This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] TrojanDownloader:Win32/Renos.IO

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:07:47 PM, on 6/16/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\msa.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\COGECO Security Services\Common\FSM32.EXE
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\COGECO Security Services\FSGUI\fsguidll.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\Owner\AppData\Local\Temp\3948.tmp
C:\Windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\Windows\system32\msxml71.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\COGECO Security Services\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\COGECO Security Services\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Cognac] C:\Users\Owner\AppData\Local\Temp\3948.tmp.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Internet Explorer.lnk = C:\Program Files\Internet Explorer\iexplore.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://www.cogeco.ca/en/OLS3.3/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E81093DA-D069-42BA-8CAA-77A5CFAD6B21}: NameServer = 4.2.2.1,4.2.2.2
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\COGECO Security Services\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\COGECO Security Services\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\COGECO Security Services\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\COGECO Security Services\Common\FSMA32.EXE
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 8340 bytes
Hi and :welcome:


NOTE:
  • Malware removal is NOT instantaneous.
  • Most infections require more than one round to properly eradicate.
  • Absence of symptoms does not always mean the job is complete.
  • You can be certain that I will advise you when the computer is clean.
  • Kindly follow my instructions in the order posted.
  • Please resist the urge to run further scans or fix items on your own without my direction.

NEXT

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.


NEXT

Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
Here are first two reports…….more to follow. DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 12:57:28.01 on Tue 06/16/2009 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_13 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2037.958 [GMT -4:00] AV: COGECO Security Services 7.03 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A- 382D3F313F15} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: COGECO Security Services 7.03 *disabled* (Updated) {0651C4B0-1D7E-4682-B965-2E9523C483A5} FW: COGECO Security Services 7.03 *disabled* {D4747503-0346-49EB-9262-997542F79BF4} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\msa.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\COGECO Security Services\Anti-Virus\fsgk32st.exe C:\Program Files\COGECO Security Services\Common\FSMA32.EXE C:\Program Files\COGECO Security Services\Anti-Virus\FSGK32.EXE C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\WINDOWS\System32\igfxtray.exe C:\WINDOWS\System32\igfxpers.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe C:\Program Files\COGECO Security Services\Anti-Virus\fssm32.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Windows\system32\NOTEPAD.EXE C:\WINDOWS\System32\mstsc.exe C:\Users\Owner\AppData\Local\Temp\3948.tmp C:\Windows\system32\ctfmon.exe C:\Windows\explorer.exe C:\Program Files\COGECO Security Services\Common\FSLAUNCH.EXE C:\Users\Owner\Downloads\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=71&bd=Pavilion&pf=laptop uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: XML Class: {500bca15-57a7-4eaf-8143-8c619470b13d} - c:\windows\system32\msxml71.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6 \bin\jp2ssv.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Cognac] c:\users\owner\appdata\local\temp\3948.tmp.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [F-Secure Manager] "c:\program files\cogeco security services\common\FSM32.EXE" /splash mRun: [F-Secure TNB] "c:\program files\cogeco security services\fsgui\TNBUtil.exe" /CHECKALL /WAITFORSW mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\intern~1.lnk - c:\program files\internet explorer\iexplore.exe StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3 \office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3 \office12\REFIEBAR.DLL LSP: c:\program files\cogeco security services\fsps\program\FSLSP.DLL DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c- b89f-c1c34c691085/LegitCheckControl.cab DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://www.cogeco.ca/en/OLS3.3/fscax.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab TCP: {E81093DA-D069-42BA-8CAA-77A5CFAD6B21} = 4.2.2.1,4.2.2.2 Notify: igfxcui - igfxdev.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\hbhwwtye.default\ ============= SERVICES / DRIVERS =============== R1 F-Secure HIPS;F-Secure HIPS;c:\program files\cogeco security services\hips\fshs.sys [2008-10-24 41184] R1 FSES;F-Secure Email Scanning Driver;c:\windows\system32\drivers\fses.sys [2008-10-24 34752] R1 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2008-10-24 60064] R1 fsvista;F-Secure Vista Support Driver;c:\program files\cogeco security services\anti- virus\minifilter\fsvista.sys [2008-10-24 12896] R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\cogeco security services\anti- virus\minifilter\fsgk.sys [2008-10-24 77824] S3 Ph3xIB32;Philips 713x Inbox PCI TV Card;c:\windows\system32\drivers\Ph3xIB32.sys [2006-11-2 1083520] S4 F-Secure Filter;F-Secure File System Filter;c:\program files\cogeco security services\anti- virus\win2k\fsfilter.sys [2008-10-24 39776] S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\cogeco security services\anti- virus\win2k\fsrec.sys [2008-10-24 25184] =============== Created Last 30 ================ 2009-06-16 12:05 –d—– c:\program files\Trend Micro 2009-06-14 12:11 428,544 a——- c:\windows\system32\EncDec.dll 2009-06-14 12:11 293,376 a——- c:\windows\system32\psisdecd.dll 2009-06-14 12:11 217,088 a——- c:\windows\system32\psisrndr.ax 2009-06-14 12:11 177,664 a——- c:\windows\system32\mpg2splt.ax 2009-06-14 12:11 80,896 a——- c:\windows\system32\MSNP.ax 2009-06-11 17:46 112,644 a——- c:\windows\msa.exe 2009-06-11 17:45 206,340 a——- c:\windows\system32\msxml71.0ll 2009-06-11 14:43 2,033,152 a——- c:\windows\system32\win32k.sys 2009-06-11 14:43 636,928 a——- c:\windows\system32\localspl.dll 2009-06-11 14:43 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-05-18 11:14 –d—– c:\users\owner\appdata\roaming\Kodak 2009-05-18 10:42 –d—– c:\program files\Kodak ==================== Find3M ==================== 2009-04-24 12:05 827,904 a——- c:\windows\system32\wininet.dll 2009-04-24 12:02 78,336 a——- c:\windows\system32\ieencode.dll 2009-04-24 09:44 26,624 a——- c:\windows\system32\ieUnatt.exe 2009-03-31 15:35 17,160 a——- c:\windows\help\oem\scripts\HC_TotalCareAdvisorUpdate.exe 2009-03-30 17:30 17,160 a——- c:\windows\help\oem\scripts\HC_DanzkaDubraBIOSUpdate.exe 2009-03-15 22:55 98 a——- c:\users\owner\appdata\roaming\wklnhst.dat 2008-11-19 21:40 51,200 a——- c:\windows\inf\infpub.dat 2008-11-19 21:40 143,360 a——- c:\windows\inf\infstrng.dat 2008-11-19 21:40 86,016 a——- c:\windows\inf\infstor.dat 2008-11-16 22:03 174 a–sh— c:\program files\desktop.ini 2008-11-16 21:30 665,600 a——- c:\windows\inf\drvindex.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 12:57:53.50 ===============

Attachments:

Hi,

no GMER may not have run correctly, but lets do the following:

Download Combofix from any of the links below, and save it to your desktop.

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 09-06-15.07 - Owner 06/16/2009 15:45.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2037.1036 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: COGECO Security Services 7.03 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: COGECO Security Services 7.03 *disabled* {D4747503-0346-49EB-9262-997542F79BF4}
SP: COGECO Security Services 7.03 *disabled* (Updated) {0651C4B0-1D7E-4682-B965-2E9523C483A5}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\msa.exe
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
c:\windows\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job
D:\Desktop.ini

.
((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.

2009-06-16 19:49 . 2009-06-16 19:49 ——– d—–w- c:\users\Mikey on the HP\AppData\Local\temp
2009-06-16 16:05 . 2009-06-16 16:05 ——– d—–w- c:\program files\Trend Micro
2009-06-14 16:11 . 2009-04-30 12:37 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-06-14 16:11 . 2009-04-30 12:37 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-11 18:43 . 2009-04-21 11:55 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-06-11 18:43 . 2009-04-23 12:42 636928 —-a-w- c:\windows\system32\localspl.dll
2009-06-11 18:43 . 2009-04-23 12:43 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-06-08 17:24 . 2009-06-08 17:24 758088 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-05-18 15:14 . 2009-05-18 15:14 ——– d—–w- c:\users\Owner\AppData\Roaming\Kodak
2009-05-18 14:42 . 2009-05-18 14:42 ——– d—–w- c:\program files\Kodak
2009-05-18 14:41 . 2009-05-18 14:41 ——– d—–w- c:\users\Owner\AppData\Local\Downloaded Installations

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 15:03 . 2006-12-21 10:59 12 —-a-w- c:\windows\bthservsdp.dat
2009-06-16 12:42 . 2008-10-25 00:35 ——– d—–w- c:\users\Owner\AppData\Roaming\F-Secure
2009-06-12 07:13 . 2006-12-21 11:44 ——– d—–w- c:\programdata\Microsoft Help
2009-06-12 07:11 . 2006-12-21 11:42 ——– d—–w- c:\program files\Microsoft Works
2009-05-17 04:27 . 2009-05-17 04:27 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-14 07:01 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-14 02:57 . 2008-01-14 01:09 5216 —-a-w- c:\users\Owner\AppData\Local\d3d9caps.dat
2009-04-28 13:12 . 2009-04-25 02:26 ——– d—–w- c:\users\Owner\AppData\Roaming\uTorrent
2009-04-25 02:26 . 2009-04-25 02:26 ——– d—–w- c:\program files\uTorrent
2009-04-24 16:05 . 2009-06-11 18:42 827904 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-11 18:42 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 15:05 . 2006-12-21 12:17 ——– d—–w- c:\program files\Java
2009-04-24 13:44 . 2009-06-11 18:42 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-20 15:48 . 2007-06-24 01:39 93504 —-a-w- c:\users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
2009-03-31 19:35 . 2009-04-30 07:44 17160 —-a-w- c:\windows\Help\OEM\scripts\HC_TotalCareAdvisorUpdate.exe
2009-03-30 21:30 . 2009-04-30 07:44 17160 —-a-w- c:\windows\Help\OEM\scripts\HC_DanzkaDubraBIOSUpdate.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"F-Secure Manager"="c:\program files\COGECO Security Services\Common\FSM32.EXE" [2008-04-23 182936]
"F-Secure TNB"="c:\program files\COGECO Security Services\FSGUI\TNBUtil.exe" [2008-04-23 744032]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-19 468264]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Internet Explorer.lnk - c:\program files\Internet Explorer\iexplore.exe [2009-6-11 634632]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\I:\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1D37A095-5BC4-4948-9821-AC5A1AF70623}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C3235F8E-4CB7-430C-B86C-B7153BD61B6A}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{07845E6D-817F-43A7-9E2B-800D005710EE}"= UDP:c:\program files\HP\QuickPlay\QP.exe:_this_program_will_be_deleted
"{9AC0928A-9CBD-4955-89D9-CE9B204268FF}"= c:\program files\HP Connections\6811507\Program\HP Connections:HP Connections
"{BA13B216-8B8C-4827-ACF4-CF9985AA24F1}"= UDP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{28D87C2C-A5EA-47F3-9E07-0F4BFAD08556}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{F6B1F63D-4DF1-465A-BB5D-B0A3CEC78C16}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{ED4E431E-6A8D-4A4B-B692-5891DE681E1C}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{9E29DCE5-7F1F-47CA-A6FB-163F31280255}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{CFE271F4-FE2C-4ADD-8428-3B501F6B1FEC}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{25995568-7F0B-45FC-928D-088ECBCBABFC}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{9CDC5396-E7FD-41CC-B266-31D666301C23}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{8936A7B0-74B3-40F6-B61C-52A4D4983141}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{180F7BD2-896A-4C80-BC28-5E4CC4BDA0BF}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{8A41AF3B-5369-4D37-9349-43E334A2FEB4}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

R1 F-Secure HIPS;F-Secure HIPS;c:\program files\COGECO Security Services\HIPS\fshs.sys [10/24/2008 3:49 PM 41184]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [10/24/2008 3:51 PM 34752]
R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [10/24/2008 3:51 PM 60064]
R1 fsvista;F-Secure Vista Support Driver;c:\program files\COGECO Security Services\Anti-Virus\minifilter\fsvista.sys [10/24/2008 3:48 PM 12896]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\COGECO Security Services\Anti-Virus\minifilter\fsgk.sys [10/24/2008 3:48 PM 77824]
S3 Ph3xIB32;Philips 713x Inbox PCI TV Card;c:\windows\System32\drivers\Ph3xIB32.sys [11/2/2006 6:32 AM 1083520]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\COGECO Security Services\Anti-Virus\win2k\fsfilter.sys [10/24/2008 3:48 PM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\COGECO Security Services\Anti-Virus\win2k\fsrec.sys [10/24/2008 3:48 PM 25184]

— Other Services/Drivers In Memory —

*NewlyCreated* - AUJASNKJ
*Deregistered* - aujasnkj

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder

2009-06-16 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\COGECO~1\ANTI-V~1\fsav.exe [2008-10-24 16:11]

2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{34B4D8E1-B155-4A34-A881-795008D90209}.job
- c:\windows\system32\msfeedssync.exe [2008-09-23 07:33]

2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{CBA25D9F-4E28-4978-8E95-A9A0CA7A217D}.job
- c:\windows\system32\msfeedssync.exe [2008-09-23 07:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: c:\program files\COGECO Security Services\FSPS\program\FSLSP.DLL
TCP: {E81093DA-D069-42BA-8CAA-77A5CFAD6B21} = 4.2.2.1,4.2.2.2
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\hbhwwtye.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 15:50
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\users\Owner\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(744)
c:\program files\COGECO Security Services\FWES\Program\fsdc.dll

- - - - - - - > 'lsass.exe'(684)
c:\program files\COGECO Security Services\FWES\Program\fsdc.dll

- - - - - - - > 'csrss.exe'(584)
c:\program files\COGECO Security Services\FWES\Program\fsdc.dll

- - - - - - - > 'csrss.exe'(640)
c:\program files\COGECO Security Services\FWES\Program\fsdc.dll
.
Completion time: 2009-06-16 15:51
ComboFix-quarantined-files.txt 2009-06-16 19:51

Pre-Run: 66,971,181,056 bytes free
Post-Run: 67,868,868,608 bytes free

169 — E O F — 2009-06-16 11:07
Hi,

P2P - I see you have P2P software uTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P file sharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


Now please do the following:


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
I appreciate your comments and concerns about uTorrent and P2P software in general, however, this program is on my computer for appraisal/research purposes (as background material for a course I teach in Business Ethic at Niagara College) and has not been used in over 6 months (even then, for only one or two test files). So, although it COULD be a contributor to my situation, I highly doubt it in this situation. Malwarebytes' Anti-Malware 1.37 Database version: 2290 Windows 6.0.6001 Service Pack 1 6/16/2009 7:05:30 PM mbam-log-2009-06-16 (19-05-30).txt Scan type: Quick Scan Objects scanned: 82332 Time elapsed: 3 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Kapersky failed to load/scan because of Java failure ("Starting Java applet has failed! Please go online to use this program".) What should I do to fix/workaround this? Thanks, Michael.
Re: Kaspersky failing to run:

That's usually because the Java Addon in IE is disabled.

Go to Tools > Internet Options > Advanced tab. Click Reset then OK and exit IE 7.

Re-open IE 7 and ensure the Java add-ons are enabled.

[external image: Posted Image]

Also

For Vista Users

The scan must be run in Internet Explorer as an Administrator.
To run Internet Explorer as an Administrator you must go to Start and in the Search box type in iexplore.exe.
When it finds iexplore.exe you must right click on it and select Run as Administrator.
After you do that you'll get the User Account Control prompt box and you must select Allow.

make sure that ActiveX is installed/enabled


if kaspersky still wont run try this scan instead:

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

Re: Kaspersky failing to run:

That's usually because the Java Addon in IE is disabled.


I'm actually running Firefox…….and after playing with Kapersky a bit, got it to run.

It's 40 minutes into its scan now…..but I'm hitting the sack! I'll send you the report in the morning.

Thanks a lot for your help today. I'm guessing you'll have this thing licked tomorrow!

Good night.

Michael.
Just realized I'm running the "critical areas" scan option in Kaspersky, as opposed to the "My Computer" version you specified. I'm over 75% finished……so, wondering if I should just let it finish. Can you use this report just as well as the My Computer one? Or should I start over? Sorry about that!
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Wednesday, June 17, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, June 17, 2009 01:02:33 Records in database: 2353079 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - Critical Areas: C:\Program Files C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\Windows Scan statistics: Files scanned: 158151 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 12:10:52 File name / Threat name / Threats count C:\Windows\System32\msxml71.0ll Infected: Trojan-Downloader.Win32.FraudLoad.epn 1 The selected area was scanned.
My computer hasn't displayed the Windows Defender Warning window today, nor has it started playing random audio as it has over the last several days. Can you advise which of the procedures we've done "so far"……"appears" to have fixed it?? Thanks,
Hi, Please can you run Kaspersky scan again and scan "My Computer" Thanks Search for the file Kaspersky reported as infected and delete it (you may need to show hidden files and folders to locate it) use Windows Explorer (windows Key +E) to locate it then delete (right click > choose delete.) ComboFix has done most of the work for me.
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Thursday, June 18, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, June 17, 2009 01:02:33 Records in database: 2353079 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 178945 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 02:10:06 No malware has been detected. The scan area is clean. The selected area was scanned. Looks like we're good to go…………..are we?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI