This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Plz Help. MALWARE

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got a trojan while downloading an mmo from G-Potato. I am not sure what the virus is, but it is annoying. It keeps appearing with fake security pop-ups and it changed the bg of my computer. I am running windows XP service pack 3 32x. I ran anti-vir and it deleted something from my system 32. The file was chkdisk.dll. It doesn't appear to be gone anymore but sometimes my computer comes up with a blue screen and has a memory dump. Something else is missing but I am not sure what. here is my hijackthis info.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:44:36 PM, on 7/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\b.exe
C:\WINDOWS\msb.exe
C:\Documents and Settings\Michael Lopez\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Michael Lopez\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [13995784] C:\Documents and Settings\All Users\Application Data\13995784\13995784.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Michael Lopez\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Cognac] C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\b.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: ChkDisk.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 11785 bytes


If you can help plz do. As i'm on the internet I think this thing is downloading more parts. It seems dormant now but i'm sure it still is in my system.


Last found in anti-vir was TR/Redol.A and HTML/Malicious.PDF.Gen
Hi,

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
I try to update malwarebytes and it crashes. I try to delete stuff in malwarebytes and it freezes. Uhhh, idk what to do.
I had to uncheck something in malwarebytes. Malbytes didn't delete the system 32 stuff. Heres the dds.txt ———————————————————- DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 17:46:55.34 on Wed 07/15/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.479.70 [GMT -7:00] AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E} ============== Running Processes =============== C:\WINDOWS\system32\savedump.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\DNA\btdna.exe C:\WINDOWS\system32\dumprep.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\Pen_Tablet.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe C:\WINDOWS\system32\Pen_Tablet.exe C:\WINDOWS\system32\mqsvc.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\WINDOWS\system32\mqtgsvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\Michael Lopez\Desktop\dds.scr C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter c:\program files\avira\antivir desktop\avcenter.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\dwwin.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=pavilion&pf=laptop uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp uRun: [Google Update] "c:\documents and settings\michael lopez\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [nwiz] nwiz.exe /installquiet /nodetect mRun: [MsmqIntCert] regsvr32 /s mqrt.dll mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe mRun: [RecGuard] c:\windows\sminst\RecGuard.exe mRun: [Reminder] c:\windows\creator\Remind_XP.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe" mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot dRun: [Windows System Recover!] c:\windows\temp\winamp.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe dPolicies-explorer: NoFolderOptions = 1 (0x1) dPolicies-system: DisableRegistryTools = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab STS: {D76AB2A1-00F3-42BD-F434-00BBC39C8953} - No File ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\michae~1\applic~1\mozilla\firefox\profiles\wu2kk6ld.default\ FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll FF - plugin: c:\documents and settings\michael lopez\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPGameWebStarter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-5-21 11608] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-21 108289] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-21 55640] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2009-6-13 1373480] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-6-26 24652] S2 hvdhtumf;hvdhtumf;c:\windows\system32\drivers\otgtlx.sys –> c:\windows\system32\drivers\otgtlx.sys [?] S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-6-6 61952] S3 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-5-21 185089] =============== Created Last 30 ================ 2009-07-15 14:45 –d—– c:\docume~1\michae~1\applic~1\Malwarebytes 2009-07-15 14:44 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-15 14:44 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-15 14:44 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-15 14:44 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-14 14:01 –d—– c:\program files\Trend Micro 2009-07-14 14:00 –d—– c:\docume~1\alluse~1\applic~1\13995784 2009-07-12 23:16 5,120 a–sh— c:\windows\system32\Thumbs.db 2009-07-12 15:24 –d—– c:\program files\LimeWire 2009-07-08 11:21 –d—– C:\My Music 2009-07-08 11:18 –d—– c:\program files\common files\xing shared 2009-06-27 02:25 –dsh— c:\documents and settings\michael lopez\IECompatCache 2009-06-27 02:25 –dsh— c:\documents and settings\michael lopez\PrivacIE 2009-06-26 23:43 –d—– c:\docume~1\alluse~1\applic~1\Viewpoint 2009-06-26 23:43 –d—– c:\program files\Viewpoint 2009-06-26 23:43 –d—– c:\docume~1\alluse~1\applic~1\acccore 2009-06-26 23:42 –d—– c:\program files\common files\AOL 2009-06-26 23:42 –d—– c:\program files\AIM6 2009-06-26 23:42 367 a—h— C:\IPH.PH 2009-06-25 20:57 –dsh— c:\documents and settings\michael lopez\IETldCache 2009-06-25 20:51 102,912 ——– c:\windows\system32\dllcache\iecompat.dll 2009-06-25 20:51 –d—– c:\windows\ie8updates 2009-06-25 20:50 12,800 ——– c:\windows\system32\dllcache\xpshims.dll 2009-06-25 20:50 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll 2009-06-25 20:49 -cd-h— c:\windows\ie8 2009-06-21 23:05 5,632 a——- c:\windows\system32\ptpusb.dll 2009-06-21 23:05 15,104 a——- c:\windows\system32\drivers\usbscan.sys 2009-06-21 23:05 15,104 a——- c:\windows\system32\dllcache\usbscan.sys 2009-06-21 23:05 159,232 a——- c:\windows\system32\ptpusd.dll 2009-06-20 22:17 –d—– c:\program files\common files\INCA Shared 2009-06-20 22:16 4,682 a——- c:\windows\system32\npptNT2.sys 2009-06-20 22:16 5,174 a——- c:\windows\system32\nppt9x.vxd 2009-06-20 22:03 49,152 a——- c:\windows\system32\CMStarter_Kor.dll 2009-06-20 22:03 49,152 a——- c:\windows\system32\CMStarter_Eng.dll 2009-06-20 22:03 323,584 a——- c:\windows\system32\CMStarterCore.exe 2009-06-18 18:57 –d—– c:\windows\system32\wbem\Repository 2009-06-18 17:20 –d—– C:\WTablet 2009-06-17 09:52 –d—– c:\program files\common files\Macrovision Shared 2009-06-16 07:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-06-16 07:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll ==================== Find3M ==================== 2009-06-16 07:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 07:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 12:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 12:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-05-22 10:50 54,416 a—h— c:\windows\system32\mlfcache.dat 2009-05-21 11:33 410,984 a——- c:\windows\system32\deploytk.dll 2009-05-12 22:15 915,456 a——- c:\windows\system32\wininet.dll 2009-05-12 22:15 5,936,128 ——– c:\windows\system32\dllcache\mshtml.dll 2009-05-12 22:15 915,456 ——– c:\windows\system32\dllcache\wininet.dll 2009-05-07 08:32 345,600 a——- c:\windows\system32\localspl.dll 2009-05-07 08:32 345,600 ——– c:\windows\system32\dllcache\localspl.dll 2009-04-30 14:22 1,985,024 ——– c:\windows\system32\dllcache\iertutil.dll 2009-04-30 14:22 11,064,832 ——– c:\windows\system32\dllcache\ieframe.dll 2009-04-30 14:22 1,207,808 ——– c:\windows\system32\dllcache\urlmon.dll 2009-04-30 14:22 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll 2009-04-30 14:22 385,536 ——– c:\windows\system32\dllcache\iedkcs32.dll 2009-04-30 04:21 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-04-29 16:46 139,552 a——- c:\windows\hpoins21.dat 2009-04-28 21:55 133,120 ——– c:\windows\system32\dllcache\extmgr.dll 2009-04-28 02:05 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-04-17 05:26 1,847,168 a——- c:\windows\system32\win32k.sys 2009-04-17 05:26 1,847,168 ——– c:\windows\system32\dllcache\win32k.sys 2009-03-14 11:15 0 ac—— c:\docume~1\michae~1\applic~1\wklnhst.dat 2009-02-06 19:07 1,046,866,013 a——- c:\program files\ao_setup_2007.exe 2008-12-29 23:54 56 -c-shr– c:\windows\system32\EC05397EAE.sys 2009-02-22 23:48 13,200 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-01-19 20:18 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009011920090120\index.dat ============= FINISH: 17:51:17.10 ===============

Attachments:

Hi,

I notice have Limewire installed. Limewire is a fantastic way to get yourself infected. I recommend you strongly consider removing it, and at the very least please stop using it until we have finished the cleaning process.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
It said their was rootkit activity, which was obvious. It gave me a list of the rootkit activity which is: C:\Windows\System32\Drivers\hjgruilyetkmtt.sys C:\Windows\System32\hjgruibndcmkqy.dll C:\Windows\System32\hjgruiqkqrqmnn.dat C:\Windows\System32\hjgruirdrnbvbj.dll C:\Windows\System32\hjgruiyaorsbow.dat I think that may have been in the report but I included it here anyways. I attached the report. Thanks for the help so far. I hope this fixxed it.

Attachments:

Things are looking a lot better. I would just like to get a good thorough scan to make sure there is nothing left. First, you should remove these old version of Java (via the Control Panel):
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 7


Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Please also run DDS again and post the first log it gives (DDS.txt). If all is running well we can wrap this up.
Here's the dds.txt while we're waiting for the online scanner. —————————————————— DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 13:01:52.25 on Thu 07/16/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.479.133 [GMT -7:00] AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\Pen_Tablet.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe C:\WINDOWS\system32\mqsvc.exe C:\WINDOWS\system32\Pen_Tablet.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\WINDOWS\system32\mqtgsvc.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\WINDOWS\explorer.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Java\jre6\bin\java.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Avira\AntiVir Desktop\avnotify.exe C:\Documents and Settings\Michael Lopez\Desktop\Malware Removal Tools\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp uRun: [Google Update] "c:\documents and settings\michael lopez\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [nwiz] nwiz.exe /installquiet /nodetect mRun: [MsmqIntCert] regsvr32 /s mqrt.dll mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe mRun: [RecGuard] c:\windows\sminst\RecGuard.exe mRun: [Reminder] c:\windows\creator\Remind_XP.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe" mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\michae~1\applic~1\mozilla\firefox\profiles\wu2kk6ld.default\ FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll FF - plugin: c:\documents and settings\michael lopez\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPGameWebStarter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-5-21 11608] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-21 108289] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-21 55640] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2009-6-13 1373480] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-6-26 24652] R3 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-5-21 185089] S2 hvdhtumf;hvdhtumf;c:\windows\system32\drivers\otgtlx.sys –> c:\windows\system32\drivers\otgtlx.sys [?] S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-6-6 61952] =============== Created Last 30 ================ 2009-07-16 12:04 –d—– c:\windows\system32\dllcache\cache 2009-07-16 11:39 a-dshr– C:\cmdcons 2009-07-16 11:36 219,648 a——- c:\windows\PEV.exe 2009-07-16 11:36 161,792 a——- c:\windows\SWREG.exe 2009-07-16 11:36 98,816 a——- c:\windows\sed.exe 2009-07-15 14:45 –d—– c:\docume~1\michae~1\applic~1\Malwarebytes 2009-07-15 14:44 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-15 14:44 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-15 14:44 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-15 14:44 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-14 14:01 –d—– c:\program files\Trend Micro 2009-07-14 14:00 –d—– c:\docume~1\alluse~1\applic~1\13995784 2009-07-12 23:16 5,120 a–sh— c:\windows\system32\Thumbs.db 2009-07-12 15:24 –d—– c:\program files\LimeWire 2009-07-08 11:21 –d—– C:\My Music 2009-07-08 11:18 –d—– c:\program files\common files\xing shared 2009-06-27 02:25 –dsh— c:\documents and settings\michael lopez\IECompatCache 2009-06-27 02:25 –dsh— c:\documents and settings\michael lopez\PrivacIE 2009-06-26 23:43 –d—– c:\docume~1\alluse~1\applic~1\Viewpoint 2009-06-26 23:43 –d—– c:\program files\Viewpoint 2009-06-26 23:43 –d—– c:\docume~1\alluse~1\applic~1\acccore 2009-06-26 23:42 –d—– c:\program files\common files\AOL 2009-06-26 23:42 –d—– c:\program files\AIM6 2009-06-26 23:42 367 a—h— C:\IPH.PH 2009-06-25 20:57 –dsh— c:\documents and settings\michael lopez\IETldCache 2009-06-25 20:51 102,912 ——– c:\windows\system32\dllcache\iecompat.dll 2009-06-25 20:51 –d—– c:\windows\ie8updates 2009-06-25 20:50 12,800 ——– c:\windows\system32\dllcache\xpshims.dll 2009-06-25 20:50 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll 2009-06-25 20:49 -cd-h— c:\windows\ie8 2009-06-21 23:05 5,632 a——- c:\windows\system32\ptpusb.dll 2009-06-21 23:05 15,104 a——- c:\windows\system32\drivers\usbscan.sys 2009-06-21 23:05 15,104 a——- c:\windows\system32\dllcache\usbscan.sys 2009-06-21 23:05 159,232 a——- c:\windows\system32\ptpusd.dll 2009-06-20 22:17 –d—– c:\program files\common files\INCA Shared 2009-06-20 22:16 4,682 a——- c:\windows\system32\npptNT2.sys 2009-06-20 22:16 5,174 a——- c:\windows\system32\nppt9x.vxd 2009-06-20 22:03 49,152 a——- c:\windows\system32\CMStarter_Kor.dll 2009-06-20 22:03 49,152 a——- c:\windows\system32\CMStarter_Eng.dll 2009-06-20 22:03 323,584 a——- c:\windows\system32\CMStarterCore.exe 2009-06-18 18:57 –d—– c:\windows\system32\wbem\Repository 2009-06-18 17:20 –d—– C:\WTablet 2009-06-17 09:52 –d—– c:\program files\common files\Macrovision Shared ==================== Find3M ==================== 2009-06-16 07:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 07:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-16 07:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-06-16 07:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll 2009-06-03 12:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 12:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-05-22 10:50 54,416 a—h— c:\windows\system32\mlfcache.dat 2009-05-21 11:33 410,984 a——- c:\windows\system32\deploytk.dll 2009-05-12 22:15 915,456 a——- c:\windows\system32\wininet.dll 2009-05-12 22:15 915,456 a——- c:\windows\system32\dllcache\cache\wininet.dll 2009-05-12 22:15 5,936,128 ——– c:\windows\system32\dllcache\mshtml.dll 2009-05-12 22:15 915,456 ——– c:\windows\system32\dllcache\wininet.dll 2009-05-07 08:32 345,600 a——- c:\windows\system32\localspl.dll 2009-05-07 08:32 345,600 ——– c:\windows\system32\dllcache\localspl.dll 2009-04-30 14:22 1,985,024 ——– c:\windows\system32\dllcache\iertutil.dll 2009-04-30 14:22 11,064,832 ——– c:\windows\system32\dllcache\ieframe.dll 2009-04-30 14:22 1,207,808 ——– c:\windows\system32\dllcache\urlmon.dll 2009-04-30 14:22 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll 2009-04-30 14:22 385,536 ——– c:\windows\system32\dllcache\iedkcs32.dll 2009-04-30 04:21 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-04-29 16:46 139,552 a——- c:\windows\hpoins21.dat 2009-04-28 21:55 133,120 ——– c:\windows\system32\dllcache\extmgr.dll 2009-04-28 02:05 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-03-14 11:15 0 ac—— c:\docume~1\michae~1\applic~1\wklnhst.dat 2009-02-06 19:07 1,046,866,013 a——- c:\program files\ao_setup_2007.exe 2008-12-29 23:54 56 -c-shr– c:\windows\system32\EC05397EAE.sys 2009-02-22 23:48 13,200 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-01-19 20:18 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009011920090120\index.dat ============= FINISH: 13:02:29.71 =============== While scanning in anti-vir it found redol.b
When KAV is done (important to wait until it finishes), click Start >> Run, then copy paste this and hit Enter:
sc delete hvdhtumf

If AntiVir finds anything else after that, make a note of where it finds it (if possible).
Anti-vir found TR/Redol.B again. it's at C:\System Volume Information\_restore{3A57956-82CF-4117-919A-DB7B394CD5BC}\RP114\A0036434.DLL
That's fine, its in the System Restore, which will be cleared when we clean up. Let me know if KAV finds anything, if not we can start the clean-up.
Hi,

Indeed it is :thumbup:

Click Start >> Run, and then type ComboFix /u and hit enter. (This will clean the System Restore among other things).

You can now delete any other tools I had you download and use, unless you wish to keep them.


Now that your system appears to be clean, there's just a few steps I'd like you to take to prevent any future infections.
  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Anti-vir has detected nothing. Thank you bunches, you saved me from having to restore my computer for the 5th time. YOUR AWESOME!!! :woot:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI