This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Rootkit.Wi

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all, I've got a problem here with a rootkit. Have it for about 3 days, first Avast only said I have an unknown malware, but today it said the name. Everytime I delete it, its back after restart, i deleted all the useless stuff with the hijackthis, but still, i cant find it. will post a picture of what avast says and the hijack log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:30:13 PM, on 6/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\FRAPS\FRAPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Poker\Expekt Poker\casino.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\taskmgr.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ParetoLogic Anti-Virus PLUS] "C:\Program

Files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.lnk" -NM -hidesplash
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program

Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA

Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O10 - Unknown file in Winsock LSP:

c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP:

c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP:

c:\windows\system32\inethttpfilter.dll
O10 - Unknown file in Winsock LSP:

c:\windows\system32\inethttpfilter.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL

Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program

Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program

Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program

Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Background Intelligent Transfer Service (BITS) -

Unknown owner - C:\WINDOWS\
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun

Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program

Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA

Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner -

C:\WINDOWS\
O23 - Service: plasservice (zeppelinservice) - ParetoLogic Inc. -

C:\Program Files\Common Files\ParetoLogic\PLAS\plasservice.exe

I see now its inethttpfinder.dll there aswell, dunno whats that yet.

[external image: Posted Image]
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous.
  • Most infections require more than one round to properly eradicate.
  • Absence of symptoms does not always mean the job is complete.
  • You can be certain that I will advise you when the computer is clean.
  • Kindly follow my instructions in the order posted.
  • Please resist the urge to run further scans or fix items on your own without my direction.



Please do the following:

STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



STEP #2


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.


Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.
Hi,
After I posted yesterday I went to safe mode and deleted that sys file by cmd prompt, installed a spybot and scanned everything. Avast stopped announcing the rootkit afterwards. Now my question is if i still have something or not. Today 3hours ago my main page of my website was modified with a chinese iframe, so the rootkit was working. Yesterday I changed all my passwords asap as the rootkit was removed (or at least after it wasnt announced anymore later).I attach the logs now, let me know if i should do a format on my windows partition or not, I dont know what is this rootkit capable of.

DDS

Attach

GMER

Thanks for helping!
Hi,

You have taken precautions by changing your passwords, however if you changed them from this machine I would change them all again from another clean computer. Notify your financial institutions / creditcard companies and any other places of business you deal with that your personal information may have been compromised.

I can clean this machine but cannot guarantee it will be 100% trustworthy, if you decide to reformat please let me know. In the meantime I'll continue to clean.

NOTE:
  • Malware removal is NOT instantaneous.
  • Most infections require more than one round to properly eradicate.
  • Absence of symptoms does not always mean the job is complete.
  • You can be certain that I will advise you when the computer is clean.
  • Kindly follow my instructions in the order posted.
  • Please resist the urge to run further scans or fix items on your own without my direction.

NEXT

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi again,
I did the scan and as the log was done the pc got blue screened and restarted, I did the scan again and here is it.

ComboFix

I just opened and i saw this

S1 4512ae5;4512ae5;c:\windows\system32\drivers\4512ae5.sys –> c:\windows\system32\drivers\4512ae5.sys [?]

this was the original rootkit, the file itself is not in the drivers now, I dont see it at least (not hidden) but 4 new files are made in the system32\drivers.
fidbox.dat
fidbox.idx
fidbox2.dat
fidbox2.idx

what are these?


ComboFix 09-06-10.02 - OZSA 06/11/2009 18:49.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1641 [GMT 3:00]
Running from: d:\firefox dl\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090610-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.

2009-06-11 14:30 . 2009-06-11 14:31 ——– d—–w- c:\windows\Internet Logs
2009-06-11 00:38 . 2009-06-11 00:38 152576 —-a-w- c:\documents and settings\OZSA\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-10 16:14 . 2009-06-10 16:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-06-10 16:14 . 2009-06-10 16:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-10 16:09 . 2009-06-10 16:09 ——– d—–w- c:\documents and settings\OZSA\Local Settings\Application Data\GHISLER
2009-06-10 15:59 . 2009-06-10 16:07 ——– d—–w- c:\program files\Safer Networking
2009-06-10 15:23 . 2009-06-10 15:46 195360 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-10 15:23 . 2009-06-10 15:46 15392 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-10 15:09 . 2009-06-10 15:43 ——– d—–w- c:\program files\Common Files\ParetoLogic
2009-06-10 15:09 . 2009-06-10 15:43 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-06-07 11:44 . 2009-06-07 11:44 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-06-07 11:36 . 2009-06-07 11:36 ——– d—–w- c:\program files\Trend Micro
2009-06-03 18:47 . 2009-06-06 12:15 ——– d—–w- c:\documents and settings\OZSA\Application Data\Microgaming
2009-06-03 18:45 . 2009-06-03 18:45 ——– d—–w- C:\MicroGaming
2009-06-03 18:35 . 2009-01-09 12:22 114688 —-a-w- c:\documents and settings\OZSA\Application Data\Mozilla\Firefox\Profiles\omhjojdq.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npfax.dll
2009-05-26 17:40 . 2009-05-26 17:40 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\NVIDIA Corporation
2009-05-26 17:40 . 2009-05-26 17:40 ——– d—–w- c:\documents and settings\OZSA\Local Settings\Application Data\NVIDIA Corporation
2009-05-26 17:39 . 2009-05-26 17:39 ——– d—–w- c:\program files\NVIDIA Corporation
2009-05-26 17:39 . 2009-05-26 17:39 ——– d—–w- c:\program files\NVIDIA nTune Performance Application
2009-05-24 16:00 . 2009-05-24 16:00 ——– d—–w- C:\Bittorent
2009-05-20 17:15 . 2009-05-20 17:29 ——– d—–w- c:\documents and settings\OZSA\Local Settings\Application Data\FullTiltPoker
2009-05-20 17:14 . 2009-06-07 18:03 ——– d—–w- c:\program files\Full Tilt Poker
2009-05-14 22:01 . 2009-05-14 22:01 73616 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-14 22:00 . 2009-05-14 22:00 ——– d—–w- c:\windows\system32\XPSViewer
2009-05-14 22:00 . 2009-05-14 22:00 ——– d—–w- c:\program files\MSBuild
2009-05-14 22:00 . 2009-05-14 22:00 ——– d—–w- c:\program files\Reference Assemblies
2009-05-14 22:00 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-05-14 22:00 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-05-14 22:00 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-05-14 22:00 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-05-14 22:00 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-05-14 22:00 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-05-14 22:00 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-05-14 21:57 . 2009-05-14 21:57 ——– d—–w- c:\program files\MSXML 6.0

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-11 15:49 . 2009-02-25 17:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-11 15:46 . 2009-02-25 21:04 ——– d—–w- c:\documents and settings\OZSA\Application Data\BitTorrent
2009-06-11 00:39 . 2009-03-27 19:56 ——– d—–w- c:\program files\Java
2009-06-10 15:46 . 2009-06-10 15:23 7868 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-10 15:46 . 2009-06-10 15:23 2492 –sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-10 15:44 . 2009-04-12 14:27 ——– d—–w- c:\program files\PokerStars
2009-06-07 22:51 . 2009-03-01 12:15 ——– d—–w- c:\documents and settings\OZSA\Application Data\Skype
2009-06-07 21:15 . 2009-03-01 11:36 ——– d—–w- c:\program files\Garena
2009-06-07 21:08 . 2009-03-01 12:16 ——– d—–w- c:\documents and settings\OZSA\Application Data\skypePM
2009-05-30 08:14 . 2009-03-08 22:27 ——– d—–w- c:\program files\Windows Live Safety Center
2009-05-27 09:56 . 2009-02-25 21:04 ——– d—–w- c:\documents and settings\OZSA\Application Data\uTorrent
2009-05-27 09:24 . 2009-03-15 21:48 ——– d—–w- c:\program files\DC++
2009-05-26 17:45 . 2009-04-25 13:12 ——– d—–w- c:\program files\Pando Networks
2009-05-26 17:44 . 2009-02-25 17:06 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-26 17:39 . 2009-02-25 17:06 ——– d—–w- c:\program files\Common Files\InstallShield
2009-05-26 17:27 . 2009-02-25 16:35 17216 —-a-w- c:\documents and settings\OZSA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-21 08:33 . 2009-03-01 11:59 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-20 21:37 . 2009-04-14 17:24 ——– d—–w- c:\program files\Xvid
2009-05-20 18:40 . 2009-02-28 23:14 ——– d—–w- c:\program files\PartyGaming
2009-05-08 17:15 . 2009-05-07 15:04 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-05-08 15:35 . 2009-05-08 15:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Insight Software Solutions
2009-05-08 15:35 . 2009-05-08 15:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Insight Software
2009-05-07 15:06 . 2009-05-07 15:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2009-04-30 15:03 . 2009-04-30 14:58 ——– d—–w- c:\program files\ICQ6.5
2009-04-30 15:03 . 2009-04-30 14:59 ——– d—–w- c:\documents and settings\OZSA\Application Data\ICQ
2009-04-25 17:22 . 2009-04-25 17:22 ——– d—–w- c:\program files\Subagames
2009-04-25 10:59 . 2009-04-25 10:18 ——– d—–w- c:\program files\CyberLink
2009-04-25 10:40 . 2009-04-25 10:21 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink
2009-04-25 10:40 . 2009-04-25 10:19 ——– d—–w- c:\documents and settings\OZSA\Application Data\CyberLink
2009-04-25 10:39 . 2009-04-25 10:20 29480 —-a-w- c:\windows\system32\msxml3a.dll
2009-04-14 17:13 . 2009-04-14 17:13 ——– d—–w- c:\program files\AC3Filter
2009-04-13 12:08 . 2009-02-25 20:15 ——– d—–w- c:\program files\Winamp
2009-03-30 17:48 . 2009-03-30 17:48 34 —ha-w- c:\windows\system32\VideoConverter_sysquict.dat
2009-03-27 19:56 . 2009-03-27 19:56 152576 —-a-w- c:\documents and settings\OZSA\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-26 20:46 . 2009-03-26 20:46 10368 —-a-w- c:\windows\system32\drivers\pfc.sys
2004-03-11 10:27 . 2009-04-25 10:18 40960 —-a-w- c:\program files\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-06-11_15.45.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-11 15:48 . 2009-06-11 15:48 16384 c:\windows\Temp\Perflib_Perfdata_5a8.dat
+ 2009-06-11 15:48 . 2009-06-11 15:48 16384 c:\windows\Temp\Perflib_Perfdata_570.dat
+ 2009-06-11 15:48 . 2009-06-11 15:48 16384 c:\windows\Temp\Perflib_Perfdata_4e4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 4662776]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Fraps"="c:\fraps\FRAPS.EXE" [2008-01-14 3182248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-06-13 16871936]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-06-28 1626112]

[HKLM\~\startupfolder\c:^documents and settings^ozsa^start menu^programs^startup^rncsys32.exe]
path=c:\documents and settings\OZSA\Start Menu\Programs\Startup\rncsys32.exe
backup=c:\windows\pss\rncsys32.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"d:\\firefox dl\\utorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2/25/2009 8:23 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/25/2009 8:23 PM 20560]
S1 4512ae5;4512ae5;c:\windows\system32\drivers\4512ae5.sys –> c:\windows\system32\drivers\4512ae5.sys [?]
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-11 18:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(384)
c:\windows\system32\msi.dll
.
Completion time: 2009-06-11 18:53
ComboFix-quarantined-files.txt 2009-06-11 15:53
ComboFix2.txt 2009-06-11 15:47

Pre-Run: 4,926,246,912 bytes free
Post-Run: 4,917,518,336 bytes free

156
Hi,

P2P - I see you have P2P software BitTorrent and utorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


NEXT

The fidbox items are generally related to Av scanners but we need to analyze them to make sure they are not infected,

please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
    • c:\windows\system32\drivers\fidbox.dat
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Please follow the same procedure for the following files:

c:\windows\system32\drivers\fidbox2.dat
c:\windows\system32\drivers\fidbox.idx
c:\windows\system32\drivers\fidbox2.idx



NEXT

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::

File::
c:\windows\system32\drivers\4512ae5.sys 
c:\documents and settings\OZSA\Start Menu\Programs\Startup\rncsys32.exe
c:\windows\pss\rncsys32.exeStartup

Driver::
4512ae5

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
In the meanwhile im scanning the files, yet nothing in them. About this: KillAll:: File:: c:\windows\system32\drivers\4512ae5.sys c:\documents and settings\OZSA\Start Menu\Programs\Startup\rncsys32.exe c:\windows\pss\rncsys32.exeStartup Driver:: 4512ae5 The .sys file i deleted previously it doesnt exist, the rncsys32.exe however still appears i deleted from startup, msconfig, regedit, all where i found, and i dont know if its still existing. Did you see anything in the logs beside this? gonna do this as the scan finnished.

The .sys file i deleted previously it doesnt exist, the rncsys32.exe however still appears i deleted from startup, msconfig, regedit, all where i found, and i dont know if its still existing. Did you see anything in the logs beside this? gonna do this as the scan finnished


Have you been fixing items / deleting files / editing the registry all the while I have been offering my assistance?

By doing so, you have changed the stability on which I created this customized fix for you.

ComboFix is a complex tool and requires a thoroughly trained helper to utilize it effectively.

Please do nothing further unless instructed by myself.

If you do not want my assistance and would prefer to continue deleting and editing the registry, please advise, I will close this thread and help another.

After that I didnt changed any


Thank-you, I appreciate that…

can you please copy/paste that log into the thread rather than attach it - for some reason i can't read it

also do you have the logs from Virscan to post yet?



Thanks

CB
Virscan showed no infection in any of those 4 files.



ComboFix 09-06-10.02 - OZSA 06/11/2009 19:53.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1467 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\OZSA\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090610-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

FILE ::
"c:\documents and settings\OZSA\Start Menu\Programs\Startup\rncsys32.exe"
"c:\windows\pss\rncsys32.exeStartup"
"c:\windows\system32\drivers\4512ae5.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_4512ae5


((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.

2009-06-11 14:30 . 2009-06-11 14:31 ——– d—–w- c:\windows\Internet Logs
2009-06-11 00:38 . 2009-06-11 00:38 152576 —-a-w- c:\documents and settings\OZSA\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-10 16:14 . 2009-06-10 16:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-06-10 16:14 . 2009-06-10 16:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-10 16:09 . 2009-06-10 16:09 ——– d—–w- c:\documents and settings\OZSA\Local Settings\Application Data\GHISLER
2009-06-10 15:59 . 2009-06-10 16:07 ——– d—–w- c:\program files\Safer Networking
2009-06-10 15:23 . 2009-06-10 15:46 195360 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-10 15:23 . 2009-06-10 15:46 15392 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-10 15:09 . 2009-06-10 15:43 ——– d—–w- c:\program files\Common Files\ParetoLogic
2009-06-10 15:09 . 2009-06-10 15:43 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-06-07 11:44 . 2009-06-07 11:44 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-06-07 11:36 . 2009-06-07 11:36 ——– d—–w- c:\program files\Trend Micro
2009-06-03 18:47 . 2009-06-06 12:15 ——– d—–w- c:\documents and settings\OZSA\Application Data\Microgaming
2009-06-03 18:45 . 2009-06-03 18:45 ——– d—–w- C:\MicroGaming
2009-06-03 18:35 . 2009-01-09 12:22 114688 —-a-w- c:\documents and settings\OZSA\Application Data\Mozilla\Firefox\Profiles\omhjojdq.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npfax.dll
2009-05-26 17:40 . 2009-05-26 17:40 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\NVIDIA Corporation
2009-05-26 17:40 . 2009-05-26 17:40 ——– d—–w- c:\documents and settings\OZSA\Local Settings\Application Data\NVIDIA Corporation
2009-05-26 17:39 . 2009-05-26 17:39 ——– d—–w- c:\program files\NVIDIA Corporation
2009-05-26 17:39 . 2009-05-26 17:39 ——– d—–w- c:\program files\NVIDIA nTune Performance Application
2009-05-24 16:00 . 2009-05-24 16:00 ——– d—–w- C:\Bittorent
2009-05-20 17:15 . 2009-05-20 17:29 ——– d—–w- c:\documents and settings\OZSA\Local Settings\Application Data\FullTiltPoker
2009-05-20 17:14 . 2009-06-07 18:03 ——– d—–w- c:\program files\Full Tilt Poker
2009-05-14 22:01 . 2009-05-14 22:01 73616 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-14 22:00 . 2009-05-14 22:00 ——– d—–w- c:\windows\system32\XPSViewer
2009-05-14 22:00 . 2009-05-14 22:00 ——– d—–w- c:\program files\MSBuild
2009-05-14 22:00 . 2009-05-14 22:00 ——– d—–w- c:\program files\Reference Assemblies
2009-05-14 22:00 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-05-14 22:00 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-05-14 22:00 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-05-14 22:00 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-05-14 22:00 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-05-14 22:00 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-05-14 22:00 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-05-14 21:57 . 2009-05-14 21:57 ——– d—–w- c:\program files\MSXML 6.0

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-11 16:56 . 2009-02-25 17:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-11 15:46 . 2009-02-25 21:04 ——– d—–w- c:\documents and settings\OZSA\Application Data\BitTorrent
2009-06-11 00:39 . 2009-03-27 19:56 ——– d—–w- c:\program files\Java
2009-06-10 15:46 . 2009-06-10 15:23 7868 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-10 15:46 . 2009-06-10 15:23 2492 –sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-10 15:44 . 2009-04-12 14:27 ——– d—–w- c:\program files\PokerStars
2009-06-07 22:51 . 2009-03-01 12:15 ——– d—–w- c:\documents and settings\OZSA\Application Data\Skype
2009-06-07 21:15 . 2009-03-01 11:36 ——– d—–w- c:\program files\Garena
2009-06-07 21:08 . 2009-03-01 12:16 ——– d—–w- c:\documents and settings\OZSA\Application Data\skypePM
2009-05-30 08:14 . 2009-03-08 22:27 ——– d—–w- c:\program files\Windows Live Safety Center
2009-05-27 09:56 . 2009-02-25 21:04 ——– d—–w- c:\documents and settings\OZSA\Application Data\uTorrent
2009-05-27 09:24 . 2009-03-15 21:48 ——– d—–w- c:\program files\DC++
2009-05-26 17:45 . 2009-04-25 13:12 ——– d—–w- c:\program files\Pando Networks
2009-05-26 17:44 . 2009-02-25 17:06 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-26 17:39 . 2009-02-25 17:06 ——– d—–w- c:\program files\Common Files\InstallShield
2009-05-26 17:27 . 2009-02-25 16:35 17216 —-a-w- c:\documents and settings\OZSA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-21 08:33 . 2009-03-01 11:59 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-20 21:37 . 2009-04-14 17:24 ——– d—–w- c:\program files\Xvid
2009-05-20 18:40 . 2009-02-28 23:14 ——– d—–w- c:\program files\PartyGaming
2009-05-08 17:15 . 2009-05-07 15:04 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-05-08 15:35 . 2009-05-08 15:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Insight Software Solutions
2009-05-08 15:35 . 2009-05-08 15:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Insight Software
2009-05-07 15:06 . 2009-05-07 15:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2009-04-30 15:03 . 2009-04-30 14:58 ——– d—–w- c:\program files\ICQ6.5
2009-04-30 15:03 . 2009-04-30 14:59 ——– d—–w- c:\documents and settings\OZSA\Application Data\ICQ
2009-04-25 17:22 . 2009-04-25 17:22 ——– d—–w- c:\program files\Subagames
2009-04-25 10:59 . 2009-04-25 10:18 ——– d—–w- c:\program files\CyberLink
2009-04-25 10:40 . 2009-04-25 10:21 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink
2009-04-25 10:40 . 2009-04-25 10:19 ——– d—–w- c:\documents and settings\OZSA\Application Data\CyberLink
2009-04-25 10:39 . 2009-04-25 10:20 29480 —-a-w- c:\windows\system32\msxml3a.dll
2009-04-14 17:13 . 2009-04-14 17:13 ——– d—–w- c:\program files\AC3Filter
2009-04-13 12:08 . 2009-02-25 20:15 ——– d—–w- c:\program files\Winamp
2009-03-30 17:48 . 2009-03-30 17:48 34 —ha-w- c:\windows\system32\VideoConverter_sysquict.dat
2009-03-27 19:56 . 2009-03-27 19:56 152576 —-a-w- c:\documents and settings\OZSA\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-26 20:46 . 2009-03-26 20:46 10368 —-a-w- c:\windows\system32\drivers\pfc.sys
2004-03-11 10:27 . 2009-04-25 10:18 40960 —-a-w- c:\program files\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-06-11_15.45.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-11 15:48 . 2009-06-11 15:48 16384 c:\windows\Temp\Perflib_Perfdata_5a8.dat
+ 2009-06-11 16:55 . 2009-06-11 16:55 16384 c:\windows\Temp\Perflib_Perfdata_59c.dat
+ 2009-06-11 16:56 . 2009-06-11 16:56 16384 c:\windows\Temp\Perflib_Perfdata_3d0.dat
+ 2004-08-04 01:07 . 2009-06-11 15:52 67516 c:\windows\system32\perfc009.dat
- 2004-08-04 01:07 . 2009-06-11 14:01 67516 c:\windows\system32\perfc009.dat
+ 2004-08-04 01:07 . 2009-06-11 15:52 432686 c:\windows\system32\perfh009.dat
- 2004-08-04 01:07 . 2009-06-11 14:01 432686 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 4662776]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Fraps"="c:\fraps\FRAPS.EXE" [2008-01-14 3182248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-06-13 16871936]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-06-28 1626112]

[HKLM\~\startupfolder\c:^documents and settings^ozsa^start menu^programs^startup^rncsys32.exe]
path=c:\documents and settings\OZSA\Start Menu\Programs\Startup\rncsys32.exe
backup=c:\windows\pss\rncsys32.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"d:\\firefox dl\\utorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2/25/2009 8:23 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/25/2009 8:23 PM 20560]
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-11 19:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1848)
c:\windows\system32\msi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-11 19:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-11 16:59
ComboFix2.txt 2009-06-11 15:53
ComboFix3.txt 2009-06-11 15:47

Pre-Run: 4,918,304,768 bytes free
Post-Run: 4,889,604,096 bytes free

186
Hi,

Virscan showed no infection in any of those 4 files

:thumbup:

Please do the following:

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean


NEXT


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.


NEXT

It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course:

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
You can refer to this animation by sundavis.
PC is just getting slower and slower, the malware scan found nothing, and I couldnt wait kaspersky, I gonna do a format and will check this thread as I'm done. I'm using avast + spybot, first will put avast then will check this thread, if u have any suggestions what other security I should use please let me know, and thanks for all ur help.
Hi,

The reason it was slow was because I used TFC to clean out all your temp files etc. It is always slow the first couple of reboots, then it gets back to speed, but if you wish to reformat that is up to you.

I know the Kaspersky scan takes a long time, but it is worth it and it is thorough, but it is your choice.

I can give you my usual recommendations for you to choose from:

I also recommend using a third party firewall to protect your computer from hackers.
We don't recommend the firewall that comes built in to Windows.
It doesn't block everything that may try to get in, and the entire firewall is written to the registry.
As various kinds of malware hack the Registry in order to disable the Windows firewall, it's far preferable to install one of the excellent third party solutions.

Three excellent free firewalls are:

Comodo
Sunbelt Kerio
Sygate
NOTE: DO NOT install more than one firewall.

Note: If you choose Comodo - Please be careful with the installation of the Comodo program, it comes bundled with an adware toolbar which you need to de-select when you are going through the installation process. It's not a malicious program, but it may be a privacy risk and I don't think you want it on your system.


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Thanks for the advices, I gonna try out a firewall, Im just stuck with this PC tbh..its going slower and slower everytime, and its a miracle for me how slow can it be with 2gig ram, 3ghz cpu, 80gb sata hdd…i got this pc for free but still, even after format its just like …anyway, thanks for all the help. All the bests

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI