This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help removing renos.OI virus from Vista

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI, complete computer novice trying to deal with virus. I have backed up registry as advised. I have run DDS and have the following result: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 11:02:59.04 on 22/07/2009 Internet Explorer: 8.0.6001.18783 BrowserJavaVersion: 1.6.0_13 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.3070.1753 [GMT 1:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Spyware Doctor *disabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\svchost.exe -k LocalService C:\Windows\System32\svchost.exe -k NetworkService C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Kontiki\KService.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\MagicTune Premium\MagicTuneEngine.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\temp\42217630.tmp C:\Windows\system32\SearchProtocolHost.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\System32\Socks.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\ehome\ehtray.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Windows\ehome\ehmsas.exe C:\Program Files\Registry Mechanic\RMTray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Strokeit\strokeit.exe C:\Users\mw\Program Files\DNA\btdna.exe C:\Program Files\MagicTune Premium\GammaTray.exe C:\Program Files\SEC\Natural Color Pro\NCProTray.exe C:\Program Files\NETGEAR\WG111T\wlan111t.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\mw\Downloads\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.bbc.co.uk/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll uRun: [] uRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [RegistryMechanic] c:\program files\registry mechanic\RMTray.exe /S uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [StrokeIt] c:\program files\strokeit\strokeit.exe uRun: [BitTorrent DNA] "c:\users\mw\program files\dna\btdna.exe" mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [WinsysMon] c:\windows\system32\Socks.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\gammat~1.lnk - c:\program files\magictune premium\GammaTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\ncprot~1.lnk - c:\program files\sec\natural color pro\NCProTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111t\wlan111t.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab TCP: NameServer = 85.255.112.75,85.255.112.95 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL AppInit_DLLs: avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\mw\appdata\roaming\mozilla\firefox\profiles\p5hghz8l.default\ FF - prefs.js: browser.startup.homepage - hxxp://apps.facebook.com/livescrabble/&source=feed.playing|http://www.lawnexperts.co.uk/dandelions-as-a-lawn-pest.html FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\program files\mozilla firefox\plugins\npBBCPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\users\mw\program files\dna\plugins\npbtdna.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-7-4 335752] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-5 108552] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-17 907032] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-4 298776] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-4-5 747912] =============== Created Last 30 ================ 2009-07-22 10:28 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-22 09:36 126,464 a——- c:\users\mw\appdata\roaming\1.exe 2009-07-22 08:48 –d—– c:\programdata\Simply Super Software 2009-07-22 08:48 –d—– c:\program files\Trojan Remover 2009-07-22 08:48 –d—– c:\progra~2\Simply Super Software 2009-07-21 19:59 89,929 a——- c:\users\mw\appdata\roaming\License.v.10.31.exe 2009-07-19 05:19 86,321 a——- c:\windows\system32\Socks.exe ==================== Find3M ==================== 2009-07-17 11:41 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-06-27 08:59 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-05-09 06:50 915,456 a——- c:\windows\system32\wininet.dll 2009-05-09 06:34 71,680 a——- c:\windows\system32\iesetup.dll 2009-04-30 13:37 293,376 a——- c:\windows\system32\psisdecd.dll 2009-04-30 13:37 428,544 a——- c:\windows\system32\EncDec.dll 2009-04-23 13:43 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-04-23 13:42 636,928 a——- c:\windows\system32\localspl.dll 2008-12-07 11:09 143,360 a——- c:\windows\inf\infstrng.dat 2008-12-07 11:09 51,200 a——- c:\windows\inf\infpub.dat 2008-12-07 11:09 86,016 a——- c:\windows\inf\infstor.dat 2008-09-09 08:45 174 a–sh— c:\program files\desktop.ini 2008-09-09 08:35 665,600 a——- c:\windows\inf\drvindex.dat 2008-05-07 16:53 56 a—h— c:\programdata\ezsidmv.dat 2008-05-07 16:53 56 a—h— c:\progra~2\ezsidmv.dat 2008-04-06 21:59 35,960,792 a——- c:\program files\avg75free_519a1276.exe 2008-04-06 17:16 874,448 a——- c:\program files\BitTorrent-6.0.3.exe 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 11:03:23.74 =============== and UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT REMOVED ==== End Of File =========================== I have tried to install Malwarebytes but my computer wont let me. What next? Any help much appreciated. Miles
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.


Please do the following:


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



NOTE: If this program will not run, try it in safe mode - or try renaming it to gmer.com and run it
Hi There. When I try to open the gmer file - even if under a different name - the hourglass just hangs and I can only crash my computer to get rid of it. tried in safe mode but cant get an internet connection to download. Sorry if i'm missing something obvious?
Hi,

Please do the following:


Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

Sorry, since last post I managed to get gmer working in safe mode:

Results here:

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-22 21:46:26
Windows 6.0.6001 Service Pack 1


—- System - GMER 1.0.15 —-

Code 85A02320 ZwEnumerateKey
Code 8595F2D8 ZwFlushInstructionCache
Code 8596A2C5 IofCallDriver
Code 85A0630E IofCompleteRequest
Code 859642DD ZwSaveKey
Code 8596331D ZwSaveKeyEx

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.15 —-

Do you want me to follow instruction above. I will wait for your lead.

Miles
ComboFix 09-07-22.01 - mw 22/07/2009 22:46.1.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.3070.2445 [GMT 1:00] Running from: c:\users\[removed]\Desktop\Combo-Fix.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Spyware Doctor *disabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500 c:\$recycle.bin\S-1-5-21-3759493215-2661729718-452490957-1000 c:\users\mw\AppData\Roaming\1.exe c:\windows\system32\drivers\ESQULqxrttpbeferxtiyidnvcviyxasxvkuii.sys c:\windows\System32\ESQULfomnbtcqhftpeodryviqrolxfxdshvni.dll c:\windows\system32\ESQULykbmcauqxipmdcrswtrdoqpmdbxugiht.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Service_ESQULserv.sys ——-\Service_ESQULserv.sys ((((((((((((((((((((((((( Files Created from 2009-06-22 to 2009-07-22 ))))))))))))))))))))))))))))))) . 2009-07-22 21:50 . 2009-07-22 21:55 ——– d—–w- c:\users\mw\AppData\Local\temp 2009-07-22 21:50 . 2009-07-22 21:50 ——– d—–w- c:\users\user\AppData\Local\temp 2009-07-22 21:50 . 2009-07-22 21:50 ——– d—–w- c:\users\Mrs Boss\AppData\Local\temp 2009-07-22 19:30 . 2009-07-22 19:30 ——– d—–w- c:\users\mw\AppData\Local\Apple Computer 2009-07-22 19:26 . 2009-07-22 19:26 ——– d—–w- c:\users\mw\AppData\Local\Adobe 2009-07-22 10:12 . 2009-07-22 10:12 ——– d—–w- c:\program files\ERUNT 2009-07-22 09:32 . 2009-07-22 09:32 89437 —-a-w- c:\users\user\AppData\Roaming\License.v.10.31.exe 2009-07-22 07:48 . 2009-07-22 07:48 ——– d—–w- c:\progra~2\Simply Super Software 2009-07-21 18:59 . 2009-07-21 18:59 89929 —-a-w- c:\users\mw\AppData\Roaming\License.v.10.31.exe 2009-07-19 04:19 . 2009-07-19 04:19 86321 —-a-w- c:\windows\system32\Socks.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-22 21:57 . 2008-06-26 19:19 ——– d—–w- c:\progra~2\Kontiki 2009-07-22 21:43 . 2008-04-06 16:16 ——– d—–w- c:\users\mw\AppData\Roaming\DNA 2009-07-22 07:22 . 2008-07-04 21:32 ——– d—–w- c:\progra~2\avg8 2009-07-21 19:24 . 2008-11-04 17:45 1 —-a-w- c:\users\mw\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2009-07-21 19:14 . 2008-04-09 21:12 ——– d—–w- c:\progra~2\Apple Computer 2009-07-21 19:11 . 2008-04-06 16:16 ——– d—–w- c:\users\mw\AppData\Roaming\BitTorrent 2009-07-21 18:59 . 2009-02-01 12:33 ——– d—–w- c:\program files\QuickTime 2009-07-21 17:16 . 2009-03-04 22:22 ——– d—–w- c:\users\mw\AppData\Roaming\Spotify 2009-07-17 10:41 . 2008-07-04 21:33 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2009-06-27 07:59 . 2008-07-04 21:33 11952 —-a-w- c:\windows\system32\avgrsstx.dll 2009-06-27 07:59 . 2008-04-06 21:00 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-06-02 16:05 . 2009-06-02 16:05 ——– d—–w- c:\program files\jZip 2009-06-01 21:35 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2009-05-12 08:38 . 2009-02-05 12:27 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2009-05-09 05:50 . 2009-06-15 07:15 915456 —-a-w- c:\windows\system32\wininet.dll 2009-05-09 05:34 . 2009-06-15 07:15 71680 —-a-w- c:\windows\system32\iesetup.dll 2009-04-30 12:37 . 2009-06-15 07:16 293376 —-a-w- c:\windows\system32\psisdecd.dll 2009-04-30 12:37 . 2009-06-15 07:16 428544 —-a-w- c:\windows\system32\EncDec.dll 2008-04-06 20:59 . 2008-04-06 20:38 35960792 —-a-w- c:\program files\avg75free_519a1276.exe 2008-04-06 16:16 . 2008-04-06 16:16 874448 —-a-w- c:\program files\BitTorrent-6.0.3.exe 2009-07-22 09:34 . 2008-07-12 10:35 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] "RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2008-07-03 812952] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920] "StrokeIt"="c:\program files\Strokeit\strokeit.exe" [2005-02-17 21504] "BitTorrent DNA"="c:\users\mw\Program Files\DNA\btdna.exe" [2008-12-19 342848] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-26 185896] "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832] "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-27 1948440] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888] "WinsysMon"="c:\windows\system32\Socks.exe" [2009-07-19 86321] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-07-06 4669440] c:\users\mw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\ GammaTray.lnk - c:\program files\MagicTune Premium\GammaTray.exe [2008-8-5 36864] NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2008-8-5 49220] NETGEAR WG111T Smart Wizard.lnk - c:\program files\NETGEAR\WG111T\wlan111t.exe [2008-8-8 884840] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux3"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{83E8A40A-D1EE-4EEC-B21F-524578647B36}"= UDP:c:\program files\DNA\btdna.exe:DNA "{3CA09B8A-5D6E-48B0-9448-66E8C1E77C33}"= TCP:c:\program files\DNA\btdna.exe:DNA "{CF8CCE9D-85EA-4672-91F8-7AC69DDBB7E4}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent "{6258875D-EED7-473E-A0A2-46D87FEFBFCC}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent "TCP Query User{79CD550E-D5C0-4855-B865-BE33641FFA11}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent "UDP Query User{BFED147C-F51E-4D82-9361-20D5A2401443}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent "TCP Query User{3FF0AC97-B8D6-48CE-B31F-007E2B4FDFD9}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts "UDP Query User{44103EED-3424-49A4-9725-4DAABB8DD82C}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts "{5A7DAC17-D42F-4C61-999A-4896DA3FC2E7}"= c:\program files\Skype\Phone\Skype.exe:Skype "TCP Query User{F3FFEDEC-48A4-4959-81FC-81F012EF09C3}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver "UDP Query User{86FCB1E4-2800-4CBC-A25B-906222934890}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver "TCP Query User{658DA40A-2CB1-4784-89A5-0DFE15D8E6D0}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application "UDP Query User{1B7968C2-F69C-4243-8469-A82E4F16A28F}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application "{262B262D-04FB-4057-8DDA-F2AED735A549}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service "{9916B9C5-5B5A-42AA-A06E-E351EC619127}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service "{2D123E90-0440-4B5D-9709-342375B88D43}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service "{F9BCCCA2-5648-40AA-9B6D-11D8A8C40C96}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service "{6EDC104F-F90D-4EA8-A3E4-56F5F3E24BB6}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe "{C93C9C75-E941-4E4A-BC94-A12BD6CAF6EE}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe "{CCAA6C73-FB41-4DA3-B8C7-383F6ABDB1A0}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{86526343-A0E1-4179-B36C-8C2AAAC3C024}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{13AF98C9-2539-4F75-82D0-165EF407EF8E}"= UDP:c:\program files\DNA\btdna.exe:DNA "{4691734B-CD6A-4E20-BCE0-B8F0C0816E8B}"= TCP:c:\program files\DNA\btdna.exe:DNA "{24F3DC76-9748-4B57-AB01-9876B6DC2F55}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{DEE48412-1268-48F1-991E-19D57A8E66D1}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "TCP Query User{A4963C03-6429-4638-8B99-4AC8CF4B51F3}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify "UDP Query User{A2321309-CB60-49D8-9F83-4889BA49B839}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify "{C040CB8F-F30A-4BAD-9C75-BDD97469A871}"= UDP:16800:tv [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List] "c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [04/07/2008 22:33 335752] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [05/02/2009 13:27 108552] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [17/07/2009 11:41 907032] R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [04/07/2008 22:32 298776] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [05/04/2008 18:21 747912] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static] msiexec /fums {DEA7C946-B8CF-7B5F-1232-EC23295FF138} /qb . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.bbc.co.uk/ uInternet Settings,ProxyOverride = *.local FF - ProfilePath - c:\users\mw\AppData\Roaming\Mozilla\Firefox\Profiles\p5hghz8l.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=home#/home.php?ref=home|http://forums.whatthetech.com/Help_removing_renos_OI_virus_Vista_t105440.html#entry580634|http://cgi.ebay.co.uk/Canon-Outlet-EOS-40D-Refurbished_W0QQitemZ270430134549QQcmdZViewItemQQptZUK_CamerasPhoto_DigitalCamer as_DigitalCameras_JN?hash=item3ef6e46115&_trksid=p4634.c0.m14.l1262&_trkparms=%7C293%3A1%7C294%3A30 FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npBBCPlugin.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll FF - plugin: c:\users\mw\Program Files\DNA\plugins\npbtdna.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true. ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'Explorer.exe'(5940) c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll . ———————— Other Running Processes ———————— . c:\windows\System32\Ati2evxx.exe c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe c:\windows\System32\audiodg.exe c:\windows\System32\Ati2evxx.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Kontiki\KService.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\MagicTune Premium\MagicTuneEngine.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\AVG\AVG8\avgemc.exe c:\program files\AVG\AVG8\avgrsx.exe c:\program files\AVG\AVG8\avgnsx.exe c:\program files\AVG\AVG8\avgcsrvx.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2009-07-22 23:08 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-22 22:08 Pre-Run: 105,210,949,632 bytes free Post-Run: 105,495,965,696 bytes free 194 — E O F — 2009-07-22 12:49 Thanks. Is that it? how do I know if I am free? Can I, for example, do online banking etc? Miles
Hi,

Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\users\user\AppData\Roaming\License.v.10.31.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


Please do the same for the following files:

c:\users\mw\AppData\Roaming\License.v.10.31.exe
c:\windows\system32\Socks.exe

This path does not exist in my computer: c:\users\user\AppData\Roaming\License.v.10.31.exe

From c:\users\mw\AppData\Roaming\License.v.10.31.exe

VirSCAN.org Scanned Report :
Scanned time : 2009/07/23 19:30:23 (BST)
Scanner results: 45% Scanner(17/38) found malware!
File Name : License.v.10.31.exe
File Size : 89929 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : f8ffa2889d28de50e71ff5713397d5a6
SHA1 : f833641e603c0ebbbad96f9d8cac5b51ca41b386
Online report : http://virscan.org/report/b4ea6dead6e5c3c6…55ed841bf6.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090723202354 2009-07-23 0.57 Trojan.Win32.Alureon!IK
AhnLab V3 2009.07.24.00 2009.07.24 2009-07-24 0.81 -
AntiVir 8.2.0.228 7.1.5.23 2009-07-23 0.37 -
Antiy 2.0.18 20090722.2632680 2009-07-22 0.12 Trojan/Win32.TDSS.aiey
Arcavir 2009 200907231240 2009-07-23 0.07 Heur.W32
Authentium 5.1.1 200907231012 2009-07-23 1.14 W32/Trojan2.HUHV (Exact)
AVAST! 4.7.4 090722-0 2009-07-22 0.02 -
AVG 8.5.288 270.13.25/2256 2009-07-23 1.76 Generic14.GXG
BitDefender 7.81008.3838692 7.26765 2009-07-24 3.48 -
CA (VET) 9.0.0.143 31.6.6634 2009-07-23 7.29 -
ClamAV 0.95.2 9607 2009-07-23 0.03 Trojan.Agent-118946
Comodo 3.10 1746 2009-07-23 0.71 TrojWare.Win32.Agent.~AA
CP Secure 1.1.0.715 2009.07.24 2009-07-24 11.31 -
Dr.Web 4.44.0.9170 2009.07.23 2009-07-23 5.01 -
F-Prot 4.4.4.56 20090723 2009-07-23 1.12 W32/Trojan2.HUHV (exact)
F-Secure 5.51.6100 2009.07.23.10 2009-07-23 6.23 Packed.Win32.Tdss.x [AVP]
Fortinet 2.81-3.120 10.637 2009-07-23 0.21 W32/TDSS.AKGA!tr
GData 19.6646/19.408 20090723 2009-07-23 4.42 Packed.Win32.Tdss.x [Engine:A]
ViRobot 20090721 2009.07.21 2009-07-21 0.41 -
Ikarus T3.1.01.64 2009.07.23.73088 2009-07-23 3.67 Trojan.Win32.Alureon
JiangMin 11.0.800 2009.07.23 2009-07-23 3.37 Trojan/TDSS.daa
Kaspersky 5.5.10 2009.07.23 2009-07-23 0.10 Packed.Win32.Tdss.x
KingSoft 2009.2.5.15 2009.7.23.21 2009-07-23 0.48 -
McAfee 5.3.00 5686 2009-07-23 2.95 -
Microsoft 1.4903 2009.07.23 2009-07-23 5.73 Trojan:Win32/Alureon.BK
mks_vir 2.01 2009.07.15 2009-07-15 3.22 -
Norman 6.01.09 6.01.00 2009-07-22 16.01 -
Panda 9.05.01 2009.07.23 2009-07-23 1.88 -
Trend Micro 8.700-1004 6.308.02 2009-07-23 0.11 -
Quick Heal 10.00 2009.07.23 2009-07-23 1.06 -
Rising 20.0 21.39.34.00 2009-07-23 0.86 -
Sophos 2.88.0 4.43 2009-07-24 2.99 Mal/EncPk-IV
Sunbelt 5277 5277 2009-07-22 1.71 -
Symantec 1.3.0.24 20090723.003 2009-07-23 0.05 -
nProtect 20090721.02 4887961 2009-07-21 7.08 -
The Hacker 6.3.4.3 v00372 2009-07-22 0.63 Trojan/TDSS.ahzi
VBA32 3.12.10.9 20090722.1357 2009-07-22 2.32 -
VirusBuster 4.5.11.10 10.109.8/1824482 2009-07-23 2.35 -

The is the c:\windows\system32\Socks.exe scan…

VirSCAN.org Scanned Report :
Scanned time : 2009/07/23 19:37:14 (BST)
Scanner results: 11% Scanner(4/38) found malware!
File Name : Socks.exe
File Size : 86321 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 6608154434b36faf0e61b31aa8455590
SHA1 : 897872afdf5125cf8216b756bec4c8d53e23e6d1
Online report : http://virscan.org/report/d168e04fe72d34fa…5b6a073f98.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090723202354 2009-07-23 0.53 -
AhnLab V3 2009.07.24.00 2009.07.24 2009-07-24 1.36 -
AntiVir 8.2.0.228 7.1.5.23 2009-07-23 0.54 -
Antiy 2.0.18 20090722.2632680 2009-07-22 0.12 -
Arcavir 2009 200907231240 2009-07-23 0.04 -
Authentium 5.1.1 200907231012 2009-07-23 1.35 -
AVAST! 4.7.4 090722-0 2009-07-22 0.01 -
AVG 8.5.288 270.13.25/2256 2009-07-23 0.40 -
BitDefender 7.81008.3838692 7.26765 2009-07-24 3.41 -
CA (VET) 9.0.0.143 31.6.6634 2009-07-23 14.57 -
ClamAV 0.95.2 9607 2009-07-23 0.02 -
Comodo 3.10 1746 2009-07-23 1.13 -
CP Secure 1.1.0.715 2009.07.24 2009-07-24 11.25 -
Dr.Web 4.44.0.9170 2009.07.23 2009-07-23 5.00 -
F-Prot 4.4.4.56 20090723 2009-07-23 1.34 -
F-Secure 5.51.6100 2009.07.23.10 2009-07-23 0.07 Trojan-Downloader.Win32.VB.pjh [AVP]
Fortinet 2.81-3.120 10.637 2009-07-23 0.27 -
GData 19.6648/19.408 20090723 2009-07-23 4.62 Trojan-Downloader.Win32.VB.pjh [Engine:A]
ViRobot 20090721 2009.07.21 2009-07-21 0.42 -
Ikarus T3.1.01.64 2009.07.23.73088 2009-07-23 3.69 -
JiangMin 11.0.800 2009.07.23 2009-07-23 5.58 -
Kaspersky 5.5.10 2009.07.23 2009-07-23 0.06 Trojan-Downloader.Win32.VB.pjh
KingSoft 2009.2.5.15 2009.7.23.21 2009-07-23 0.59 -
McAfee 5.3.00 5686 2009-07-23 3.07 -
Microsoft 1.4903 2009.07.23 2009-07-23 5.30 -
mks_vir 2.01 2009.07.15 2009-07-15 3.33 -
Norman 6.01.09 6.01.00 2009-07-22 4.01 -
Panda 9.05.01 2009.07.23 2009-07-23 1.77 -
Trend Micro 8.700-1004 6.308.02 2009-07-23 0.03 -
Quick Heal 10.00 2009.07.23 2009-07-23 1.09 -
Rising 20.0 21.39.34.00 2009-07-23 0.97 Trojan.DL.Win32.VBcode.ec
Sophos 2.88.0 4.43 2009-07-24 3.00 -
Sunbelt 5277 5277 2009-07-22 1.46 -
Symantec 1.3.0.24 20090723.003 2009-07-23 0.06 -
nProtect 20090721.02 4887961 2009-07-21 6.19 -
The Hacker 6.3.4.3 v00372 2009-07-22 0.91 -
VBA32 3.12.10.9 20090722.1357 2009-07-22 1.75 -
VirusBuster 4.5.11.10 10.109.8/1824482 2009-07-23 2.30 -
Hi,

Please do the following;

Note: you must disable AVG or it will interfere with this script.

If you cannot disable it - please temporarily uninstall it.

AVG
Please open the AVG Control Center program -> double-click on the "AVG Resident Shield" component (looks like this: [external image: Posted Image]) -> deselect the "Turn on AVG Resident Shield" checkmark and save the setting.
When you need to enable the AVG Resident Shield, ( I will let you know when) just open the AVG Control Center program -> double-click on the "AVG Resident Shield" component -> select the "Turn on AVG Resident Shield" checkmark and save the setting.


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Help_removing_renos_OI_virus_Vista_t105440.html&view=findpost&p=580953#entry580953

Collect::
c:\users\user\AppData\Roaming\License.v.10.31.exe
c:\users\mw\AppData\Roaming\License.v.10.31.exe
c:\windows\system32\Socks.exe

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinsysMon"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
combo-fix:

ComboFix 09-07-22.01 - mw 23/07/2009 22:34.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.3070.1775 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\users\mw\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spyware Doctor *disabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

file zipped: c:\users\mw\AppData\Roaming\License.v.10.31.exe
file zipped: c:\users\user\AppData\Roaming\License.v.10.31.exe
file zipped: c:\windows\system32\Socks.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\mw\AppData\Roaming\License.v.10.31.exe
c:\users\user\AppData\Roaming\License.v.10.31.exe
c:\windows\system32\Socks.exe

.
((((((((((((((((((((((((( Files Created from 2009-06-23 to 2009-07-23 )))))))))))))))))))))))))))))))
.

2009-07-23 21:36 . 2009-07-23 21:36 ——– d—–w- c:\users\user\AppData\Local\temp
2009-07-23 21:36 . 2009-07-23 21:36 ——– d—–w- c:\users\Mrs Boss\AppData\Local\temp
2009-07-22 19:30 . 2009-07-22 19:30 ——– d—–w- c:\users\mw\AppData\Local\Apple Computer
2009-07-22 19:26 . 2009-07-22 19:26 ——– d—–w- c:\users\mw\AppData\Local\Adobe
2009-07-22 12:49 . 2009-06-15 15:24 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-07-22 12:49 . 2009-06-15 15:20 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-07-22 12:49 . 2009-06-15 15:20 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-07-22 12:49 . 2009-06-15 12:52 289792 —-a-w- c:\windows\system32\atmfd.dll
2009-07-22 10:12 . 2009-07-22 10:12 ——– d—–w- c:\program files\ERUNT
2009-07-22 07:48 . 2009-07-22 07:48 ——– d—–w- c:\progra~2\Simply Super Software

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-23 21:36 . 2008-06-26 19:19 ——– d—–w- c:\progra~2\Kontiki
2009-07-23 21:34 . 2008-04-06 16:16 ——– d—–w- c:\users\mw\AppData\Roaming\DNA
2009-07-23 18:59 . 2008-11-04 17:45 1 —-a-w- c:\users\mw\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-23 07:15 . 2008-11-04 17:32 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-23 06:55 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-07-22 07:22 . 2008-07-04 21:32 ——– d—–w- c:\progra~2\avg8
2009-07-21 19:14 . 2008-04-09 21:12 ——– d—–w- c:\progra~2\Apple Computer
2009-07-21 19:11 . 2008-04-06 16:16 ——– d—–w- c:\users\mw\AppData\Roaming\BitTorrent
2009-07-21 18:59 . 2009-02-01 12:33 ——– d—–w- c:\program files\QuickTime
2009-07-21 17:16 . 2009-03-04 22:22 ——– d—–w- c:\users\mw\AppData\Roaming\Spotify
2009-07-17 10:41 . 2008-07-04 21:33 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-27 07:59 . 2008-07-04 21:33 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-06-27 07:59 . 2008-04-06 21:00 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-02 16:05 . 2009-06-02 16:05 ——– d—–w- c:\program files\jZip
2009-05-12 08:38 . 2009-02-05 12:27 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-09 05:50 . 2009-06-15 07:15 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-15 07:15 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-04-30 12:37 . 2009-06-15 07:16 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-04-30 12:37 . 2009-06-15 07:16 428544 —-a-w- c:\windows\system32\EncDec.dll
2008-04-06 20:59 . 2008-04-06 20:38 35960792 —-a-w- c:\program files\avg75free_519a1276.exe
2008-04-06 16:16 . 2008-04-06 16:16 874448 —-a-w- c:\program files\BitTorrent-6.0.3.exe
2009-07-22 09:34 . 2008-07-12 10:35 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-07-22_21.55.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-22 12:49 . 2009-06-15 14:58 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\lpk.dll
+ 2009-07-22 12:49 . 2009-06-15 14:58 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 14:58 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\dciman32.dll
+ 2009-07-22 12:49 . 2009-06-15 12:45 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\atmlib.dll
+ 2009-07-22 12:49 . 2009-06-15 14:52 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\lpk.dll
+ 2009-07-22 12:49 . 2009-06-15 14:52 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 14:51 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\dciman32.dll
+ 2009-07-22 12:49 . 2009-04-11 06:28 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\atmlib.dll
+ 2009-07-22 12:49 . 2009-06-15 15:22 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\lpk.dll
+ 2009-07-22 12:49 . 2009-06-15 15:20 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 15:19 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\dciman32.dll
+ 2009-07-22 12:49 . 2009-06-15 15:19 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\atmlib.dll
+ 2009-07-22 12:49 . 2009-06-15 15:20 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 15:20 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\dciman32.dll
+ 2009-07-22 12:49 . 2009-06-15 15:04 24064 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\lpk.dll
+ 2009-07-22 12:49 . 2009-06-15 15:03 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 15:02 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\dciman32.dll
+ 2009-07-22 12:49 . 2009-06-15 15:02 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\atmlib.dll
+ 2009-07-22 12:49 . 2009-06-15 15:23 24064 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\lpk.dll
+ 2009-07-22 12:49 . 2009-06-15 15:22 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 15:21 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\dciman32.dll
+ 2009-07-22 12:49 . 2009-06-15 15:20 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\atmlib.dll
+ 2008-04-05 14:52 . 2009-07-23 12:41 51366 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-07-23 12:41 74194 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-04-05 13:09 . 2009-07-23 07:18 15562 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4018408940-227347569-2150742145-1001_UserData.bin
+ 2008-04-05 11:59 . 2009-07-23 18:26 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-05 11:59 . 2009-07-22 21:55 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-05 11:59 . 2009-07-22 21:55 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-05 11:59 . 2009-07-23 18:26 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-05 11:59 . 2009-07-22 21:55 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-05 11:59 . 2009-07-23 18:26 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-23 12:34 . 2009-07-23 12:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-07-23 12:34 . 2009-07-23 12:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-22 12:49 . 2009-06-30 11:31 101376 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.22895_none_8405f92d60197b7e\iecompat.dll
+ 2009-07-22 12:49 . 2009-06-30 03:37 101376 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.18805_none_83ddad9446b2dd62\iecompat.dll
+ 2009-07-22 12:49 . 2009-06-15 12:45 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 12:42 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 12:56 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 12:52 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 12:53 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 13:03 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 15:00 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6002.22152_none_b7fc28a4355e72c9\t2embed.dll
+ 2009-07-22 12:49 . 2009-06-15 14:53 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6002.18051_none_b7718b8f1c41b9a8\t2embed.dll
+ 2009-07-22 12:49 . 2009-06-15 15:26 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6001.22450_none_b613b6283839eaf7\t2embed.dll
+ 2009-07-22 12:49 . 2009-06-15 15:24 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6001.18272_none_b57678331f2ab896\t2embed.dll
+ 2009-07-22 12:49 . 2009-06-15 15:09 156160 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6000.21067_none_b4297fd83b155d73\t2embed.dll
+ 2009-07-22 12:49 . 2009-06-15 15:29 156160 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6000.16870_none_b38e38f92205f4f7\t2embed.dll
+ 2008-04-05 17:11 . 2009-07-23 18:24 283968 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2006-11-02 10:33 . 2009-07-23 12:40 598660 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-07-23 12:40 104580 c:\windows\System32\perfc009.dat
+ 2009-06-02 07:10 . 2009-07-23 12:34 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-06-02 07:10 . 2009-07-22 21:55 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-22 12:49 . 2009-06-17 08:02 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22160_none_f4b74f0181eee730\OESpamFilter.dat
+ 2009-07-22 12:49 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18056_none_f43e83de68c3c37f\OESpamFilter.dat
+ 2009-07-22 12:49 . 2009-06-17 07:30 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22459_none_f2e4af9f84b85a2a\OESpamFilter.dat
+ 2009-07-22 12:49 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18278_none_f24470cc6babdbc4\OESpamFilter.dat
+ 2009-07-22 12:49 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21074_none_f0e3a5eb87a6b883\OESpamFilter.dat
+ 2009-07-22 12:49 . 2009-06-17 07:36 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16876_none_f05c31926e871825\OESpamFilter.dat
- 2006-11-02 10:22 . 2009-07-22 12:48 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-07-23 12:47 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 12:47 . 2009-07-23 07:16 1588024 c:\windows\System32\FNTCACHE.DAT
- 2006-11-02 12:47 . 2009-07-22 20:48 1588024 c:\windows\System32\FNTCACHE.DAT
+ 2009-07-23 21:32 . 2009-07-23 21:33 6299648 c:\windows\ERDNT\Hiv-backup\schema.dat
+ 2006-11-02 10:24 . 2009-07-07 15:10 24539592 c:\windows\System32\mrt.exe
+ 2009-07-23 06:55 . 2009-07-23 06:55 15706112 c:\windows\Installer\66ece.msp
+ 2009-06-02 09:23 . 2009-07-23 06:55 171961867 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2008-07-03 812952]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"StrokeIt"="c:\program files\Strokeit\strokeit.exe" [2005-02-17 21504]
"BitTorrent DNA"="c:\users\mw\Program Files\DNA\btdna.exe" [2008-12-19 342848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-26 185896]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-27 1948440]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-07-06 4669440]

c:\users\mw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
GammaTray.lnk - c:\program files\MagicTune Premium\GammaTray.exe [2008-8-5 36864]
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2008-8-5 49220]
NETGEAR WG111T Smart Wizard.lnk - c:\program files\NETGEAR\WG111T\wlan111t.exe [2008-8-8 884840]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{83E8A40A-D1EE-4EEC-B21F-524578647B36}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{3CA09B8A-5D6E-48B0-9448-66E8C1E77C33}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{CF8CCE9D-85EA-4672-91F8-7AC69DDBB7E4}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{6258875D-EED7-473E-A0A2-46D87FEFBFCC}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{79CD550E-D5C0-4855-B865-BE33641FFA11}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{BFED147C-F51E-4D82-9361-20D5A2401443}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"TCP Query User{3FF0AC97-B8D6-48CE-B31F-007E2B4FDFD9}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{44103EED-3424-49A4-9725-4DAABB8DD82C}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"{5A7DAC17-D42F-4C61-999A-4896DA3FC2E7}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{F3FFEDEC-48A4-4959-81FC-81F012EF09C3}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{86FCB1E4-2800-4CBC-A25B-906222934890}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{658DA40A-2CB1-4784-89A5-0DFE15D8E6D0}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{1B7968C2-F69C-4243-8469-A82E4F16A28F}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"{262B262D-04FB-4057-8DDA-F2AED735A549}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{9916B9C5-5B5A-42AA-A06E-E351EC619127}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{2D123E90-0440-4B5D-9709-342375B88D43}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{F9BCCCA2-5648-40AA-9B6D-11D8A8C40C96}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{6EDC104F-F90D-4EA8-A3E4-56F5F3E24BB6}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{C93C9C75-E941-4E4A-BC94-A12BD6CAF6EE}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{CCAA6C73-FB41-4DA3-B8C7-383F6ABDB1A0}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{86526343-A0E1-4179-B36C-8C2AAAC3C024}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{13AF98C9-2539-4F75-82D0-165EF407EF8E}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{4691734B-CD6A-4E20-BCE0-B8F0C0816E8B}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{24F3DC76-9748-4B57-AB01-9876B6DC2F55}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{DEE48412-1268-48F1-991E-19D57A8E66D1}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{A4963C03-6429-4638-8B99-4AC8CF4B51F3}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify
"UDP Query User{A2321309-CB60-49D8-9F83-4889BA49B839}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify
"{C040CB8F-F30A-4BAD-9C75-BDD97469A871}"= UDP:16800:tv

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [04/07/2008 22:33 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [05/02/2009 13:27 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [17/07/2009 11:41 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [04/07/2008 22:32 298776]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [05/04/2008 18:21 747912]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {DEA7C946-B8CF-7B5F-1232-EC23295FF138} /qb
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bbc.co.uk/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\mw\AppData\Roaming\Mozilla\Firefox\Profiles\p5hghz8l.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=home#/home.php?ref=home|http://forums.whatthetech.com/Help_removing_renos_OI_virus_Vista_t105440.html#entry580634|http://cgi.ebay.co.uk/Canon-Outlet-EOS-40D-Refurbished_W0QQitemZ270430134549QQcmdZViewItemQQptZUK_CamerasPhoto_DigitalCamer
as_DigitalCameras_JN?hash=item3ef6e46115&_trksid=p4634.c0.m14.l1262&_trkparms=%7C293%3A1%7C294%3A30
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npBBCPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\users\mw\Program Files\DNA\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-23 22:36
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\users\mw\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2009-07-23 22:38
ComboFix-quarantined-files.txt 2009-07-23 21:38
ComboFix2.txt 2009-07-22 22:08

Pre-Run: 104,100,601,856 bytes free
Post-Run: 104,068,620,288 bytes free

243 — E O F — 2009-07-23 06:55
EBAM:

Malwarebytes' Anti-Malware 1.39
Database version: 2490
Windows 6.0.6001 Service Pack 1

23/07/2009 22:52:22
mbam-log-2009-07-23 (22-52-22).txt

Scan type: Quick Scan
Objects scanned: 90526
Time elapsed: 2 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Kaspersky:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Friday, July 24, 2009
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Friday, July 24, 2009 08:38:54
Records in database: 2524646
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Files scanned: 175050
Threat name: 4
Infected objects: 7
Suspicious objects: 0
Duration of the scan: 01:47:27


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\Users\mw\AppData\Roaming\1.exe.vir Infected: Trojan-Spy.Win32.Agent.aygh 1
C:\Qoobox\Quarantine\C\Windows\System32\ESQULfomnbtcqhftpeodryviqrolxfxdshvni.dll.vir Infected: Packed.Win32.Tdss.w 1
C:\Qoobox\Quarantine\C\Windows\System32\ESQULykbmcauqxipmdcrswtrdoqpmdbxugiht.dll.vir Infected: Packed.Win32.Tdss.w 1
C:\Qoobox\Quarantine\[4]-Submit_2009-07-23_22.33.56.zip Infected: Packed.Win32.Tdss.x 1
C:\Qoobox\Quarantine\[4]-Submit_2009-07-23_22.33.56.zip Infected: Trojan-Downloader.Win32.VB.pjh 1
C:\STUFF\Music\Downloads\QuickTime_Pro_v7.60.92\QuickTime Pro v7.60.92\Keygen.exe Infected: Trojan-Downloader.Win32.VB.pjh 1
C:\STUFF\Music\Downloads\QuickTime_Pro_v7.60.92\QuickTime Pro v7.60.92\QuickTimeInstaller.exe Infected: Trojan-Downloader.Win32.VB.pjh 1

The selected area was scanned.
Hi,

Please do the following:

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Files
C:\STUFF\Music\Downloads\QuickTime_Pro_v7.60.92\QuickTime Pro v7.60.92\Keygen.exe 
C:\STUFF\Music\Downloads\QuickTime_Pro_v7.60.92\QuickTime Pro v7.60.92\QuickTimeInstaller.exe 

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



NEXT


Please run DDS and post a fresh DDS.txt and Attach.txt into your next reply.

Also please describe how your computer is running now and if there are any outstanding issues.
DDS: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 16:07:13.51 on 24/07/2009 Internet Explorer: 8.0.6001.18783 BrowserJavaVersion: 1.6.0_13 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.3070.2024 [GMT 1:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Spyware Doctor *disabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Kontiki\KService.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\MagicTune Premium\MagicTuneEngine.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Windows\system32\Dwm.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Windows\Explorer.EXE C:\Windows\RtHDVCpl.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Registry Mechanic\RMTray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Strokeit\strokeit.exe C:\Users\mw\Program Files\DNA\btdna.exe C:\Program Files\MagicTune Premium\GammaTray.exe C:\Program Files\SEC\Natural Color Pro\NCProTray.exe C:\Program Files\NETGEAR\WG111T\wlan111t.exe C:\Windows\system32\taskeng.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\mw\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.bbc.co.uk/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll uRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [RegistryMechanic] c:\program files\registry mechanic\RMTray.exe /S uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [StrokeIt] c:\program files\strokeit\strokeit.exe uRun: [BitTorrent DNA] "c:\users\mw\program files\dna\btdna.exe" mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\users\mw\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\gammat~1.lnk - c:\program files\magictune premium\GammaTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\ncprot~1.lnk - c:\program files\sec\natural color pro\NCProTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111t\wlan111t.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL AppInit_DLLs: c:\windows\system32\avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\mw\appdata\roaming\mozilla\firefox\profiles\p5hghz8l.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=home#/home.php?ref=home|http://forums.whatthetech.com/Help_removing_renos_OI_virus_Vista_t105440.html#entry580634|http://cgi.ebay.co.uk/Canon-Outlet-EOS-40D-Refurbished_W0QQitemZ270430134549QQcmdZViewItemQQptZUK_CamerasPhoto_DigitalCamer as_DigitalCameras_JN?hash=item3ef6e46115&_trksid=p4634.c0.m14.l1262&_trkparms=%7C293%3A1%7C294%3A30 FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\program files\mozilla firefox\plugins\npBBCPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\users\mw\program files\dna\plugins\npbtdna.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-7-4 335752] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-5 108552] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-17 907032] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-4 298776] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-4-5 747912] =============== Created Last 30 ================ 2009-07-24 15:51 –d—– C:\_OTM 2009-07-23 22:47 –d—– c:\users\mw\appdata\roaming\Malwarebytes 2009-07-23 22:47 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-23 22:47 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-23 22:47 –d—– c:\programdata\Malwarebytes 2009-07-23 22:47 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-23 22:47 –d—– c:\progra~2\Malwarebytes 2009-07-23 22:38 –dsh— C:\$RECYCLE.BIN 2009-07-23 22:33 1,277 a——- C:\CF-Submit.htm 2009-07-22 22:36 219,648 a——- c:\windows\PEV.exe 2009-07-22 22:36 161,792 a——- c:\windows\SWREG.exe 2009-07-22 22:36 98,816 a——- c:\windows\sed.exe 2009-07-22 13:49 289,792 a——- c:\windows\system32\atmfd.dll 2009-07-22 13:49 156,672 a——- c:\windows\system32\t2embed.dll 2009-07-22 13:49 72,704 a——- c:\windows\system32\fontsub.dll 2009-07-22 13:49 10,240 a——- c:\windows\system32\dciman32.dll 2009-07-22 08:48 –d—– c:\programdata\Simply Super Software 2009-07-22 08:48 –d—– c:\progra~2\Simply Super Software 2009-07-21 20:00 4 a——- c:\windows\system32\ESQULzcounter ==================== Find3M ==================== 2009-07-17 11:41 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-06-27 08:59 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-05-09 06:50 915,456 a——- c:\windows\system32\wininet.dll 2009-05-09 06:34 71,680 a——- c:\windows\system32\iesetup.dll 2009-04-30 13:37 293,376 a——- c:\windows\system32\psisdecd.dll 2009-04-30 13:37 428,544 a——- c:\windows\system32\EncDec.dll 2008-12-07 11:09 143,360 a——- c:\windows\inf\infstrng.dat 2008-12-07 11:09 51,200 a——- c:\windows\inf\infpub.dat 2008-12-07 11:09 86,016 a——- c:\windows\inf\infstor.dat 2008-09-09 08:45 174 a–sh— c:\program files\desktop.ini 2008-09-09 08:35 665,600 a——- c:\windows\inf\drvindex.dat 2008-05-07 16:53 56 a—h— c:\programdata\ezsidmv.dat 2008-05-07 16:53 56 a—h— c:\progra~2\ezsidmv.dat 2008-04-06 21:59 35,960,792 a——- c:\program files\avg75free_519a1276.exe 2008-04-06 17:16 874,448 a——- c:\program files\BitTorrent-6.0.3.exe 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 16:07:53.79 =============== Hi There. Computer seams fine - no pop-ups, no wanings, all looks good. Please let me know if there is anything more i need to do. Thanks you so much for your help - a really great job. Is there an 'donate' page? Cheers, Miles

Attachments:

Hi,

you are clean,

just a little housekeeping to do now.

P2P - I see you have P2P software Bittorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


NEXT


Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Scroll down to the Java SE Runtime Environment (JRE) option.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer. (version 6, update 14)


NEXT

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.


Is there a 'donate' page?


There is a link in my signature - thank-you ———————>
Thanks again for you help, and for the advise. Yes, I did get this infection using P2p sharing and so cannot complain; my fault completely. Cheers, Miles

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI