This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HJT Logfile: Removed most of xp-shield virus, still have

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I had a rather nasty set of viruses. I have run Malware bytes and Spybot. They both caught and removed many items, but i still have the red button on the task bar that says 'Windows Security Center" and other pop up messages that tell me to install their anti-virus. When I run Spybot, it gets to checking for Virtumonde.dll and freezes. I would appreciate some help getting the last few bad items from my PC as it is now out of my basic knowledge.


Thanks,
Sean




HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:34 PM, on 5/4/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\internet explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vwvortex.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {d7b50f34-07da-4e0a-b222-1e16f5303bf8} - c:\windows\system32\ojlplap.dll
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 5394 bytes
Hello & Welcome to What the Tech
Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Options, then click Track this topic. Make sure it is set to Immediate Email Notification, then click Proceed.

In the meantime please note the following:
  • Any recommendations made are for your computer problems only and should NOT be used on any other computer.
  • Please DO NOT run any scans/tools or other fixes unless I ask you to. This is very important for several reasons. Here are just two of them:
    1. The tools that we use are very powerful and can cause >>irreparable damage<< to your computer if not used correctly.
    2. Commercial scanners, for the most part can not completely remove some of the more "resistant" infections. This makes it much more difficult to get rid of completely.
  • If you get stuck or are unsure of something please ask for a further explanation, do not guess.
  • It will require more than one round to properly clean your system. Continue to respond to this thread until I give you the All Clean! even if symptoms seemingly abate.
Please note that the forum is very busy and if I don't hear from you within five days this thread will be closed.
If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave & if there is no contact for that amount of time I will have to assume you have abandoned your topic.

Thanks

DDS
Download DDS.scr by sUBs from one of the following links & save it to your desktop.
http://download.bleepingcomputer.com/sUBs/dds.scr
http://www.forospyware.com/sUBs/dds
  • Double-Click on dds.scr and a command window will appear. This is normal
  • Shortly after two logs will appear, DDS.txt & Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply
Gmer
Download gmer.zip from Gmer here & save it to your desktop.
  • Right click on gmer.zip, select Extract All… & extract the contents to your desktop
  • Double click the Gmer.exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post
  • Save it where you can easily find it, such as your desktop, and post it in reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Note: Do not run any programs while Gmer is running.

To post in next reply:
Contents of DDS log
Contents of Attach.txt
Contents of Gmer log
OK, here we go…..DDS and GMER logs, and attached the zipped Attach log. You said to post, but when I ran the program it said all over it to attach it as a zip. If this is wrong, I can post it as well. Thanks in advance for taking the time to help me get this sorted….



Sean







DDS Log:
DDS (Ver_09-03-16.01) - NTFSx86
Run by [removed] at 20:34:29.07 on Wed 05/06/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.255.108 [GMT -4:00]

AV: AVG 7.5.557 *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Sean Brereton\Desktop\dds.scr

============== Pseudo HJT Report ===============

uLocal Page = \blank.htm
uStart Page = hxxp://vwvortex.com/
mStart Page = hxxp://www.dell4me.com/mywaybiz
uInternet Settings,ProxyOverride = *.local;
uInternet Settings,ProxyServer = http=localhost:7171
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: : {d7b50f34-07da-4e0a-b222-1e16f5303bf8} - c:\windows\system32\ojlplap.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
dRun: [AVG7_Run] c:\progra~1\grisoft\avgfre~1\avgw.exe /RUNONCE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\dell\bluetooth software\btsendto_ie_ctx.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www1.snapfish.com/SnapfishActivia.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
SEH: CShellExecuteHookImpl Object: {57b86673-276a-48b2-bae7-c6dbb3020eb8} - c:\program files\grisoft\avg anti-spyware 7.5\shellexecutehook.dll

============= SERVICES / DRIVERS ===============

R0 ozoshkbu;ozoshkbu;c:\windows\system32\drivers\ozoshkbu.sys [2004-8-4 23424]
R1 AVG Anti-Spyware Driver;AVG Anti-Spyware Driver;c:\program files\grisoft\avg anti-spyware 7.5\guard.sys [2006-9-28 11000]
R1 Avg7Core;AVG7 Kernel;c:\windows\system32\drivers\avg7core.sys [2006-12-1 821856]
R1 Avg7RsW;AVG7 Wrap Driver;c:\windows\system32\drivers\avg7rsw.sys [2006-12-1 4224]
R1 Avg7RsXP;AVG7 Resident Driver XP;c:\windows\system32\drivers\avg7rsxp.sys [2006-12-1 27776]
R1 AvgAsCln;AVG Anti-Spyware Clean Driver;c:\windows\system32\drivers\AvgAsCln.sys [2006-12-6 3968]
R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2006-12-1 10760]
R2 AVG Anti-Spyware Guard;AVG Anti-Spyware Guard;c:\program files\grisoft\avg anti-spyware 7.5\guard.exe [2006-9-28 312880]
R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avgfre~1\avgamsvr.exe [2006-12-1 418816]
R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avgfre~1\avgupsvc.exe [2006-12-1 49664]
R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avgfre~1\avgemc.exe [2006-12-1 406528]
R2 AvgTdi;AVG Network Redirector;c:\windows\system32\drivers\avgtdi.sys [2006-12-1 4960]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys –> c:\windows\system32\drivers\pavboot.sys [?]
S2 GCVQDQGO;GCVQDQGO;\??\c:\windows\system32\gcvqdqgo.ose –> c:\windows\system32\gcvqdqgo.ose [?]
S2 ZPMODEMSYSNTDRVNT;ZPMODEMSYSNTDRVNT;c:\windows\system32\drivers\zpmodemnt.sys [2006-1-2 1792]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys –> c:\windows\system32\vsdatant.sys [?]
S4 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\adobe\photoshop elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-2 124832]

=============== Created Last 30 ================

2009-05-04 07:07 –d—– c:\program files\SpywareBlaster
2009-05-03 22:02 a-dshr– C:\cmdcons
2009-05-03 21:57 161,792 a——- c:\windows\SWREG.exe
2009-05-03 21:57 98,816 a——- c:\windows\sed.exe
2009-05-03 21:31 –d—– c:\program files\Trend Micro
2009-05-03 18:01 –d—– c:\program files\Panda Security
2009-05-02 23:21 –d—– c:\docume~1\seanbr~1\applic~1\Malwarebytes
2009-05-02 23:21 15,504 a——- c:\windows\system32\drivers\mbam.sys
2009-05-02 23:21 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-02 23:21 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-05-02 23:21 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-05-02 15:59 –d—– c:\docume~1\seanbr~1\applic~1\jpbbjzja
2009-04-30 22:03 94,204 a——- c:\windows\system32\drivers\70b0139d.sys
2009-04-30 22:00 14,336 a——- c:\windows\system32\OLD2.tmp
2009-04-29 18:44 182,912 a——- c:\windows\system32\dllcache\ndis.sys
2009-04-29 18:40 101,884 a——- c:\windows\system32\drivers\20f1bf4f.sys
2009-04-29 18:39 2 a——- C:\1959545883
2009-04-25 09:10 –d—– c:\program files\EPSON
2009-04-25 09:01 6,478 a——- c:\windows\system32\EPPICLocal_PT.cfg
2009-04-25 09:01 6,478 a——- c:\windows\system32\EPPICLocal_BP.cfg
2009-04-25 09:01 –d—– C:\epson

==================== Find3M ====================

2009-05-03 22:08 143,872 a——- c:\windows\system32\jcrprpuj.dll
2009-05-03 22:07 103,424 a——- c:\windows\system32\qtiqrtf.dll
2009-05-02 16:29 61,440 a–sh— c:\windows\system32\matehabu.exe
2009-04-30 22:14 14,336 a——- c:\windows\system32\svchost.exe
2009-04-29 18:44 212,480 a——- c:\windows\system32\drivers\NDIS.SYS
2009-04-29 18:39 303,104 a–sh— c:\windows\system32\vikuzeja.exe
2009-04-29 18:39 60,416 a–sh— c:\windows\system32\taruyola.exe

============= FINISH: 20:35:21.06 ===============



GMER log:

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-06 21:59:10
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\drivers\20f1bf4f.sys ZwCreateEvent [0xF964C8AD]
SSDT \SystemRoot\System32\drivers\20f1bf4f.sys ZwCreateKey [0xF964A985]
SSDT \SystemRoot\System32\drivers\20f1bf4f.sys ZwOpenKey [0xF964AA45]
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess [0xF9F108AC]
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess [0xF9F10812]

Code 81F35500 pIofCallDriver

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntoskrnl.exe!RtlCopySid + FF 805673BA 7 Bytes JMP 81F9B1B8
.reloc C:\WINDOWS\system32\drivers\NDIS.sys section is executable [0x81EC8200, 0x32BAA, 0xE0000060]
? C:\WINDOWS\system32\drivers\NDIS.sys Access is denied.
? C:\WINDOWS\System32\drivers\70b0139d.sys The system cannot find the file specified.
? C:\WINDOWS\System32\drivers\20f1bf4f.sys The system cannot find the file specified.

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 20f1bf4f.sys

AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \Driver\NDIS \Device\Ndis [81ECF982] NDIS.sys[.reloc]
Device \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\IPMULTICAST avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \FileSystem\Fastfat \Fat F19ADC8A

AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\System32\drivers\20f1bf4f.sys (*** hidden *** ) [SYSTEM] 20f1bf4f <– ROOTKIT !!!
Service C:\WINDOWS\System32\drivers\70b0139d.sys (*** hidden *** ) [SYSTEM] 70b0139d <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\20f1bf4f@ImagePath \SystemRoot\System32\drivers\20f1bf4f.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\20f1bf4f@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\20f1bf4f@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\20f1bf4f@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\20f1bf4f@F96ZK6nPB YmluZGVyeXNlcnZpY2UubW9iaQ==
Reg HKLM\SYSTEM\CurrentControlSet\Services\70b0139d@ImagePath \SystemRoot\System32\drivers\70b0139d.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\70b0139d@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\70b0139d@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\70b0139d@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\70b0139d@F96ZK6nPB YmluZGVyeXNlcnZpY2UubW9iaQ==
Reg HKLM\SYSTEM\ControlSet003\Services\20f1bf4f@ImagePath \SystemRoot\System32\drivers\20f1bf4f.sys
Reg HKLM\SYSTEM\ControlSet003\Services\20f1bf4f@Type 1
Reg HKLM\SYSTEM\ControlSet003\Services\20f1bf4f@Start 1
Reg HKLM\SYSTEM\ControlSet003\Services\20f1bf4f@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet003\Services\20f1bf4f@F96ZK6nPB YmluZGVyeXNlcnZpY2UubW9iaQ==
Reg HKLM\SYSTEM\ControlSet003\Services\70b0139d@ImagePath \SystemRoot\System32\drivers\70b0139d.sys
Reg HKLM\SYSTEM\ControlSet003\Services\70b0139d@Type 1
Reg HKLM\SYSTEM\ControlSet003\Services\70b0139d@Start 1
Reg HKLM\SYSTEM\ControlSet003\Services\70b0139d@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet003\Services\70b0139d@F96ZK6nPB YmluZGVyeXNlcnZpY2UubW9iaQ==

—- Files - GMER 1.0.15 —-

File C:\I386\btwdndis.sys (size mismatch) 147864/182912 bytes executable
File C:\Program Files\Dell\Bluetooth Software\bin\btwdndis.sys (size mismatch) 147864/182912 bytes executable
File C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ndis.sys (size mismatch) 182656/182912 bytes executable
File C:\WINDOWS\SYSTEM32\DLLCACHE\ndis.sys (size mismatch) 212480/182912 bytes executable
File C:\WINDOWS\SYSTEM32\DRIVERS\btwdndis.sys (size mismatch) 147864/182912 bytes executable
ADS C:\WINDOWS\SYSTEM32\OLD2.tmp:ext.exe 32256 bytes executable

—- EOF - GMER 1.0.15 —-

Attachments:

Hi

Disable Spybot's TeaTimer 1.5 & 1.6
  • If you have version 1.5, right click the Spybot Icon in the system tray near the clock (looks like a blue/white calendar with a padlock symbol)
  • Click once on Resident Protection, then right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless
  • Go to Start > All Programs > Spybot - Search & Destroy > Spybot Search & Destroy
  • Click on Mode > Advanced Mode. When it prompts you, click Yes
  • On the left hand side, click on Tools
  • Check this box if it is not yet ticked: Resident
  • You will notice that Resident is now added under Tools. Click on Resident
  • Uncheck this box: Resident "TeaTimer" (Protection of over-all system settings) active
  • Exit Spybot Search & Destroy
  • Restart your computer for the changes to take effect
We'll leave TeaTimer disabled for the duration of the fix, then turn it back on when your all clean.

P2P Warning!
IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

LimeWire 4.16.6

Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur.
P2P file sharing used to be fairly safe. That is no longer true. I'd like you to read the Perils of P2P File Sharing where we explain why it's not a good idea to have them.
References for the risk of these programs can be found in these links: http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm
See Clean/Infected P2P Programs here

I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

Remove Programs
Click Start > Control Panel > Add/Remove Programs
Remove these programs by clicking Remove

NoAdware v5.0
ZoneAlarm Spy Blocker


If some programs listed are not present, please do not panic

ATF Cleaner
Download ATF Cleaner here by Atribune.
Double-click ATF-Cleaner.exe to run the program
Under Main choose: Select All
Click the Empty Selected button
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button
NOTE: If you would like to keep your saved passwords, please click No at the prompt
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button
NOTE: If you would like to keep your saved passwords, please click No at the prompt
Click Exit on the Main menu to close the program.

Combofix
Delete the version of Combofix you have already used & download it again from one of these locations:
Link 1
Link 2
Link 3

**IMPORTANT !!! Save ComboFix.exe to your Desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
    A guide to do this can be found here
  • Double click on ComboFix.exe & follow the prompts
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply along with a new HijackThis log.
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


To post in next reply:
Combofix log
OK, it may have just been a site hick-ip, because now I can post…..

I have disabled TeaTimer…..


Also have removed the NoAdware v5.0, ZoneAlarm Spy Blocker, and also Limewire which I have not used in a year or so, but I took your advice and got rid of it all together. I ran ATF Cleaner, delted and reloaded Combofix, and have some new logs below.


Sean


Combo Fix Log:

ComboFix 09-05-08.03 - Sean Brereton 05/09/2009 16:34.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.255.69 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG 7.5.557 *On-access scanning disabled* (Outdated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\20f1bf4f.sys
c:\windows\system32\drivers\70b0139d.sys
c:\windows\system32\matehabu.exe
c:\windows\system32\taruyola.exe
c:\windows\system32\jcrprpuj.dll . . . . failed to delete
c:\windows\system32\ojlplap.dll . . . . failed to delete
c:\windows\system32\qtiqrtf.dll . . . . failed to delete

Infected copy of c:\windows\system32\drivers\ndis.sys was found and disinfected
Restored copy from - c:\i386\NDIS.SYS

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_20f1bf4f
——-\Service_70b0139d


((((((((((((((((((((((((( Files Created from 2009-04-09 to 2009-05-09 )))))))))))))))))))))))))))))))
.

2009-05-04 11:07 . 2009-05-04 11:07 ——– d—–w c:\documents and settings\All Users\Application Data\TEMP
2009-05-04 11:07 . 2009-05-04 11:09 ——– d—–w c:\program files\SpywareBlaster
2009-05-04 01:31 . 2009-05-04 01:31 ——– d—–w c:\program files\Trend Micro
2009-05-03 22:01 . 2009-05-03 22:01 ——– d—–w c:\program files\Panda Security
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\documents and settings\Sean Brereton\Application Data\Malwarebytes
2009-05-03 03:21 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-03 03:21 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-02 19:59 . 2009-05-02 19:59 ——– d—–w c:\documents and settings\Sean Brereton\Application Data\jpbbjzja
2009-05-02 19:59 . 2009-05-02 19:59 ——– d—–w c:\documents and settings\Sean Brereton\Local Settings\Application Data\jpbbjzja
2009-04-25 13:10 . 2009-04-25 13:11 ——– d—–w c:\program files\EPSON
2009-04-25 13:01 . 2009-04-25 13:01 ——– d—–w c:\documents and settings\Sean Brereton\Application Data\InstallShield
2009-04-25 13:01 . 2009-04-25 13:09 ——– d—–w C:\epson

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-09 20:36 . 2004-08-04 11:00 182912 —-a-w c:\windows\system32\drivers\ndis.sys
2009-05-04 11:34 . 2006-01-03 06:20 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-04 02:08 . 2004-08-04 11:00 143872 —-a-w c:\windows\system32\jcrprpuj.dll
2009-05-04 02:07 . 2004-08-04 11:00 103424 —-a-w c:\windows\system32\qtiqrtf.dll
2009-05-01 02:14 . 2004-08-04 11:00 14336 —-a-w c:\windows\system32\svchost.exe
2009-05-01 01:56 . 2009-05-01 02:00 14336 —-a-w c:\windows\system32\OLD2.tmp
2009-04-29 22:39 . 2009-01-29 22:39 303104 –sha-w c:\windows\system32\vikuzeja.exe
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\SDHelper (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-01-29 22:32 . 2009-01-29 22:32 68608 –sha-w c:\windows\SYSTEM32\divimuvo.dll.tmp
2009-01-29 22:32 . 2009-01-29 22:32 68608 –sha-w c:\windows\SYSTEM32\vofehafi.dll.tmp
.

((((((((((((((((((((((((((((( SnapShot@2009-05-04_02.18.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 11:00 . 2004-08-04 11:00 182912 c:\windows\SYSTEM32\DLLCACHE\ndis.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d7b50f34-07da-4e0a-b222-1e16f5303bf8}]
2004-08-04 11:00 103424 —-a-w c:\windows\SYSTEM32\ojlplap.dll

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-24 219136]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor.lnk
backup=c:\windows\pss\Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TapiSrv"=3 (0x3)
"RasMan"=3 (0x3)
"mnmsrvc"=3 (0x3)
"CiSvc"=3 (0x3)
"btwdins"=2 (0x2)
"AdobeActiveFileMonitor6.0"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"EPSON Stylus Photo R340 Series"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB001" /M "Stylus Photo R340"
"EPSON Stylus Photo R340 Series (Copy 1)"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P39 "EPSON Stylus Photo R340 Series (Copy 1)" /O6 "USB001" /M "Stylus Photo R340"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"DwlClient"=c:\program files\Common Files\Dell\EUSW\Support.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\ZCfgSvc.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\WLKEEPER.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15818:TCP"= 15818:TCP:@xpsp2res.dll,-22009

R0 ozoshkbu;ozoshkbu;c:\windows\SYSTEM32\DRIVERS\ozoshkbu.sys [8/4/2004 7:00 AM 23424]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys –> c:\windows\system32\drivers\pavboot.sys [?]
S2 GCVQDQGO;GCVQDQGO;\??\c:\windows\system32\gcvqdqgo.ose –> c:\windows\system32\gcvqdqgo.ose [?]
S2 ZPMODEMSYSNTDRVNT;ZPMODEMSYSNTDRVNT;c:\windows\SYSTEM32\DRIVERS\zpmodemnt.sys [1/2/2006 12:36 PM 1792]
S4 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [10/2/2007 3:46 PM 124832]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30a8b950-8e93-11dd-b239-000e35d48f02}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uStart Page = hxxp://vwvortex.com/
mStart Page = hxxp://www.dell4me.com/mywaybiz
uInternet Settings,ProxyOverride = *.local;
uInternet Settings,ProxyServer = http=localhost:7171
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-09 16:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\system32\OLD2.tmp:ext.exe 32256 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GCVQDQGO]
"ImagePath"="\??\c:\windows\system32\gcvqdqgo.ose"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3263456595-3722201187-1372389037-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(968)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\windows\SYSTEM32\SCARDSVR.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\progra~1\Grisoft\AVGFRE~1\avgamsvr.exe
c:\progra~1\Grisoft\AVGFRE~1\avgupsvc.exe
c:\progra~1\Grisoft\AVGFRE~1\avgemc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\windows\SYSTEM32\WSCNTFY.EXE
.
**************************************************************************
.
Completion time: 2009-05-09 16:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-09 20:46
ComboFix2.txt 2009-05-04 02:24

Pre-Run: 2,814,783,488 bytes free
Post-Run: 2,800,320,512 bytes free

169 — E O F — 2008-10-06 04:09



New HiJack This log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:08:12 PM, on 5/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vwvortex.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {d7b50f34-07da-4e0a-b222-1e16f5303bf8} - c:\windows\system32\ojlplap.dll
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 5227 bytes
Hi

OK, it may have just been a site hick-ip, because now I can post…..

:thumbup: Good stuff

I have disabled TeaTimer…..

We'll re-enable it once your clean.

CFScript
Close any open browsers.
Open notepad and copy/paste the text in the code box below into it:

http://forums.whatthetech.com/HJT_Logfile_Removed_most_xp_shield_virus_still_have_infections_t102787.html
Driver::
ozoshkbu
GCVQDQGO
ZPMODEMSYSNTDRVNT
Collect::
c:\windows\system32\jcrprpuj.dll
c:\windows\system32\qtiqrtf.dll
c:\windows\system32\vikuzeja.exe
c:\windows\SYSTEM32\ojlplap.dll
c:\windows\SYSTEM32\DRIVERS\ozoshkbu.sys
c:\windows\SYSTEM32\DRIVERS\zpmodemnt.sys
c:\windows\system32\gcvqdqgo.ose
Rootkit::
c:\windows\system32\OLD2.tmp
File::
c:\windows\SYSTEM32\divimuvo.dll.tmp
c:\windows\SYSTEM32\vofehafi.dll.tmp
Folder::
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja
c:\documents and settings\Sean Brereton\Local Settings\Application Data\jpbbjzja
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d7b50f34-07da-4e0a-b222-1e16f5303bf8}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30a8b950-8e93-11dd-b239-000e35d48f02}]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GCVQDQGO]
DDS::
uLocal Page = \blank.htm
mStart Page = hxxp://www.dell4me.com/mywaybiz
uInternet Settings,ProxyOverride = *.local;
uInternet Settings,ProxyServer = http=localhost:7171
Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


Update Java Runtime
You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, & also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 13.
  • Download the latest version of Java Runtime Environment (JRE) 6 Here
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 13. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the Download button to the right
  • Select the Windows platform from the dropdown menu
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh
  • Click on the link to download Windows Offline Installation & save the file to your desktop
  • Close any programs you may have running - especially your web browser
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs & remove all older versions of Java
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions
  • Reboot your computer once all Java components are removed
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel
Kaspersky Online Scan
Do an online scan with >Kaspersky Online Scanner<
  • Read through the requirements and privacy statement and click on Accept button
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run
  • When the downloads have finished, click on Settings
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan
  • Once the scan is complete, it will display the results. Click on View Scan Report
  • You will see a list of infected items there. Click on Save Report As…
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button
  • Please post this log in your next reply
I would also like to see a new Gmer log, so could you run Gmer again following the instructions previously posted.

To post in next reply:
Combofix log
Kaspersky Scan log
New Gmer log
OK, I am not sure if the Combo Fix thing worked right. I saved waht you posted, and then dragged it into Combofix. When combofix started, it said there was an update and asked if I wanted it. I said yes, it updated, restarted and then ran a scan. When it was done, it opened a log, but it did not open a message window as your instructions said….never a pop upasking me to say yes. The log is below with the others. I took care of getting the new Java, and I will post the other logs in a few minutes when I have them run and saved….


Sean



ComboFix Log from 5/12:

ComboFix 09-05-12.04 - Sean Brereton 05/12/2009 21:27.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.255.99 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sean Brereton\Desktop\CFscript.txt
AV: AVG 7.5.557 *On-access scanning disabled* (Outdated)

FILE ::
c:\windows\SYSTEM32\divimuvo.dll.tmp
c:\windows\SYSTEM32\vofehafi.dll.tmp

file zipped: c:\windows\SYSTEM32\DRIVERS\ozoshkbu.sys
file zipped: c:\windows\SYSTEM32\DRIVERS\zpmodemnt.sys
file zipped: c:\windows\system32\jcrprpuj.dll
file zipped: c:\windows\SYSTEM32\ojlplap.dll
file zipped: c:\windows\system32\qtiqrtf.dll
file zipped: c:\windows\system32\vikuzeja.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Sean Brereton\Application Data\jpbbjzja
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\profiles.ini
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\cert8.db
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\compatibility.ini
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\compreg.dat
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\cookies.sqlite
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\formhistory.sqlite
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\key3.db
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\localstore.rdf
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\permissions.sqlite
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\places.sqlite-journal
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\places.sqlite
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\pluginreg.dat
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\prefs.js
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\secmod.db
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\webappsstore.sqlite
c:\documents and settings\Sean Brereton\Application Data\jpbbjzja\Profiles\jfadlt30.default\xpti.dat
c:\documents and settings\Sean Brereton\Local Settings\Application Data\jpbbjzja
c:\documents and settings\Sean Brereton\Local Settings\Application Data\jpbbjzja\Profiles\jfadlt30.default\urlclassifier3.sqlite
c:\documents and settings\Sean Brereton\Local Settings\Application Data\jpbbjzja\Profiles\jfadlt30.default\XPC.mfl
c:\windows\SYSTEM32\divimuvo.dll.tmp
c:\windows\SYSTEM32\DRIVERS\ozoshkbu.sys
c:\windows\SYSTEM32\DRIVERS\zpmodemnt.sys
c:\windows\system32\jcrprpuj.dll
c:\windows\SYSTEM32\ojlplap.dll
c:\windows\system32\OLD2.tmp
c:\windows\system32\qtiqrtf.dll
c:\windows\system32\vikuzeja.exe
c:\windows\SYSTEM32\vofehafi.dll.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_GCVQDQGO
——-\Legacy_ozoshkbu
——-\Legacy_ZPMODEMSYSNTDRVNT
——-\Service_ozoshkbu
——-\Service_ZPMODEMSYSNTDRVNT


((((((((((((((((((((((((( Files Created from 2009-04-13 to 2009-05-13 )))))))))))))))))))))))))))))))
.

2009-05-04 11:07 . 2009-05-04 11:07 ——– d—–w c:\documents and settings\All Users\Application Data\TEMP
2009-05-04 11:07 . 2009-05-04 11:09 ——– d—–w c:\program files\SpywareBlaster
2009-05-04 01:31 . 2009-05-04 01:31 ——– d—–w c:\program files\Trend Micro
2009-05-03 22:01 . 2009-05-03 22:01 ——– d—–w c:\program files\Panda Security
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\documents and settings\Sean Brereton\Application Data\Malwarebytes
2009-05-03 03:21 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-03 03:21 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-25 13:10 . 2009-04-25 13:11 ——– d—–w c:\program files\EPSON
2009-04-25 13:01 . 2009-04-25 13:01 ——– d—–w c:\documents and settings\Sean Brereton\Application Data\InstallShield
2009-04-25 13:01 . 2009-04-25 13:09 ——– d—–w C:\epson

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-13 01:27 . 2004-08-04 11:00 23424 —-a-w c:\windows\system32\drivers\eeizkvyv.sys
2009-05-09 20:36 . 2004-08-04 11:00 182912 —-a-w c:\windows\system32\drivers\ndis.sys
2009-05-04 11:34 . 2006-01-03 06:20 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-01 02:14 . 2004-08-04 11:00 14336 —-a-w c:\windows\system32\svchost.exe
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\SDHelper (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\TeaTimer (Spybot - Search & Destroy)
.

((((((((((((((((((((((((((((( SnapShot@2009-05-04_02.18.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 11:00 . 2004-08-04 11:00 182912 c:\windows\SYSTEM32\DLLCACHE\ndis.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-24 219136]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor.lnk
backup=c:\windows\pss\Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TapiSrv"=3 (0x3)
"RasMan"=3 (0x3)
"mnmsrvc"=3 (0x3)
"CiSvc"=3 (0x3)
"btwdins"=2 (0x2)
"AdobeActiveFileMonitor6.0"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"EPSON Stylus Photo R340 Series"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB001" /M "Stylus Photo R340"
"EPSON Stylus Photo R340 Series (Copy 1)"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P39 "EPSON Stylus Photo R340 Series (Copy 1)" /O6 "USB001" /M "Stylus Photo R340"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"DwlClient"=c:\program files\Common Files\Dell\EUSW\Support.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\ZCfgSvc.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\WLKEEPER.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15818:TCP"= 15818:TCP:@xpsp2res.dll,-22009

S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys –> c:\windows\system32\drivers\pavboot.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - OZOSHKBU
*Deregistered* - Ati HotKey Poller
*Deregistered* - AudioSrv
*Deregistered* - AVG Anti-Spyware Guard
*Deregistered* - Avg7UpdSvc
*Deregistered* - AVGEMS
*Deregistered* - BITS
*Deregistered* - Bonjour Service
*Deregistered* - Browser
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - EvtEng
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - helpsvc
*Deregistered* - HidServ
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RegSrvc
*Deregistered* - RpcSs
*Deregistered* - S24EventMonitor
*Deregistered* - SamSs
*Deregistered* - SCardSvr
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - UMWdf
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WLANKEEPER
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://vwvortex.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-12 21:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3263456595-3722201187-1372389037-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(968)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\windows\SYSTEM32\SCARDSVR.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\progra~1\Grisoft\AVGFRE~1\avgupsvc.exe
c:\progra~1\Grisoft\AVGFRE~1\avgemc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\windows\SYSTEM32\WSCNTFY.EXE
.
**************************************************************************
.
Completion time: 2009-05-13 21:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-13 01:41
ComboFix2.txt 2009-05-09 20:46
ComboFix3.txt 2009-05-04 02:24

Pre-Run: 2,813,026,304 bytes free
Post-Run: 2,798,583,808 bytes free

229 — E O F — 2008-10-06 04:09

Kaspersky Log from 5/12

KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, May 13, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, May 13, 2009 04:26:30
Records in database: 2170757
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 58763
Threat name: 5
Infected objects: 6
Suspicious objects: 0
Duration of the scan: 02:17:36


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS.vir Infected: Virus.Win32.Protector.b 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\OLD2.tmp.vir Infected: Trojan.Win32.Inject.xmi 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_jcrprpuj_.dll.zip Infected: Trojan-Clicker.Win32.Delf.cbe 1
C:\Qoobox\Quarantine\[4]-Submit_2009-05-12_21.26.50.zip Infected: Trojan.Win32.BHO.ext 1
C:\Qoobox\Quarantine\[4]-Submit_2009-05-12_21.26.50.zip Infected: Trojan-Dropper.Win32.Agent.ahfp 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP8\A0000387.sys Infected: Virus.Win32.Protector.b 1

The selected area was scanned.

GMer Scan 5/12

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-13 07:53:25
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess [0xFA0348AC]
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess [0xFA034812]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\IPMULTICAST avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \FileSystem\Fastfat \Fat F0DAFC8A

AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- Files - GMER 1.0.15 —-

ADS C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\OLD2.tmp.vir:ext.exe 32256 bytes executable

—- EOF - GMER 1.0.15 —-
Hi
One more round I think should do it hopefully.
CFScript
Close any open browsers.
Open notepad and copy/paste the text in the code box below into it:

http://forums.whatthetech.com/HJT_Logfile_Removed_most_xp_shield_virus_still_have_infections_t102787.html
Collect::
c:\windows\system32\drivers\eeizkvyv.sys
Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


It doesn't look like those files from the previous run of Combofix were recieved. Could you do the following:
Please visit this site and follow the instructions for uploading this file: C:\Qoobox\Quarantine\[4]-Submit_2009-05-12_21.26.50.zip.

To post in next reply:
Combofix log
Update on how the computer is running / problems
OK, this time it worked, and Combo Fix said it was uploading something. I posted the log below. After, I went to the link you gave for Bleeping Computer and uploaded the specific file. The machine is actually running really, really good right now….faster then it was before the infection actually. Once we are at a clean point, my final question will be what you'd recommend as a suite of software for me to keep and use on a daily/weekly basis for protection and detection. I had been running AVG free editions, and occasionally would run Spybot or Adaware to check for junk. I did try using a firewall, but it was so cumbersome I could barely surf the internet. What should a normal PC have on it, and which actual product do you think works best for me? Also, I assume some of the older things I have can be uninstalled since they seem to be duplicates. I made a partial list below of what I have now…


Sean


ComboFix Log 5/13:

ComboFix 09-05-12.04 - Sean Brereton 05/13/2009 22:34.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.255.82 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sean Brereton\Desktop\CFScript.txt
AV: AVG 7.5.557 *On-access scanning disabled* (Outdated)

file zipped: c:\windows\system32\drivers\eeizkvyv.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\eeizkvyv.sys

.
((((((((((((((((((((((((( Files Created from 2009-04-14 to 2009-05-14 )))))))))))))))))))))))))))))))
.

2009-05-13 02:01 . 2009-05-13 02:00 410984 —-a-w c:\windows\system32\deploytk.dll
2009-05-04 11:07 . 2009-05-04 11:07 ——– d—–w c:\documents and settings\All Users\Application Data\TEMP
2009-05-04 11:07 . 2009-05-04 11:09 ——– d—–w c:\program files\SpywareBlaster
2009-05-04 01:31 . 2009-05-04 01:31 ——– d—–w c:\program files\Trend Micro
2009-05-03 22:01 . 2009-05-03 22:01 ——– d—–w c:\program files\Panda Security
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\documents and settings\Sean Brereton\Application Data\Malwarebytes
2009-05-03 03:21 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-03 03:21 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-03 03:21 . 2009-05-03 03:21 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-25 13:10 . 2009-04-25 13:11 ——– d—–w c:\program files\EPSON
2009-04-25 13:01 . 2009-04-25 13:01 ——– d—–w c:\documents and settings\Sean Brereton\Application Data\InstallShield
2009-04-25 13:01 . 2009-04-25 13:09 ——– d—–w C:\epson

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-13 02:00 . 2005-03-25 13:27 ——– d—–w c:\program files\Java
2009-05-09 20:36 . 2004-08-04 11:00 182912 —-a-w c:\windows\system32\drivers\ndis.sys
2009-05-04 11:34 . 2006-01-03 06:20 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-01 02:14 . 2004-08-04 11:00 14336 —-a-w c:\windows\system32\svchost.exe
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\SDHelper (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-03-24 21:47 . 2009-03-24 21:47 ——– d—–w c:\program files\TeaTimer (Spybot - Search & Destroy)
.

((((((((((((((((((((((((((((( SnapShot@2009-05-04_02.18.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-14 01:52 . 2009-05-14 01:52 16384 c:\windows\temp\Perflib_Perfdata_778.dat
+ 2009-05-13 02:01 . 2009-05-13 02:00 148888 c:\windows\SYSTEM32\javaws.exe
+ 2009-05-13 02:01 . 2009-05-13 02:00 144792 c:\windows\SYSTEM32\javaw.exe
+ 2009-05-13 02:01 . 2009-05-13 02:00 144792 c:\windows\SYSTEM32\java.exe
+ 2004-08-04 11:00 . 2004-08-04 11:00 182912 c:\windows\SYSTEM32\DLLCACHE\ndis.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-13 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-24 219136]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor.lnk
backup=c:\windows\pss\Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TapiSrv"=3 (0x3)
"RasMan"=3 (0x3)
"mnmsrvc"=3 (0x3)
"CiSvc"=3 (0x3)
"btwdins"=2 (0x2)
"AdobeActiveFileMonitor6.0"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"EPSON Stylus Photo R340 Series"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB001" /M "Stylus Photo R340"
"EPSON Stylus Photo R340 Series (Copy 1)"=c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P39 "EPSON Stylus Photo R340 Series (Copy 1)" /O6 "USB001" /M "Stylus Photo R340"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"DwlClient"=c:\program files\Common Files\Dell\EUSW\Support.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\ZCfgSvc.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\WLKEEPER.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15818:TCP"= 15818:TCP:@xpsp2res.dll,-22009

S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys –> c:\windows\system32\drivers\pavboot.sys [?]
S4 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [10/2/2007 3:46 PM 124832]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://vwvortex.com/
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth; - c:\program files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-13 22:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3263456595-3722201187-1372389037-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(964)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-05-14 22:40
ComboFix-quarantined-files.txt 2009-05-14 02:39
ComboFix2.txt 2009-05-13 01:41
ComboFix3.txt 2009-05-09 20:46
ComboFix4.txt 2009-05-04 02:24

Pre-Run: 2,764,832,768 bytes free
Post-Run: 2,820,792,320 bytes free

126 — E O F — 2008-10-06 04:09
Upload was successful



What I have installed now:


AVG Free Edition
AVG Anti Spyware
Spyware Blaster
CCleaner
Spybot Search & Destroy (which when I tried to use it last time kept locking up half way through a scan…)
Ad Aware SE Personal
Combofix
HiJack This
Gmer
Malwarebytes'
Bugoff
Zone Alarm

I also have MyWaysearch assistant listed in the add/remove programs list, but there is no remove/uninstall button. Did we get this out already and it is just still on the list? I don't use or want it, and assume it is a mild maleware of sorts….
Hi

The machine is actually running really, really good right now….faster then it was before the infection actually

Excellent… that's good to hear :thumbup:

Once we are at a clean point, my final question will be what you'd recommend as a suite of software for me to keep and use on a daily/weekly basis for protection and detection.

Some recommendations below. Let's clean up a little first.

Clean Up
Now we need to clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately.
Remove Combofix
The following will implement some cleanup procedures as well as reset System Restore points:
Click Start > Run and copy/paste the following bolded text into the Run box and click OK:
ComboFix /u
OTCleanIt
Download OTCleanIt here & save it to your desktop.
Double click on OTCleanIt.exe. Click on CleanUp!.
You will receive a prompt that it needs to restart the computer to remove the files. Click Yes.
It will restart your computer automatically. If it doesn't, please restart your computer manually.
You should also uninstall HijackThis
You can delete the following from your desktop:
DDS.scr
Any logs that may have been saved to your desktop

You can either keep or delete ATF-Cleaner. It's a handy program for cleaning out temporary folders.

I also have MyWaysearch assistant listed in the add/remove programs list, but there is no remove/uninstall button. Did we get this out already and it is just still on the list? I don't use or want it, and assume it is a mild maleware of sorts….

Yes… this is something we usually remove. I didn't see this in any of your lists of installed programs. Have you tried removing that left over with CCleaner. Open CCleaner, click Tools then Uninstall. Highlight MyWaysearch assistant then click Delete Entry. If that doesn't work let me know & we'll try something else.

Update Adobe Reader
Recently there have been vunerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version: Adobe Reader 9.1
You can download it from http://www.adobe.com/products/acrobat/readstep2.html
If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed Uncheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

Adobe 9 is a large program and if you prefer a smaller program you can get Foxit 3 instead from http://www.foxitsoftware.com/pdf/rd_intro.php

All Clean
Congratulations, good work, your system is now clean. Now that your system is safe we would like you to keep it that way.
First up let's take a look at your security programs:
AVG Free Edition
AVG Anti Spyware

- If you are going to keep AVG make sure you update it to the latest version as all the logs flagged it as OutDated - links below for latest version plus a couple of others if you want to change. AVG is not bad but of the three free AVs below I would go with Avira Antivir
Link to latest version - AVG Anti-Virus Free Edition - Free edition of the AVG anti-virus program for Windows.
1) Antivir PersonalEdition Classic- Free anti-virus software for Windows. Detects and removes more than 50,000 viruses. Free support.
2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
Your computer must have only ONE anti-virus program installed at any time. Having more than one anti-virus program installed & active will cause program conflicts, false virus alerts, and system crashes.

Spyware Blaster - Keep this. It is an excellent little program. SpywareBlaster adds a list of ActiveX controls, tracking cookies and sites which will be blocked in either Internet Explorer or Firefox browsers. You need to manually check for updates regularly.

CCleaner - This good also for cleaning out temp folders, IE History etc., however I would stay clear of its Registry Cleaner. It can be quite aggressive at times. Plus reg cleaners make little to no difference to the the performance of a computer.

Spybot Search & Destroy
Ad Aware SE Personal

Personally I believe these two programs are outdated & no longer as good as they once were. There are better programs available. Your choice but I would get rid of them. While we are here If your going to keep Spybot you can re-enable TeaTimer now if you like.

Combofix - this will be deleted during the CleanUp procedure above. Please do not use this program on your own. It is extremely powerful tool that can turn a computer into an expensive doorstop if used incorrectly.

HiJack This - you should also uninstall this. It can also wreck a computer if used inappropriately.

Gmer - this will be removed in the CleanUp procedure. Again can be dangerous if used incorrectly.

Malwarebytes' - definitely keep this. Probably the best AntiMalware program available at the moment. I would highly recommend you pay the small fee for the real time protection. If not then keep it updated & run it regularly.

Bugoff - don't know much about this one…. sorry

Zone Alarm - it's quite a good firewall. You should keep it as the XP firewall is very average. The XP firewall is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

Here's a couple of links to a some other free firewalls:
1)Webroot Desktop Firewall (Registration is needed to download the firewall)
2)PC Tools Firewall Plus
3)Netchina S3 2008
Make sure you only have one firewall installed

And some other tips to keep you safe.

Microsoft Windows Update
Update your Windows XP to Service Pack 3!
It is CRITICAL that you keep your Windows updated. Otherwise you're open to dozens of security holes which WILL cause you to get reinfected.
Visit Windows Update NOW and download Service Pack 3 + ALL critical updates! (Click Start :arrow: All Programs :arrow: Windows Update to launch Windows Update)

Microsoft releases patches for Windows and Office products regularly to patch up Windows and Office products loopholes and fix any bugs found. Install the updates immediately if they are found.
To update Windows
Go to Start > All Programs > Windows Update
To update Office
Open up any Office program.
Go to Help > Check for Updates

Download and Install a HOSTS File
A HOSTS file is a big list of bad web sites. The list has a specific format, a specific name, (name is just HOSTS with no file extension), and a specific location. Your machine always looks at that file in that location before connecting to a web site to verify the address. So the HOSTS listing can be used to "short circuit" a request to a bad website by giving it the address of your own machine.

Download BlueTack's HOSTS Manager here, using Internet Explorer (Firefox won't work):
  • Double click the Installer on your desktop and let it Install the Hosts Manager
  • After the installation is complete, click on the Hosts Manager icon on your desktop. (You can delete the other Hosts Switch icon from your desktop)
  • When the Hosts Manager comes up, click the small down arrows on the right side of the bar labeled Options and Tools,
  • Click Disable DNS Service. This is important
  • In the Left Pane, click Download
  • It will load 80,000 lines or more. When it finishes, also in the left pane, click Replace, and then click Save
You can use this manager to handle your HOSTS file download, edits, and most any other HOSTS issue.
If you have a separate party firewall or Winpatrol, you may have to give permissions at various times to Unlock the present default HOSTS file and install the new one.

Install WinPatrol
Download it here
You can find information about how WinPatrol works here

Read some information here on how to prevent Malware.

Hopefully these steps will help keep your computer clean.

Stand Up and Be Counted —> Malware Complaints <— where you can make difference!
The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.
OK, I uninstalled HiJack this and Combo fix, deleted the logs. I have run OTCleanit. When i used CCleaner, it says cannot uninstall MyWaySearchAssistant. I am going to switch to Antivir, and also pay to have the real time Malewarebytes protection. I assume these two always should be running in the background. For the firewall, of the one I have and the 3 you listed, which would be the best choice?I will update Windows before I shut down tonite, and also Adobe. Finally, I will install the HOSTS file as you recommend. I am leaving for vacation for a week tommorow, so if I don't finish it, I'll check in when I am back…… Thanks again for your time, you have been a lifesaver! Sean

Thanks again for your time, you have been a lifesaver!

No problem at all. Glad I could help :thumbup:

When i used CCleaner, it says cannot uninstall MyWaySearchAssistant.

Just confirm you clicked Delete Entry & not Run Uninstaller? If not, lets have a look at the Registry:

Export A Registry Key
Open Notepad then copy & paste the contents of the Code Box below into it:
regedit.exe /e C:\reglook.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall"
notepad C:\reglook.txt
  • Click on File > Save As… & save to your desktop
  • In the File Name box, copy & paste in reglook.bat
  • In the Save As Type box, select All Files from the drop-down list
  • Click Save
  • Double click on reglook.bat to run it. A Command Prompt will open briefly, followed by Notepad shortly afterwards
  • Post the contents of this Notepad file in your next reply
If this log is too large for one post you can either break it up over a couple of posts or attach it as a file.

For the firewall, of the one I have and the 3 you listed, which would be the best choice?

The one you have is not too bad. If your happy with it… stick with it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI