This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Various Malware Issues

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been trying for the better part of today to diagnose and fix my roommate's PC. I've ran a number of AV programs as well as a few different Anti-Spyware ones. I noticed that another user on this site encountered one of the errors that has been plaguing this machine as well:

svchost.exe - Application Error
The instructions at "0x75606e6a" referenced memory at "0x00000008". The memory could not be "read".
Click on OK to terminate the program

I ran across a Vundo infection on here as well, which I (hopefully) took care of with a specialized removal tool. There also seems to be a process called krakbqe.exe running. After a failed google search on the subject, I ran it through Virustotal's identifier program. It ID'd it as Win32-Zlob, among others. This is a link to Virustotal's conclusions. After doing that, I ran SuperAntiSpyware again to check for any lingering infections. During the scan, the PC suddenly rebooted on me, which prompted me to seek outside assistance. I don't know if it's related to the infection(s) on the machine, but there is also a periodic ringing sound that occurs at random times.

I'm hoping someone on here will be able to help me out.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:31:18 AM, on 5/16/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\krakbqe.exe
C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
c:\lsass.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [4445] C:\krakbqe.exe
O4 - HKUS\.DEFAULT\..\Run: [Diagnostic Manager] C:\WINDOWS\TEMP\106067068.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: NETGEAR WG311v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O20 - Winlogon Notify: bbdaaafdbccbaccffafe - C:\WINDOWS\system32\bbdaaafdbccbaccffafe.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\


Edit: I forgot to mention that Malwarebytes cannot update. I keep getting an error stating that the update server could not be reached.
Hi,

Please do not run any other tools or fix anything else on your own while we are working together.

I ran across a Vundo infection on here as well, which I (hopefully) took care of with a specialized removal tool

what did you use and are there any logs I can see, the more info I have the better.

In the meantime please do the following:

First

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

NEXT

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

what did you use and are there any logs I can see, the more info I have the better.


Unfortunately, there are no logs. The PC in question is used by several different people a day, and, while I tried to preserve a copy of the log, I was unable to. However, the program I used was VundoFix by Atribune.

ComboFix 09-05-16.03 - Compaq_Administrator 05/16/2009 16:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.605 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\lsass.exe
c:\recycler\S-1-5-21-3097091178-9120942338-493889864-0805\service.exe
c:\recycler\S-1-5-21-9909677002-0852867659-509066389-8421\service.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\b6d61891.sys
c:\windows\Temp\1020514636.exe
c:\windows\Temp\10256672.exe
c:\windows\Temp\106067068.exe
c:\windows\Temp\1093476094.exe
c:\windows\Temp\122302440.exe
c:\windows\Temp\1378385340.exe
c:\windows\Temp\168908604.exe
c:\windows\Temp\1700405490.exe
c:\windows\Temp\1974406302.exe
c:\windows\Temp\198112836.exe
c:\windows\Temp\2104984080.exe
c:\windows\Temp\2159548122.exe
c:\windows\Temp\2259311858.exe
c:\windows\Temp\246263204.exe
c:\windows\Temp\3103592436.exe
c:\windows\Temp\3750398316.exe
c:\windows\Temp\3987756584.exe
c:\windows\Temp\573007597.exe
c:\windows\Temp\903683322.exe
C:\xcrashdump.dat
D:\Autorun.inf

Infected copy of c:\windows\system32\drivers\ndis.sys was found and disinfected
Restored copy from - The cat ate it :)

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_b6d61891


((((((((((((((((((((((((( Files Created from 2009-04-16 to 2009-05-16 )))))))))))))))))))))))))))))))
.

2009-05-16 20:33 . 2009-05-16 20:33 20480 —-a-w C:\lsass.exe
2009-05-16 05:31 . 2009-05-16 05:31 ——– d—–w c:\program files\Trend Micro
2009-05-16 05:07 . 2009-05-16 05:07 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-16 05:07 . 2009-05-16 05:07 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-16 05:07 . 2009-05-16 05:07 ——– d—–w c:\documents and settings\Compaq_Administrator\Application Data\SUPERAntiSpyware.com
2009-05-16 05:07 . 2009-05-16 05:07 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-16 03:13 . 2009-05-16 03:13 ——– d—–w C:\VundoFix Backups
2009-05-16 02:36 . 2009-05-16 02:36 ——– d—–w c:\documents and settings\Compaq_Administrator\Application Data\Malwarebytes
2009-05-16 02:36 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-16 02:35 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-16 02:35 . 2009-05-16 02:35 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-16 02:35 . 2009-05-16 02:36 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-16 01:50 . 2009-05-16 03:37 ——– d—–w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-05-16 01:50 . 2009-05-16 04:13 ——– d—–w c:\program files\Security Task Manager
2009-05-15 12:49 . 2009-05-15 12:49 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\AdobeUM
2009-05-15 12:49 . 2009-05-15 12:49 ——– d—–w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2009-05-14 21:32 . 2009-05-14 21:32 ——– d—–w c:\documents and settings\Compaq_Administrator\Application Data\HPQ
2009-05-14 21:31 . 2009-05-14 21:31 ——– d—–w c:\program files\ASIO4ALL v2
2009-05-14 21:31 . 2009-05-14 21:31 ——– d—–w c:\program files\VstPlugins
2009-05-14 21:31 . 2006-06-20 08:56 225280 —-a-w c:\windows\system32\rewire.dll
2009-05-14 21:30 . 2009-05-14 21:30 ——– d—–w c:\program files\Outsim
2009-05-14 21:28 . 2009-05-14 21:31 ——– d—–w c:\program files\Image-Line
2009-05-14 07:28 . 2009-05-14 07:28 ——– d—–w c:\windows\Sun
2009-05-14 06:32 . 2009-05-14 06:32 ——– d—–w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\Identities
2009-05-14 06:09 . 2009-05-14 06:09 ——– d-s—w c:\windows\system32\config\systemprofile\UserData
2009-05-14 02:04 . 2009-05-16 03:32 ——– d—–w c:\windows\system32\218538
2009-05-14 02:02 . 2009-05-14 02:02 ——– d—–w c:\windows\system32\LogFiles
2009-05-13 21:54 . 2009-05-13 21:54 13135 —-a-w C:\adspl.exe
2009-05-13 21:54 . 2009-05-16 19:59 20480 —-a-w C:\krakbqe.exe
2009-05-13 19:04 . 2009-05-13 19:04 ——– d—–w c:\program files\MSXML 4.0
2009-05-13 18:53 . 2009-05-14 16:59 ——– d—–w c:\documents and settings\Compaq_Administrator\Application Data\EuroOffice2008
2009-05-13 18:51 . 2009-05-13 18:51 ——– d—–w c:\program files\EuroOffice 2008
2009-05-13 10:28 . 2008-06-13 13:10 272128 ——w c:\windows\system32\dllcache\bthport.sys
2009-05-13 10:28 . 2008-06-13 13:10 272128 ——w c:\windows\system32\drivers\bthport.sys
2009-05-13 10:25 . 2009-02-06 17:22 2136064 ——w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-13 10:25 . 2009-02-06 17:24 2180480 ——w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-13 10:25 . 2009-02-06 16:49 2015744 ——w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-13 10:25 . 2009-02-06 16:49 2057728 ——w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-05-13 10:18 . 2006-03-21 03:23 23040 ——w c:\windows\kb913800.exe
2009-05-13 07:53 . 2009-05-13 07:53 ——– d—–w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\Adobe
2009-05-12 15:45 . 2009-05-12 20:52 ——– d—–w c:\documents and settings\Compaq_Administrator\Application Data\vlc
2009-05-12 15:40 . 2004-08-04 03:08 31616 —-a-w c:\windows\system32\dllcache\usbccgp.sys
2009-05-12 15:40 . 2004-08-04 03:08 31616 —-a-w c:\windows\system32\drivers\usbccgp.sys
2009-05-12 08:17 . 2009-05-12 08:17 ——– d—–w C:\OEMSettings
2009-05-12 08:17 . 2009-05-12 08:17 ——– d—–w c:\program files\NETGEAR
2009-05-12 08:16 . 2009-05-12 08:16 ——– d—–w c:\windows\Downloaded Installations
2009-05-12 08:06 . 2009-05-15 01:24 ——– d—–w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\ApplicationHistory
2009-05-12 08:05 . 2005-11-11 20:51 136 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\fusioncache.dat
2009-05-12 08:05 . 2005-11-11 21:31 45584 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-12 08:05 . 2005-11-11 21:15 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\Digital Interactive Systems Corporation
2009-05-12 08:05 . 2005-11-11 21:28 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\Intuit
2009-05-12 08:05 . 2005-11-11 21:45 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\Symantec
2009-05-12 08:05 . 2005-11-11 21:27 ——– d—–w c:\windows\system32\config\systemprofile\WINDOWS
2009-05-12 08:05 . 2005-11-11 21:32 ——– d—–w c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory
2009-05-12 08:05 . 2005-11-11 21:41 ——– d—–w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Google
2009-05-12 08:05 . 2005-11-11 20:58 ——– d—–w c:\windows\system32\config\systemprofile\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150050}
2009-05-12 08:05 . 2005-11-11 21:27 ——– d—–w c:\documents and settings\Default User\WINDOWS
2009-05-12 08:03 . 2009-05-14 06:04 179 —-a-w c:\windows\system\hpsysdrv.DAT
2009-05-12 08:02 . 2001-08-17 20:48 12160 —-a-w c:\windows\system32\drivers\mouhid.sys
2009-05-12 08:02 . 2001-08-17 21:02 9600 —-a-w c:\windows\system32\drivers\hidusb.sys
2009-05-12 06:49 . 2009-05-16 20:31 ——– d-sh–r c:\windows\system32\dllcache
2009-05-12 06:39 . 2009-05-12 20:31 ——– d—–w c:\program files\BitLord
2009-05-12 06:14 . 2009-05-12 06:14 ——– d—–w c:\program files\VideoLAN
2009-05-12 05:21 . 2004-08-10 10:00 12288 —-a-w c:\windows\system32\dllcache\wb32.exe
2009-05-12 05:20 . 2004-08-10 10:00 61440 —-a-w c:\windows\system32\dllcache\rrcm.dll
2009-05-12 05:19 . 2004-08-10 10:00 188416 —-a-w c:\windows\system32\dllcache\nmwb.dll
2009-05-12 05:19 . 2004-08-10 10:00 172032 —-a-w c:\windows\system32\dllcache\nmoldwb.dll
2009-05-12 05:19 . 2004-08-10 10:00 28672 —-a-w c:\windows\system32\dllcache\nmmkcert.dll
2009-05-12 05:19 . 2004-08-10 10:00 28672 —-a-w c:\windows\system32\nmmkcert.dll
2009-05-12 05:19 . 2004-08-10 10:00 12288 —-a-w c:\windows\system32\dllcache\nmevtmsg.dll
2009-05-12 05:19 . 2004-08-10 10:00 151552 —-a-w c:\windows\system32\dllcache\nmft.dll
2009-05-12 05:19 . 2004-08-10 10:00 12288 —-a-w c:\windows\system32\nmevtmsg.dll
2009-05-12 05:19 . 2004-08-10 10:00 77824 —-a-w c:\windows\system32\dllcache\nmcom.dll
2009-05-12 05:19 . 2004-08-10 10:00 81920 —-a-w c:\windows\system32\dllcache\nmchat.dll
2009-05-12 05:19 . 2004-08-10 10:00 28672 —-a-w c:\windows\system32\dllcache\nmasnt.dll
2009-05-12 05:19 . 2004-08-10 10:00 229376 —-a-w c:\windows\system32\dllcache\nmas.dll
2009-05-12 05:19 . 2004-08-10 10:00 221184 —-a-w c:\windows\system32\dllcache\nac.dll
2009-05-12 05:18 . 2004-08-10 10:00 57344 —-a-w c:\windows\system32\dllcache\mst123.dll
2009-05-12 05:18 . 2004-08-10 10:00 274432 —-a-w c:\windows\system32\dllcache\mst120.dll
2009-05-12 05:18 . 2004-08-10 10:00 188416 —-a-w c:\windows\system32\msh261.drv
2009-05-12 05:18 . 2004-08-10 10:00 69632 —-a-w c:\windows\system32\dllcache\msconf.dll
2009-05-12 05:18 . 2004-08-10 10:00 69632 —-a-w c:\windows\system32\msconf.dll
2009-05-12 05:18 . 2004-08-10 10:00 32768 —-a-w c:\windows\system32\dllcache\mnmsrvc.exe
2009-05-12 05:18 . 2004-08-10 10:00 32768 —-a-w c:\windows\system32\mnmsrvc.exe
2009-05-12 05:18 . 2004-08-10 10:00 34560 —-a-w c:\windows\system32\dllcache\mnmdd.dll
2009-05-12 05:18 . 2004-08-10 10:00 34560 —-a-w c:\windows\system32\mnmdd.dll
2009-05-12 05:16 . 2004-08-10 10:00 32768 —-a-w c:\windows\system32\dllcache\isrdbg32.dll
2009-05-12 05:16 . 2004-08-10 10:00 32768 —-a-w c:\windows\system32\isrdbg32.dll
2009-05-12 05:16 . 2004-08-10 10:00 81920 —-a-w c:\windows\system32\dllcache\ils.dll
2009-05-12 05:16 . 2004-08-10 10:00 81920 —-a-w c:\windows\system32\ils.dll
2009-05-12 05:16 . 2004-08-10 10:00 57344 —-a-w c:\windows\system32\dllcache\h323cc.dll
2009-05-12 05:12 . 2004-08-10 10:00 40960 —-a-w c:\windows\system32\dllcache\dcap32.dll
2009-05-12 05:12 . 2004-08-10 10:00 45056 —-a-w c:\windows\system32\dllcache\confmrsl.dll
2009-05-12 05:12 . 2004-08-10 10:00 1032192 —-a-w c:\windows\system32\dllcache\conf.exe
2009-05-12 05:12 . 2004-08-10 10:00 12288 —-a-w c:\windows\system32\dllcache\cb32.exe
2009-05-12 05:12 . 2004-08-10 10:00 385024 —-a-w c:\windows\system32\dllcache\callcont.dll
2009-05-12 04:27 . 2009-05-12 04:27 0 —-a-w c:\windows\nsreg.dat
2009-05-12 04:27 . 2009-05-12 04:27 ——– d—–w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-16 20:33 . 2005-11-11 21:44 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-16 20:24 . 2004-08-10 12:00 182912 —-a-w c:\windows\system32\drivers\ndis.sys
2009-05-15 16:29 . 2004-07-02 05:14 312847 —-a-w c:\windows\system32\bbdaaafdbccbaccffafe.dll
2009-05-13 19:19 . 2005-11-11 21:15 47560 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-13 04:12 . 2009-05-12 08:06 143 —-a-w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\fusioncache.dat
2009-05-12 08:08 . 2009-05-12 08:08 1865 –sha-r c:\windows\system32\drivers\103C_HP_CPC_EL445AA-ABA SR1750NX NA650_YC_0Pres_QCNH604_E61NAemRED1_48_IAmberine M_SASUSTek Computer INC._V1.03_B3.13_T051115_WXP2_L409_M959_J200_7AMD_8Athlon 64_92.19_#090512_N10EC8139_Z11C10620_G10025954.MRK
2009-03-06 14:44 . 2004-08-10 12:00 283648 —-a-w c:\windows\system32\pdh.dll
2009-02-20 08:30 . 2004-08-10 12:00 81920 —-a-w c:\windows\system32\ieencode.dll
2009-02-20 08:30 . 2004-08-10 12:00 659456 —-a-w c:\windows\system32\wininet.dll
2006-02-25 21:30 . 2009-05-12 06:59 32 –sha-w c:\windows\SMINST\HPCD.SYS
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"10383"="C:\krakbqe.exe" [2009-05-16 20480]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG311v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG311v3\wlancfg5.exe [2006-1-26 1486848]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"\\"= c:\\WINDOWS\\system\\svchost.exe

R1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/14/2009 2:22 PM 9968]
R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/14/2009 2:22 PM 72944]
S0 a5f2bf00eb19537bfce81d1c1b77029c;a5f2bf00eb19537bfce81d1c1b77029c;c:\windows\system32\a5f2bf00eb19537bfce81d1c1b77029c.sys –> c:\windows\system32\a5f2bf00eb19537bfce81d1c1b77029c.sys [?]
S3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/14/2009 2:22 PM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-05-12 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]

2009-05-16 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Compaq_Administrator.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2005-03-24 14:21]

2009-05-12 c:\windows\Tasks\Register Reminder 7 Days.job
- c:\hp\bin\cloaker.exe [2005-11-11 07:11]

2009-05-15 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-11-11 03:24]

2009-05-12 c:\windows\Tasks\Warranty Reminder 11 Months.job
- c:\hp\bin\cloaker.exe [2005-11-11 07:11]

2009-05-12 c:\windows\Tasks\Warranty Reminder 15 Days.job
- c:\hp\bin\cloaker.exe [2005-11-11 07:11]
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-Diagnostic Manager - c:\windows\TEMP\106067068.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q106&bd;=presario&pf;=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q106&bd;=presario&pf;=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q106&bd;=presario&pf;=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q106&bd;=presario&pf;=desktop
IE: &Google; Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate; English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\hvy4nktx.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-16 16:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\MrvGINA.dll
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Norton Internet Security\ISSVC.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\system32\ati2evxx.exe
c:\windows\arservice.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\windows\system32\dllhost.exe
C:\lsass.exe
.
**************************************************************************
.
Completion time: 2009-05-16 16:35 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-16 20:35

Pre-Run: 163,259,469,824 bytes free
Post-Run: 163,296,264,192 bytes free

268 — E O F — 2009-05-13 19:14

The PC -seems- to be running better. However, there were really no noticeable signs that an infection was present on this machine to begin with. Aside from the mystery processes, both of which are still there, the only things that were noticeable were the seemingly perpetual hourglass by the cursor and the random beeping noise. The hourglass is still there, and while I haven't yet heard the beeping, I'm assuming it is gone. (It was almost always heard whenever the system booted up/shut down.)
Hi,

Please do the following:

I would like you to upload a couple of suspicious files for analysis
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
    • c:\windows\system32\drivers\103C_HP_CPC_EL445AA-ABA SR1750NX NA650_YC_0Pres_QCNH604_E61NAemRED1_48_IAmberine M_SASUSTek Computer INC._V1.03_B3.13_T051115_WXP2_L409_M959_J200_7AMD_8Athlon 64_92.19_#090512_N10EC8139_Z11C10620_G10025954.MRK
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


Do the same for this following file:

C:\lsass.exe



NEXT

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Various_Malware_Issues_t103113.html&view=findpost&p=559212#entry559212

KillAll::

Collect::
c:\windows\system32\218538
C:\adspl.exe
C:\krakbqe.exe
c:\windows\system32\bbdaaafdbccbaccffafe.dll
c:\windows\system32\a5f2bf00eb19537bfce81d1c1b77029c.sys

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"10383"=-

Driver::
a5f2bf00eb19537bfce81d1c1b77029c

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
VirSCAN.org Scanned Report :
Scanned time : 2009/05/16 17:14:57 (EDT)
Scanner results: All Scanners reported not find malware!
File Name : 103C_HP_CPC_EL445AA-ABA SR1750NX NA650_YC_0Pres_QCNH604_E61NAemRE…
File Size : 1865 byte
File Type : ASCII text, with CRLF line terminators
MD5 : d9799813fbce9372e096cdbd2c7ecb5f
SHA1 : f779291441734a52d216410178ea89f8d0f265a0
Online report : http://virscan.org/report/fde95514e169fafa…6321cdd98d.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090516190230 2009-05-16 2.58 -
AhnLab V3 2009.05.17.00 2009.05.17 2009-05-17 0.69 -
AntiVir 8.2.0.168 7.1.3.215 2009-05-15 0.49 -
Antiy 2.0.18 20090516.2420010 2009-05-16 0.12 -
Arcavir 2009 200905160757 2009-05-16 0.02 -
Authentium 5.1.1 200905161041 2009-05-16 1.10 -
AVAST! 4.7.4 090516-0 2009-05-16 0.00 -
AVG 8.5.286 270.12.32/2118 2009-05-17 3.19 -
BitDefender 7.81008.2985350 7.25445 2009-05-17 2.81 -
CA (VET) 9.0.0.143 31.6.6507 2009-05-16 5.26 -
ClamAV 0.95 9364 2009-05-16 0.00 -
Comodo 3.8 1157 2009-05-08 0.73 -
CP Secure 1.1.0.715 2009.05.17 2009-05-17 9.07 -
Dr.Web 4.44.0.9170 2009.05.16 2009-05-16 4.53 -
F-Prot 4.4.4.56 20090516 2009-05-16 1.10 -
F-Secure 5.51.6100 2009.05.16.01 2009-05-16 0.04 -
Fortinet 2.81-3.117 10.396 2009-05-16 0.24 -
GData 19.5251/19.333 20090516 2009-05-16 3.94 -
ViRobot 20090515 2009.05.15 2009-05-15 0.41 -
Ikarus T3.1.01.49 2009.05.16.72727 2009-05-16 3.14 -
JiangMin 11.0.706 2009.05.16 2009-05-16 1.98 -
Kaspersky 5.5.10 2009.05.16 2009-05-16 0.02 -
KingSoft 2009.2.5.15 2009.5.16.21 2009-05-16 0.52 -
McAfee 5.3.00 5616 2009-05-15 2.86 -
Microsoft 1.4602 2009.05.15 2009-05-15 4.52 -
mks_vir 2.01 2009.05.16 2009-05-16 3.12 -
Norman 6.01.05 6.01.00 2009-05-15 4.01 -
Panda 9.05.01 2009.05.16 2009-05-16 1.58 -
Trend Micro 8.700-1004 6.134.09 2009-05-16 0.02 -
Quick Heal 10.00 2009.05.15 2009-05-15 1.20 -
Rising 20.0 21.29.52.00 2009-05-16 0.38 -
Sophos 2.86.0 4.41 2009-05-17 2.34 -
Sunbelt 5139 5139 2009-05-16 0.84 -
Symantec 1.3.0.24 20090516.003 2009-05-16 0.04 -
nProtect 20090516.01 3700025 2009-05-16 5.16 -
The Hacker [removed] v00326 2009-05-15 0.57 -
VBA32 3.12.10.5 20090515.1445 2009-05-15 1.85 -
VirusBuster 4.5.11.10 10.105.28/1378347 2009-05-16 1.67 -


Now for C:\Isass.exe

VirSCAN.org Scanned Report :
Scanned time : 2009/05/16 17:18:49 (EDT)
Scanner results: 55% Scanner(21/38) found malware!
File Name : lsass.exe
File Size : 20480 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 9f887dcdbc997f6e9594a879867c3e60
SHA1 : 277580cc9f6bc58c021e7bbfb7389681fc5a3614
Online report : http://virscan.org/report/ce81dbe40d0ec1fb…3f789ce3b7.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090516190230 2009-05-16 2.23 Trojan-Downloader.Win32.Zlob!IK
AhnLab V3 2009.05.17.00 2009.05.17 2009-05-17 0.91 Win-Trojan/Agent.57344.RV
AntiVir 8.2.0.168 7.1.3.215 2009-05-15 0.45 TR/Spy.Gen
Antiy 2.0.18 20090516.2420010 2009-05-16 0.12 -
Arcavir 2009 200905160757 2009-05-16 0.08 -
Authentium 5.1.1 200905161041 2009-05-16 1.24 W32/Heuristic-424!Eldorado (Heuristic)
AVAST! 4.7.4 090516-0 2009-05-16 0.01 Win32:Zlob-CWB [Trj]
AVG 8.5.286 270.12.32/2118 2009-05-17 3.22 Agent_r.MM
BitDefender 7.81008.2985350 7.25445 2009-05-17 2.78 BehavesLike:Win32.Malware (suspected)
CA (VET) 9.0.0.143 31.6.6507 2009-05-16 4.83 Win32/Puper.XR trojan.
ClamAV 0.95 9364 2009-05-16 0.03 -
Comodo 3.8 1157 2009-05-08 0.73 -
CP Secure 1.1.0.715 2009.05.17 2009-05-17 9.17 -
Dr.Web 4.44.0.9170 2009.05.16 2009-05-16 4.54 Trojan.DownLoad.37254
F-Prot 4.4.4.56 20090516 2009-05-16 1.24 Possible W32/Heuristic-424!Eldorado (not disinfectable)
F-Secure 5.51.6100 2009.05.16.01 2009-05-16 5.51 Trojan.Win32.Obfuscated.afqi [AVP]
Fortinet 2.81-3.117 10.396 2009-05-16 0.19 W32/Obfuscated.AFQI!tr
GData 19.5251/19.333 20090516 2009-05-16 3.96 Trojan.Win32.Obfuscated.afqi [Engine:A]
ViRobot 20090515 2009.05.15 2009-05-15 0.41 -
Ikarus T3.1.01.49 2009.05.16.72727 2009-05-16 3.15 Trojan-Downloader.Win32.Zlob
JiangMin 11.0.706 2009.05.16 2009-05-16 1.88 -
Kaspersky 5.5.10 2009.05.16 2009-05-16 0.05 Trojan.Win32.Obfuscated.afqi
KingSoft 2009.2.5.15 2009.5.16.21 2009-05-16 0.49 Win32.Troj.Obfuscated.73728
McAfee 5.3.00 5616 2009-05-15 2.96 -
Microsoft 1.4602 2009.05.15 2009-05-15 4.60 Trojan:Win32/Puvbed.B
mks_vir 2.01 2009.05.16 2009-05-16 3.25 -
Norman 6.01.05 6.01.00 2009-05-15 4.01 Renos.CVV
Panda 9.05.01 2009.05.16 2009-05-16 1.64 -
Trend Micro 8.700-1004 6.134.09 2009-05-16 0.07 -
Quick Heal 10.00 2009.05.15 2009-05-15 1.20 -
Rising 20.0 21.29.52.00 2009-05-16 1.04 -
Sophos 2.86.0 4.41 2009-05-17 2.38 Mal/Zlob-AG
Sunbelt 5139 5139 2009-05-16 0.88 -
Symantec 1.3.0.24 20090516.003 2009-05-16 0.24 Suspicious.MH690
nProtect 20090516.01 3700025 2009-05-16 5.45 BehavesLike:Win32.Malware
The Hacker 6.3.4.1 v00326 2009-05-15 0.65 -
VBA32 3.12.10.5 20090515.1445 2009-05-15 1.86 -
VirusBuster 4.5.11.10 10.105.28/1378347 2009-05-16 1.80 -


I'll be posting the combofix log afterwards. I wanted to get these posted before Combofix reboots the machine.
ComboFix 09-05-16.03 - 05/16/2009 17:40.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.621 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Compaq_Administrator\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

file zipped: C:\adspl.exe
file zipped: C:\krakbqe.exe
file zipped: c:\windows\system32\bbdaaafdbccbaccffafe.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\adspl.exe
C:\krakbqe.exe
C:\lsass.exe
c:\windows\system32\bbdaaafdbccbaccffafe.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_a5f2bf00eb19537bfce81d1c1b77029c
——-\Service_a5f2bf00eb19537bfce81d1c1b77029c


((((((((((((((((((((((((( Files Created from 2009-04-16 to 2009-05-16 )))))))))))))))))))))))))))))))
.

2009-05-16 05:31 . 2009-05-16 05:31 ——– d—–w c:\program files\Trend Micro
2009-05-16 05:07 . 2009-05-16 05:07 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-16 05:07 . 2009-05-16 05:07 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-16 05:07 . 2009-05-16 05:07 ——– d—–w c:\documents and settings\Compaq_Administrator\Application Data\SUPERAntiSpyware.com
2009-05-16 05:07 . 2009-05-16 05:07 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-16 03:13 . 2009-05-16 03:13 ——– d—–w C:\VundoFix Backups
2009-05-16 02:36 . 2009-05-16 02:36 ——– d—–w c:\documents and settings\Compaq_Administrator\Application Data\Malwarebytes
2009-05-16 02:36 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-16 02:35 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-16 02:35 . 2009-05-16 02:35 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-16 02:35 . 2009-05-16 02:36 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-16 01:50 . 2009-05-16 03:37 ——– d—–w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-05-16 01:50 . 2009-05-16 04:13 ——– d—–w c:\program files\Security Task Manager
2009-05-15 12:49 . 2009-05-15 12:49 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\AdobeUM
2009-05-15 12:49 . 2009-05-15 12:49 ——– d—–w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2009-05-14 21:32 . 2009-05-14 21:32 ——– d—–w c:\documents and settings\Compaq_Administrator\Application Data\HPQ
2009-05-14 21:31 . 2009-05-14 21:31 ——– d—–w c:\program files\ASIO4ALL v2
2009-05-14 21:31 . 2009-05-14 21:31 ——– d—–w c:\program files\VstPlugins
2009-05-14 21:31 . 2006-06-20 08:56 225280 —-a-w c:\windows\system32\rewire.dll
2009-05-14 21:30 . 2009-05-14 21:30 ——– d—–w c:\program files\Outsim
2009-05-14 21:28 . 2009-05-14 21:31 ——– d—–w c:\program files\Image-Line
2009-05-14 07:28 . 2009-05-14 07:28 ——– d—–w c:\windows\Sun
2009-05-14 06:32 . 2009-05-14 06:32 ——– d—–w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\Identities
2009-05-14 06:09 . 2009-05-14 06:09 ——– d-s—w c:\windows\system32\config\systemprofile\UserData
2009-05-14 02:04 . 2009-05-16 03:32 ——– d—–w c:\windows\system32\218538
2009-05-14 02:02 . 2009-05-14 02:02 ——– d—–w c:\windows\system32\LogFiles
2009-05-13 19:04 . 2009-05-13 19:04 ——– d—–w c:\program files\MSXML 4.0
2009-05-13 18:53 . 2009-05-14 16:59 ——– d—–w c:\documents and settings\Compaq_Administrator\Application Data\EuroOffice2008
2009-05-13 18:51 . 2009-05-13 18:51 ——– d—–w c:\program files\EuroOffice 2008
2009-05-13 10:28 . 2008-06-13 13:10 272128 ——w c:\windows\system32\dllcache\bthport.sys
2009-05-13 10:28 . 2008-06-13 13:10 272128 ——w c:\windows\system32\drivers\bthport.sys
2009-05-13 10:25 . 2009-02-06 17:22 2136064 ——w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-13 10:25 . 2009-02-06 17:24 2180480 ——w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-13 10:25 . 2009-02-06 16:49 2015744 ——w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-13 10:25 . 2009-02-06 16:49 2057728 ——w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-05-13 10:18 . 2006-03-21 03:23 23040 ——w c:\windows\kb913800.exe
2009-05-13 07:53 . 2009-05-13 07:53 ——– d—–w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\Adobe
2009-05-12 15:45 . 2009-05-12 20:52 ——– d—–w c:\documents and settings\Compaq_Administrator\Application Data\vlc
2009-05-12 15:40 . 2004-08-04 03:08 31616 —-a-w c:\windows\system32\dllcache\usbccgp.sys
2009-05-12 15:40 . 2004-08-04 03:08 31616 —-a-w c:\windows\system32\drivers\usbccgp.sys
2009-05-12 08:17 . 2009-05-12 08:17 ——– d—–w C:\OEMSettings
2009-05-12 08:17 . 2009-05-12 08:17 ——– d—–w c:\program files\NETGEAR
2009-05-12 08:16 . 2009-05-12 08:16 ——– d—–w c:\windows\Downloaded Installations
2009-05-12 08:06 . 2009-05-15 01:24 ——– d—–w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\ApplicationHistory
2009-05-12 08:05 . 2005-11-11 20:51 136 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\fusioncache.dat
2009-05-12 08:05 . 2005-11-11 21:31 45584 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-12 08:05 . 2005-11-11 21:15 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\Digital Interactive Systems Corporation
2009-05-12 08:05 . 2005-11-11 21:28 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\Intuit
2009-05-12 08:05 . 2005-11-11 21:45 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\Symantec
2009-05-12 08:05 . 2005-11-11 21:27 ——– d—–w c:\windows\system32\config\systemprofile\WINDOWS
2009-05-12 08:05 . 2005-11-11 21:32 ——– d—–w c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory
2009-05-12 08:05 . 2005-11-11 21:41 ——– d—–w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Google
2009-05-12 08:05 . 2005-11-11 20:58 ——– d—–w c:\windows\system32\config\systemprofile\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150050}
2009-05-12 08:05 . 2005-11-11 21:27 ——– d—–w c:\documents and settings\Default User\WINDOWS
2009-05-12 08:03 . 2009-05-14 06:04 179 —-a-w c:\windows\system\hpsysdrv.DAT
2009-05-12 08:02 . 2001-08-17 20:48 12160 —-a-w c:\windows\system32\drivers\mouhid.sys
2009-05-12 08:02 . 2001-08-17 21:02 9600 —-a-w c:\windows\system32\drivers\hidusb.sys
2009-05-12 06:49 . 2009-05-16 20:31 ——– d-sh–r c:\windows\system32\dllcache
2009-05-12 06:39 . 2009-05-12 20:31 ——– d—–w c:\program files\BitLord
2009-05-12 06:14 . 2009-05-12 06:14 ——– d—–w c:\program files\VideoLAN
2009-05-12 05:21 . 2004-08-10 10:00 12288 —-a-w c:\windows\system32\dllcache\wb32.exe
2009-05-12 05:20 . 2004-08-10 10:00 61440 —-a-w c:\windows\system32\dllcache\rrcm.dll
2009-05-12 05:19 . 2004-08-10 10:00 188416 —-a-w c:\windows\system32\dllcache\nmwb.dll
2009-05-12 05:19 . 2004-08-10 10:00 172032 —-a-w c:\windows\system32\dllcache\nmoldwb.dll
2009-05-12 05:19 . 2004-08-10 10:00 28672 —-a-w c:\windows\system32\dllcache\nmmkcert.dll
2009-05-12 05:19 . 2004-08-10 10:00 28672 —-a-w c:\windows\system32\nmmkcert.dll
2009-05-12 05:19 . 2004-08-10 10:00 12288 —-a-w c:\windows\system32\dllcache\nmevtmsg.dll
2009-05-12 05:19 . 2004-08-10 10:00 151552 —-a-w c:\windows\system32\dllcache\nmft.dll
2009-05-12 05:19 . 2004-08-10 10:00 12288 —-a-w c:\windows\system32\nmevtmsg.dll
2009-05-12 05:19 . 2004-08-10 10:00 77824 —-a-w c:\windows\system32\dllcache\nmcom.dll
2009-05-12 05:19 . 2004-08-10 10:00 81920 —-a-w c:\windows\system32\dllcache\nmchat.dll
2009-05-12 05:19 . 2004-08-10 10:00 28672 —-a-w c:\windows\system32\dllcache\nmasnt.dll
2009-05-12 05:19 . 2004-08-10 10:00 229376 —-a-w c:\windows\system32\dllcache\nmas.dll
2009-05-12 05:19 . 2004-08-10 10:00 221184 —-a-w c:\windows\system32\dllcache\nac.dll
2009-05-12 05:18 . 2004-08-10 10:00 57344 —-a-w c:\windows\system32\dllcache\mst123.dll
2009-05-12 05:18 . 2004-08-10 10:00 274432 —-a-w c:\windows\system32\dllcache\mst120.dll
2009-05-12 05:18 . 2004-08-10 10:00 188416 —-a-w c:\windows\system32\msh261.drv
2009-05-12 05:18 . 2004-08-10 10:00 69632 —-a-w c:\windows\system32\dllcache\msconf.dll
2009-05-12 05:18 . 2004-08-10 10:00 69632 —-a-w c:\windows\system32\msconf.dll
2009-05-12 05:18 . 2004-08-10 10:00 32768 —-a-w c:\windows\system32\dllcache\mnmsrvc.exe
2009-05-12 05:18 . 2004-08-10 10:00 32768 —-a-w c:\windows\system32\mnmsrvc.exe
2009-05-12 05:18 . 2004-08-10 10:00 34560 —-a-w c:\windows\system32\dllcache\mnmdd.dll
2009-05-12 05:18 . 2004-08-10 10:00 34560 —-a-w c:\windows\system32\mnmdd.dll
2009-05-12 05:16 . 2004-08-10 10:00 32768 —-a-w c:\windows\system32\dllcache\isrdbg32.dll
2009-05-12 05:16 . 2004-08-10 10:00 32768 —-a-w c:\windows\system32\isrdbg32.dll
2009-05-12 05:16 . 2004-08-10 10:00 81920 —-a-w c:\windows\system32\dllcache\ils.dll
2009-05-12 05:16 . 2004-08-10 10:00 81920 —-a-w c:\windows\system32\ils.dll
2009-05-12 05:16 . 2004-08-10 10:00 57344 —-a-w c:\windows\system32\dllcache\h323cc.dll
2009-05-12 05:12 . 2004-08-10 10:00 40960 —-a-w c:\windows\system32\dllcache\dcap32.dll
2009-05-12 05:12 . 2004-08-10 10:00 45056 —-a-w c:\windows\system32\dllcache\confmrsl.dll
2009-05-12 05:12 . 2004-08-10 10:00 1032192 —-a-w c:\windows\system32\dllcache\conf.exe
2009-05-12 05:12 . 2004-08-10 10:00 12288 —-a-w c:\windows\system32\dllcache\cb32.exe
2009-05-12 05:12 . 2004-08-10 10:00 385024 —-a-w c:\windows\system32\dllcache\callcont.dll
2009-05-12 04:27 . 2009-05-12 04:27 0 —-a-w c:\windows\nsreg.dat
2009-05-12 04:27 . 2009-05-12 04:27 ——– d—–w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-16 21:42 . 2005-11-11 21:44 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-16 20:24 . 2004-08-10 12:00 182912 —-a-w c:\windows\system32\drivers\ndis.sys
2009-05-13 19:19 . 2005-11-11 21:15 47560 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-13 04:12 . 2009-05-12 08:06 143 —-a-w c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\fusioncache.dat
2009-05-12 08:08 . 2009-05-12 08:08 1865 –sha-r c:\windows\system32\drivers\103C_HP_CPC_EL445AA-ABA SR1750NX NA650_YC_0Pres_QCNH604_E61NAemRED1_48_IAmberine M_SASUSTek Computer INC._V1.03_B3.13_T051115_WXP2_L409_M959_J200_7AMD_8Athlon 64_92.19_#090512_N10EC8139_Z11C10620_G10025954.MRK
2009-03-06 14:44 . 2004-08-10 12:00 283648 —-a-w c:\windows\system32\pdh.dll
2009-02-20 08:30 . 2004-08-10 12:00 81920 —-a-w c:\windows\system32\ieencode.dll
2009-02-20 08:30 . 2004-08-10 12:00 659456 —-a-w c:\windows\system32\wininet.dll
2006-02-25 21:30 . 2009-05-12 06:59 32 –sha-w c:\windows\SMINST\HPCD.SYS
.

((((((((((((((((((((((((((((( SnapShot@2009-05-16_20.33.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-16 21:41 . 2009-05-16 21:41 60416 c:\windows\temp\Perflib_Perfdata__755.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG311v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG311v3\wlancfg5.exe [2006-1-26 1486848]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"\\"= c:\\WINDOWS\\system\\svchost.exe

R1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/14/2009 2:22 PM 9968]
R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/14/2009 2:22 PM 72944]
S3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/14/2009 2:22 PM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-05-12 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]

2009-05-16 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Compaq_Administrator.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2005-03-24 14:21]

2009-05-15 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-11-11 03:24]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-20048 - C:\krakbqe.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\hvy4nktx.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-16 17:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\MrvGINA.dll
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Norton Internet Security\ISSVC.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\arservice.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\ati2evxx.exe
c:\windows\SoftwareDistribution\Download\2bc0b3c55e0c166e04844934d1c7c342\update\update.exe
.
**************************************************************************
.
Completion time: 2009-05-16 17:46 - machine was rebooted [Compaq_Administrator]
ComboFix-quarantined-files.txt 2009-05-16 21:46
ComboFix2.txt 2009-05-16 20:35

Pre-Run: 163,315,150,848 bytes free
Post-Run: 163,131,469,824 bytes free

240 — E O F — 2009-05-16 21:45

Also, I received the error I mentioned in my first post right as the machine rebooted. This time, though, it was SymWSC that prompted it. It mentioned that a memory address could not be read. The perpetual hourglass is gone now, too. During the running of Combofix, an error message stating that krakbqe.exe had encountered a problem and needed to be shut down. I assume this was due to the script that Combofix was running, but I figured I would let you know regardless.
Hi,

That looks better…

krakbqe.exe was one of the bad files that didn't want to be deleted so was complaining….we have one more stubborn one to delete

please do the following:

Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c del /f/a/s "c:\windows\system32\218538"


NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply please include
  • MBAM Log
  • Kaspersky report

Also, please advise how your computer is running now
Malwarebytes' Anti-Malware 1.36 Database version: 2142 Windows 5.1.2600 Service Pack 2 5/16/2009 6:51:33 PM mbam-log-2009-05-16 (18-51-33).txt Scan type: Quick Scan Objects scanned: 82108 Time elapsed: 1 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 1 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\fe345.fe345mgr (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\fe345.fe345mgr.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\WINDOWS\system32\218538 (Trojan.BHO) -> Quarantined and deleted successfully. Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Saturday, May 16, 2009 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Sunday, May 17, 2009 01:15:05 Records in database: 2186750 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan statistics: Files scanned: 85394 Threat name: 10 Infected objects: 58 Suspicious objects: 0 Duration of the scan: 01:39:27 File name / Threat name / Threats count C:\Documents and Settings\All Users\Application Data\SecTaskMan\krakbqe.exe.q_Quarantine_25000_q Infected: Trojan.Win32.Obfuscated.afqi 1 C:\Documents and Settings\All Users\Application Data\SecTaskMan\lsass.exe.q_Quarantine_25000_q Infected: Trojan.Win32.Obfuscated.afqi 1 C:\Documents and Settings\All Users\Application Data\SecTaskMan\lsass.exe.q_Quarantine_25000_q.old Infected: Trojan.Win32.Obfuscated.afqi 1 C:\Qoobox\Quarantine\C\krakbqe.exe.vir Infected: Trojan.Win32.Obfuscated.afqi 1 C:\Qoobox\Quarantine\C\lsass.exe.vir Infected: Trojan.Win32.Obfuscated.afqi 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ndis.sys.vir Infected: Virus.Win32.Protector.b 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_b6d61891_.sys.zip Infected: Backdoor.Win32.NewRest.z 2 C:\Qoobox\Quarantine\[4]-Submit_2009-05-16_17.40.24.zip Infected: Trojan-PSW.Win32.QQPass.hwt 1 C:\Qoobox\Quarantine\[4]-Submit_2009-05-16_17.40.24.zip Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP0\A0000698.exe Infected: not-a-virus:AdWare.Win32.WeatherBug.a 2 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP11\A0004006.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP12\A0004008.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP12\A0004009.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP12\A0004014.exe Infected: Trojan.Win32.Agent2.hxw 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP12\A0004035.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP13\A0006040.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP13\A0006050.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP13\A0006055.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP13\A0006070.exe Infected: Worm.Win32.Agent.lz 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP13\A0006077.exe Infected: Worm.Win32.Agent.lz 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP13\A0006078.sys Infected: Virus.Win32.Protector.b 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP13\A0006083.sys Infected: Virus.Win32.Protector.b 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP13\A0006167.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP2\A0000859.dll Infected: not-a-virus:AdWare.Win32.Shopper.ar 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP4\A0000978.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP4\A0000981.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP4\A0000983.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP4\A0000985.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP4\A0000992.exe Infected: not-a-virus:AdWare.Win32.Shopper.ar 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0001612.dll Infected: not-a-virus:AdWare.Win32.Shopper.ar 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0001614.exe Infected: not-a-virus:AdWare.Win32.Shopper.ar 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0001615.dll Infected: not-a-virus:AdWare.Win32.Shopper.ar 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0001618.dll Infected: not-a-virus:AdWare.Win32.Shopper.ar 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0001620.dll Infected: not-a-virus:AdWare.Win32.HotBar.ck 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0001622.exe Infected: not-a-virus:AdWare.Win32.Shopper.ar 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0001623.dll Infected: not-a-virus:AdWare.Win32.Shopper.ar 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0001770.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0002767.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0002772.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP5\A0002780.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP6\A0002797.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP6\A0002804.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP6\A0002815.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP6\A0002959.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP6\A0002965.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP6\A0002972.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP6\A0002985.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP6\A0003984.exe Infected: Trojan-Spy.Win32.Zbot.gen 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP7\A0003990.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP7\A0003991.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP7\A0003998.exe Infected: Trojan.Win32.Obfuscated.afqi 1 C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP9\A0004003.exe Infected: Trojan.Win32.Obfuscated.afqi 1 D:\I386\Apps\APP15894\src\CompaqPresario_Spring06.exe Infected: not-a-virus:AdWare.Win32.WeatherBug.a 2 D:\I386\Apps\APP15894\src\HPPavillion_Spring06.exe Infected: not-a-virus:AdWare.Win32.WeatherBug.a 2 The selected area was scanned. Well, for starters, I was actually able to update Malwarebytes this time. When I first installed it, I was unable to do so. I'm guessing it was due to the previous infections. Also, as I mentioned earlier, there wasn't a real significant decrease in performance due to the infections. But, the PC did boot up a lot faster than it has been doing in the past. Not to say it was slow before, but I did notice an increase in booting speed.
Hi,

Everything Kaspersky found is in quarantine or old restore points which we will be cleaning up shortly.

Please do the following:

Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 13)

NEXT


Please run HJT - system scan - save a log file

post a fresh HJT log in your next reply
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:18 PM, on 5/16/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: NETGEAR WG311v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 6825 bytes
Hi,

Good news, your log is clean :thumbup:

now we just have some housekeeping to do,

please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]



NEXT



Below I have included a number of recommendations for how to protect your computer against malware infections.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • For Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI