This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help Me

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I tried to update windows and it said it couldn't connect. I tried to go to the microsoft update website and I got an error message saying page not found, and other times the link took me to what looked like a fake google search page. I scanned with Anti-Malware and it found numerous trojans. It deleted them all. I then scanned using Windows Live OneCare, which corrected several hundred errors and a few more infected files. Windows update will still not connect nor can I access the Malwarebytes website, but I can access every other website I try to go to.

here are the log files for hijackthis and Anti-Malware scans

Malwarebytes' Anti-Malware 1.36
Database version: 2070
Windows 6.0.6001 Service Pack 1

5/4/2009 10:12:33 AM
mbam-log-2009-05-04 (10-12-33).txt

Scan type: Quick Scan
Objects scanned: 80746
Time elapsed: 6 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 4
Registry Data Items Infected: 18
Folders Infected: 1
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\{NSINAME} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Hotfix-KB5504305 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Hotfix-KB5504305 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Hotfix-KB5504305 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Hotfix-KB5504305 (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6be0358a-33f0-4f31-a221-2ed05d93b289}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{bd0ba4c2-2047-4983-bcff-327384c9d5bd}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{bd0ba4c2-2047-4983-bcff-327384c9d5bd}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{e460c675-5da9-4dd8-af6b-203c50983081}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{e460c675-5da9-4dd8-af6b-203c50983081}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6be0358a-33f0-4f31-a221-2ed05d93b289}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{bd0ba4c2-2047-4983-bcff-327384c9d5bd}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{bd0ba4c2-2047-4983-bcff-327384c9d5bd}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{e460c675-5da9-4dd8-af6b-203c50983081}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{e460c675-5da9-4dd8-af6b-203c50983081}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{6be0358a-33f0-4f31-a221-2ed05d93b289}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{bd0ba4c2-2047-4983-bcff-327384c9d5bd}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{bd0ba4c2-2047-4983-bcff-327384c9d5bd}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{e460c675-5da9-4dd8-af6b-203c50983081}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{e460c675-5da9-4dd8-af6b-203c50983081}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.120,85.255.112.83 -> Quarantined and deleted successfully.

Folders Infected:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDQuality (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Files Infected:
C:\Users\JACKIE WATSON\AppData\Local\Temp\58944.exe (Rogue.FakeAlert) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDQuality\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\RECYCLER\S-7-9-94-100021010-100012604-100018892-6114.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\gxvxccounter (Trojan.DNSchanger) -> Quarantined and deleted successfully.
C:\Windows\System32\gxvxcdqblgetynxsniipwlcfwhfrgqjxpihfu.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\drivers\gxvxcekbsvqlxenteiteqiqrdpxntnhcehrdf.sys (Trojan.Agent) -> Quarantined and deleted successfully.
________________________________________________________________________________
______
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:37 PM, on 5/4/2009

Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Sierra Wireless Inc\3G Watcher\WaHelper.exe
C:\Windows\WindowsMobile\wmdcBase.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\helppane.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\DllHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://myspam.cableone.net/login.aspx?Retu…%2fDefault.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: 200.124.131.116 casinocontroller.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {23176EC3-CBB5-4B77-B898-7F5EB465C530} - C:\Windows\system32\gebaw.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9A5BD632-EBF0-4C6A-BC19-77F85293F7A7} - C:\Windows\system32\gebaw.dll (file missing)
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [WatcherHelper] "C:\Program Files\Sierra Wireless Inc\3G Watcher\WaHelper.exe"
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\Users\JACKIE~1\AppData\Local\Temp\~DFACEE.tmp C:\Users\JACKIE~1\AppData\Local\Temp\Low\HSPERF~1.SH! C:\Users\JACKIE~1\AppData\Local\Temp\HSPERF~1.SH! (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\Users\JACKIE~1\AppData\Local\Temp\~DFACEE.tmp C:\Users\JACKIE~1\AppData\Local\Temp\Low\HSPERF~1.SH! C:\Users\JACKIE~1\AppData\Local\Temp\HSPERF~1.SH! (User 'Default user')
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\JACKIE WATSON\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\JACKIE WATSON\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\JACKIE WATSON\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\JACKIE WATSON\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O13 - Gopher Prefix:
O15 - Trusted Zone: http://usa.asus.com
O15 - Trusted Zone: http://www.wireless.att.com
O15 - Trusted Zone: http://www.churchsprojects.com
O15 - Trusted Zone: http://www.cisgroup.net
O15 - Trusted Zone: http://*.countyassessor.info
O15 - Trusted Zone: http://*.ftabin.info
O15 - Trusted Zone: http://www.greatinsurancejobs.com
O15 - Trusted Zone: http://www.guardianps.com
O15 - Trusted Zone: http://www.inspections.net
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: http://www.melissadata.com
O15 - Trusted Zone: http://cims.mortgageramp.com
O15 - Trusted Zone: http://www.pokerfatcat.net
O15 - Trusted Zone: http://www.taxnetusa.com
O15 - Trusted Zone: http://www.therepreport.com
O15 - Trusted Zone: http://online.wilife.com
O15 - Trusted IP range: http://168.51.178.33
O16 - DPF: {434A2E00-1F9C-4DD6-ADE5-49923398FAB7} (ctlProductChecker.ProductChecker) - https://inspi2.safeguardproperties.com/insp…ductChecker.cab
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1238792779335
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Unknown owner - C:\WINDOWS\system32\bmwebcfg.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe

–
End of file - 11105 bytes
Hi,

Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I need to see another log from HijackThis.
  • Run Hijackthis.
  • Click on Open the Misc Tools section.
  • Next click on Open uninstall manager.
  • Press the Save list button.
  • Save the file to your desktop, with the default name of uninstall_list
  • Copy & Paste the entire contents of that file in your in your next post.
Thanks.
I have tried running ComboFix, but it just stops after it says trying to create a restore point. It appears to back up the registry but then does nothing at all. Am I doing it wrong? Any suggestions? Thanks for all your help. Jackie
Hi,

Please delete your copy of ComboFix. Is is likely that the Malware is preventing ComboFix from running properly, so let's try a different way of running it.

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Right-click on Combo-Fix.exe, select Run As Administrator… & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.

If that still doesn't work, try booting into Safe Mode (restart computer and tap F8 before Windows Loads) and running it from there. If that's still no good let me know and we'll try something different.
Hi,

Let's try a different route for a moment.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
I tried to run the first file and it started scanning then stopped responding twice. The first time it gave me a blue screen, but the 2nd time it just closed the program. The DDS file worked so here it is. 📎Attach.txt DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 2:49:18.14 on Wed 05/06/2009 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_07 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2037.1325 [GMT -5:00] AV: Windows Live OneCare *On-access scanning disabled* (Updated) FW: Windows Live OneCare Firewall *disabled* ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Protector Suite QL\upeksvr.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k apphost C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\inetsrv\inetinfo.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Sierra Wireless Inc\3G Watcher\WaHelper.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\taskeng.exe C:\Program Files\Synaptics\SynTP\SynToshiba.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\System32\mobsync.exe C:\Windows\system32\taskeng.exe C:\Users\JACKIE WATSON\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uStart Page = hxxp://myspam.cableone.net/login.aspx?ReturnUrl=%2fDefault.aspx uSearch Bar = hxxp://www.google.com/ie uDefault_Search_URL = hxxp://www.google.com/ie mStart Page = hxxp://home.sweetim.com uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {23176ec3-cbb5-4b77-b898-7f5eb465c530} - c:\windows\system32\gebaw.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: {9a5bd632-ebf0-4c6a-bc19-77f85293f7a7} - c:\windows\system32\gebaw.dll BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File TB: {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - No File TB: {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - No File uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [] mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [AirCardEnabler] mRun: [WatcherHelper] "c:\program files\sierra wireless inc\3g watcher\WaHelper.exe" mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe mRun: [OneCareUI] "c:\program files\microsoft windows onecare live\winssnotify.exe" dRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" dRunOnce: [DelayShred] "c:\program files\mcafee\mshr\shrcl.exe" /p7 /q c:\users\jackie~1\appdata\local\temp\~dfacee.tmp c:\users\jackie~1\appdata\local\temp\low\hsperf~1.sh! c:\users\jackie~1\appdata\local\temp\HSPERF~1.SH! mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: DisableCAD = 1 (0x1) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: Download Link Using Mega Manager… - c:\program files\megaupload\mega manager\mm_file.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {13C1DBF6-7535-495c-91F6-8C13714ED485} - c:\users\jackie watson\appdata\roaming\microsoft\windows\start menu\programs\absolute poker\Absolute Poker.lnk IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL Trusted Zone: adpselect.com\www Trusted Zone: asus.com\usa Trusted Zone: att.com\www.wireless Trusted Zone: churchsprojects.com\www Trusted Zone: cisgroup.net\www Trusted Zone: countyassessor.info Trusted Zone: ftabin.info Trusted Zone: greatinsurancejobs.com\www Trusted Zone: guardianps.com\www Trusted Zone: inspections.net\www Trusted Zone: internet Trusted Zone: mcafee.com Trusted Zone: melissadata.com\www Trusted Zone: microsoft.com\windowshelp Trusted Zone: millinfo.com\wide Trusted Zone: mortgageramp.com\cims Trusted Zone: nationalcreditors.com\www Trusted Zone: pokerfatcat.net\www Trusted Zone: safeguardproperties.com\inspi2 Trusted Zone: taxnetusa.com\www Trusted Zone: therepreport.com\www Trusted Zone: wilife.com\online Trusted Zone: yahoo.com\finance.groups Trusted Zone: yahoo.com\login Trusted Zone: yahoo.com\us.f354.mail DPF: {556DDE35-E955-11D0-A707-000000521957} - hxxp://www.xblock.com/download/xclean_micro.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Notify: igfxcui - igfxdev.dll Notify: psfus - c:\windows\system32\psqlpwd.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\jackie~1\appdata\roaming\mozilla\firefox\profiles\l1for5bl.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://myspam.cableone.net/login.aspx?ReturnUrl=%2fDefault.aspx FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=megaup&p= FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll ============= SERVICES / DRIVERS =============== R0 C2SCSI;C2SCSI;c:\windows\system32\drivers\C2SCSI.SYS [2006-10-26 248568] R0 lfsfilt;Lean File Sharing;c:\windows\system32\drivers\lfsfilt.sys [2007-6-30 254704] R0 lpx;LPX Protocol;c:\windows\system32\drivers\lpx.sys [2007-4-11 61424] R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2007-5-20 7168] R3 ndasbus;NDAS Bus Driver;c:\windows\system32\drivers\ndasbus.sys [2007-4-11 76144] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-11-17 3668480] R3 swivsp;AC8xx Virtual Serial Port;c:\windows\system32\drivers\swivspnt.sys [2007-1-9 20352] S3 ACGPRS;Sierra Wireless 3G Adapter;c:\windows\system32\drivers\acgprs.sys [2007-1-9 103808] S3 netngmps;Sierra Wireless MP Series Network Adapter;c:\windows\system32\drivers\ngmps.sys [2007-3-12 102272] S3 scrswi;Sierra Wireless Smart Card Reader;c:\windows\system32\drivers\scrswi.sys [2007-3-26 43904] S3 VNic;ULan Network Driver Module;c:\windows\system32\drivers\VNic.sys [2007-8-3 57516] S4 BRA_Scheduler;Brother BRAdminPro Scheduler;c:\program files\brother\bradmin professional 3\bratimer.exe [2008-1-9 65536] S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\nbservice.exe –> c:\program files\common files\nero\nero backitup 4\NBService.exe [?] S4 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\microsoft windows onecare live\OcHealthMon.exe [2009-3-22 24936] =============== Created Last 30 ================ 2009-05-06 02:30 281,348,275 a——- c:\windows\MEMORY.DMP 2009-05-05 21:28 –d—– C:\Combo-Fix 2009-05-05 21:28 318,976 a——- c:\windows\system32\CF15864.exe 2009-05-05 20:30 318,976 a——- c:\windows\system32\CF6159.exe 2009-05-05 13:37 –d—– c:\users\jackie~1\appdata\roaming\VTExtra 2009-05-05 12:56 318,976 a——- c:\windows\system32\CF15518.exe 2009-05-05 12:28 161,792 a——- c:\windows\SWREG.exe 2009-05-05 12:28 98,816 a——- c:\windows\sed.exe 2009-05-05 12:28 318,976 a——- c:\windows\system32\CF10042.exe 2009-05-05 12:26 37,440 a——- c:\windows\system32\drivers\msfwhlpr.sys 2009-05-05 12:26 91,200 a——- c:\windows\system32\drivers\msfwdrv.sys 2009-05-05 12:24 53,168 a——- c:\windows\system32\drivers\MpFilter.sys 2009-05-05 12:15 –d—– c:\program files\Microsoft Windows OneCare Live 2009-05-04 22:36 –d—– c:\program files\Trend Micro 2009-05-03 21:40 –d—– c:\users\jackie~1\appdata\roaming\uTorrent 2009-04-15 04:59 376,832 a——- c:\windows\system32\winhttp.dll 2009-04-15 04:59 562,176 a——- c:\windows\system32\msdtcprx.dll 2009-04-15 04:59 38,912 a——- c:\windows\system32\xolehlp.dll 2009-04-15 04:59 3,599,328 a——- c:\windows\system32\ntkrnlpa.exe 2009-04-15 04:59 3,547,632 a——- c:\windows\system32\ntoskrnl.exe 2009-04-15 04:59 551,424 a——- c:\windows\system32\rpcss.dll 2009-04-15 04:59 666,624 a——- c:\windows\system32\printfilterpipelinesvc.exe 2009-04-15 04:57 1,383,424 a——- c:\windows\system32\mshtml.tlb 2009-04-08 13:44 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf 2009-04-08 12:03 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-04-08 12:03 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-04-08 12:03 –d—– c:\program files\iPod 2009-04-08 12:03 –d—– c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-04-08 12:03 –d—– c:\program files\iTunes 2009-04-08 12:03 –d—– c:\progra~2\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-04-08 11:58 –d—– c:\program files\Bonjour ==================== Find3M ==================== 2009-04-12 14:56 143,360 a——- c:\windows\inf\infstrng.dat 2009-04-12 14:56 143,360 a——- c:\windows\inf\infstor.dat 2009-04-12 14:56 86,016 a——- c:\windows\inf\infpub.dat 2009-03-19 15:33 0 a—h— c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf 2009-03-19 06:59 0 a—h— c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf 2009-03-16 22:38 40,960 a——- c:\windows\apppatch\apihex86.dll 2009-03-16 22:38 13,824 a——- c:\windows\system32\apilogen.dll 2009-03-16 22:38 24,064 a——- c:\windows\system32\amxread.dll 2009-03-07 22:03 319,456 a——- c:\windows\DIFxAPI.dll 2009-03-05 23:59 1,900,544 a——- c:\windows\system32\usbaaplrc.dll 2009-03-02 23:40 827,392 a——- c:\windows\system32\wininet.dll 2009-03-02 23:39 183,296 a——- c:\windows\system32\sdohlp.dll 2009-03-02 23:39 26,112 a——- c:\windows\system32\printfilterpipelineprxy.dll 2009-03-02 23:37 78,336 a——- c:\windows\system32\ieencode.dll 2009-03-02 23:37 98,304 a——- c:\windows\system32\iasrecst.dll 2009-03-02 23:37 54,784 a——- c:\windows\system32\iasads.dll 2009-03-02 23:37 44,032 a——- c:\windows\system32\iasdatastore.dll 2009-03-02 21:38 17,408 a——- c:\windows\system32\iashost.exe 2009-03-02 21:28 26,624 a——- c:\windows\system32\ieUnatt.exe 2009-02-13 03:49 72,704 a——- c:\windows\system32\secur32.dll 2009-02-13 03:49 1,255,936 a——- c:\windows\system32\lsasrv.dll 2009-02-08 22:10 2,033,152 a——- c:\windows\system32\win32k.sys 2009-02-06 19:03 307,576 a——- c:\windows\WLXPGSS.SCR 2009-02-06 18:52 49,504 a——- c:\windows\system32\sirenacm.dll 2008-10-01 04:00 174 a–sh— c:\program files\desktop.ini 2008-10-01 03:43 665,600 a——- c:\windows\inf\drvindex.dat 2008-07-06 15:07 262,144 a——- c:\progra~2\ntuser.dat 2008-02-18 16:08 22,685,480 a——- c:\users\jackie watson\SkypeSetup.exe 2007-11-24 21:55 376 a——- c:\users\jackie~1\appdata\roaming\wklnhst.dat 2007-08-02 23:16 1,133 a——- c:\users\jackie watson\FixSingleSelect.zip 2007-05-17 21:55 177,224 a——- c:\users\jackie watson\Favorites.zip 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2006-08-12 00:51 4,912,184 a——- c:\users\jackie watson\roboform.dll 2007-06-06 00:11 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat 2007-06-06 00:11 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 2007-06-06 00:11 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat ============= FINISH: 2:49:41.57 ===============
Hi,

Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please right-click OTMoveIt3.exe and select Run As Administrator… to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{23176ec3-cbb5-4b77-b898-7f5eb465c530}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9a5bd632-ebf0-4c6a-bc19-77f85293f7a7}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{0BF43445-2F28-4351-9252-17FE6E806AA0}"=-
    "{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938}"=-
    "{A057A204-BACC-4D26-C39E-35F1D2A32EC8}"=-

    :Files
    c:\windows\system32\gebaw.dll

    :Commands
    [emptytemp]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Right-click SystemLook.exe and select Run As Administrator… to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *gxvxc*
    
    :regfind
    gxvxc
    
    :file
    c:\windows\system32\psqlpwd.dll
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Thanks.
The system look tool stopped working. but here is the other log file SystemLook v1.0 by jpshortstuff (24.04.09) Log created at 08:37 on 06/05/2009 by JACKIE WATSON (Administrator - Elevation successful) ========== filefind ========== Searching for "*gxvxc*" No files found. ========== regfind ========== Searching for "gxvxc" ___________________________________________________________________ ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{23176ec3-cbb5-4b77-b898-7f5eb465c530}\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9a5bd632-ebf0-4c6a-bc19-77f85293f7a7}\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{0BF43445-2F28-4351-9252-17FE6E806AA0} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BF43445-2F28-4351-9252-17FE6E806AA0}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{A057A204-BACC-4D26-C39E-35F1D2A32EC8} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}\ not found. ========== FILES ========== File/Folder c:\windows\system32\gebaw.dll not found. ========== COMMANDS ========== User's Temp folder emptied. User's Internet Explorer cache folder emptied. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05062009_082557
========== regfind ========== Searching for "gxvxc" No data found. ========== file ========== c:\windows\system32\psqlpwd.dll - File found and opened. MD5: 570AFC93E224AFE83E9647AA4B9335E2 Created at 16:34 on 06/11/2006 Modified at 16:34 on 06/11/2006 Size: 52224 bytes Attributes: –a— FileDescription: Logon stub FileVersion: 5.6.0.3219 ProductVersion: 5.6.0 OriginalFilename: psqlpwd.dll InternalName: PSQLPWD ProductName: Protector Suite QL CompanyName: UPEK Inc. LegalCopyright: Copyright © 2001-2006 UPEK Inc. -=End Of File=-
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI