This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Unable to access internet after spware removal

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I recently made an idiotic mistake and ended up getting infected by a virus/s. I was unable to run malwarebytes, which everyone seems to recommend. I used super Anit-Spyware (recommended on c-net), which found Vundo, Juan and Frmwrk32.exe, that seemed to have taken care of the virus/malware/spyware, but i was having problems with internet access, changing my background, plus the virus turned of my windows task manager. I manually fixed the script for the task manager and then ran advanced system care to helpfix any problems. things seem to be okay except for the internet and the ability to change my background. right now I'm trying to back up files to a separate hard drive as a precaution, but it is taking a long time. I have been trying to run in safe mode, but seem unable to, maybe I'm not fast enough with the F8 key, was hoping that it would make my file transfer quicker?!?

I am worried that i still have a virus on my computer, if anyone can help that would be great.

I ran Hijack this and am adding the report to the end of this message.

Thanks!!!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:50:24 PM, on 5/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Josh\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\SUPERAntiSpyware\ff4a07d6-b1ee-44f7-b8fd-5236810c5ac4.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
c:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Trend Micro\HijackThis\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: (no name) - {025F5B5F-015B-41BE-96F9-DA6613B929E7} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {08791C99-725E-4EA0-9354-B04212BC9882} - (no file)
O2 - BHO: (no name) - {18163159-7CEF-4B92-8051-FCF8FC308C29} - (no file)
O2 - BHO: (no name) - {1FDFABEC-CE88-4DCE-B94C-0DDEDF305AC0} - (no file)
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: (no name) - {29C88E20-4234-41B9-A9DB-982958C95FB1} - (no file)
O2 - BHO: (no name) - {2C1DC75B-812A-4CB2-B84B-A87A89FB2AA9} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {3B2D0A9F-4659-48A4-A491-EC07FCD6415F} - (no file)
O2 - BHO: (no name) - {3C32DFB6-6288-447D-AF39-3205B7F264E6} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {43EB2B5D-052F-4825-8750-9AB5FC05E391} - (no file)
O2 - BHO: (no name) - {44714357-ca06-4419-b933-25267901a38a} - (no file)
O2 - BHO: (no name) - {5140F88A-BD71-436B-800D-D960466098F4} - (no file)
O2 - BHO: {1c4b0165-ea28-2a3a-b344-9e1d50a7b535} - {535b7a05-d1e9-443b-a3a2-82ae5610b4c1} - (no file)
O2 - BHO: (no name) - {57673DDD-E4DE-4531-A11E-83FFB025A412} - (no file)
O2 - BHO: (no name) - {5C9B7F62-0FC6-40DD-BD37-7E5A3A052BDD} - (no file)
O2 - BHO: (no name) - {75B1A646-CDCE-4C06-B52F-84F4463B4FC8} - (no file)
O2 - BHO: (no name) - {777015b3-2bea-4eee-aefe-d54b0f38865b} - (no file)
O2 - BHO: (no name) - {77D7E795-33C5-4323-974D-A2A49AB75517} - (no file)
O2 - BHO: (no name) - {7BFC5EE6-4584-4B31-8298-F0E5D1A2525B} - (no file)
O2 - BHO: (no name) - {84926821-F42C-42D4-8194-35F92AC31B27} - (no file)
O2 - BHO: (no name) - {8DC0E75C-9DCD-4EC5-8825-009FD0F7FD16} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {A2020B97-02FC-4D5D-ABCC-4AB7C86B3514} - (no file)
O2 - BHO: (no name) - {A2C25045-3203-4581-8338-6162B66AA63C} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: (no name) - {C32F42D2-C853-4BA4-B365-4B6B560B0054} - (no file)
O2 - BHO: (no name) - {C448F31C-15E8-4CD4-A878-209180C418B3} - (no file)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: (no name) - {CF9FD21D-869A-4640-A872-E96DABB0E2D0} - (no file)
O2 - BHO: (no name) - {d0cdebd6-276a-4625-91ee-9d8967c71d8a} - (no file)
O2 - BHO: (no name) - {D37B8D81-E874-4D05-B8CD-8C2E88C173C1} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.19.0\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {EEEB5B05-5D94-4965-BB04-261AC0DFAE33} - (no file)
O2 - BHO: (no name) - {F5762C3A-A502-4745-BEA2-A271FC15073E} - (no file)
O2 - BHO: (no name) - {FA567573-3DCC-4E82-8332-7655639B0FD5} - (no file)
O2 - BHO: (no name) - {FE57B3BC-6DF4-4CA4-8277-DEC81516C976} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [YCentral] c:\progra~1\yahoo!\YCentral\YahooCentral.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [16e4c2a6] rundll32.exe "C:\WINDOWS\system32\omlfaasr.dll",b
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Josh\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\ff4a07d6-b1ee-44f7-b8fd-5236810c5ac4.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [AutoVer] C:\Program Files\AutoVer\AutoVer.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Send To &Bluetooth - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.19.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.19.0\gears.dll
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\temp\ntdll64.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://preciseportal.precisionimages.com/ImageUploader4.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {804F9BC5-0EAB-4150-8065-0DF485420670} (InstallShield Setup Player V11.5) - http://www.knoll.com/FSL/KnFSLInstall/setup.exe
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} (CentrinoCheck Control) - http://entriq.vo.llnwd.net/o1/NBCUniversal…eck_1_0_0_5.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} (MediaControl Class) - http://entriq.vo.llnwd.net/o1/NBCUniversal…0_15_Silent.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://l.yimg.com/jh/games/web_games/popca…aploader_v6.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.136,85.255.112.145
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: ljjbuz.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: yayyWoNh - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c8aa41256c2660) (gupdate1c8aa41256c2660) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit (mi-raysat_3dsMax2009_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
O23 - Service: OKI OPHC DCS Loader - Oki Data Corporation - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHCLDCS.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 19656 bytes
Hi,

your machine is still infected, please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


O2 - BHO: (no name) - {025F5B5F-015B-41BE-96F9-DA6613B929E7} - (no file)
O2 - BHO: (no name) - {08791C99-725E-4EA0-9354-B04212BC9882} - (no file)
O2 - BHO: (no name) - {18163159-7CEF-4B92-8051-FCF8FC308C29} - (no file)
O2 - BHO: (no name) - {1FDFABEC-CE88-4DCE-B94C-0DDEDF305AC0} - (no file)
O2 - BHO: (no name) - {29C88E20-4234-41B9-A9DB-982958C95FB1} - (no file)
O2 - BHO: (no name) - {2C1DC75B-812A-4CB2-B84B-A87A89FB2AA9} - (no file)
O2 - BHO: (no name) - {3B2D0A9F-4659-48A4-A491-EC07FCD6415F} - (no file)
O2 - BHO: (no name) - {3C32DFB6-6288-447D-AF39-3205B7F264E6} - (no file)
O2 - BHO: (no name) - {43EB2B5D-052F-4825-8750-9AB5FC05E391} - (no file)
O2 - BHO: (no name) - {44714357-ca06-4419-b933-25267901a38a} - (no file)
O2 - BHO: (no name) - {5140F88A-BD71-436B-800D-D960466098F4} - (no file)
O2 - BHO: {1c4b0165-ea28-2a3a-b344-9e1d50a7b535} - {535b7a05-d1e9-443b-a3a2-82ae5610b4c1} - (no file)
O2 - BHO: (no name) - {57673DDD-E4DE-4531-A11E-83FFB025A412} - (no file)
O2 - BHO: (no name) - {5C9B7F62-0FC6-40DD-BD37-7E5A3A052BDD} - (no file)
O2 - BHO: (no name) - {75B1A646-CDCE-4C06-B52F-84F4463B4FC8} - (no file)
O2 - BHO: (no name) - {777015b3-2bea-4eee-aefe-d54b0f38865b} - (no file)
O2 - BHO: (no name) - {77D7E795-33C5-4323-974D-A2A49AB75517} - (no file)
O2 - BHO: (no name) - {7BFC5EE6-4584-4B31-8298-F0E5D1A2525B} - (no file)
O2 - BHO: (no name) - {84926821-F42C-42D4-8194-35F92AC31B27} - (no file)
O2 - BHO: (no name) - {8DC0E75C-9DCD-4EC5-8825-009FD0F7FD16} - (no file)
O2 - BHO: (no name) - {A2020B97-02FC-4D5D-ABCC-4AB7C86B3514} - (no file)
O2 - BHO: (no name) - {A2C25045-3203-4581-8338-6162B66AA63C} - (no file)
O2 - BHO: (no name) - {C32F42D2-C853-4BA4-B365-4B6B560B0054} - (no file)
O2 - BHO: (no name) - {C448F31C-15E8-4CD4-A878-209180C418B3} - (no file)
O2 - BHO: (no name) - {CF9FD21D-869A-4640-A872-E96DABB0E2D0} - (no file)
O2 - BHO: (no name) - {d0cdebd6-276a-4625-91ee-9d8967c71d8a} - (no file)
O2 - BHO: (no name) - {D37B8D81-E874-4D05-B8CD-8C2E88C173C1} - (no file)
O2 - BHO: (no name) - {EEEB5B05-5D94-4965-BB04-261AC0DFAE33} - (no file)
O2 - BHO: (no name) - {F5762C3A-A502-4745-BEA2-A271FC15073E} - (no file)
O2 - BHO: (no name) - {FA567573-3DCC-4E82-8332-7655639B0FD5} - (no file)
O2 - BHO: (no name) - {FE57B3BC-6DF4-4CA4-8277-DEC81516C976} - (no file)
O4 - HKLM\..\Run: [16e4c2a6] rundll32.exe "C:\WINDOWS\system32\omlfaasr.dll",b
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.136,85.255.112.145
O20 - AppInit_DLLs: ljjbuz.dll
O20 - Winlogon Notify: yayyWoNh - C:\WINDOWS\

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.


NEXT

If you cannot access the internet from this machine still - download the following programs onto a USB stick and transfer over to the infected machine.

First: run this program on all your USB sticks and other removable media so the infection is not transferred from one machine to the other:

Download Flash_Disinfector.exe from HERE and save it to your desktop.

  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.


NEXT


Please download Winsock Fix. to your desktop in case we need it after running this next program LSPFix (NOTE: DONOT run this program unless I advise)


NEXT

Please download LSPFix from here.
  • Run the LSPFix.exe that you have just finished downloading,
  • Check the I know what I'm doing box.
  • In the Keep box you should see one or more instances of ntdll64.dll.
  • Select every instance of ntdll64.dll and move each one to the Remove box by clicking the >> button.
  • When you are done click Finish>>


NEXT

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi!

Everything appears to be running back to normal!
I'm trying out some programs to make sure.

It took a bit of finagling to, hijackthis would only run in safemode andto be renamed HJT, Combofix would only run after I renamed it CFX.

Thanks ever so much!!!

Here is a copy of the ComboFix log:

ComboFix 09-05-26.05 - Josh 05/27/2009 11:26.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1557 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\CFx.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\LocalService\Local Settings\Temporary Internet Files\CPV.stt
C:\install.exe
c:\windows\system32\drivers\gxvxckowbfpmbivkypeoufhqpxxtqscofties.sys
c:\windows\system32\drivers\gxvxcyafmyvxfdwmdgmxksedrnotwueyvbyqn.sys
c:\windows\system32\drivers\kungsflqxwtvwc.sys
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\giwrneei.ini
c:\windows\system32\gxvxcmviswsttdipveijcophcblbucaamxkue.dll
c:\windows\system32\gxvxcypuovkcwamiwqfsfnipydvpithtreeco.dll
c:\windows\system32\kungsfkyvbbkfa.dll
c:\windows\system32\kungsftcifljyd.dat
c:\windows\system32\kungsfwhbagwgl.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\MWxxbcdd.ini
c:\windows\system32\MWxxbcdd.ini2
c:\windows\system32\ntnet.drv
c:\windows\system32\rsaaflmo.ini
c:\windows\system32\uniq.tll
c:\windows\system32\win32hlp.cnf
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
c:\windows\userinit.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SENEKA
——-\Service_GXVXCSERV.SYS
——-\Service_kungsfqstxifse


((((((((((((((((((((((((( Files Created from 2009-04-27 to 2009-05-27 )))))))))))))))))))))))))))))))
.

2009-05-26 22:34 . 2009-05-26 22:34 ——– d—–w c:\program files\ERUNT
2009-05-26 21:47 . 2009-03-09 19:06 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-26 21:12 . 2009-05-26 21:12 ——– d—–w c:\program files\AskBarDis
2009-05-26 21:12 . 2009-05-26 21:16 ——– d—–w c:\program files\Wise Registry Cleaner
2009-05-26 20:57 . 2009-05-27 04:43 ——– d—–w c:\program files\AutoVer
2009-05-26 20:34 . 2009-05-26 20:34 ——– d—–w c:\documents and settings\Josh\Application Data\IObit
2009-05-26 20:34 . 2009-05-26 20:34 ——– d—–w c:\program files\IObit
2009-05-26 18:45 . 2009-04-06 22:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-26 18:45 . 2009-04-06 22:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 18:45 . 2009-05-26 18:45 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-26 18:28 . 2009-05-26 18:28 ——– d—–w c:\program files\Trend Micro
2009-05-26 16:09 . 2009-05-27 18:44 117760 —-a-w c:\documents and settings\Josh\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-26 16:09 . 2009-05-26 16:09 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-26 16:08 . 2009-05-27 05:11 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-26 16:08 . 2009-05-26 16:08 ——– d—–w c:\documents and settings\Josh\Application Data\SUPERAntiSpyware.com
2009-05-26 16:07 . 2009-05-26 16:07 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-26 15:46 . 2009-03-09 19:06 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-26 15:46 . 2009-05-26 15:46 ——– dc-h–w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-26 15:46 . 2009-03-12 08:17 2902048 -c–a-w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-05-26 15:46 . 2009-05-26 15:46 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-26 15:46 . 2009-05-26 15:46 ——– d—–w c:\program files\Lavasoft
2009-05-26 06:40 . 2009-05-26 06:40 ——– d—–w C:\VundoFix Backups
2009-05-26 06:21 . 2009-05-26 06:21 ——– d—–w c:\documents and settings\Josh\Application Data\MalwareRemovalBot
2009-05-26 05:01 . 2009-05-26 19:06 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-26 01:16 . 2009-05-26 01:16 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\AVGTOOLBAR
2009-05-26 01:16 . 2009-05-26 01:16 ——– d—–w c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-05-26 01:16 . 2009-05-26 01:16 ——– d—–w c:\windows\system32\config\systemprofile\Local Settings\Application Data\AIM Toolbar
2009-05-26 00:34 . 2009-05-26 00:34 ——– d—–w c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-05-26 00:33 . 2009-05-26 00:33 ——– d—–w c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-05-26 00:31 . 2009-05-26 00:31 ——– d—–w c:\program files\FreeHDplay
2009-05-21 04:14 . 2009-05-21 04:14 131072 —-a-r c:\documents and settings\Josh\Application Data\Microsoft\Installer\{3254FD51-9910-48C4-AC9B-AF3691C1544C}\NewShortcut3_3254FD51991048C4AC9BAF3691C1544C.exe
2009-05-21 04:14 . 2009-05-21 04:14 131072 —-a-r c:\documents and settings\Josh\Application Data\Microsoft\Installer\{3254FD51-9910-48C4-AC9B-AF3691C1544C}\NewShortcut1_3254FD51991048C4AC9BAF3691C1544C.exe
2009-05-21 04:14 . 2009-05-21 04:14 10134 —-a-r c:\documents and settings\Josh\Application Data\Microsoft\Installer\{3254FD51-9910-48C4-AC9B-AF3691C1544C}\ARPPRODUCTICON.exe
2009-05-21 04:06 . 2009-05-21 04:06 131072 —-a-r c:\documents and settings\Josh\Application Data\Microsoft\Installer\{3A4BEF94-179B-43DC-8380-76EEC6DB5EF4}\NewShortcut3_3A4BEF94179B43DC838076EEC6DB5EF4.exe
2009-05-21 04:06 . 2009-05-21 04:06 131072 —-a-r c:\documents and settings\Josh\Application Data\Microsoft\Installer\{3A4BEF94-179B-43DC-8380-76EEC6DB5EF4}\NewShortcut1_3A4BEF94179B43DC838076EEC6DB5EF4.exe
2009-05-21 04:06 . 2009-05-21 04:06 10134 —-a-r c:\documents and settings\Josh\Application Data\Microsoft\Installer\{3A4BEF94-179B-43DC-8380-76EEC6DB5EF4}\ARPPRODUCTICON.exe
2009-05-21 04:06 . 2009-05-21 04:06 ——– d—–w c:\program files\Neoretix
2009-05-21 03:46 . 2009-05-21 03:46 ——– d—–w c:\program files\WinPcap
2009-05-05 15:36 . 2009-05-05 15:36 186 —-a-w c:\windows\system32\c.bat
2009-05-05 15:36 . 2009-05-05 15:36 45984 —-a-w c:\windows\system32\cardvr.exe
2009-05-05 01:58 . 2007-05-17 00:45 443752 —-a-w c:\windows\system32\d3dx10_34.dll
2009-05-05 01:58 . 2007-05-17 00:45 1124720 —-a-w c:\windows\system32\D3DCompiler_34.dll
2009-05-05 01:58 . 2007-05-17 00:45 3497832 —-a-w c:\windows\system32\d3dx9_34.dll
2009-05-05 01:58 . 2006-11-29 21:06 3426072 —-a-w c:\windows\system32\d3dx9_32.dll
2009-05-05 01:58 . 2006-09-29 00:05 2414360 —-a-w c:\windows\system32\d3dx9_31.dll
2009-05-05 01:50 . 2009-02-10 16:05 952832 —-a-w c:\windows\system32\javac.exe
2009-05-05 01:38 . 2009-05-05 01:39 ——– d—–w c:\program files\MagicISO
2009-05-03 20:44 . 2008-05-30 22:19 507400 —-a-w c:\windows\system32\XAudio2_1.dll
2009-05-03 20:44 . 2008-05-30 22:17 65032 —-a-w c:\windows\system32\XAPOFX1_0.dll
2009-05-03 20:44 . 2008-05-30 22:18 238088 —-a-w c:\windows\system32\xactengine3_1.dll
2009-05-03 20:44 . 2008-05-30 22:17 25608 —-a-w c:\windows\system32\X3DAudio1_4.dll
2009-05-03 20:44 . 2008-05-30 22:11 467984 —-a-w c:\windows\system32\d3dx10_38.dll
2009-05-03 20:44 . 2008-05-30 22:11 1491992 —-a-w c:\windows\system32\D3DCompiler_38.dll
2009-05-03 20:44 . 2008-05-30 22:11 3850760 —-a-w c:\windows\system32\D3DX9_38.dll
2009-05-03 20:44 . 2009-05-03 20:44 ——– d—–w c:\windows\Logs
2009-05-03 16:24 . 2009-05-03 16:24 ——– d—–w c:\documents and settings\Josh\Application Data\iWin
2009-04-30 01:18 . 2009-04-30 01:18 ——– d—–w c:\program files\iTunes
2009-04-30 01:18 . 2009-04-30 01:18 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-30 01:12 . 2009-03-26 23:23 1900544 —-a-w c:\windows\system32\usbaaplrc.dll
2009-04-30 01:01 . 2009-03-06 14:22 284160 ——w c:\windows\system32\dllcache\pdh.dll
2009-04-30 01:01 . 2009-02-09 12:10 401408 ——w c:\windows\system32\dllcache\rpcss.dll
2009-04-30 01:01 . 2009-02-09 12:10 729088 ——w c:\windows\system32\dllcache\lsasrv.dll
2009-04-30 01:01 . 2009-02-09 12:10 473600 ——w c:\windows\system32\dllcache\fastprox.dll
2009-04-30 01:01 . 2009-02-09 12:10 453120 ——w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-30 01:01 . 2009-02-06 11:11 110592 ——w c:\windows\system32\dllcache\services.exe
2009-04-30 01:01 . 2009-02-06 10:10 227840 ——w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-30 01:01 . 2009-02-09 12:10 714752 ——w c:\windows\system32\dllcache\ntdll.dll
2009-04-30 01:01 . 2009-02-09 12:10 617472 ——w c:\windows\system32\dllcache\advapi32.dll
2009-04-30 00:53 . 2009-04-30 00:53 75048 —-a-w c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-29 23:47 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-29 23:47 . 2008-04-21 12:08 215552 ——w c:\windows\system32\dllcache\wordpad.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-26 01:44 . 2009-02-20 06:17 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-05-26 01:29 . 2008-01-03 21:03 ——– d—–w c:\documents and settings\Josh\Application Data\Azureus
2009-05-22 05:17 . 2009-02-20 06:18 ——– d—–w c:\documents and settings\Josh\Application Data\AVGTOOLBAR
2009-05-20 16:30 . 2009-02-20 06:18 11952 —-a-w c:\windows\system32\avgrsstx.dll
2009-05-20 16:30 . 2009-02-20 06:18 325896 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-20 16:30 . 2007-01-15 08:17 27784 —-a-w c:\windows\system32\drivers\avgmfx86.sys
2009-05-20 16:30 . 2009-02-20 06:18 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-05-09 20:27 . 2006-02-04 19:49 ——– d—–w c:\program files\Common Files\Autodesk Shared
2009-05-09 20:22 . 2009-02-09 03:45 ——– d—–w c:\program files\Yahoo! Games
2009-05-08 17:40 . 2006-02-06 08:45 21870 —-a-w c:\documents and settings\Josh\Application Data\wklnhst.dat
2009-05-05 02:07 . 2006-02-04 19:49 ——– d—–w c:\documents and settings\Josh\Application Data\Autodesk
2009-05-05 01:59 . 2006-10-19 03:13 ——– d—–w c:\program files\Autodesk
2009-05-02 09:35 . 2008-01-03 20:54 ——– d—–w c:\program files\Azureus
2009-04-30 01:18 . 2006-02-04 18:39 ——– d—–w c:\program files\iPod
2009-04-30 01:18 . 2007-07-23 23:54 ——– d—–w c:\program files\Common Files\Apple
2009-04-30 01:16 . 2008-07-23 20:35 ——– d—–w c:\program files\Bonjour
2009-04-30 01:16 . 2008-09-13 06:46 ——– d—–w c:\program files\QuickTime
2009-04-24 16:48 . 2007-03-22 19:24 ——– d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2009-04-22 18:59 . 2008-11-06 00:53 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-26 23:23 . 2008-07-23 20:30 36864 —-a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-20 00:32 . 2009-03-20 00:32 23400 —-a-w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-20 00:32 . 2008-01-29 19:01 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-17 20:31 . 2009-03-11 21:55 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-17 20:29 . 2009-03-17 20:29 152576 —-a-w c:\documents and settings\Josh\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-03-14 01:53 . 2009-03-14 01:53 27136 —-a-w c:\windows\system32\drivers\nchssvad.sys
2009-03-11 21:54 . 2009-03-11 21:54 152576 —-a-w c:\documents and settings\Josh\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
2009-03-06 14:22 . 2004-08-04 08:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-04 08:00 826368 —-a-w c:\windows\system32\wininet.dll
2008-04-07 21:15 . 2008-03-25 06:51 1210935 —-a-w c:\program files\.png
2008-04-07 21:14 . 2008-03-25 06:50 122372 —-a-w c:\program files\_tmp.mxs
2008-03-25 13:16 . 2008-03-25 06:52 875611 —-a-w c:\program files\Shoe.mxs
2008-03-25 13:15 . 2008-03-25 07:17 875602 —-a-w c:\program files\Shoe_tmp.mxs
2007-01-29 22:12 . 2006-04-25 03:16 61038 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2007-01-29 22:12 . 2006-04-25 03:16 49256 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-01-29 22:12 . 2006-04-25 03:16 166000 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-12-10 01:40 333192 —-a-w c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-04-03 389120]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\Josh\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-08-31 133104]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\ff4a07d6-b1ee-44f7-b8fd-5236810c5ac4.exe" [2009-04-28 1830128]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-05-01 2329936]
"AutoVer"="c:\program files\AutoVer\AutoVer.exe" [2008-04-30 229376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YCentral"="c:\progra~1\yahoo!\YCentral\YahooCentral.exe" [2005-12-07 409112]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 692316]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"HydraVisionDesktopManager"="c:\program files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-16 270336]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-01 794624]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-10-22 229438]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-09 339968]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-23 620152]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-12 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-12 81920]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-20 1947928]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-23 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-17 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-03 342312]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]

c:\documents and settings\Josh\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-18 4742184]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2008-10-6 295606]
Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-6-2 565309]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-20 16:30 11952 —-a-w c:\windows\system32\avgrsstx.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"aux"= sysaudio.sys

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hp\\HP Photosmart Pro B8300 series\\Toolbox\\HPWVTBX.exe"=
"c:\\Program Files\\Next Limit\\Maxwell\\mxcl.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Google\\Google SketchUp 6\\SketchUp.exe"=
"c:\\Program Files\\Google\\Google SketchUp 6\\LayOut\\LayOut.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Revit Architecture 2009\\Program\\Revit.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2009\\3dsmax.exe"=
"c:\\Documents and Settings\\Josh\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:*:Disabled:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:*:Disabled:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:*:Disabled:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:*:Disabled:Adobe Version Cue CS3 Server

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/26/2009 8:46 AM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/19/2009 11:18 PM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/19/2009 11:18 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2/19/2009 11:17 PM 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2/19/2009 11:17 PM 298776]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 12:06 PM 951632]
R2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [3/10/2008 1:04 AM 65536]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [6/1/2008 12:13 AM 34064]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/31/2008 1:29 PM 24652]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
S0 hbnqrhkg;hbnqrhkg;c:\windows\system32\drivers\giwbwxqs.sys –> c:\windows\system32\drivers\giwbwxqs.sys [?]
S2 gupdate1c8aa41256c2660;Google Update Service (gupdate1c8aa41256c2660);c:\program files\Google\Update\GoogleUpdate.exe [7/11/2008 8:06 PM 133104]
S3 OKI OPHC DCS Loader;OKI OPHC DCS Loader;c:\windows\system32\spool\drivers\w32x86\3\OPHCLDCS.EXE [2/21/2007 1:52 PM 24576]
.
Contents of the 'Scheduled Tasks' folder

2009-05-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]

2009-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:34]

2009-05-27 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-07-12 23:02]

2009-05-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3016158968-4015646977-231257814-1006.job
- c:\documents and settings\Josh\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-13 23:02]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.myspace.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AIM; Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: PimpFish Grab movies on this page
IE: PimpFish Grab pictures on this page
IE: PimpFish Grab pictures this page links to
IE: PimpFish Grab Target File
IE: PimpFish Grab This Picture
IE: Send To &Bluetooth; - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {804F9BC5-0EAB-4150-8065-0DF485420670} - hxxp://www.knoll.com/FSL/KnFSLInstall/setup.exe
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
FF - ProfilePath -

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-27 11:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????6?4?6?9??????? ???B?????????????H
scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3016158968-4015646977-231257814-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|ù•Ôw*]
"91A14B995DF7C0B42ABAA16065968F3A"="c:\\Program Files\\Alias\\Maya7.0\\presets\\Ashli\\"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ôw*]
"91A14B995DF7C0B42ABAA16065968F3A"="c:\\Program Files\\Alias\\Maya7.0\\presets\\Ashli\\"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(752)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3832)
c:\program files\ATI Technologies\ATI HYDRAVISION\HydraDMH.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\snmp.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\ati2evxx.exe
c:\program files\HPQ\Shared\hpqwmi.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Completion time: 2009-05-27 11:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-27 18:54

Pre-Run: 2,902,007,808 bytes free
Post-Run: 2,927,538,176 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

361 — E O F — 2009-05-19 06:05
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Unable_access_internet_after_spware_removal_t103490.html&view=findpost&p=562660#entry562660

KillAll::

Collect::
c:\windows\system32\drivers\giwbwxqs.sys

Driver::
hbnqrhkg

DDS::
uInternet Settings,ProxyOverride = localhost;*.local
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.
Hi, Do you still need help with your machine? If my instructions are unclear or you are experiencing other issues, please advise.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI