This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Baseline

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my computer
windows xp
service pack 3
firefox
int explorer version 6.0.2
——————————————-
what is wrong that i think my comp is infected?
1 computer very slow
2 crashing fairly consistently
3 mouse keeps getting stuck , will not
what i have done to keep computer clean and safe

1 uninstalled yahoo toolbar that i did not know i had - must have been installed when i did a clean istall using windows SP 3 along with internet explorer

2 read all and applied 7 pinned on http://forums.whatthetech.com/Self_Help_Fi…alware_f97.html

3 did all of these things for slow computer http://www.malwareremoval.com/tutorials/runningslowly.php#8

EXCEPTING How to remove all but your last System Restore Point
i could not get it to work following the below posted instructions
ie when i opened up DISK CLEANUP, THERE was no prompt "if you want to remove all but the most recent Restore Point."
—————-
For users of XP

* Click Start > All Programs > Accessories > System Tools > Disk
Cleanup
* This will bring up the Disk Cleanup window.
* Click the More Options tab.
o In the System Restore field, click Clean up
o You will be prompted if you want to remove all but the most recent Restore Point.
o Click Yes.
* Click OK.
* When prompted whether you're sure you want to do this click Yes.
——————

4 ran AFT cleaner

5 ran Malwarebytes' Anti-Malware

6 used ERUNT backup

7 posted here with hijack this log and

HIJACK THIS LOG


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:55:06 AM, on 16/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\khooker.exe
C:\Program Files\HP\HP Mouse\Panel.exe
C:\Program Files\DriveHQ\DriveHQ FileManager\DHQFMSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
D:\DL Progs IN USE\HiJackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\system32\khooker.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [OfficeWeb mouse] C:\Program Files\HP\HP Mouse\Panel.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DriveHQ FileManagerFun - Drive Headquarter - C:\Program Files\DriveHQ\DriveHQ FileManager\DHQFMSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

–
End of file - 3946 bytes

Malwarebytes' Anti-Malware LOG

Malwarebytes' Anti-Malware 1.39
Database version: 2437
Windows 5.1.2600 Service Pack 3

16/07/2009 11:56:40 AM
mbam-log-2009-07-16 (11-56-40).txt

Scan type: Quick Scan
Objects scanned: 78897
Time elapsed: 4 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Hello altoyes,
Welcome to What the Tech.
My name is OCD, I will be helping you with your log today.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HijackThis log now, I will post back shortly with instructions.

Hello altoyes,

  • You may want to print out these instructions for reference prior to proceeding.
  • This solution is specifically tailored for this particular problem, please do not attempt to use this solution on another computer.
  • If you have any questions, or are uncertain about any steps please ask 'before' proceeding.
- - - - - Next - - - - -

I didn't find any indication of a firewall in your log. Can you tell me what firewall if any you are using?

- - - - - Next - - - - -

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs) < < Important
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
- - - - - Next - - - - -

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
- - - - - Next - - - - -

On your next post please provide the following:
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
  • GMER.txt

hi OCE thankyou for assisting. i have just realised that i do not have the AVG icon in the bottom right i do not know whether or not it has been turned on i am downloading the latest version now i have always used Windows firewall my security settings tell me that it is turned on
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 16:30:11.65 on Wed 22/07/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.735.340 [GMT 10:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\khooker.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\HP\HP Mouse\Panel.exe
svchost.exe
C:\Program Files\DriveHQ\DriveHQ FileManager\DHQFMSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\marion willow\Desktop\dds.scr

============== Pseudo HJT Report ===============

uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [OfficeWeb mouse] c:\program files\hp\hp mouse\Panel.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [SiS KHooker] c:\windows\system32\khooker.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\marion~1\applic~1\mozilla\firefox\profiles\knxwckl1.default\
FF - prefs.js: browser.startup.homepage - hxxp://worldpeacepoll.com/fabradio/wp-login.php
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-30 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-30 325128]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-30 27656]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-30 107272]
R2 DriveHQ FileManagerFun;DriveHQ FileManagerFun;c:\program files\drivehq\drivehq filemanager\DHQFMSvc.exe [2009-7-6 45568]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-10 1029456]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-6-30 903960]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-30 298264]

=============== Created Last 30 ================

2009-07-19 14:47 –d—– c:\docume~1\marion~1\applic~1\DriveHQHOOK
2009-07-19 14:08 13,192,737 a——- C:\02.3.ogg
2009-07-19 14:08 6,269,477 a——- C:\02.1.ogg
2009-07-19 14:08 13,680,812 a——- C:\02.4.ogg
2009-07-19 14:08 9,620,816 a——- C:\02.5.ogg
2009-07-18 10:51 586 a——- c:\windows\MyHeritage.INI
2009-07-18 10:50 –d—– c:\docume~1\marion~1\applic~1\MyHeritage
2009-07-18 10:50 –d—– c:\docume~1\alluse~1\applic~1\MyHeritage
2009-07-17 15:00 –d—– c:\program files\MSXML 4.0
2009-07-17 06:03 27 a——- c:\windows\BRPP2KA.INI
2009-07-17 06:03 32,128 ac—— c:\windows\system32\dllcache\usbccgp.sys
2009-07-17 06:03 32,128 a——- c:\windows\system32\drivers\usbccgp.sys
2009-07-17 06:02 226 a——- c:\windows\Brpfx04a.ini
2009-07-17 06:02 94 a——- c:\windows\brpcfx.ini
2009-07-17 06:02 50 a——- c:\windows\system32\bridf07a.dat
2009-07-17 06:00 –d—– C:\Brother
2009-07-17 06:00 6,224 ——– c:\windows\CVRPAGE.BMP
2009-07-17 06:00 86 a——- c:\windows\Brfaxrx.ini
2009-07-17 06:00 0 a——- c:\windows\brdfxspd.dat
2009-07-17 06:00 126,976 ——– c:\windows\system32\BrfxD05a.dll
2009-07-17 06:00 163,840 ——– c:\windows\system32\NSSearch.dll
2009-07-17 06:00 106,496 ——– c:\windows\system32\BrMuSNMP.dll
2009-07-17 06:00 73,728 ——– c:\windows\system32\BRCrypt.dll
2009-07-17 06:00 61,440 ——– c:\windows\system32\BrMfNt.dll
2009-07-17 06:00 131,072 ——– c:\windows\brunin03.dll
2009-07-17 05:58 –d—– c:\program files\Nuance
2009-07-17 05:57 31,567 a——- c:\windows\maxlink.ini
2009-07-17 05:57 –d—– c:\program files\common files\ScanSoft Shared
2009-07-17 05:56 –d—– c:\program files\ScanSoft
2009-07-17 05:54 –d—– c:\docume~1\alluse~1\applic~1\Brother
2009-07-17 05:48 –d—– c:\program files\Brother
2009-07-16 11:43 –d—– c:\docume~1\marion~1\applic~1\Malwarebytes
2009-07-16 11:43 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-16 11:43 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-16 11:43 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-07-16 11:43 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-16 11:17 1,191,520 a——- c:\windows\system32\XWheel.dll
2009-07-16 11:17 983,040 a——- c:\windows\system32\MousePage.dll
2009-07-16 11:17 151,136 a——- c:\windows\system32\Hook.dll
2009-07-16 11:17 30,848 a——- c:\windows\system32\drivers\HidMouse.sys
2009-07-16 11:17 1,489 a——- c:\windows\system32\drivers\HidMouse.inf
2009-07-16 11:17 –d—– c:\program files\HP
2009-07-16 10:16 –d—– c:\windows\SxsCaPendDel
2009-07-12 08:49 499,712 a——- c:\windows\system32\msvcp71.dll
2009-07-12 08:49 –d—– c:\program files\WinMerge
2009-07-09 10:49 5,632 a——- c:\windows\system32\ptpusb.dll
2009-07-09 10:49 159,232 a——- c:\windows\system32\ptpusd.dll
2009-07-09 10:49 15,104 ac—— c:\windows\system32\dllcache\usbscan.sys
2009-07-09 10:49 15,104 a——- c:\windows\system32\drivers\usbscan.sys
2009-07-06 09:33 –d—– c:\docume~1\marion~1\applic~1\DriveHQ
2009-07-06 09:32 –d—– c:\program files\DriveHQ
2009-07-05 11:23 58 a——- c:\windows\system32\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2009-07-05 11:23 –d—– c:\docume~1\marion~1\applic~1\DonationCoder
2009-07-05 11:22 –d—– c:\program files\ScreenshotCaptor
2009-07-05 11:22 –d—– c:\docume~1\alluse~1\applic~1\DonationCoder
2009-07-04 14:47 –d-h— c:\windows\PIF
2009-07-04 13:44 –d—– c:\program files\Lame for Audacity
2009-07-04 12:51 –d—– c:\documents and settings\marion willow\.thinupload
2009-07-03 06:37 13,646 a——- c:\windows\system32\wpa.bak
2009-07-02 13:24 15,688 a——- c:\windows\system32\lsdelete.exe
2009-07-02 09:37 –d—– c:\program files\DVD Decrypter
2009-07-01 19:08 –d—– c:\program files\Bibliopolis
2009-07-01 18:12 –d—– C:\New Folder
2009-07-01 15:17 –d—– c:\program files\FireTrust
2009-07-01 15:17 –d—– c:\docume~1\marion~1\applic~1\MailWasherFree
2009-07-01 14:08 –d-h— C:\$AVG8.VAULT$
2009-07-01 01:33 –d—– c:\docume~1\marion~1\applic~1\OpenOffice.org
2009-07-01 01:30 3,072 a——- c:\windows\system32\drivers\audstub.sys
2009-07-01 01:29 25,856 a——- c:\windows\system32\drivers\usbprint.sys
2009-07-01 01:29 57,600 a——- c:\windows\system32\drivers\redbook.sys
2009-07-01 01:28 40,960 a——- c:\windows\system32\drivers\sisagp.sys
2009-07-01 01:28 32,768 a——- c:\windows\system32\drivers\sisnic.sys
2009-07-01 01:28 74,240 a——- c:\windows\system32\usbui.dll
2009-07-01 01:27 –d—– c:\program files\common files\ODBC
2009-07-01 01:27 –d—– c:\program files\common files\SpeechEngines
2009-07-01 01:26 –d–r– c:\documents and settings\all users\Documents
2009-07-01 01:26 7,382 ac—— c:\windows\system32\dllcache\OEMBIOS.CAT
2009-07-01 01:26 797,189 ac—— c:\windows\system32\dllcache\NT5IIS.CAT
2009-07-01 01:26 399,645 ac—— c:\windows\system32\dllcache\MAPIMIG.CAT
2009-07-01 01:26 37,484 ac—— c:\windows\system32\dllcache\MW770.CAT
2009-07-01 01:26 13,472 ac—— c:\windows\system32\dllcache\HPCRDP.CAT
2009-07-01 01:26 8,574 ac—— c:\windows\system32\dllcache\IASNT4.CAT
2009-07-01 01:26 13,608 a—-r– c:\windows\SET7.tmp
2009-07-01 01:26 1,086,182 a—-r– c:\windows\SET3.tmp
2009-07-01 01:26 –d—– c:\windows\system32\CatRoot2
2009-07-01 01:26 –d—– c:\windows\system32\CatRoot
2009-07-01 01:26 –d—– C:\Documents and Settings
2009-07-01 01:25 261 a——- c:\windows\system32\$winnt$.inf
2009-06-30 21:49 –d–r– c:\docume~1\marion~1\applic~1\FX
2009-06-30 21:46 –d—– c:\program files\Brownie
2009-06-30 21:45 –d—– c:\program files\Fuji Xerox
2009-06-30 21:34 –d—– c:\program files\QuickTime Alternative
2009-06-30 21:31 -cd-h— c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-30 21:31 –d—– c:\program files\Lavasoft
2009-06-30 21:08 –d—– c:\docume~1\marion~1\applic~1\Any Video Converter
2009-06-30 21:08 –d—– c:\program files\Any Video Converter
2009-06-30 20:54 –d—– c:\program files\Audacity
2009-06-30 20:39 –d—– c:\program files\DVD Shrink
2009-06-30 20:18 –d—– c:\docume~1\alluse~1\applic~1\Nero
2009-06-30 20:18 –d—– c:\program files\Nero
2009-06-30 20:12 –d—– c:\program files\Chami
2009-06-30 20:00 –d—– c:\program files\VLC player
2009-06-30 19:52 –d—– c:\program files\C-Media 3D Audio
2009-06-30 19:42 –d—– c:\program files\ReNamer
2009-06-30 19:38 –d—– c:\program files\NetVisualize
2009-06-30 19:33 –d—– c:\program files\Foxit Software
2009-06-30 19:22 –d—– c:\program files\Spybot - Search & Destroy
2009-06-30 19:22 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-06-30 19:13 –d—– c:\program files\uTorrent
2009-06-30 19:12 –d—– c:\docume~1\marion~1\applic~1\uTorrent
2009-06-30 19:07 –d—– c:\docume~1\marion~1\applic~1\The Complete Genealogy Reporter - FTB
2009-06-30 19:03 –d—– c:\program files\Yahoo!
2009-06-30 19:02 –d—– c:\program files\CCleaner
2009-06-30 18:57 –d—– c:\program files\SUPER
2009-06-30 18:54 –d—– c:\program files\MyHeritage
2009-06-30 18:35 –d—– c:\program files\JRE
2009-06-30 18:35 –d—– c:\program files\OpenOffice.org 3
2009-06-30 17:37 –d—– c:\program files\SpywareBlaster
2009-06-30 17:07 –d—– c:\program files\SiSVGA
2009-06-30 17:06 –d—– c:\program files\SiS Compatible VGA V2.18
2009-06-30 17:05 –d—– c:\documents and settings\marion willow\WINDOWS
2009-06-30 17:03 –d—– c:\program files\AVG
2009-06-30 17:03 –d—– c:\docume~1\alluse~1\applic~1\avg8
2009-06-30 15:39 –dsh— c:\documents and settings\all users\DRM
2009-06-30 15:37 –d—– c:\program files\common files\MSSoap
2009-06-30 15:35 –d-h— c:\program files\WindowsUpdate
2009-06-30 15:35 –d—– c:\program files\Messenger
2009-06-30 15:35 –d—– c:\program files\MSN Gaming Zone
2009-06-30 15:34 –d—– c:\program files\Windows NT

==================== Find3M ====================

2009-07-22 13:06 325,128 a——- c:\windows\system32\drivers\avgldx86.sys
2009-07-22 13:06 107,272 a——- c:\windows\system32\drivers\avgtdix.sys
2009-07-22 13:06 10,520 a——- c:\windows\system32\avgrsstx.dll
2009-07-03 20:54 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-06-30 20:40 682 a——- c:\program files\DVD Shrink 3.2.lnk
2009-06-30 18:34 410,984 a——- c:\windows\system32\deploytk.dll
2009-06-30 16:03 70,691 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-06-30 15:36 21,640 a——- c:\windows\system32\emptyregdb.dat
2009-06-17 00:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-17 00:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-04 05:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-05-08 01:32 345,600 a——- c:\windows\system32\localspl.dll
2009-04-29 14:46 666,624 a——- c:\windows\system32\wininet.dll
2009-04-29 14:46 81,920 ——– c:\windows\system32\ieencode.dll
2001-11-22 23:08 712,704 a——- c:\windows\inf\other\AUDIO3D.DLL
2006-05-03 20:06 163,328 —shr– c:\windows\system32\flvDX.dll
2007-02-21 21:47 31,232 —shr– c:\windows\system32\msfDX.dll
2008-03-16 23:30 216,064 —shr– c:\windows\system32\nbDX.dll

============= FINISH: 16:31:04.09 ===============


GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-23 07:11:23
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF781E87E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF781EBFE]

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!_abnormal_termination + F0 804E274C 4 Bytes CALL 16B71ED2

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp Lbd.sys (Boot Driver/Lavasoft AB)

—- EOF - GMER 1.0.15 —-

Attachments:

altoyes,

We have noticed that many people seeking help from us are coming with infections contracted from the use of P2P programs.

P2P programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

This article from InfoWorld illustrates perfectly the dangers of a poorly configured P2P program.
http://www.infoworld.com/article/07/09/06/…ID-theft_1.html

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

If you wish to keep it, please do not use it until your computer is cleaned.

I would recommend that you uninstall uTorrent, however that choice is up to you.

To remove uTorrent, follow the instructions below:

Please go to Start Menu > Control Panel > Add/ Remove Programs
Scroll Down and locate the following programs:

  • uTorrent
Select the program, then select remove.
(if the program is not listed don't be alarmed, just continue)

Exit the Control Panel when finished.

- - - - - Next - - - - -

Please download ComboFix from one of these locations:

Link 1
Link 2

A guide can be found here

* IMPORTANT : Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
*Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.
When finished, it will produce a log for you. The log will be located here C:\ComboFix.txt (Provided 'C' is your root directory)
Notes:
  • Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it at least 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".

On your next post please provide:
  • ComboFix.txt

ComboFix 09-07-25.08 - marion willow 27/07/2009 7:11.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.735.375 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\windows\system32\AVSredirect.dll
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.

2009-07-24 00:52 . 2009-07-26 19:56 ——– d—–w- c:\windows\system32\CatRoot_bak
2009-07-24 00:40 . 2009-02-06 17:22 2136064 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-07-24 00:40 . 2009-02-06 17:24 2180480 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-07-24 00:40 . 2009-02-06 16:49 2015744 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-07-24 00:40 . 2009-02-06 16:49 2057728 -c—-w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-07-24 00:27 . 2008-10-24 11:10 453632 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-24 00:25 . 2008-06-13 13:10 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-07-23 21:26 . 2007-05-17 07:30 318976 —-a-w- c:\windows\system32\avisynth.dll
2009-07-23 21:26 . 2004-02-22 00:11 719872 —-a-w- c:\windows\system32\devil.dll
2009-07-23 21:26 . 2004-01-24 14:00 70656 —-a-w- c:\windows\system32\yv12vfw.dll
2009-07-23 21:26 . 2004-01-24 14:00 70656 —-a-w- c:\windows\system32\i420vfw.dll
2009-07-23 21:26 . 2009-07-23 21:26 ——– d—–w- c:\program files\AviSynth 2.5
2009-07-23 20:48 . 2009-06-27 04:35 1008896 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-07-23 04:31 . 2009-07-23 04:31 ——– d—–w- c:\documents and settings\marion willow\Local Settings\Application Data\AVG Security Toolbar
2009-07-23 04:23 . 2009-07-23 04:23 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-07-23 04:23 . 2009-07-23 04:23 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-07-23 04:23 . 2009-07-23 04:23 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-23 04:22 . 2009-07-26 20:41 ——– d—–w- c:\windows\system32\drivers\Avg
2009-07-23 04:22 . 2009-07-23 20:48 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-07-23 04:22 . 2009-07-23 04:22 ——– d—–w- c:\program files\AVG
2009-07-23 04:22 . 2009-07-26 20:10 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-07-23 01:56 . 2009-07-23 04:23 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-23 01:47 . 2004-08-03 14:56 236544 -c–a-w- c:\windows\system32\dllcache\smi2smir.exe
2009-07-23 01:46 . 2004-08-03 14:56 22528 -c–a-w- c:\windows\system32\dllcache\lpdsvc.dll
2009-07-23 01:45 . 2004-08-03 12:31 480256 -c–a-w- c:\windows\system32\dllcache\cintsetp.exe
2009-07-23 01:44 . 2003-03-24 06:52 188480 -c–a-w- c:\windows\system32\dllcache\cfgwiz.exe
2009-07-23 01:44 . 2003-03-24 06:52 20540 -c–a-w- c:\windows\system32\dllcache\author.dll
2009-07-23 01:44 . 2003-03-24 06:52 16439 -c–a-w- c:\windows\system32\dllcache\author.exe
2009-07-23 01:44 . 2003-03-24 06:52 16439 -c–a-w- c:\windows\system32\dllcache\admin.exe
2009-07-23 01:44 . 2003-03-24 06:52 20540 -c–a-w- c:\windows\system32\dllcache\admin.dll
2009-07-23 01:44 . 2004-08-03 14:56 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-07-23 01:44 . 2009-07-23 01:44 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft
2009-07-23 01:42 . 2003-03-31 12:00 16384 -c–a-w- c:\windows\system32\dllcache\isignup.exe
2009-07-23 01:29 . 2003-03-31 12:00 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-07-23 01:29 . 2003-03-31 12:00 24661 —-a-w- c:\windows\system32\spxcoins.dll
2009-07-23 01:29 . 2003-03-31 12:00 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll
2009-07-23 01:29 . 2003-03-31 12:00 13312 —-a-w- c:\windows\system32\irclass.dll
2009-07-23 00:47 . 2009-07-23 00:47 ——– d—–w- c:\documents and settings\marion willow\Application Data\AVG8
2009-07-19 04:47 . 2009-07-19 04:47 ——– d—–w- c:\documents and settings\marion willow\Application Data\DriveHQHOOK
2009-07-18 00:50 . 2009-07-18 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\MyHeritage
2009-07-18 00:50 . 2009-07-18 00:50 ——– d—–w- c:\documents and settings\marion willow\Application Data\MyHeritage
2009-07-17 05:00 . 2009-07-17 05:00 ——– d—–w- c:\program files\MSXML 4.0
2009-07-16 20:06 . 2009-07-16 20:06 ——– d—–w- c:\documents and settings\marion willow\Local Settings\Application Data\Scansoft
2009-07-16 20:02 . 2009-07-16 20:02 50 —-a-w- c:\windows\system32\bridf07a.dat
2009-07-16 20:00 . 2009-07-16 20:00 ——– d—–w- C:\Brother
2009-07-16 20:00 . 2003-11-28 08:57 0 —-a-w- c:\windows\brdfxspd.dat
2009-07-16 20:00 . 2006-01-16 15:03 126976 —-a-w- c:\windows\system32\BrfxD05a.dll
2009-07-16 20:00 . 2007-04-27 07:13 61440 —-a-w- c:\windows\system32\BrMfNt.dll
2009-07-16 20:00 . 2007-01-18 03:51 163840 —-a-w- c:\windows\system32\NSSearch.dll
2009-07-16 20:00 . 2006-07-07 02:40 73728 —-a-w- c:\windows\system32\BRCrypt.dll
2009-07-16 20:00 . 2002-11-26 03:43 106496 —-a-w- c:\windows\system32\BrMuSNMP.dll
2009-07-16 20:00 . 2007-02-15 03:54 131072 —-a-w- c:\windows\brunin03.dll
2009-07-16 19:59 . 2009-07-16 19:59 ——– d—–w- c:\documents and settings\marion willow\Application Data\InstallShield
2009-07-16 19:58 . 2009-07-16 19:58 ——– d—–w- c:\program files\Nuance
2009-07-16 19:57 . 2009-07-16 19:57 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2009-07-16 19:57 . 2009-07-16 19:57 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2009-07-16 19:56 . 2009-07-16 19:57 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-07-16 19:56 . 2009-07-16 19:56 ——– d—–w- c:\program files\ScanSoft
2009-07-16 19:54 . 2009-07-16 19:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Brother
2009-07-16 19:48 . 2009-07-16 20:01 ——– d—–w- c:\program files\Brother
2009-07-16 01:43 . 2009-07-16 01:43 ——– d—–w- c:\documents and settings\marion willow\Application Data\Malwarebytes
2009-07-16 01:43 . 2009-07-13 03:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-16 01:43 . 2009-07-16 01:43 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-16 01:43 . 2009-07-16 01:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-16 01:43 . 2009-07-13 03:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-16 01:17 . 2009-07-16 01:17 ——– d—–w- c:\program files\HP
2009-07-16 01:17 . 2007-11-22 02:13 1191520 —-a-w- c:\windows\system32\XWheel.dll
2009-07-16 01:17 . 2007-11-22 02:11 151136 —-a-w- c:\windows\system32\Hook.dll
2009-07-16 01:17 . 2007-11-22 02:05 983040 —-a-w- c:\windows\system32\MousePage.dll
2009-07-16 01:17 . 2006-02-06 06:26 30848 —-a-w- c:\windows\system32\drivers\HidMouse.sys
2009-07-16 01:12 . 2009-07-16 01:12 ——– d—–w- c:\documents and settings\Administrator
2009-07-16 00:16 . 2009-07-16 00:16 ——– d—–w- c:\windows\SxsCaPendDel
2009-07-15 22:27 . 2009-07-16 00:50 ——– d—–w- c:\documents and settings\marion willow\Local Settings\Application Data\LastPass
2009-07-15 10:54 . 2009-07-15 10:54 ——– d—–w- c:\program files\ERUNT
2009-07-11 22:49 . 2006-09-21 13:01 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-07-11 22:49 . 2009-07-14 04:50 ——– d—–w- c:\program files\WinMerge
2009-07-09 00:49 . 2001-08-17 12:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2009-07-09 00:49 . 2008-04-13 19:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2009-07-09 00:49 . 2004-08-03 12:58 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-07-08 01:59 . 2009-07-23 22:39 ——– d—–w- c:\documents and settings\marion willow\Application Data\FileZilla
2009-07-07 11:37 . 2009-07-07 11:37 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-07-07 11:36 . 2009-07-07 11:36 1630560 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-07-07 11:36 . 2009-07-07 11:36 2353480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-07-05 23:33 . 2009-07-19 04:47 ——– d—–w- c:\documents and settings\marion willow\Application Data\DriveHQ
2009-07-05 23:32 . 2009-07-05 23:32 ——– d—–w- c:\program files\DriveHQ
2009-07-05 01:23 . 2009-07-05 01:23 58 —-a-w- c:\windows\system32\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2009-07-05 01:23 . 2009-07-05 01:23 58 —-a-w- c:\documents and settings\marion willow\Local Settings\Application Data\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2009-07-05 01:23 . 2009-07-05 01:23 ——– d—–w- c:\documents and settings\marion willow\Application Data\DonationCoder
2009-07-05 01:22 . 2009-07-23 11:54 ——– d—–w- c:\program files\ScreenshotCaptor
2009-07-05 01:22 . 2009-07-05 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\DonationCoder
2009-07-04 04:47 . 2009-07-04 04:47 ——– d–h–w- c:\windows\PIF
2009-07-04 03:44 . 2009-07-04 03:44 ——– d—–w- c:\program files\Lame for Audacity
2009-07-04 02:51 . 2009-07-19 06:32 ——– d—–w- c:\documents and settings\marion willow\.thinupload
2009-07-03 10:57 . 2009-07-03 10:57 314712 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-07-03 10:57 . 2009-07-03 10:57 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-07-03 10:57 . 2009-07-03 10:57 169312 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-07-03 10:56 . 2009-07-03 10:56 348496 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-07-03 10:56 . 2009-07-03 10:56 298336 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-07-03 10:56 . 2009-07-03 10:56 84832 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-07-03 10:54 . 2009-07-03 10:54 246128 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-07-03 10:54 . 2009-07-03 10:54 40288 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-07-03 10:54 . 2009-07-03 10:54 64160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-07-03 10:54 . 2009-07-03 10:54 85352 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-07-03 10:54 . 2009-07-03 10:54 664424 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-07-03 10:54 . 2009-07-03 10:54 563064 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-07-03 10:54 . 2009-07-03 10:54 566632 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-07-03 10:53 . 2009-07-03 10:53 629072 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-07-03 10:53 . 2009-07-03 10:53 520024 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-07-03 10:53 . 2009-07-03 10:53 1029456 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-07-02 03:24 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-07-02 02:45 . 2009-07-26 20:06 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft
2009-07-02 00:51 . 2009-07-02 00:51 ——– d—–w- c:\windows\Sun
2009-07-01 23:37 . 2009-07-01 23:38 ——– d—–w- c:\program files\DVD Decrypter
2009-07-01 09:08 . 2009-07-01 09:08 ——– d—–w- c:\program files\Bibliopolis
2009-07-01 09:05 . 2009-07-01 09:05 ——– d—–w- c:\documents and settings\marion willow\Local Settings\Application Data\FileMaker
2009-07-01 08:12 . 2009-07-01 08:12 ——– d—–w- C:\New Folder
2009-07-01 05:18 . 2009-07-01 05:18 ——– d—–w- c:\documents and settings\marion willow\Local Settings\Application Data\Identities
2009-07-01 05:17 . 2009-07-26 19:47 ——– d—–w- c:\documents and settings\marion willow\Application Data\MailWasherFree
2009-07-01 05:17 . 2009-07-01 05:17 ——– d—–w- c:\program files\FireTrust
2009-07-01 01:32 . 2009-07-01 01:33 ——– d—–w- c:\documents and settings\marion willow\Application Data\vlc

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 21:08 . 2009-06-30 09:12 ——– d—–w- c:\documents and settings\marion willow\Application Data\uTorrent
2009-07-23 21:27 . 2009-06-30 08:57 ——– d—–w- c:\program files\SUPER
2009-07-23 15:13 . 2009-06-30 05:39 76487 —-a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-07-23 01:41 . 2009-06-30 05:36 22720 —-a-w- c:\windows\system32\emptyregdb.dat
2009-07-20 22:21 . 2009-06-30 11:30 ——– d—–w- c:\program files\FileZilla FTP Client
2009-07-18 13:55 . 2009-06-30 09:22 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-18 00:52 . 2009-06-30 08:54 ——– d—–w- c:\program files\MyHeritage
2009-07-16 21:46 . 2009-06-30 15:34 1 —-a-w- c:\documents and settings\marion willow\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-16 20:07 . 2009-06-30 06:59 17744 —-a-w- c:\documents and settings\marion willow\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-16 20:03 . 2009-06-30 11:47 34 —-a-w- c:\windows\system32\FD203A.DAT
2009-07-16 20:00 . 2009-06-30 11:45 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-16 19:57 . 2009-06-30 07:05 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-16 00:42 . 2009-06-30 09:03 ——– d—–w- c:\program files\Yahoo!
2009-07-04 22:27 . 2009-06-30 09:33 ——– d—–w- c:\program files\Foxit Software
2009-07-03 10:54 . 2009-06-30 11:35 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-02 00:05 . 2009-06-30 11:46 ——– d—–w- c:\program files\Brownie
2009-07-01 05:31 . 2009-06-30 10:21 ——– d—–w- c:\documents and settings\marion willow\Application Data\Ahead
2009-07-01 01:32 . 2009-06-30 10:00 ——– d—–w- c:\program files\VLC player
2009-06-30 15:33 . 2009-06-30 15:33 ——– d—–w- c:\documents and settings\marion willow\Application Data\OpenOffice.org
2009-06-30 12:06 . 2009-06-30 09:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-30 11:49 . 2009-06-30 11:49 ——– d—–r- c:\documents and settings\marion willow\Application Data\FX
2009-06-30 11:45 . 2009-06-30 11:45 ——– d—–w- c:\program files\Fuji Xerox
2009-06-30 11:36 . 2009-06-30 11:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-30 11:34 . 2009-06-30 11:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-30 11:34 . 2009-06-30 11:34 ——– d—–w- c:\program files\QuickTime Alternative
2009-06-30 11:31 . 2009-06-30 11:31 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-30 11:31 . 2009-06-30 11:31 ——– d—–w- c:\program files\Lavasoft
2009-06-30 11:08 . 2009-06-30 11:08 ——– d—–w- c:\program files\Any Video Converter
2009-06-30 11:08 . 2009-06-30 11:08 ——– d—–w- c:\documents and settings\marion willow\Application Data\Any Video Converter
2009-06-30 10:54 . 2009-06-30 10:54 ——– d—–w- c:\program files\Audacity
2009-06-30 10:39 . 2009-06-30 10:39 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-06-30 10:39 . 2009-06-30 10:39 ——– d—–w- c:\program files\DVD Shrink
2009-06-30 10:30 . 2009-06-30 10:30 ——– d—–w- c:\program files\Recuva
2009-06-30 10:23 . 2009-06-30 10:23 ——– d—–w- c:\program files\7-Zip
2009-06-30 10:22 . 2009-06-30 10:18 ——– d—–w- c:\program files\Common Files\Ahead
2009-06-30 10:18 . 2009-06-30 10:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Nero
2009-06-30 10:18 . 2009-06-30 10:18 ——– d—–w- c:\program files\Nero
2009-06-30 10:12 . 2009-06-30 10:12 ——– d—–w- c:\program files\Chami
2009-06-30 10:08 . 2009-06-30 09:38 ——– d—–w- c:\program files\NetVisualize
2009-06-30 09:52 . 2009-06-30 09:52 ——– d—–w- c:\program files\C-Media 3D Audio
2009-06-30 09:42 . 2009-06-30 09:42 ——– d—–w- c:\program files\ReNamer
2009-06-30 09:13 . 2009-06-30 09:13 ——– d—–w- c:\program files\uTorrent
2009-06-30 09:07 . 2009-06-30 09:07 ——– d—–w- c:\documents and settings\marion willow\Application Data\The Complete Genealogy Reporter - FTB
2009-06-30 09:03 . 2009-06-30 09:02 ——– d—–w- c:\program files\CCleaner
2009-06-30 08:56 . 2009-06-30 08:35 ——– d—–w- c:\program files\OpenOffice.org 3
2009-06-30 08:35 . 2009-06-30 08:35 ——– d—–w- c:\program files\JRE
2009-06-30 08:34 . 2009-06-30 08:34 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-30 08:34 . 2009-06-30 08:34 ——– d—–w- c:\program files\Java
2009-06-30 07:38 . 2009-06-30 07:37 ——– d—–w- c:\program files\SpywareBlaster
2009-06-30 07:38 . 2009-06-30 07:38 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-30 07:34 . 2009-06-30 07:34 0 —-a-w- c:\windows\nsreg.dat
2009-06-30 07:07 . 2009-06-30 07:07 ——– d—–w- c:\program files\SiSVGA
2009-06-30 07:06 . 2009-06-30 07:06 ——– d—–w- c:\program files\SiS Compatible VGA V2.18
2009-06-30 05:40 . 2009-06-30 05:40 ——– d—–w- c:\program files\microsoft frontpage
2009-06-16 14:55 . 2004-08-03 14:56 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2003-03-31 12:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:27 . 2004-08-03 14:56 1290752 —-a-w- c:\windows\system32\quartz.dll
2009-05-07 15:44 . 2004-08-03 14:56 344064 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 04:52 . 2004-08-03 14:56 659456 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:52 . 2004-08-03 14:56 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-07-15 21:41 . 2009-06-30 07:33 137208 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2006-05-03 10:06 . 2009-06-30 08:57 163328 –sha-r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2009-06-30 08:57 31232 –sha-r- c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2009-06-30 08:57 216064 –sha-r- c:\windows\system32\nbDX.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-07-26_21.05.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-26 21:08 . 2009-07-26 21:09 16384 c:\windows\Temp\Perflib_Perfdata_7d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-27 1008896]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-27 04:35 1008896 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-27 1008896]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-27 1008896]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-06-30 288048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS KHooker"="c:\windows\system32\khooker.exe" [2003-05-28 294912]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-23 1948440]
"Cmaudio"="cmicnfg.cpl" [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-23 04:23 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe"
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe"
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "c:\documents and settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
"ControlCenter3"=c:\program files\Brother\ControlCenter3\brctrcen.exe /autorun
"BrMfcWnd"=c:\program files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\DL torrent FULL version\\Foxit.PDF.Editor.v1.5.2722-TE\\Foxit.PDF.Editor.v1.5.2722-TE\\Crack\\PDFEdit.exe"=
"d:\\DL Progs IN USE\\foxit PDF editor v1\\Crack\\PDFEdit.exe"=
"c:\\Program Files\\Foxit Software\\PDF Editor\\PDFEdit.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [30/06/2009 9:35 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [23/07/2009 2:23 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [23/07/2009 2:23 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [23/07/2009 2:22 PM 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [23/07/2009 2:22 PM 298776]
R2 DriveHQ FileManagerFun;DriveHQ FileManagerFun;c:\program files\DriveHQ\DriveHQ FileManager\DHQFMSvc.exe [6/07/2009 9:32 AM 45568]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [10/03/2009 5:06 AM 1029456]
.
Contents of the 'Scheduled Tasks' folder

2009-07-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 10:54]
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\marion willow\Application Data\Mozilla\Firefox\Profiles\knxwckl1.default\
FF - prefs.js: browser.startup.homepage - hxxp://worldpeacepoll.com/fabradio/wp-login.php
FF - prefs.js: keyword.URL - hxxp://au.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_au&p=

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-27 07:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-07-26 7:19
ComboFix-quarantined-files.txt 2009-07-26 21:19

Pre-Run: 23,678,554,112 bytes free
Post-Run: 23,641,448,448 bytes free

331 — E O F — 2009-07-26 19:13

altoyes,

I have a few questions:

Have you run Combofix on a previous occasion?
Did the Combofix scan "hang" when you ran it?

- - - - - Next - - - - -

It is important to run a current version of Combofix.
I would like for you to delete the version you have on your computer and install a new one.

Please locate Combofix.exe (it should be on your desktop) and delete it.

- - - - - Next - - - - -

Please download ComboFix from one of these locations:

Link 1
Link 2

A guide can be found here

* IMPORTANT : Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
*Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.
When finished, it will produce a log for you. The log will be located here C:\ComboFix.txt (Provided 'C' is your root directory)
Notes:
  • Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it at least 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".

On your next post please provide:
  • ComboFix.txt
  • Answer my questions above
  • Tell me how your computer is running at the moment

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI