This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Scan Turns Up Multiple Trojans

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:46 PM, on 4/14/2009
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Acer\Empowering Technology\eDSMSNfix.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Users\Pamela\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101760&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [eDSMSNfix] C:\Acer\Empowering Technology\eDSMSNfix.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Windows Sidebar] "C:\Program Files\Windows Sidebar\Sidebar.exe" /autorun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Pamela\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Htolese] rundll32.exe "C:\Users\Pamela\AppData\Local\Snesogapogax.dll",e
O4 - HKCU\..\Run: [Bkebu] rundll32.exe "C:\Users\Pamela\AppData\Local\evuxozuv.dll",e
O4 - HKCU\..\Run: [1c9ef6cd] rundll32.exe "C:\ProgramData\joyabihu\joyabihu.dll",b
O4 - HKCU\..\Run: [fopovulibe] Rundll32.exe "C:\ProgramData\yihigiyo\yihigiyo.dll",s
O4 - HKCU\..\Run: [CPM1fadc551] Rundll32.exe "C:\ProgramData\moligefa\moligefa.dll",a
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix: 
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll eNetHook.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe

–
End of file - 10645 bytes

I've got Windows Vista running on an acer laptop. I'm not too literate in the terms used to describe computer processes, so I'll try to be descriptive. This is not originally my laptop, it was first my father-in-law's but he only used it once, I believe. After I took it, I ran scans, and you know, all the maintenance things you do to keep the computer running properly. This past week, I lent the computer to my 11 year old sister in law, because she needed to work on a school project over spring break when she went away for the weekend. Upon her return, I scanned the computer for viruses, and found the computer to be a little slow, and a little buggy, maybe. The mouse was a little skittery, that kind of thing. At first I thought it was just that my sister in law hadn't restarted the computer in a while, and running the scanner and the internet at the same time was a bit much for it, but the scan turned out 25 Trojans, and many, many more Tracking Cookies. I don't know where she went, or what she did, but she does admit to using the computer to play games and surf the web. She remembered specifically MSN, disney, and hotmail. I'm thinking maybe she had a malicious attachment? She is the type of person who would open an unexpected email and attachment to "find out what the hell it is" so…

The scan I did said it "removed" the virus files, but my girlfriend told me that basically means nothing, and pointed me in the direction of these forums. n.nU So I guess you can thanks her for sending me here to provide you with more work. At this point, any and all help would be appreciated. Thank you much in advance. <3

-hakidarete
Hi,

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
I ran ComboFIx after uninstalling Norton, since it wouldn't allow me to disable it, as well as a few other, unrelated programs, primarily from the Acer Empower whatever group, since I never use it anyway. o.O I don't think any of the programs I removed should affect anything really, but if you need, I can list what I removed. And thank you so much for the help so far. n.n

ETA: almost forgot. Since I ran HijackThis, every time I restart the computer, I have about five or six RunDLL errors. They're a mashup of letters, and don't seem to be Microsoft related, and I'm thinking they may be part of the virus. If you need me to take down the names and repost them here, I can.

The ComboFIx log:



ComboFix 09-04-17.01 - Pamela 04/16/2009 22:03.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6000.0.1252.1.1033.18.1014.399 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
 * Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\x64

.
(((((((((((((((((((((((((   Files Created from 2009-03-17 to 2009-04-17  )))))))))))))))))))))))))))))))
.

2009-04-17 00:17 . 2009-04-17 00:17	——–	d—–w	c:\users\Pamela\AppData\Local\PowerCinema
2009-04-15 01:42 . 2008-12-08 04:34	376832	—-a-w	c:\windows\system32\winhttp.dll
2009-04-15 01:42 . 2008-06-05 04:50	500736	—-a-w	c:\windows\system32\msdtcprx.dll
2009-04-15 01:42 . 2008-06-05 04:50	30208	—-a-w	c:\windows\system32\xolehlp.dll
2009-04-15 01:41 . 2009-03-03 04:19	549888	—-a-w	c:\windows\system32\rpcss.dll
2009-04-15 01:41 . 2009-03-03 04:24	3469280	—-a-w	c:\windows\system32\ntoskrnl.exe
2009-04-15 01:41 . 2009-03-03 04:24	3503584	—-a-w	c:\windows\system32\ntkrnlpa.exe
2009-04-15 01:41 . 2009-03-03 02:40	654336	—-a-w	c:\windows\system32\printfilterpipelinesvc.exe
2009-04-15 01:41 . 2009-03-03 04:19	158720	—-a-w	c:\windows\system32\sdohlp.dll
2009-04-15 01:41 . 2009-03-03 04:19	24576	—-a-w	c:\windows\system32\printfilterpipelineprxy.dll
2009-04-15 01:41 . 2009-03-03 04:16	97280	—-a-w	c:\windows\system32\iasrecst.dll
2009-04-15 01:41 . 2009-03-03 04:16	37888	—-a-w	c:\windows\system32\iasdatastore.dll
2009-04-15 01:41 . 2009-03-03 04:16	53248	—-a-w	c:\windows\system32\iasads.dll
2009-04-15 01:35 . 2009-03-03 04:16	78336	—-a-w	c:\windows\system32\ieencode.dll
2009-04-15 01:35 . 2009-03-03 04:15	72704	—-a-w	c:\windows\system32\admparse.dll
2009-04-15 01:35 . 2009-03-03 02:08	26624	—-a-w	c:\windows\system32\ieUnatt.exe
2009-04-15 01:35 . 2009-03-03 04:16	56320	—-a-w	c:\windows\system32\iesetup.dll
2009-04-15 01:35 . 2009-03-03 00:38	1383424	—-a-w	c:\windows\system32\mshtml.tlb
2009-04-15 01:35 . 2009-03-03 00:44	48128	—-a-w	c:\windows\system32\mshtmler.dll
2009-04-14 02:25 . 2009-04-16 07:23	——–	d–h–w	C:\$AVG8.VAULT$
2009-04-14 02:15 . 2009-04-14 02:15	10520	—-a-w	c:\windows\system32\avgrsstx.dll
2009-04-14 02:15 . 2009-04-14 02:15	108552	—-a-w	c:\windows\system32\drivers\avgtdix.sys
2009-04-14 02:14 . 2009-04-14 02:14	325640	—-a-w	c:\windows\system32\drivers\avgldx86.sys
2009-04-14 02:14 . 2009-04-16 23:34	——–	d—–w	c:\windows\system32\drivers\Avg
2009-04-14 02:13 . 2009-04-14 02:13	——–	d—–w	c:\users\All Users\avg8
2009-04-14 02:13 . 2009-04-14 02:13	——–	d—–w	c:\programdata\avg8
2009-04-13 21:49 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\mimahila
2009-04-13 21:49 . 2009-04-14 03:19	——–	d—–w	c:\programdata\mimahila
2009-04-13 21:49 . 2009-04-14 02:25	——–	d—–w	c:\users\All Users\moligefa
2009-04-13 21:49 . 2009-04-14 02:25	——–	d—–w	c:\programdata\moligefa
2009-04-12 21:05 . 2009-04-12 22:39	——–	d—–w	c:\users\Pamela\AppData\Roaming\gtk-2.0
2009-04-12 20:53 . 2009-04-16 07:23	——–	d—–w	c:\users\All Users\vezogupi
2009-04-12 20:53 . 2009-04-16 07:23	——–	d—–w	c:\programdata\vezogupi
2009-04-12 20:53 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\lininofa
2009-04-12 20:53 . 2009-04-14 03:19	——–	d—–w	c:\programdata\lininofa
2009-04-12 07:36 . 2009-04-14 03:21	——–	d—–w	c:\users\All Users\yusuyufe
2009-04-12 07:36 . 2009-04-14 03:21	——–	d—–w	c:\programdata\yusuyufe
2009-04-12 07:36 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\fodevuna
2009-04-12 07:36 . 2009-04-14 03:19	——–	d—–w	c:\programdata\fodevuna
2009-04-11 19:37 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\sunotadi
2009-04-11 19:37 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\savogiju
2009-04-11 19:37 . 2009-04-14 03:19	——–	d—–w	c:\programdata\sunotadi
2009-04-11 19:37 . 2009-04-14 03:19	——–	d—–w	c:\programdata\savogiju
2009-04-11 19:37 . 2009-04-14 02:27	——–	d—–w	c:\users\All Users\yihigiyo
2009-04-11 19:37 . 2009-04-14 02:27	——–	d—–w	c:\programdata\yihigiyo
2009-04-11 19:36 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\miyowepa
2009-04-11 19:36 . 2009-04-14 03:19	——–	d—–w	c:\programdata\miyowepa
2009-04-11 19:36 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\joyabihu
2009-04-11 19:36 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\dibafeya
2009-04-11 19:36 . 2009-04-14 03:19	——–	d—–w	c:\programdata\joyabihu
2009-04-11 19:36 . 2009-04-14 03:19	——–	d—–w	c:\programdata\dibafeya
2009-04-11 19:36 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\debeviva
2009-04-11 19:36 . 2009-04-14 03:19	——–	d—–w	c:\programdata\debeviva
2009-04-11 01:31 . 2009-04-16 07:13	0	—-a-w	c:\users\Pamela\AppData\Local\Ubojakecofezipa.bin
2009-04-11 01:31 . 2009-04-11 01:31	——–	d—–w	c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}
2009-04-11 01:31 . 2009-04-16 07:13	408	—-a-w	c:\users\Pamela\AppData\Local\Rfarijohapuhi.dat
2009-04-11 01:31 . 2009-04-11 01:31	158720	—-a-w	c:\users\Pamela\AppData\Local\evuxozuv.dll
2009-04-11 01:19 . 2009-04-15 01:53	——–	d—–w	c:\users\All Users\wizuyebi
2009-04-11 01:19 . 2009-04-15 01:53	——–	d—–w	c:\programdata\wizuyebi
2009-04-11 01:19 . 2009-04-14 03:21	——–	d—–w	c:\users\All Users\tavagato
2009-04-11 01:19 . 2009-04-14 03:21	——–	d—–w	c:\programdata\tavagato
2009-04-11 01:19 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\semusoji
2009-04-11 01:19 . 2009-04-14 03:19	——–	d—–w	c:\programdata\semusoji
2009-04-11 01:19 . 2009-04-14 03:19	——–	d—–w	c:\users\All Users\dovukipo
2009-04-11 01:19 . 2009-04-14 03:19	——–	d—–w	c:\programdata\dovukipo
2009-04-11 01:13 . 2009-04-16 07:22	——–	d—–w	c:\users\All Users\sohoyota
2009-04-11 01:13 . 2009-04-16 07:22	——–	d—–w	c:\programdata\sohoyota
2009-04-11 01:13 . 2009-04-16 07:22	——–	d—–w	c:\users\All Users\rusahene
2009-04-11 01:13 . 2009-04-16 07:22	——–	d—–w	c:\programdata\rusahene
2009-04-11 01:13 . 2009-04-16 07:21	——–	d—–w	c:\users\All Users\guserohu
2009-04-11 01:13 . 2009-04-16 07:21	——–	d—–w	c:\programdata\guserohu
2009-03-24 19:25 . 2009-03-31 20:39	——–	d—–w	c:\users\Pamela\AppData\Roaming\uTorrent

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-17 01:44 . 2007-03-28 11:00	——–	d–h–w	c:\program files\InstallShield Installation Information
2009-04-17 01:43 . 2007-05-30 04:59	——–	d—–w	c:\program files\Acer Inc
2009-04-17 01:39 . 2007-08-22 02:38	——–	d—–w	c:\program files\Yahoo!
2009-04-17 01:15 . 2007-10-27 02:15	——–	d—–w	c:\program files\palmOne
2009-04-17 01:09 . 2007-03-28 12:07	——–	d—–w	c:\program files\Common Files\Symantec Shared
2009-04-17 01:01 . 2007-03-28 12:07	——–	d—–w	c:\programdata\Symantec
2009-04-17 00:19 . 2007-03-28 11:13	——–	d—–w	c:\program files\Acer Arcade Deluxe
2009-04-17 00:19 . 2009-04-17 00:18	380	—-a-w	C:\PowerDV.log
2009-04-17 00:18 . 2009-04-17 00:18	91	—-a-w	C:\MDR.log
2009-04-17 00:18 . 2009-04-17 00:17	91	—-a-w	C:\MDisc.log
2009-04-16 23:59 . 2009-04-16 23:59	3919	—-a-w	C:\-20090416.log
2009-04-15 07:12 . 2006-11-02 11:18	——–	d—–w	c:\program files\Windows Mail
2009-04-15 02:09 . 2009-04-15 02:09	——–	d—–w	c:\program files\Trend Micro
2009-04-14 02:13 . 2009-04-14 02:13	——–	d—–w	c:\program files\AVG
2009-03-25 17:27 . 2009-03-25 17:27	——–	d—–w	c:\program files\WinGZip
2009-03-24 19:26 . 2009-03-24 19:26	——–	d—–w	c:\program files\uTorrent
2009-03-17 03:16 . 2009-04-15 01:36	40960	—-a-w	c:\windows\AppPatch\apihex86.dll
2009-03-17 03:16 . 2009-04-15 01:36	14848	—-a-w	c:\windows\System32\apilogen.dll
2009-03-17 03:16 . 2009-04-15 01:36	25600	—-a-w	c:\windows\System32\amxread.dll
2009-03-12 06:48 . 2009-03-09 19:19	90	—-a-w	c:\users\Pamela\AppData\Roaming\wklnhst.dat
2009-03-09 19:19 . 2009-03-09 19:19	——–	d—–w	c:\users\Pamela\AppData\Roaming\Template
2009-03-05 00:54 . 2009-03-05 00:54	——–	d—–w	c:\users\Pamela\AppData\Roaming\Unity
2009-03-05 00:51 . 2009-03-05 00:51	——–	d—–w	c:\program files\Unity
2009-03-03 04:20 . 2009-04-15 01:36	826368	—-a-w	c:\windows\System32\wininet.dll
2009-03-03 04:16 . 2009-04-15 01:35	52736	—-a-w	c:\windows\AppPatch\iebrshim.dll
2009-02-13 07:26 . 2009-04-15 01:36	72704	—-a-w	c:\windows\System32\secur32.dll
2009-02-13 07:26 . 2009-04-15 01:36	1233408	—-a-w	c:\windows\System32\lsasrv.dll
2009-02-13 07:26 . 2009-04-15 01:36	7680	—-a-w	c:\windows\System32\lsass.exe
2009-02-09 01:59 . 2009-03-11 16:52	2028032	—-a-w	c:\windows\System32\win32k.sys
2009-01-27 03:09 . 2006-11-02 10:25	86016	—-a-w	c:\windows\Inf\infstrng.dat
2009-01-27 03:09 . 2006-11-02 10:25	51200	—-a-w	c:\windows\Inf\infpub.dat
2009-01-27 03:09 . 2006-11-02 10:25	86016	—-a-w	c:\windows\Inf\infstor.dat
2009-01-12 11:52 . 2006-11-02 12:50	174	–sha-w	c:\program files\desktop.ini
2007-08-22 02:39 . 2007-08-22 02:39	70104	—-a-w	c:\users\Pamela\AppData\Local\GDIPFONTCACHEV1.DAT
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-01-11 1232896]
"Windows Sidebar"="c:\program files\Windows Sidebar\Sidebar.exe" [2009-01-11 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"Bkebu"="c:\users\Pamela\AppData\Local\evuxozuv.dll" [2009-04-11 158720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-16 815104]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-06 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-06 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-06 81920]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2007-01-11 483328]
"eDSMSNfix"="c:\acer\Empowering Technology\eDSMSNfix.exe" [2007-02-08 13312]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-14 1932568]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-12-01 4186112]

c:\users\Pamela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-3-28 528384]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{652EEB8C-CE2F-4443-94F3-61D1C9779AA6}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0BCD854A-5C93-4D3D-A8ED-66616CB0D8CF}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9E74A2CD-A50D-46C0-A653-103D8B1E9AD7}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{A89D081F-2C9C-4D7E-B2C2-C1C729905F41}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{4A805A4B-0A0E-4AE8-9FAE-1B8401C105BF}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{48E817BE-C37A-49B0-9F01-E264DB4AC45B}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{B90B6E28-4699-47CA-8F4B-010E5A34CF2E}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{7DA17813-37FF-4CEA-9D76-4246B9998C10}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{741F6E25-1CB8-4A5C-B40F-39B393948D93}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-04-14 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-14 298264]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-14 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-14 108552]
S2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688]

.
Contents of the 'Scheduled Tasks' folder

2009-04-16 c:\windows\Tasks\User_Feed_Synchronization-{F192F9E1-880D-4051-9A66-2CD18495AAB4}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Htolese - c:\users\Pamela\AppData\Local\Snesogapogax.dll
HKCU-Run-1c9ef6cd - c:\programdata\joyabihu\joyabihu.dll
HKCU-Run-fopovulibe - c:\programdata\yihigiyo\yihigiyo.dll
HKCU-Run-CPM1fadc551 - c:\programdata\moligefa\moligefa.dll
HKCU-Run-Acer Tour Reminder - (no file)
HKLM-Run-ALaunch - c:\acer\ALaunch\AlaunchClient.exe
HKLM-Run-Acer Tour Reminder - c:\acer\AcerTour\Reminder.exe
HKLM-Run-SetPanel - c:\acer\APanel\APanel.cmd
HKLM-Run-eRecoveryService - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ask.com/?o=101760&l;=dis
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Pamela\AppData\Roaming\Mozilla\Firefox\Profiles\cf7i2g2e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=101760&l;=dis
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct;=&gc;=1&q;=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-16 22:05
Windows 6.0.6000  NTFS

scanning hidden processes …  

scanning hidden autostart entries … 

scanning hidden files …  

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-04-17 22:07
ComboFix-quarantined-files.txt  2009-04-17 02:07

Pre-Run: 47,417,909,248 bytes free
Post-Run: 47,356,600,320 bytes free

224	— E O F —	2009-04-15 07:06
Hi;

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
c:\users\Pamela\AppData\Local\Ubojakecofezipa.bin
c:\users\Pamela\AppData\Local\Rfarijohapuhi.dat
c:\users\Pamela\AppData\Local\evuxozuv.dll

Folder::
c:\users\All Users\mimahila
c:\programdata\mimahila
c:\users\All Users\moligefa
c:\programdata\moligefa
c:\users\All Users\vezogupi
c:\programdata\vezogupi
 c:\users\All Users\lininofa
c:\programdata\lininofa
c:\users\All Users\yusuyufe
c:\programdata\yusuyufe
c:\users\All Users\fodevuna
c:\programdata\fodevuna
c:\users\All Users\sunotadi
c:\users\All Users\savogiju
c:\programdata\sunotadi
c:\programdata\savogiju
c:\users\All Users\yihigiyo
c:\programdata\yihigiyo
c:\users\All Users\miyowepa
c:\programdata\miyowepa
c:\users\All Users\joyabihu
c:\users\All Users\dibafeya
c:\programdata\joyabihu
c:\programdata\dibafeya
c:\users\All Users\debeviva
c:\programdata\debeviva
c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}
c:\users\All Users\wizuyebi
c:\programdata\wizuyebi
c:\users\All Users\tavagato
c:\programdata\tavagato
c:\users\All Users\semusoji
c:\programdata\semusoji
c:\users\All Users\dovukipo
c:\programdata\dovukipo
c:\users\All Users\sohoyota
c:\programdata\sohoyota
c:\users\All Users\rusahene
c:\programdata\rusahene
c:\users\All Users\guserohu
c:\programdata\guserohu

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Bkebu"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

* Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
* ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
* When finished, it shall produce a log for you.
* Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NOTE: CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


>>>NEXT<<<


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply please include

  • ComboFix Log
  • MBAM Log
  • Kaspersky report
  • Fresh HJT log
Due to inactivity this topic will be closed. If you need help please start a new thread and post a new HJT log Topic reopened at request of original poster
I fell ill and didn't respond to this thread in time, so I'm continuing it here.

My ComboFix Log:
ComboFix 09-04-17.01 - Pamela 04/22/2009 14:28.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1014.380 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Pamela\Desktop\cfscript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point

FILE ::
c:\users\Pamela\AppData\Local\evuxozuv.dll
c:\users\Pamela\AppData\Local\Rfarijohapuhi.dat
c:\users\Pamela\AppData\Local\Ubojakecofezipa.bin
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\debeviva
c:\programdata\dibafeya
c:\programdata\dovukipo
c:\programdata\fodevuna
c:\programdata\guserohu
c:\programdata\joyabihu
c:\programdata\joyabihu\uhibayoj.ini
c:\programdata\lininofa
c:\programdata\mimahila
c:\programdata\miyowepa
c:\programdata\moligefa
c:\programdata\rusahene
c:\programdata\savogiju
c:\programdata\semusoji
c:\programdata\semusoji\ijosumes.ini
c:\programdata\sohoyota
c:\programdata\sunotadi
c:\programdata\tavagato
c:\programdata\vezogupi
c:\programdata\wizuyebi
c:\programdata\yihigiyo
c:\programdata\yusuyufe
c:\users\All Users\joyabihu\uhibayoj.ini
c:\users\All Users\semusoji\ijosumes.ini
c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}
c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}\chrome.manifest
c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}\chrome\content\_cfg.js
c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}\chrome\content\c.js
c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}\chrome\content\overlay.xul
c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}\install.rdf
c:\users\Pamela\AppData\Local\evuxozuv.dll
c:\users\Pamela\AppData\Local\Rfarijohapuhi.dat
c:\users\Pamela\AppData\Local\Ubojakecofezipa.bin

.
((((((((((((((((((((((((( Files Created from 2009-03-22 to 2009-04-22 )))))))))))))))))))))))))))))))
.

2009-04-17 00:17 . 2009-04-17 00:17 ——– d—–w c:\users\Pamela\AppData\Local\PowerCinema
2009-04-15 01:42 . 2008-12-08 04:34 376832 —-a-w c:\windows\system32\winhttp.dll
2009-04-15 01:42 . 2008-06-05 04:50 500736 —-a-w c:\windows\system32\msdtcprx.dll
2009-04-15 01:42 . 2008-06-05 04:50 30208 —-a-w c:\windows\system32\xolehlp.dll
2009-04-15 01:41 . 2009-03-03 04:19 549888 —-a-w c:\windows\system32\rpcss.dll
2009-04-15 01:41 . 2009-03-03 04:24 3469280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-04-15 01:41 . 2009-03-03 04:24 3503584 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-04-15 01:41 . 2009-03-03 02:40 654336 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-04-15 01:41 . 2009-03-03 04:19 158720 —-a-w c:\windows\system32\sdohlp.dll
2009-04-15 01:41 . 2009-03-03 04:19 24576 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-04-15 01:41 . 2009-03-03 04:16 97280 —-a-w c:\windows\system32\iasrecst.dll
2009-04-15 01:41 . 2009-03-03 04:16 37888 —-a-w c:\windows\system32\iasdatastore.dll
2009-04-15 01:41 . 2009-03-03 04:16 53248 —-a-w c:\windows\system32\iasads.dll
2009-04-15 01:35 . 2009-03-03 04:16 78336 —-a-w c:\windows\system32\ieencode.dll
2009-04-15 01:35 . 2009-03-03 04:15 72704 —-a-w c:\windows\system32\admparse.dll
2009-04-15 01:35 . 2009-03-03 02:08 26624 —-a-w c:\windows\system32\ieUnatt.exe
2009-04-15 01:35 . 2009-03-03 04:16 56320 —-a-w c:\windows\system32\iesetup.dll
2009-04-15 01:35 . 2009-03-03 00:38 1383424 —-a-w c:\windows\system32\mshtml.tlb
2009-04-15 01:35 . 2009-03-03 00:44 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-04-14 02:25 . 2009-04-16 07:23 ——– d–h–w C:\$AVG8.VAULT$
2009-04-14 02:15 . 2009-04-14 02:15 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-04-14 02:15 . 2009-04-14 02:15 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-14 02:14 . 2009-04-14 02:14 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-14 02:14 . 2009-04-16 23:34 ——– d—–w c:\windows\system32\drivers\Avg
2009-04-14 02:13 . 2009-04-14 02:13 ——– d—–w c:\users\All Users\avg8
2009-04-14 02:13 . 2009-04-14 02:13 ——– d—–w c:\programdata\avg8
2009-04-12 21:05 . 2009-04-12 22:39 ——– d—–w c:\users\Pamela\AppData\Roaming\gtk-2.0
2009-03-24 19:25 . 2009-03-31 20:39 ——– d—–w c:\users\Pamela\AppData\Roaming\uTorrent

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-17 01:44 . 2007-03-28 11:00 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-17 01:43 . 2007-05-30 04:59 ——– d—–w c:\program files\Acer Inc
2009-04-17 01:39 . 2007-08-22 02:38 ——– d—–w c:\program files\Yahoo!
2009-04-17 01:15 . 2007-10-27 02:15 ——– d—–w c:\program files\palmOne
2009-04-17 01:09 . 2007-03-28 12:07 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-04-17 01:01 . 2007-03-28 12:07 ——– d—–w c:\programdata\Symantec
2009-04-17 00:19 . 2007-03-28 11:13 ——– d—–w c:\program files\Acer Arcade Deluxe
2009-04-17 00:19 . 2009-04-17 00:18 380 —-a-w C:\PowerDV.log
2009-04-17 00:18 . 2009-04-17 00:18 91 —-a-w C:\MDR.log
2009-04-17 00:18 . 2009-04-17 00:17 91 —-a-w C:\MDisc.log
2009-04-16 23:59 . 2009-04-16 23:59 3919 —-a-w C:\-20090416.log
2009-04-15 07:12 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-04-15 02:09 . 2009-04-15 02:09 ——– d—–w c:\program files\Trend Micro
2009-04-14 02:13 . 2009-04-14 02:13 ——– d—–w c:\program files\AVG
2009-03-25 17:27 . 2009-03-25 17:27 ——– d—–w c:\program files\WinGZip
2009-03-24 19:26 . 2009-03-24 19:26 ——– d—–w c:\program files\uTorrent
2009-03-17 03:16 . 2009-04-15 01:36 40960 —-a-w c:\windows\AppPatch\apihex86.dll
2009-03-17 03:16 . 2009-04-15 01:36 14848 —-a-w c:\windows\System32\apilogen.dll
2009-03-17 03:16 . 2009-04-15 01:36 25600 —-a-w c:\windows\System32\amxread.dll
2009-03-12 06:48 . 2009-03-09 19:19 90 —-a-w c:\users\Pamela\AppData\Roaming\wklnhst.dat
2009-03-09 19:19 . 2009-03-09 19:19 ——– d—–w c:\users\Pamela\AppData\Roaming\Template
2009-03-05 00:54 . 2009-03-05 00:54 ——– d—–w c:\users\Pamela\AppData\Roaming\Unity
2009-03-05 00:51 . 2009-03-05 00:51 ——– d—–w c:\program files\Unity
2009-03-03 04:20 . 2009-04-15 01:36 826368 —-a-w c:\windows\System32\wininet.dll
2009-03-03 04:16 . 2009-04-15 01:35 52736 —-a-w c:\windows\AppPatch\iebrshim.dll
2009-02-13 07:26 . 2009-04-15 01:36 72704 —-a-w c:\windows\System32\secur32.dll
2009-02-13 07:26 . 2009-04-15 01:36 1233408 —-a-w c:\windows\System32\lsasrv.dll
2009-02-13 07:26 . 2009-04-15 01:36 7680 —-a-w c:\windows\System32\lsass.exe
2009-02-09 01:59 . 2009-03-11 16:52 2028032 —-a-w c:\windows\System32\win32k.sys
2009-01-27 03:09 . 2006-11-02 10:25 86016 —-a-w c:\windows\Inf\infstrng.dat
2009-01-27 03:09 . 2006-11-02 10:25 51200 —-a-w c:\windows\Inf\infpub.dat
2009-01-27 03:09 . 2006-11-02 10:25 86016 —-a-w c:\windows\Inf\infstor.dat
2009-01-12 11:52 . 2006-11-02 12:50 174 –sha-w c:\program files\desktop.ini
2007-08-22 02:39 . 2007-08-22 02:39 70104 —-a-w c:\users\Pamela\AppData\Local\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-04-17_02.06.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-08-22 02:39 . 2009-04-22 18:25 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-08-22 02:39 . 2009-04-17 00:41 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-08-22 02:39 . 2009-04-17 00:41 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-08-22 02:39 . 2009-04-22 18:25 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-08-22 02:39 . 2009-04-17 00:41 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-08-22 02:39 . 2009-04-22 18:25 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-08-23 03:31 . 2009-04-22 09:31 215624 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2006-11-02 12:47 . 2009-04-17 02:06 262144 c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2006-11-02 12:47 . 2009-04-17 01:58 262144 c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2007-08-22 02:46 . 2009-04-17 02:02 262144 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2007-08-22 02:46 . 2009-04-17 23:39 262144 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2006-11-02 12:47 . 2009-04-17 01:59 262144 c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2006-11-02 12:47 . 2009-04-17 02:06 262144 c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2007-08-22 02:45 . 2009-04-17 23:38 262144 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2007-08-22 02:45 . 2009-04-17 01:58 262144 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-01-11 1232896]
"Windows Sidebar"="c:\program files\Windows Sidebar\Sidebar.exe" [2009-01-11 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-16 815104]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-06 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-06 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-06 81920]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2007-01-11 483328]
"eDSMSNfix"="c:\acer\Empowering Technology\eDSMSNfix.exe" [2007-02-08 13312]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-14 1932568]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-12-01 4186112]

c:\users\Pamela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-3-28 528384]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{652EEB8C-CE2F-4443-94F3-61D1C9779AA6}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0BCD854A-5C93-4D3D-A8ED-66616CB0D8CF}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9E74A2CD-A50D-46C0-A653-103D8B1E9AD7}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{A89D081F-2C9C-4D7E-B2C2-C1C729905F41}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{4A805A4B-0A0E-4AE8-9FAE-1B8401C105BF}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{48E817BE-C37A-49B0-9F01-E264DB4AC45B}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{B90B6E28-4699-47CA-8F4B-010E5A34CF2E}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{7DA17813-37FF-4CEA-9D76-4246B9998C10}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{741F6E25-1CB8-4A5C-B40F-39B393948D93}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-04-14 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-14 298264]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-14 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-14 108552]
S2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688]

.
Contents of the 'Scheduled Tasks' folder

2009-04-22 c:\windows\Tasks\User_Feed_Synchronization-{F192F9E1-880D-4051-9A66-2CD18495AAB4}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ask.com/?o=101760&l;=dis
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Pamela\AppData\Roaming\Mozilla\Firefox\Profiles\cf7i2g2e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=101760&l;=dis
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct;=&gc;=1&q;=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-22 14:30
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-04-22 14:32
ComboFix-quarantined-files.txt 2009-04-22 18:32
ComboFix2.txt 2009-04-17 02:07

Pre-Run: 46,813,761,536 bytes free
Post-Run: 46,580,146,176 bytes free

225 — E O F — 2009-04-17 23:41

However, this is as far as I could get. For some reason, downloading is disabled on my computer, and I can't figure out how to re-enable it. Suggestions?
Hi, Can you please tell me what happens when you try and download? Do you get some type of error message or you cannot access the internet? Please describe in detail what takes place? Please post a fresh HJT log
It's actually really odd. I have FF3, so it loads in the downloads pane, but upon completion, it's greyed out, like it's inactive. I can't open the download, nor the folder it's in. I tried looking for it in the target folder, but it isn't there. I tried this with several different file types, as well as saving specifically to the target folder as well as to different folders. The result is the same. It will look like it has downloaded successfully, but it's no where to be found and I can't search for it.
Hi, I will need to ask our tech experts what is going on as this is unusual…It may take a little while for a response, but I will try and have a response as soon as possible…
Hi,

Please do the following - please print out these instructions for reference

In Firefox

Type: About:Config in the browser address bar.

Copy / paste the following string(s) in the text field in About:Config

browser.download.pluginOverrideTypes If present, right-click and choose reset

Next string would be

plugin.disable_full_page_plugin_for_types If present, right-click and choose reset

Exit browser, and go to the FireFox profile folder:

C:\Applications data\Mozilla\"FireFoxuseraccountName"\

(if you don't use User account name in Firefox, the path to the Firefox profile folder will be slightly different.
C:\Documents and settings\"LogonUserName"\Application Data\Mozilla\FireFox\Profiles\xxxxxxtj.mm
Where xxxxxx is a random string of letters/numbers.)

Note that sometimes this folder is hidden.

Delete the following file in that folder:

MIMEtypes.rdf

Caution Note: There is also a MIMEtypes.rdf in the "Program Folder"...DO not delete that one!

NEXT

In the same folder, as told above, find the following file:

downloads.rdf

Right-click and choose "Open with"
Select Notepad for this
Delete the content, but not the file!
Close NotePad


FireFox will take a few extra seconds on start the first time, as it have to repopulate this file.
Please advise if you can now download and open programs

Thanks

CB
Neither of the strings were present in my configuration settings, so I doubt those are the problems. I tried to follow the instructions regarding Documents and Settings, but for some reason access is denied.I have UAC turned off, so I'm not sure what could be keeping me from accessing it. Do you know what I should do about this
Hi,

Please try the following fix….. one other thing…have you tried to download with I.E., do you have the same issues in IE.

Have you tried to completely uninstall FF and remove your FF profile, then reinstall the latest version of FF, as removing the malware may have corrupted FireFox.

Try this first…if it doesn't resolve the issue, uninstall then reinstall FF.


Take ownership of the files following this guide:

http://neosmart.net/forums/showthread.php?t=1257

This should allow you to open the files. And delete the content using the aforementioned method.
If this doesn't work, please try the steps below.


On desktop, make a new Folder, calling it "something" (it is only temporarily)

Go to the FireFox Profile folder.

Find the two files:

downloads.rdf
downloads.sqlite


Copy each file into this new folder.
Go back to the profile folder and rename the original files to:

Downloads.rdf.old
downloads.sqlite.old


Next open the copied files in the desktop folder with notepad. (Right-click and choose: open with –> Notepad)
Delete the content, but not the files
Close Notepad

Copy both files and insert back into the Profile Folder.

If the above doesn't work, you can safely delete the copied files and remove the .old on the original.
I can't follow the tutorial, because there is no "advanced" option under properties. I see where it should be, but it isn't. I'm very confused. I'm the computer's administrator. As far as I've been told, this is the only account ever made on the computer, and I'm the only one who's ever changed any of the personal settings (mostly just downloading FF, changing the theme, etc.). Could this be part of the problem, or am I overlooking something?
It could be the malware has corrupted your Firefox Try using IE to download - see if you have the same problem…uninstall FireFox completely, reinstall the latest version
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Dequarantine::
C:\Qoobox\Quarantine\c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}.vir
C:\Qoobox\Quarantine\c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}\chrome.manifest.vir
C:\Qoobox\Quarantine\c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}\chrome\content\_cfg.js.vir
C:\Qoobox\Quarantine\c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}\chrome\content\c.js.vir
C:\Qoobox\Quarantine\c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}\chrome\content\overlay.xul.vir
C:\Qoobox\Quarantine\c:\users\Pamela\AppData\Local\{028E8203-A3A9-415D-9684-651897DAAB92}\install.rdf.vir

Quit::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

* Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
* ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
* When finished, it shall produce a log for you.
* Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NOTE: CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI