This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] uacinit.dll problem

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm having a huge problem with my computer. It's been infected with this malware which cannot be removed with any program. I've been reading around and it seems the solution is different for every computer. Malwarebytes can't remove the .dll file. Here's my log: Malwarebytes' Anti-Malware 1.38 Database version: 2384 Windows 6.0.6000 7/07/2009 11:55:28 PM mbam-log-2009-07-07 (23-55-28).txt Scan type: Quick Scan Objects scanned: 84355 Time elapsed: 6 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe (Security.Hijack) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Windows\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot. —– Please help me! Thanks.
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require more than one round to properly eradicate.
  • Absence of symptoms does not always mean the job is complete, you can be certain that I will advise you when the computer is clean.
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi Catbyte, firstly thank you so much for helping me out here. I just wanted to give you a bit more information about the symptoms I've got, I think they are the same with everyone else who has been infected with this: - Google re-directs - Had to re-name spyware programs in order for them to run - Disabling Windows Security Centre - Sluggish on startup during the Windows Vista "welcome screen" - Random popups on IE (don't use it, just comes up) Attached are the three files requested.
Hi,

Please do the following:

Download Combofix from any of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, make sure you delete it (right click > delete) this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2
Link 3


During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

That one took a while, finally done. Computer already feels like it's going faster, did that do anything? :P

Attached is the combofix file.

ComboFix 09-07-07.A2 - Tony 08/07/2009 14:55.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.61.1033.18.1919.828 [GMT 10:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
AV: Norton Internet Security *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
SP: Norton Internet Security *disabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Tony\Tony.exe
c:\windows\PGMonitor.exe
c:\windows\system32\acovcnt.exe
c:\windows\system32\drivers\UACkffppckpsawnjhxpe.sys
c:\windows\system32\UACgyulbdmgpqhdrvyob.dll
c:\windows\system32\UAChtnvtqipbsmeflqto.db
c:\windows\system32\uacinit.dll
c:\windows\system32\UACmabxwpyrcwoeljwio.dll
c:\windows\system32\UACmnwlujfwbyojhlfit.dat
c:\windows\system32\UACmrxwnhmjgpxpbepqc.dll
c:\windows\system32\UACsjyjouueenumpkprk.dll
c:\windows\system32\UACsoittuqpowbkpscuo.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-06-08 to 2009-07-08 )))))))))))))))))))))))))))))))
.

2009-07-08 05:19 . 2009-07-08 05:19 ——– d—–w- c:\users\Tony\AppData\Local\temp
2009-07-07 05:34 . 2009-07-07 05:34 ——– d—–w- c:\users\Tony\AppData\Roaming\Malwarebytes
2009-07-07 05:28 . 2009-06-17 01:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-07 05:28 . 2009-07-07 11:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-07 05:28 . 2009-07-07 05:28 ——– d—–w- c:\programdata\Malwarebytes
2009-07-07 05:28 . 2009-06-17 01:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-21 07:38 . 2009-06-21 07:38 ——– d—–w- c:\users\Tony\AppData\Roaming\Megaupload
2009-06-21 07:37 . 2009-06-21 07:37 ——– d—–w- c:\program files\Megaupload
2009-06-21 07:36 . 2009-06-21 07:36 ——– d—–w- c:\users\Tony\AppData\Roaming\InstallShield
2009-06-15 01:14 . 2009-04-30 12:42 428032 —-a-w- c:\windows\system32\EncDec.dll
2009-06-15 01:14 . 2009-04-30 12:52 292352 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-15 01:14 . 2009-04-30 12:44 1244672 —-a-w- c:\windows\system32\mcmde.dll
2009-06-13 00:52 . 2009-06-13 00:52 ——– d—–w- c:\program files\Xvid
2009-06-12 10:59 . 2009-06-12 10:59 ——– d—–w- c:\program files\MKVtoolnix
2009-06-12 10:50 . 2009-06-12 10:55 ——– d—–w- c:\users\Tony\AppData\Local\StaxRip
2009-06-12 10:49 . 2009-06-12 10:49 ——– d—–w- c:\program files\StaxRip
2009-06-12 02:27 . 2009-04-21 11:55 2030080 —-a-w- c:\windows\system32\win32k.sys
2009-06-12 02:27 . 2009-04-23 13:01 788992 —-a-w- c:\windows\system32\rpcrt4.dll
2009-06-12 02:27 . 2009-04-23 12:56 696832 —-a-w- c:\windows\system32\localspl.dll
2009-06-11 11:58 . 2009-06-13 04:33 ——– d—–w- c:\program files\megui

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-07 15:19 . 2008-03-12 09:46 12 —-a-w- c:\windows\bthservsdp.dat
2009-07-07 13:16 . 2008-04-15 08:32 89960 —-a-w- c:\users\Tony\AppData\Roaming\nvModes.dat
2009-07-03 05:15 . 2008-04-12 10:49 ——– d—–w- c:\users\Tony\AppData\Roaming\.BitTornado
2009-07-02 11:38 . 2009-01-09 13:16 ——– d—–w- c:\users\Tony\AppData\Roaming\dvdcss
2009-06-21 07:37 . 2008-03-12 12:06 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-21 07:16 . 2008-03-12 12:26 ——– d—–w- c:\program files\PowerForPhone
2009-06-21 07:14 . 2009-03-19 04:44 ——– d—–w- c:\program files\Free Download Manager
2009-06-21 07:14 . 2009-03-19 04:44 ——– d—–w- c:\users\Tony\AppData\Roaming\Free Download Manager
2009-06-21 04:19 . 2008-04-12 10:01 ——– d—–w- c:\users\Tony\AppData\Roaming\Apple Computer
2009-06-16 03:16 . 2008-03-12 09:53 ——– d—–w- c:\programdata\Microsoft Help
2009-06-05 12:11 . 2009-06-05 12:11 1878984 —-a-w- c:\users\Tony\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-05-24 02:46 . 2009-03-18 11:44 ——– d—–w- c:\users\Tony\AppData\Roaming\AccurateRip
2009-05-15 04:26 . 2008-04-15 10:21 ——– d—–w- c:\users\Tony\AppData\Roaming\LimeWire
2009-05-15 00:30 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-04-27 01:38 . 2008-04-12 07:43 105296 —-a-w- c:\users\Tony\AppData\Local\GDIPFONTCACHEV1.DAT
2009-04-24 16:22 . 2009-06-12 02:26 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:14 . 2009-06-12 02:26 56320 —-a-w- c:\windows\system32\iesetup.dll
2009-04-24 16:14 . 2009-06-12 02:26 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 16:11 . 2009-06-12 02:26 72704 —-a-w- c:\windows\system32\admparse.dll
2009-04-24 13:53 . 2009-06-12 02:26 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-24 12:25 . 2009-06-12 02:26 48128 —-a-w- c:\windows\system32\mshtmler.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 —-a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-04-12 1232896]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-06-20 451872]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"iSproggler"="c:\program files\iSproggler-1.1.0\iSproggler\iSproggler.exe" [2008-12-16 17694283]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-04-14 2321600]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-03-12 1006264]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-05-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-14 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-14 81920]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-09-03 630784]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"ASUSTPE"="c:\windows\system32\ASUSTPE.exe" [2007-01-16 106496]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 857648]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2008-03-12 37232]
"ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2008-03-12 33136]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-13 144784]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-30 648072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-03 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-23 33648]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-07-06 4669440]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-06-15 1826816]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
VPN Client.lnk - c:\windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2008-4-14 6144]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{10F25708-3450-401E-B70F-B4C309A4BA64}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6BC3C445-B836-4CFE-9A37-888FD2CD98CC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{59C470D3-DA2F-40B6-8B05-706CC4DE85C6}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{BC823DCF-CAEB-44F6-9D18-4E8B2FE1F38C}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{07B72A99-2056-4A16-80FF-3FED4975C096}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{A2D3C555-9D43-4C64-BAB4-E9ADAD0D7412}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{8081456E-9BDF-4ACB-9F5E-872065EA032F}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{14BF6034-45EB-46FB-B017-36FD45CA5BB5}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{96BB88C9-05A7-440C-AA79-A53887955481}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E22C0CA2-FED3-4590-B507-21BC506DFC5C}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20080521.001\IDSvix86.sys [22/05/2008 11:12 AM 261680]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/04/2008 6:24 PM 109616]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [3/10/2008 1:14 PM 37936]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-06-22 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Tony.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-01-14 01:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.asus.com
uInternet Settings,ProxyOverride = *.local
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\f5ty5po5.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-08 15:19
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\users\Tony\AppData\Local\Temp\catchme.dll 53248 bytes executable
C:\ADSM_PData_0150

scan completed successfully
hidden files: 2

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3955432054-374707567-2575976948-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D356F652-8C25-9B6B-EDA8-FB6BC88E097B}*]
"hakkngpbjcalomja"=hex:6b,61,6d,6a,62,69,62,6d,67,67,6d,6b,6d,66,65,6d,6d,6e,
6b,62,69,6a,00,00
"iaallijhecieobkdeh"=hex:6b,61,6d,6a,6d,6c,65,6c,67,66,6b,6d,64,64,6e,63,65,63,
68,6b,61,61,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-07-08 15:24
ComboFix-quarantined-files.txt 2009-07-08 05:24

Pre-Run: 40,970,657,792 bytes free
Post-Run: 41,764,454,400 bytes free

201 — E O F — 2009-07-07 11:39

Attachments:

Hi,

P2P - I see you have P2P software BitTornado and Limewire installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


NEXT



Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.

NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT



Run an on-line scan with Kaspersky


**Vista users - right click on the IE icon and run as administrator
Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report


Also please describe how your computer is running and if there are any outstanding issues.
Malwarebytes log:

Malwarebytes' Anti-Malware 1.38
Database version: 2392
Windows 6.0.6000

9/07/2009 9:59:16 PM
mbam-log-2009-07-09 (21-59-16).txt

Scan type: Quick Scan
Objects scanned: 82686
Time elapsed: 4 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Scan Report

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Friday, July 10, 2009
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit (build 6000)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Thursday, July 09, 2009 12:59:55
Records in database: 2449369
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 103685
Threat name: 4
Infected objects: 6
Suspicious objects: 0
Duration of the scan: 02:33:47


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\Windows\System32\drivers\UACkffppckpsawnjhxpe.sys.vir Infected: Rootkit.Win32.Agent.lzl 1
C:\Qoobox\Quarantine\C\Windows\System32\UACgyulbdmgpqhdrvyob.dll.vir Infected: Packed.Win32.Tdss.m 1
C:\Qoobox\Quarantine\C\Windows\System32\UACmabxwpyrcwoeljwio.dll.vir Infected: Trojan.Win32.TDSS.adzz 1
C:\Qoobox\Quarantine\C\Windows\System32\UACmrxwnhmjgpxpbepqc.dll.vir Infected: Trojan.Win32.TDSS.aekg 1
C:\Qoobox\Quarantine\C\Windows\System32\UACsjyjouueenumpkprk.dll.vir Infected: Packed.Win32.Tdss.m 1
C:\Qoobox\Quarantine\C\Windows\System32\UACsoittuqpowbkpscuo.dll.vir Infected: Packed.Win32.Tdss.m 1

The scan was stopped by the user.

——

I stopped it when it was scanning my D drive, as there are only multimedia files on that drive and it was taking forever to complete. It scanned my whole C drive though.
Hi,

The files found by Kaspersky are already in quarantine so cannot harm the computer.

Please post a fresh DDS log and describe how your computer is running now and if there are any outstanding issues.

NEXT

P2P - I see you have P2P software Limewire installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


NEXT


Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Scroll down to the Java SE Runtime Environment (JRE) option.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 14)
The computer has improved. Most of the symptoms I described earlier are gone. The only thing - my startup is more sluggish than it was before.

Fresh DDS Log:


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:15:47.41 on Fri 10/07/2009
Internet Explorer: 7.0.6000.16851
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.61.1033.18.1919.899 [GMT 10:00]

AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Windows\System32\ACEngSvr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\ATK Hotkey\KBFiltr.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Windows\System32\ASUSTPE.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\iSproggler-1.1.0\iSproggler\iSproggler.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\System32\mobsync.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Tony\Desktop\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.asus.com
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.5\NppBho.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [iSproggler] "c:\program files\isproggler-1.1.0\isproggler\iSproggler.exe"
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [AdobeUpdater] c:\program files\common files\adobe\updater5\AdobeUpdater.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe
mRun: [ATKMEDIA] c:\program files\asus\atk media\DMEDIA.EXE
mRun: [ASUSTPE] c:\windows\system32\ASUSTPE.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ASUS Camera ScreenSaver] c:\windows\ASScrProlog.exe
mRun: [ASUS Screen Saver Protector] c:\windows\ASScrPro.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_04\bin\jusched.exe"
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{ccbaa1f7-e5e1-48b2-9ed9-a79c6a37ce78}\Icon3E5562ED7.ico
IE: Download Link Using Mega Manager… - c:\program files\megaupload\mega manager\mm_file.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/E/3/9/E39C664F-A8E3-4F69-A109-1AE9849204EE/OGAControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\tony\appdata\roaming\mozilla\firefox\profiles\f5ty5po5.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20080521.001\IDSvix86.sys [2008-5-22 261680]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-4-12 109616]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2008-10-3 37936]

=============== Created Last 30 ================

2009-07-08 15:24 –dsh— C:\$RECYCLE.BIN
2009-07-08 14:48 161,792 a——- c:\windows\SWREG.exe
2009-07-08 14:48 155,136 a——- c:\windows\PEV.exe
2009-07-08 14:48 98,816 a——- c:\windows\sed.exe
2009-07-07 15:34 –d—– c:\users\tony\appdata\roaming\Malwarebytes
2009-07-07 15:28 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-07 15:28 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-07 15:28 –d—– c:\programdata\Malwarebytes
2009-07-07 15:28 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-07-07 15:28 –d—– c:\progra~2\Malwarebytes
2009-06-21 17:38 –d—– c:\users\tony\appdata\roaming\Megaupload
2009-06-21 17:37 –d—– c:\program files\Megaupload
2009-06-15 11:14 428,032 a——- c:\windows\system32\EncDec.dll
2009-06-15 11:14 292,352 a——- c:\windows\system32\psisdecd.dll
2009-06-15 11:14 1,244,672 a——- c:\windows\system32\mcmde.dll
2009-06-15 11:14 217,088 a——- c:\windows\system32\psisrndr.ax
2009-06-15 11:14 177,152 a——- c:\windows\system32\mpg2splt.ax
2009-06-15 11:14 68,608 a——- c:\windows\system32\Mpeg2Data.ax
2009-06-15 11:14 80,896 a——- c:\windows\system32\MSNP.ax
2009-06-15 11:14 57,856 a——- c:\windows\system32\MSDvbNP.ax
2009-06-13 10:52 –d—– c:\program files\Xvid
2009-06-12 20:59 –d—– c:\program files\MKVtoolnix
2009-06-12 20:49 –d—– c:\program files\StaxRip
2009-06-12 12:27 2,030,080 a——- c:\windows\system32\win32k.sys
2009-06-12 12:27 788,992 a——- c:\windows\system32\rpcrt4.dll
2009-06-12 12:27 696,832 a——- c:\windows\system32\localspl.dll
2009-06-11 21:58 –d—– c:\program files\megui

==================== Find3M ====================

2009-07-09 21:28 89,960 a——- c:\users\tony\appdata\roaming\nvModes.dat
2009-04-25 02:22 827,392 a——- c:\windows\system32\wininet.dll
2009-04-25 02:14 56,320 a——- c:\windows\system32\iesetup.dll
2009-04-25 02:14 78,336 a——- c:\windows\system32\ieencode.dll
2009-04-25 02:14 52,736 a——- c:\windows\apppatch\iebrshim.dll
2009-04-25 02:11 72,704 a——- c:\windows\system32\admparse.dll
2009-04-24 23:53 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-04-24 22:25 48,128 a——- c:\windows\system32\mshtmler.dll
2009-01-23 19:49 86,016 a——- c:\windows\inf\infstrng.dat
2009-01-23 19:49 51,200 a——- c:\windows\inf\infpub.dat
2009-01-23 19:49 86,016 a——- c:\windows\inf\infstor.dat
2008-12-15 20:09 174 a–sh— c:\program files\desktop.ini
2008-06-14 16:36 665,600 a——- c:\windows\inf\drvindex.dat
2006-11-02 22:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 22:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 22:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 22:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 19:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 19:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 19:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 19:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2008-06-02 13:57 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-06-02 13:57 32,768 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-06-02 13:57 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat

============= FINISH: 11:22:14.98 ===============

Will get around to installing updated acrobat and java soon.
Hi,

my startup is more sluggish than it was before


That will improve with a couple of boot cycles.

Try this for better performance:

Download and run Auslogics Disc Defragmenter

Your computer is clean,

just a little housekeeping to do now.

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI