This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect, recurring trojans

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm having trouble with google-redirect.com hijacking my searches and all the links I click on. I downloaded HJT as recommended by several websites and forums, but I need help interpreting and solving the problems.

I have Zone Alarm security suite and VIPRE antivirus/antispyware installed and have run scans for viruses, trojans, and spyware several times, each coming up with either a new or recurring virus or trojan.

Here's the report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:10:25 PM, on 4/29/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lexmark X125\LEX125SU.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\iPod\bin\iPodService.exe
\?\globalroot\C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMUI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/go/notebookaccessories
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: 82.98.231.89 url.adtrgt.com
O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {b20f48b7-b3d0-4df5-a93f-c9729ce22e99} - C:\WINDOWS\system32\fohebesi.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [LMPDPSRV] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [neberajiwo] Rundll32.exe "C:\WINDOWS\system32\jobapoja.dll",s
O4 - HKLM\..\Run: [CPM75400e5c] Rundll32.exe "c:\windows\system32\vofehafi.dll",a
O4 - HKLM\..\Run: [76733dc0] rundll32.exe "C:\WINDOWS\system32\yizesoko.dll",b
O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [autochk] rundll32.exe C:\DOCUME~1\ANDREW~1.AND\protect.dll,_IWMPEvents@16
O4 - HKUS\S-1-5-18\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\config\SYSTEM~1\protect.dll,_IWMPEvents@16 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\config\SYSTEM~1\protect.dll,_IWMPEvents@16 (User 'Default user')
O4 - Startup: ChkDisk.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = ?
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Lexmark X125 Settings Utility.lnk = C:\Program Files\Lexmark X125\LEX125SU.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
O20 - AppInit_DLLs: C:\WINDOWS\system32\kuwotevi.dll c:\windows\system32\vofehafi.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8410 bytes
Hello & Welcome to What the Tech
Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Options, then click Track this topic. Make sure it is set to Immediate Email Notification, then click Proceed.

In the meantime please note the following:
  • Any recommendations made are for your computer problems only and should NOT be used on any other computer.
  • Please DO NOT run any scans/tools or other fixes unless I ask you to. This is very important for several reasons. Here are just two of them:
    1. The tools that we use are very powerful and can cause >>irreparable damage<< to your computer if not used correctly.
    2. Commercial scanners, for the most part can not completely remove some of the more "resistant" infections. This makes it much more difficult to get rid of completely.
  • If you get stuck or are unsure of something please ask for a further explanation, do not guess.
  • It will require more than one round to properly clean your system. Continue to respond to this thread until I give you the All Clean! even if symptoms seemingly abate.
Please note that the forum is very busy and if I don't hear from you within five days this thread will be closed.
If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave & if there is no contact for that amount of time I will have to assume you have abandoned your topic.

Thanks

ATF Cleaner
Download ATF Cleaner here by Atribune.
Double-click ATF-Cleaner.exe to run the program
Under Main choose: Select All
Click the Empty Selected button
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button
NOTE: If you would like to keep your saved passwords, please click No at the prompt
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button
NOTE: If you would like to keep your saved passwords, please click No at the prompt
Click Exit on the Main menu to close the program.

Combofix
Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

**IMPORTANT !!! Save ComboFix.exe to your Desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
    A guide to do this can be found here
  • Double click on ComboFix.exe & follow the prompts
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply along with a new HijackThis log.
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


I'd also like to see a list of installed programs so please do this:
Create an Uninstall List
  • Start HijackThis
  • Click on the Config button
  • Click on the Misc Tools button
  • Click on the Open Uninstall Manager button
  • Click on the Save list… button and specify where you would like to save this file
  • When you press the Save button a notepad will open with the contents of that file
  • Copy and paste the contents of that notepad here in your next reply
To post in next reply:
Combofix log
Uninstall List
New HijackThis log
Update on how the computer is running
ComboFix 09-04-29.07 - Andrew 04/30/2009 10:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.564 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated)
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated)
FW: ZoneAlarm Security Suite Firewall *disabled*
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Andrew.ANDREW\protect.dll
c:\documents and settings\Andrew.ANDREW\Start Menu\Programs\Startup\ChkDisk.lnk
c:\documents and settings\LocalService\protect.dll
c:\program files\Common Files\dobe~1
c:\program files\Common Files\ecurit~1
c:\program files\Common Files\pppatc~1
c:\program files\Common Files\racle~1
c:\program files\Common Files\sembly~1
c:\program files\Common Files\smbols~1
c:\program files\Common Files\stem32~1
c:\program files\Common Files\wnsxs~1
c:\program files\Common Files\wnsxs~1\??crosoft\ctxad-502.0001
c:\program files\Common Files\wnsxs~1\??crosoft\ctxad-502.0002
c:\program files\Common Files\wnsxs~1\??crosoft\ctxad-502.0003
c:\program files\Common Files\wnsxs~1\??crosoft\ctxad-502.0004
c:\program files\Common Files\wnsxs~1\??crosoft\ctxad-502.0005
c:\program files\Common Files\Yazzle1409OinUninstaller.exe
c:\program files\fnts~1
c:\program files\mcroso~1.net
c:\program files\ymante~1
c:\windows\fnts~1
c:\windows\icroso~1.net
c:\windows\mcroso~1.net
c:\windows\sks~1
c:\windows\smbols~1
c:\windows\stem~1
c:\windows\system32\autochk.dll
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\drivers\ovfsthwwlqrqbtqdcrdmcssywxopqadspitobi.sys
c:\windows\system32\lmppcsetup.exe
c:\windows\system32\ovfsthajkdocmwqbkqdwwkdmruqtmkvgjwsqji.dll
c:\windows\system32\ovfsthasahkgonppqyramuemphrleehpohphdq.dat
c:\windows\system32\ovfsthddysextkkxoxhgccuhdswvdiqhodfnhi.dll
c:\windows\system32\ovfsthiprssktulbeqahjpfptodtusbfkywwpl.dat
c:\windows\system32\ovfsthwrqfaqouvgdkbknonlxssgdprgtweshu.dll
c:\windows\system32\uniq.tll
c:\windows\ymbols~1
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_ovfsthpoanfrhbroyksavxutrvaenodfssupbn


((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-30 )))))))))))))))))))))))))))))))
.

2009-04-25 04:09 . 2009-04-25 07:00 ——– d—–w c:\documents and settings\Andrew.ANDREW\Application Data\Download Manager
2009-04-23 04:51 . 2009-04-23 04:51 115 —-a-w c:\documents and settings\Andrew.ANDREW\Application Data\netstat.bat
2009-04-23 02:39 . 2009-03-05 04:30 69936 —-a-w c:\windows\system32\drivers\sbapifs.sys
2009-04-23 02:39 . 2008-09-12 14:38 13360 —-a-w c:\windows\system32\drivers\sbaphd.sys
2009-04-23 02:26 . 2009-04-23 02:26 ——– d—–w c:\documents and settings\Andrew.ANDREW\Application Data\Sunbelt
2009-04-23 02:03 . 2009-04-23 02:03 ——– d—–w c:\documents and settings\All Users\Application Data\Sunbelt
2009-04-23 02:00 . 2008-10-09 14:48 202928 —-a-w c:\windows\system32\drivers\sbtis.sys
2009-04-23 02:00 . 2009-04-23 02:00 ——– d—–w c:\program files\Sunbelt Software
2009-04-17 18:18 . 2009-04-17 18:18 268 —-a-w c:\documents and settings\Andrew.ANDREW\Application Data\LMCPaper.dat
2009-04-15 16:20 . 2009-03-06 14:22 284160 ——w c:\windows\system32\dllcache\pdh.dll
2009-04-15 16:20 . 2009-02-06 10:39 35328 ——w c:\windows\system32\dllcache\sc.exe
2009-04-15 16:20 . 2009-02-09 12:10 401408 ——w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 16:20 . 2009-02-06 11:11 110592 ——w c:\windows\system32\dllcache\services.exe
2009-04-15 16:20 . 2009-02-09 12:10 473600 ——w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 16:20 . 2009-02-06 10:10 227840 ——w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 16:20 . 2009-02-09 12:10 453120 ——w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 16:20 . 2009-02-09 12:10 729088 ——w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 16:20 . 2009-02-09 12:10 617472 ——w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 16:20 . 2009-02-09 12:10 714752 ——w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 16:19 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-15 16:19 . 2008-04-21 12:08 215552 ——w c:\windows\system32\dllcache\wordpad.exe
2009-04-03 21:52 . 2009-04-03 21:52 ——– d—–w C:\spoolerlogs

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 16:21 . 2008-09-30 22:41 348506400 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-30 16:05 . 2008-09-30 22:41 4666196 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-30 15:57 . 2008-09-30 22:41 4212 —ha-w c:\windows\system32\zllictbl.dat
2009-04-30 00:09 . 2006-08-04 18:35 ——– d—–w c:\program files\Trend Micro
2009-04-29 06:31 . 2009-01-29 06:31 52224 –sha-w c:\windows\system32\lahesumo.exe
2009-04-25 07:17 . 2008-12-06 15:36 9681860 —-a-w c:\windows\Internet Logs\tvDebug.zip
2009-04-23 05:00 . 2009-04-23 15:19 2894848 —-a-w c:\windows\Internet Logs\xDBA.tmp
2009-04-17 18:18 . 2009-03-01 19:02 3932 —-a-w c:\documents and settings\Andrew.ANDREW\Application Data\LMLayout.dat
2009-04-03 04:12 . 2009-04-03 04:12 46400 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_11_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 46333 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_08_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 46301 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_10_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 45967 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_07_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 46389 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_02_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 46195 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_04_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 45918 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_05_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 46692 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_00_small.dmp.zip
2009-04-01 00:20 . 2008-08-14 02:14 72584 —-a-w c:\windows\zllsputility.exe
2009-04-01 00:20 . 2009-03-07 18:45 1221512 —-a-w c:\windows\system32\zpeng25.dll
2009-03-17 18:26 . 2009-03-17 18:26 65320 —-a-w c:\windows\system32\sbbd.exe
2009-03-13 00:42 . 2008-03-04 00:05 ——– d—–w c:\program files\iTunes
2009-03-13 00:42 . 2008-09-10 01:08 ——– d—–w c:\program files\iPod
2009-03-13 00:38 . 2008-09-10 01:02 ——– d—–w c:\program files\QuickTime
2009-03-13 00:25 . 2008-09-10 01:04 ——– d—–w c:\program files\Bonjour
2009-03-06 14:22 . 2004-08-10 15:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-06 04:59 . 2009-03-13 00:33 1900544 —-a-w c:\windows\system32\usbaaplrc.dll
2009-03-06 04:59 . 2008-09-28 05:28 36864 —-a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-03 06:58 . 2009-03-03 15:03 2663424 —-a-w c:\windows\Internet Logs\xDB8.tmp
2009-03-03 06:49 . 2009-03-03 15:03 2663424 —-a-w c:\windows\Internet Logs\xDB9.tmp
2009-03-02 16:28 . 2006-08-04 22:57 ——– d—–w c:\program files\GameSpy Arcade
2009-03-02 16:05 . 2009-03-02 16:05 2275840 —-a-w c:\windows\Internet Logs\xDB65.tmp
2009-03-02 03:07 . 2009-03-02 03:06 21752120 —-a-w c:\windows\Internet Logs\vsmon_on_demand_2009_03_01_18_11_59_full.dmp.zip
2009-03-02 00:11 . 2009-03-02 03:01 2653696 —-a-w c:\windows\Internet Logs\xDB7.tmp
2009-03-01 19:00 . 2009-03-01 19:00 ——– d—–w c:\program files\Lexmark X125
2009-03-01 19:00 . 2006-04-13 12:47 ——– d–h–w c:\program files\InstallShield Installation Information
2009-02-20 08:10 . 2004-08-10 15:00 666112 —-a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-10 15:00 81920 —-a-w c:\windows\system32\ieencode.dll
2009-02-10 14:33 . 2006-04-13 13:56 70016 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-02-09 12:10 . 2004-08-10 15:00 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-10 15:00 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-10 15:00 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-10 15:00 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2004-08-10 15:00 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-08 00:02 . 2004-08-10 15:00 2066048 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-07 08:57 . 2009-02-07 17:14 1176576 —-a-w c:\windows\Internet Logs\xDB6.tmp
2009-02-06 11:11 . 2004-08-10 15:00 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2004-08-10 15:00 2189056 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-10 15:00 35328 —-a-w c:\windows\system32\sc.exe
2009-02-03 19:59 . 2004-08-10 15:00 56832 —-a-w c:\windows\system32\secur32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-11 344064]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-22 405504]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"Reminder"="c:\windows\CREATOR\Remind_XP.exe" [2006-02-09 643072]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"LMPDPSRV"="c:\windows\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE" [2002-09-05 45056]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-11 342312]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-04-01 982408]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2009-03-17 955688]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Sunbelt Software\\VIPRE\\SBAMTray.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"=

R2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [2009-03-17 894248]
R3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-10-06 33752]
S1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2008-09-12 13360]
S1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2008-10-09 202928]
S2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2009-03-05 69936]
S3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFHWATI.sys [2005-08-22 231424]

.
- - - - ORPHANS REMOVED - - - -

BHO-{b20f48b7-b3d0-4df5-a93f-c9729ce22e99} - c:\windows\system32\fohebesi.dll
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-neberajiwo - c:\windows\system32\jobapoja.dll
HKLM-Run-CPM75400e5c - c:\windows\system32\vofehafi.dll
HKLM-Run-76733dc0 - c:\windows\system32\yizesoko.dll
HKU-Default-Run-autochk - c:\windows\system32\config\SYSTEM~1\protect.dll
SharedTaskScheduler-{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/go/notebookaccessories
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Andrew.ANDREW\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\
FF - prefs.js: browser.startup.homepage - hxxps://howdy.tamu.edu/cp/home/displaylogin
FF - component: c:\documents and settings\Andrew.ANDREW\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npWebLaunch.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-30 11:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????????n??|?????? ???B?????????????hLC? ??????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1813439212-3754893985-731045217-1005\Software\SecuROM\License information*]
"datasecu"=hex:7b,54,51,a6,2c,93,5d,c6,91,b7,06,64,0e,18,25,b2,fc,b8,2c,63,ab,
9f,78,bf,96,58,83,96,60,cd,3f,41,bc,29,2a,b6,f8,f3,47,3b,f2,80,e0,ca,af,2d,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\HPZipm12.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\ati2evxx.exe
c:\windows\ehome\ehmsas.exe
c:\progra~1\HPQ\shared\HPQTOA~1.EXE
c:\program files\Lexmark X125\LEX125SU.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-30 11:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-30 16:24

Pre-Run: 5,648,928,768 bytes free
Post-Run: 5,911,965,696 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

276 — E O F — 2009-04-16 01:03





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:25:15 AM, on 4/30/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Lexmark X125\LEX125SU.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/go/notebookaccessories
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [LMPDPSRV] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = ?
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Lexmark X125 Settings Utility.lnk = C:\Program Files\Lexmark X125\LEX125SU.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 6880 bytes



Uninstall list:

Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 7.0
AIM 6
AIMTunes
Apple Mobile Device Support
Apple Software Update
Athlon 64 Processor Driver
ATI Control Panel
ATI Display Driver
Battlefield 2: Special Forces
Bonjour
Compatibility Pack for the 2007 Office system
Conexant AC-Link Audio
Customer Experience Enhancement
GameSpy Arcade
Garmin Communicator Plugin
getPlus® for Adobe
Google Talk (remove only)
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
HP Help and Support
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Photosmart, Officejet and Deskjet 7.0.A
HP QuickPlay 2.0
HP Rhapsody
HP Software Update
HP User Guides 0025
HP User Guides–System Recovery
HP Wireless Assistant 2.00 C1
iTunes
J2SE Runtime Environment 5.0 Update 6
Lexmark X125
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Halo
Microsoft Office Standard Edition 2003
Microsoft Office Word Viewer 2003
Microsoft Works
Mozilla Firefox (3.0.8)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
muvee autoProducer 4.5
Office 2003 Trial Assistant
Otto
Privacy center



The computer seems to be running fine, I'm not having any more problems with google-redirect.com. However, Both this forum website and Facebook have a problem; I cannot see the regular interface/ display, all I see is a text page. I'll include a screen shot of Facebook in my next reply if you'd like. If this is a problem with one of the programs that was deleted, is it possible to fix by reinstalling from a trusted site?
Hi

Multiple Anti-virus Programs
You are operating your computer with multiple Anti-virus programs running in memory at once:
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated)
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated)

Anti-virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash. Please remove one of them NOW.

The Uninstall List doesn't look complete. Was that the entire list?

CFScript
Close any open browsers.
Open notepad and copy/paste the text in the code box below into it:

File::
c:\windows\system32\lahesumo.exe
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000000
Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


Gmer
Download gmer.zip from Gmer here & save it to your desktop.
  • Right click on gmer.zip, select Extract All… & extract the contents to your desktop
  • Double click the Gmer.exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post
  • Save it where you can easily find it, such as your desktop, and post it in reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Note: Do not run any programs while Gmer is running.

Update Java Runtime
You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, & also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 13.
  • Download the latest version of Java Runtime Environment (JRE) 6 Here
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 13. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the Download button to the right
  • Select the Windows platform from the dropdown menu
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh
  • Click on the link to download Windows Offline Installation & save the file to your desktop
  • Close any programs you may have running - especially your web browser
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs & remove all older versions of Java
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions
  • Reboot your computer once all Java components are removed
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel
Kaspersky Online Scan
Do an online scan with >Kaspersky Online Scanner<
  • Read through the requirements and privacy statement and click on Accept button
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run
  • When the downloads have finished, click on Settings
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan
  • Once the scan is complete, it will display the results. Click on View Scan Report
  • You will see a list of infected items there. Click on Save Report As…
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button
  • Please post this log in your next reply
To post in next reply:
Combofix log
Gmer log
Kaspersky Scan log
Let me know if still problems with web pages not rendering properly
Hello

I had two anti-virus programs because I downloaded VIPRE per recommendations of another website to remove PrivacyCenter, which my current program, Zone Alarm, did not catch. I did this before I realized I had a more serious problem. Do you have any recomendations for a reliable anti-virus or Internet security package programs? I have tried Trend Micro and Zone Alarm, and Trend Micro seems to be the better of the two.

I apologize, when I copy/pasted the uninstall list, I did not get everything copied; here is the complete list:

Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 7.0
AIM 6
AIMTunes
Apple Mobile Device Support
Apple Software Update
Athlon 64 Processor Driver
ATI Control Panel
ATI Display Driver
Battlefield 2: Special Forces
Bonjour
Compatibility Pack for the 2007 Office system
Conexant AC-Link Audio
Customer Experience Enhancement
GameSpy Arcade
Garmin Communicator Plugin
getPlus® for Adobe
Google Talk (remove only)
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
HP Help and Support
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Photosmart, Officejet and Deskjet 7.0.A
HP QuickPlay 2.0
HP Rhapsody
HP Software Update
HP User Guides 0025
HP User Guides–System Recovery
HP Wireless Assistant 2.00 C1
iTunes
J2SE Runtime Environment 5.0 Update 6
Lexmark X125
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Halo
Microsoft Office Standard Edition 2003
Microsoft Office Word Viewer 2003
Microsoft Works
Mozilla Firefox (3.0.8)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
muvee autoProducer 4.5
Office 2003 Trial Assistant
Otto
Privacy center
Quick Launch Buttons 5.20 G1
QuickTime
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB963027)
Soft Data Fax Modem with SmartCP
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
SonicAC3Encoder
SonicMPEGEncoder
Synaptics Pointing Device Driver
TAMUScan 1.0
Texas Instruments PCIxx21/x515/xx12 drivers.
TrueCrypt
Update for Windows Media Player 10 (KB913800)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VC 9.0 Runtime
Windows Media Format Runtime
Windows XP Media Center Edition 2005 KB908250
Windows XP Service Pack 3
Wireless Home Network Setup
ZoneAlarm Security Suite


The logs:


ComboFix 09-04-30.05 - Andrew 05/01/2009 2:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.609 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Andrew.ANDREW\Desktop\CFScript.txt
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated)
FW: ZoneAlarm Security Suite Firewall *disabled*

FILE ::
c:\windows\system32\lahesumo.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\lahesumo.exe

.
((((((((((((((((((((((((( Files Created from 2009-04-01 to 2009-05-01 )))))))))))))))))))))))))))))))
.

2009-04-25 04:09 . 2009-04-25 07:00 ——– d—–w c:\documents and settings\Andrew.ANDREW\Application Data\Download Manager
2009-04-23 04:51 . 2009-04-23 04:51 115 —-a-w c:\documents and settings\Andrew.ANDREW\Application Data\netstat.bat
2009-04-17 18:18 . 2009-04-17 18:18 268 —-a-w c:\documents and settings\Andrew.ANDREW\Application Data\LMCPaper.dat
2009-04-15 16:20 . 2009-03-06 14:22 284160 ——w c:\windows\system32\dllcache\pdh.dll
2009-04-15 16:20 . 2009-02-06 10:39 35328 ——w c:\windows\system32\dllcache\sc.exe
2009-04-15 16:20 . 2009-02-09 12:10 401408 ——w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 16:20 . 2009-02-06 11:11 110592 ——w c:\windows\system32\dllcache\services.exe
2009-04-15 16:20 . 2009-02-09 12:10 473600 ——w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 16:20 . 2009-02-06 10:10 227840 ——w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 16:20 . 2009-02-09 12:10 453120 ——w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 16:20 . 2009-02-09 12:10 729088 ——w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 16:20 . 2009-02-09 12:10 617472 ——w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 16:20 . 2009-02-09 12:10 714752 ——w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 16:19 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-15 16:19 . 2008-04-21 12:08 215552 ——w c:\windows\system32\dllcache\wordpad.exe
2009-04-03 21:52 . 2009-04-03 21:52 ——– d—–w C:\spoolerlogs

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-01 07:06 . 2008-09-30 22:41 350778656 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-01 06:54 . 2008-09-30 22:41 4212 —ha-w c:\windows\system32\zllictbl.dat
2009-04-30 16:05 . 2008-09-30 22:41 4666196 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-30 00:09 . 2006-08-04 18:35 ——– d—–w c:\program files\Trend Micro
2009-04-25 07:17 . 2008-12-06 15:36 9681860 —-a-w c:\windows\Internet Logs\tvDebug.zip
2009-04-23 05:00 . 2009-04-23 15:19 2894848 —-a-w c:\windows\Internet Logs\xDBA.tmp
2009-04-17 18:18 . 2009-03-01 19:02 3932 —-a-w c:\documents and settings\Andrew.ANDREW\Application Data\LMLayout.dat
2009-04-03 04:12 . 2009-04-03 04:12 46400 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_11_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 46333 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_08_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 46301 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_10_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 45967 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_07_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 46389 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_02_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 46195 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_04_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 45918 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_05_small.dmp.zip
2009-04-03 04:12 . 2009-04-03 04:12 46692 —-a-w c:\windows\Internet Logs\vsmon_2nd_2009_04_02_21_43_00_small.dmp.zip
2009-04-01 00:20 . 2008-08-14 02:14 72584 —-a-w c:\windows\zllsputility.exe
2009-04-01 00:20 . 2009-03-07 18:45 1221512 —-a-w c:\windows\system32\zpeng25.dll
2009-03-13 00:42 . 2008-03-04 00:05 ——– d—–w c:\program files\iTunes
2009-03-13 00:42 . 2008-09-10 01:08 ——– d—–w c:\program files\iPod
2009-03-13 00:38 . 2008-09-10 01:02 ——– d—–w c:\program files\QuickTime
2009-03-13 00:25 . 2008-09-10 01:04 ——– d—–w c:\program files\Bonjour
2009-03-06 14:22 . 2004-08-10 15:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-06 04:59 . 2009-03-13 00:33 1900544 —-a-w c:\windows\system32\usbaaplrc.dll
2009-03-06 04:59 . 2008-09-28 05:28 36864 —-a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-03 06:58 . 2009-03-03 15:03 2663424 —-a-w c:\windows\Internet Logs\xDB8.tmp
2009-03-03 06:49 . 2009-03-03 15:03 2663424 —-a-w c:\windows\Internet Logs\xDB9.tmp
2009-03-02 16:28 . 2006-08-04 22:57 ——– d—–w c:\program files\GameSpy Arcade
2009-03-02 16:05 . 2009-03-02 16:05 2275840 —-a-w c:\windows\Internet Logs\xDB65.tmp
2009-03-02 03:07 . 2009-03-02 03:06 21752120 —-a-w c:\windows\Internet Logs\vsmon_on_demand_2009_03_01_18_11_59_full.dmp.zip
2009-03-02 00:11 . 2009-03-02 03:01 2653696 —-a-w c:\windows\Internet Logs\xDB7.tmp
2009-02-20 08:10 . 2004-08-10 15:00 666112 —-a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-10 15:00 81920 —-a-w c:\windows\system32\ieencode.dll
2009-02-10 14:33 . 2006-04-13 13:56 70016 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-02-09 12:10 . 2004-08-10 15:00 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-10 15:00 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-10 15:00 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-10 15:00 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2004-08-10 15:00 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-08 00:02 . 2004-08-10 15:00 2066048 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-07 08:57 . 2009-02-07 17:14 1176576 —-a-w c:\windows\Internet Logs\xDB6.tmp
2009-02-06 11:11 . 2004-08-10 15:00 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2004-08-10 15:00 2189056 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-10 15:00 35328 —-a-w c:\windows\system32\sc.exe
2009-02-03 19:59 . 2004-08-10 15:00 56832 —-a-w c:\windows\system32\secur32.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-04-30_16.21.44 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-03 04:07 . 2009-05-01 07:02 492644 c:\windows\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2009-05-01 06:54 . 2009-04-06 12:57 24921544 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-11 344064]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-22 405504]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"Reminder"="c:\windows\CREATOR\Remind_XP.exe" [2006-02-09 643072]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"LMPDPSRV"="c:\windows\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE" [2002-09-05 45056]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-11 342312]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-04-01 982408]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"=

R3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-10-06 33752]
S3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFHWATI.sys [2005-08-22 231424]
S4 sbaphd;sbaphd; [x]
S4 sbapifs;sbapifs; [x]

.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/go/notebookaccessories
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Andrew.ANDREW\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\
FF - prefs.js: browser.startup.homepage - hxxps://howdy.tamu.edu/cp/home/displaylogin
FF - component: c:\documents and settings\Andrew.ANDREW\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npWebLaunch.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-01 02:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????????n??|?????? ???B?????????????hLC? ??????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1813439212-3754893985-731045217-1005\Software\SecuROM\License information*]
"datasecu"=hex:7b,54,51,a6,2c,93,5d,c6,91,b7,06,64,0e,18,25,b2,fc,b8,2c,63,ab,
9f,78,bf,96,58,83,96,60,cd,3f,41,bc,29,2a,b6,f8,f3,47,3b,f2,80,e0,ca,af,2d,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-05-01 2:08
ComboFix-quarantined-files.txt 2009-05-01 07:08
ComboFix2.txt 2009-04-30 16:24

Pre-Run: 6,023,774,208 bytes free
Post-Run: 6,015,791,104 bytes free

185 — E O F — 2009-05-01 06:56





GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-01 11:04:24
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwConnectPort [0xEE9B2FC0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateFile [0xEE9AFC80]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateKey [0xEE9CA170]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreatePort [0xEE9B3580]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateProcess [0xEE9C7900]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0xEE9C7B10]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateSection [0xEE9CBB10]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xEE9B3670]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteFile [0xEE9B0210]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteKey [0xEE9CA9F0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0xEE9CA7A0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0xEE9C7280]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwLoadKey [0xEE9CAF10]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xEE9CAF90]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwMapViewOfSection [0xEE9CBD90]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenFile [0xEE9B0070]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenProcess [0xEE9C9180]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenThread [0xEE9C8F40]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRenameKey [0xEE9CB6F0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwReplaceKey [0xEE9CB150]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xEE9B2BE0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRestoreKey [0xEE9CB540]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0xEE9B3190]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xEE9B0440]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSetValueKey [0xEE9CA4E0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0xEE9C8200]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwTerminateProcess [0xEE9C8080]

—- Devices - GMER 1.0.15 —-

Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)

Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-





——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Friday, May 1, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Friday, May 01, 2009 14:52:27
Records in database: 2117868
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 95686
Threat name: 6
Infected objects: 19
Suspicious objects: 0
Duration of the scan: 02:43:35


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\Documents and Settings\Andrew.ANDREW\protect.dll.vir Infected: Trojan-Spy.Win32.Agent.amjg 1
C:\Qoobox\Quarantine\C\Documents and Settings\LocalService\protect.dll.vir Infected: Trojan-Spy.Win32.Agent.amjg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\protect.dll.vir Infected: Trojan-Spy.Win32.Agent.amjg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ovfsthwwlqrqbtqdcrdmcssywxopqadspitobi.sys.vir Infected: Trojan.Win32.Tdss.aalf 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthajkdocmwqbkqdwwkdmruqtmkvgjwsqji.dll.vir Infected: Trojan.Win32.Tdss.aalg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthddysextkkxoxhgccuhdswvdiqhodfnhi.dll.vir Infected: Trojan.Win32.Tdss.aalc 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthwrqfaqouvgdkbknonlxssgdprgtweshu.dll.vir Infected: Trojan.Win32.Tdss.aald 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\_autochk_.dll.zip Infected: Trojan-Spy.Win32.Agent.amjg 1
C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP183\A0024488.exe Infected: not-a-virus:FraudTool.Win32.PrivacyCenter.c 1
C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP186\A0028246.sys Infected: Trojan.Win32.Tdss.aalf 1
C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP186\A0028247.dll Infected: Trojan.Win32.Tdss.aalc 1
C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP186\A0028248.dll Infected: Trojan.Win32.Tdss.aalg 1
C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP186\A0028249.dll Infected: Trojan.Win32.Tdss.aald 1
C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP186\A0028268.dll Infected: Trojan-Spy.Win32.Agent.amjg 1
C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP186\A0028269.dll Infected: Trojan-Spy.Win32.Agent.amjg 1
C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP186\A0028274.dll Infected: Trojan-Spy.Win32.Agent.amjg 1
C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP186\A0028275.dll Infected: Trojan-Spy.Win32.Agent.amjg 1
C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP186\A0028277.dll Infected: Trojan-Spy.Win32.Agent.amjg 1
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll Infected: Trojan-Spy.Win32.Agent.amjg 1

The selected area was scanned.



I believe the Java update solved the redering errors I was having. Facebook, What the Tech, and my other problems seem to be running fine now.

Do you have any recomendations for a reliable anti-virus or Internet security package programs?

Both Vipre & Zone Alarm are good products. I've been using Vipre for quite a while now & always found it quite reliable. Is your Vipre the free trial or full paid version? If Vipre is the full version why not keep that as your AV/AS program & disable the ZoneAlarm AV & just use the firewall. Just a suggestion.

Remove Programs
Click Start > Control Panel > Add/Remove Programs
Remove these programs by clicking Remove

Privacy center

If some programs listed are not present, please do not panic

Update Adobe Reader
Recently there have been vunerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version: Adobe Reader 9.1
You can download it from http://www.adobe.com/products/acrobat/readstep2.html
If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed Uncheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Adobe 9 is a large program and if you prefer a smaller program you can get Foxit 3 instead from http://www.foxitsoftware.com/pdf/rd_intro.php

OTMoveIt3
Download OTMoveIt3.exe by OldTimer and save it to your desktop.
  • Double click on OTMoveIt3.exe to run it
  • Copy & paste the contents of the Code box below into Paste Instructions for Items to be Moved
Note: Do not type it out to minimize the risk of typo error
:Files
c:\program files\Java\jre1.5.0_06
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll
:Commands
[Purity]
[EmptyTemp]
[Reboot]
  • Click on MoveIt!
  • When done, click on Exit
Note: If a file or folder can't be moved immediately, you may be asked to restart your computer. Choose Yes.
A log will be produced at C:\_OTMoveIt\MovedFiles\date_time.log, where date_time are numbers. Post this log in your next reply.
========== FILES ========== c:\program files\Java\jre1.5.0_06\lib\ext moved successfully. c:\program files\Java\jre1.5.0_06\lib moved successfully. c:\program files\Java\jre1.5.0_06 moved successfully. LoadLibrary failed for C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll NOT unregistered. File move failed. C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll scheduled to be moved on reboot. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\etilqs_rmkJ0CQMLvCKE3CPdeRu scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\Perflib_Perfdata_c88.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\~DF1726.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\~DF86DF.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\~DF9FC9.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\Andrew.ANDREW\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_2b0.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\ZLT05d36.TMP scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Andrew.ANDREW\Local Settings\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Andrew.ANDREW\Local Settings\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Andrew.ANDREW\Local Settings\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Andrew.ANDREW\Local Settings\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Andrew.ANDREW\Local Settings\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\urlclassifier3.sqlite scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05022009_073748 Files moved on Reboot… File C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll not found! File C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\etilqs_rmkJ0CQMLvCKE3CPdeRu not found! File C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\Perflib_Perfdata_c88.dat not found! File C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\~DF1726.tmp not found! C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\~DF86DF.tmp moved successfully. C:\DOCUME~1\ANDREW~1.AND\LOCALS~1\Temp\~DF9FC9.tmp moved successfully. File C:\WINDOWS\temp\Perflib_Perfdata_2b0.dat not found! File C:\WINDOWS\temp\ZLT05d36.TMP not found! C:\Documents and Settings\Andrew.ANDREW\Local Settings\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Andrew.ANDREW\Local Settings\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Andrew.ANDREW\Local Settings\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Andrew.ANDREW\Local Settings\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Andrew.ANDREW\Local Settings\Application Data\Mozilla\Firefox\Profiles\0ewgbpqa.default\urlclassifier3.sqlite moved successfully.
Hi
OK… looks good.

Clean Up
Now we need to clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately.
Remove Combofix
The following will implement some cleanup procedures as well as reset System Restore points:
Click Start > Run and copy/paste the following bolded text into the Run box and click OK:
ComboFix /u
  • Double-click OTMoveIt3.exe
  • Click the CleanUp! button
  • Select Yes when the Begin cleanup Process? prompt appears
  • If you are prompted to Reboot during the cleanup, select Yes
  • The tool will delete itself once it finishes, if not delete it yourself
You can also uninstall HijackThis by clicking Start>Control Panel>Add or Remove Programs, click on HijackThis 2.0.2 then Change/Remove
You can also delete any logs that may have been saved to the desktop
You can either delete or keep ATF-Cleaner. It's a handy tool for cleaning out temporary folders.

Any problems?
Should I remove Gmer as well? Other than that, I believe everything is running great. Thank you for all your help!
Hi

The OTmoveIt3 Clean Up routine should have removed Gmer, if not, yes you can remove it.

All Clean
Congratulations, good work, your system is now clean. Now that your system is safe we would like you to keep it that way.
Take the time to follow these recommendations & it will greatly reduce the risk of further infections and greatly diminish the chances of you having to visit here again.

Microsoft Windows Update
Microsoft releases patches for Windows and Office products regularly to patch up Windows and Office products loopholes and fix any bugs found. Install the updates immediately if they are found.
To update Windows
Go to Start > All Programs > Windows Update
To update Office
Open up any Office program.
Go to Help > Check for Updates

Malwarebytes' Anti-Malware
Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is totally free but for real-time protection you will have to pay a small one-time fee.
You can download it here & find a tutorial here.

SpywareBlaster
Download and install Javacools SpywareBlaster from here
SpywareBlaster adds a list of ActiveX controls, tracking cookies and sites which will be blocked in either Internet Explorer or Firefox browsers. You need to manually check for updates regularly.

Download and Install a HOSTS File
A HOSTS file is a big list of bad web sites. The list has a specific format, a specific name, (name is just HOSTS with no file extension), and a specific location. Your machine always looks at that file in that location before connecting to a web site to verify the address. So the HOSTS listing can be used to "short circuit" a request to a bad website by giving it the address of your own machine.

Download BlueTack's HOSTS Manager here, using Internet Explorer (Firefox won't work):
  • Double click the Installer on your desktop and let it Install the Hosts Manager
  • After the installation is complete, click on the Hosts Manager icon on your desktop. (You can delete the other Hosts Switch icon from your desktop)
  • When the Hosts Manager comes up, click the small down arrows on the right side of the bar labeled Options and Tools,
  • Click Disable DNS Service. This is important
  • In the Left Pane, click Download
  • It will load 80,000 lines or more. When it finishes, also in the left pane, click Replace, and then click Save
You can use this manager to handle your HOSTS file download, edits, and most any other HOSTS issue.
If you have a separate party firewall or Winpatrol, you may have to give permissions at various times to Unlock the present default HOSTS file and install the new one.

Install WinPatrol
Download it here
You can find information about how WinPatrol works here

Read some information here on how to prevent Malware.

Hopefully these steps will help keep your computer clean.

Stand Up and Be Counted —> Malware Complaints <— where you can make difference!
The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.
Thank you! I have taken your advice and installed all the prevention/security programs. I really appreciate all your help
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI