\RRT.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wscntfy.exe H:\software\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.in/ BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\user\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [RRT-Auto] e:\rrt\RRT.exe auto uPolicies-explorer: NoWindowsUpdate = 0 (0x0) uPolicies-explorer: NoViewOnDrive = 0 (0x0) mPolicies-explorer: NoWindowsUpdate = 0 (0x0) mPolicies-explorer: NoViewOnDrive = 0 (0x0) IE: Add to Banner Ad Blocker - c:\program files\kaspersky lab\kaspersky internet security 2009\ie_banner_deny.htm IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1239991601937 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: klogon - c:\windows\system32\klogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\hmgjz387.default\ FF - plugin: c:\documents and settings\user\local settings\application data\google\update\1.2.141.5\npGoogleOneClick7.dll ============= SERVICES / DRIVERS =============== R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2008-7-21 121872] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 33808] R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2009-4-14 226832] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-3-23 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-3-23 72944] R2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe [2008-11-11 206088] R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-4-30 24592] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-3-23 7408] S2 ukqtn;Task Boot;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] =============== Created Last 30 ================ 2009-04-21 20:51 –d—– C:\RRTVAULT 2009-04-21 20:50 16,244 a——- c:\windows\system32\rrt_is.wav 2009-04-21 20:50 7,302 a——- c:\windows\system32\rrt_vf.wav 2009-04-21 20:50 7,148 a——- c:\windows\system32\rrt_tv.wav 2009-04-21 20:50 6,282 a——- c:\windows\system32\rrt_tn.wav 2009-04-21 00:07 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-04-21 00:07 –d—– c:\program files\SUPERAntiSpyware 2009-04-21 00:07 –d—– c:\docume~1\user\applic~1\SUPERAntiSpyware.com 2009-04-21 00:07 –d—– c:\program files\common files\Wise Installation Wizard 2009-04-18 00:14 –d—– c:\windows\system32\XPSViewer 2009-04-18 00:13 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-04-18 00:13 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-04-18 00:13 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-04-18 00:13 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-04-18 00:13 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-04-18 00:13 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-04-18 00:13 117,760 ——– c:\windows\system32\prntvpt.dll 2009-04-18 00:10 –d—– c:\program files\MSXML 6.0 2009-04-17 23:41 31,768 a——- c:\windows\system32\wucltui.dll.mui 2009-04-17 23:41 23,576 a——- c:\windows\system32\wuaucpl.cpl.mui 2009-04-17 23:41 23,576 a——- c:\windows\system32\wuapi.dll.mui 2009-04-17 23:41 18,456 a——- c:\windows\system32\wuaueng.dll.mui 2009-04-17 23:41 –d—– c:\windows\system32\SoftwareDistribution 2009-04-16 22:27 410,976 a——- c:\windows\system32\deploytk.dll 2009-04-16 22:27 73,728 a——- c:\windows\system32\javacpl.cpl 2009-04-16 22:25 453,632 -c—— c:\windows\system32\dllcache\mrxsmb.sys 2009-04-16 21:47 –d—– c:\program files\Trend Micro 2009-04-15 15:53 –d—– c:\docume~1\user\applic~1\TeamViewer 2009-04-15 15:53 –d—– c:\documents and settings\user\temp 2009-04-15 11:58 –d—– C:\123 2009-04-14 22:53 –d—– c:\docume~1\user\applic~1\Malwarebytes 2009-04-14 22:53 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-04-14 17:14 69 a——- c:\windows\NeroDigital.ini 2009-04-14 17:08 359,040 a——- c:\windows\system32\drivers\tcpip.sys.flg 2009-04-14 17:08 –d—– c:\program files\FlashGet 2009-04-14 17:00 –d—– c:\program files\CCleaner 2009-04-14 14:34 1,289 a——- c:\windows\system32\%LocalXml% 2009-04-14 14:20 335,904 a–sh— c:\windows\system32\drivers\fidbox2.dat 2009-04-14 14:20 5,372 a–sh— c:\windows\system32\drivers\fidbox2.idx 2009-04-14 13:55 101,287 a——- c:\windows\system32\drivers\klin.dat 2009-04-14 13:55 89,601 a——- c:\windows\system32\drivers\klick.dat 2009-04-14 13:54 –d—– c:\program files\Kaspersky Lab 2009-04-14 13:54 –d—– c:\docume~1\alluse~1\applic~1\Kaspersky Lab 2009-04-14 13:53 –d—– c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files 2009-04-14 13:52 5,451,579 a——- c:\windows\REGBK00.ZIP ==================== Find3M ==================== 2009-04-21 20:53 3,211,296 a–sh— c:\windows\system32\drivers\fidbox.dat 2009-04-21 20:53 49,304 a–sh— c:\windows\system32\drivers\fidbox.idx 2009-04-14 14:33 33,808 a——- c:\windows\system32\drivers\klbg.sys 2008-07-20 16:34 2,516 a–sh— c:\windows\system32\KGyGaAvL.sys ============= FINISH: 20:57:54.28 ===============

Attachments:

smiling ninja,

It looks like you installed SuperAntiSpyware this morning. What did it find?

Please don't install and/or run any programs, unless directed, while being helped.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please go to Kaspersky website and perform an online antivirus scan. (I realize you have Kaspersky security suite. I need you to run the online scan).

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI