This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware Trojan Virus

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

You have Limewire & BitTorrent, P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm

I would recommend that you uninstall Limewire & BitTorrent, however that choice is up to you.

Please go to Start Menu > Control Panel > Add/ Remove Programs
Scroll Down and locate the following programs:
  • BitTorrent
  • Limewire 4.18.8
Select each one of the programs, then select remove.
(if the program is not listed don't be alarmed, just continue with the list)

Exit the Control Panel when finished.

================================

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update (10) can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.

================================

Please do a scan with the Kaspersky Online Scanner

As you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan. The scan will not work if you do not do this. Please ensure you close your browser after completion.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a long time, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report

To obtain the report:
  • Click on Save Report As
  • In the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar
  • In Save as type, click the drop arrow and select Text file [*.txt]
  • Click Save

(Note for Internet Explorer users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75%. Once the license has been accepted, reset to 100%.)

In your next reply post:
Kaspersky log
New DDS log taken after the above scan has run
How the computer is performing now
Raktor, here is the logs. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Friday, July 24, 2009 Operating System: Microsoft Windows Vista Ultimate Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Friday, July 24, 2009 19:51:15 Records in database: 2526956 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Files scanned: 121858 Threat name: 8 Infected objects: 12 Suspicious objects: 0 Duration of the scan: 01:31:05 File name / Threat name / Threats count C:\Qoobox\Quarantine\C\Windows\System32\drivers\UACuriynxxbsd.sys.vir Infected: Rootkit.Win32.Agent.moy 1 C:\Qoobox\Quarantine\C\Windows\System32\UACbnqvxnpmvm.dll.vir Infected: Packed.Win32.Tdss.m 1 C:\Qoobox\Quarantine\C\Windows\System32\UACjtccjjkllu.dll.vir Infected: Trojan.Win32.Agent2.kym 1 C:\Qoobox\Quarantine\C\Windows\System32\UAClfiwpmxtpi.dll.vir Infected: Trojan.Win32.Agent2.kyk 1 C:\Qoobox\Quarantine\C\Windows\System32\UACsrqxfcpgmw.dll.vir Infected: Trojan.Win32.Agent2.kyj 1 C:\Qoobox\Quarantine\C\Windows\System32\UACtbeaivotis.dll.vir Infected: Trojan.Win32.Tdss.ajkj 1 D:\carp**\DivX\Good\Cr_-_Tutorial\ad4.120.installer.exe Infected: not-a-virus:NetTool.Win32.AccessDiver.4103 1 D:\carp**\DivX\Good\Cr_-_Tutorial.rar Infected: not-a-virus:NetTool.Win32.AccessDiver.4103 1 D:\carp**\DivX\PI\Cr_-_Tutorial\ad4.120.installer.exe Infected: not-a-virus:NetTool.Win32.AccessDiver.4103 1 D:\carp**\DivX\PI\Cr_-_Tutorial.rar Infected: not-a-virus:NetTool.Win32.AccessDiver.4103 1 D:\Program Files\Hacking\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 D:\Program Files\Hacking\mirc635.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 The selected area was scanned.
DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 13:04:20.91 on Fri 07/24/2009 Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_13 Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3326.1939 [GMT -7:00] SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\RtHDVCpl.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Skype\Phone\Skype.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\ASUS\Six Engine\SixEngine.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe C:\Program Files\Java\jre6\bin\java.exe C:\Users\Travis\AppData\Local\temp\jkos-Travis\binaries\ScanningProcess.exe C:\Users\Travis\AppData\Local\temp\jkos-Travis\binaries\ScanningProcess.exe C:\Windows\system32\NOTEPAD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Travis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\14T7SIPC\dds[1].pif C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL AppInit_DLLs: c:\windows\system32\avgrsstx.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\travis\appdata\roaming\mozilla\firefox\profiles\mrdq9282.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-22 64160] R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2008-6-23 150568] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-5-15 176128] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456] R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-4-23 95544] R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\L1E60x86.sys [2008-10-20 47616] S2 XAMPP;XAMPP Service;d:\rivatuner\xampp\service.exe [2007-12-21 60928] S3 PsSdk41;PsSdk41;c:\windows\system32\drivers\pssdk41.sys [2009-5-1 37440] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-4-27 79888] S4 Apache2.2;Apache2.2;d:\rivatuner\xampp\apache\bin\httpd.exe [2008-12-10 24636] =============== Created Last 30 ================ 2009-07-23 22:48 –dsh— C:\$RECYCLE.BIN 2009-07-23 22:39 219,648 a——- c:\windows\PEV.exe 2009-07-23 22:39 161,792 a——- c:\windows\SWREG.exe 2009-07-23 22:39 98,816 a——- c:\windows\sed.exe 2009-07-23 22:38 –ds—- C:\Combo-Fix 2009-07-23 11:00 181,239,639 a——- c:\windows\MEMORY.DMP 2009-07-22 21:41 –d—– c:\users\travis\appdata\roaming\Malwarebytes 2009-07-22 20:50 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-22 20:50 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-22 20:50 –d—– c:\programdata\Malwarebytes 2009-07-22 20:50 –d—– c:\progra~2\Malwarebytes 2009-07-22 19:08 –d-h— C:\$AVG8.VAULT$ 2009-07-22 18:50 –d—– c:\programdata\avg8 2009-07-22 18:50 –d—– c:\progra~2\avg8 2009-07-22 18:47 –d—– c:\users\travis\appdata\roaming\AVG8 2009-07-22 14:33 15,688 a——- c:\windows\system32\lsdelete.exe 2009-07-22 13:50 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-07-22 13:50 -cd-h— c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864} 2009-07-22 13:50 -cd-h— c:\progra~2\{EF63305C-BAD7-4144-9208-D65528260864} 2009-07-22 13:50 –d—– c:\programdata\Lavasoft 2009-07-22 13:50 –d—– c:\program files\Lavasoft 2009-07-22 13:35 –d—– c:\users\travis\appdata\roaming\Sammsoft 2009-07-22 08:13 –d—– c:\users\travis\appdata\roaming\quickhit.football.QHFootball.8546B1890A6B85B099F9D0733AC3C3D3855F0E72.1 2009-07-14 10:20 289,792 a——- c:\windows\system32\atmfd.dll 2009-07-14 10:20 156,672 a——- c:\windows\system32\t2embed.dll 2009-07-14 10:20 72,704 a——- c:\windows\system32\fontsub.dll 2009-07-14 10:20 23,552 a——- c:\windows\system32\lpk.dll 2009-07-14 10:20 10,240 a——- c:\windows\system32\dciman32.dll 2009-07-09 22:58 –d—– c:\windows\system32\vi-VN 2009-07-09 22:58 –d—– c:\windows\system32\eu-ES 2009-07-09 22:58 –d—– c:\windows\system32\ca-ES 2009-07-09 22:55 –d—– c:\windows\system32\SPReview 2009-07-09 22:51 928,768 a——- c:\windows\system32\scavenge.dll 2009-07-09 22:51 57,856 a——- c:\windows\system32\compcln.exe 2009-07-09 22:49 2,167,808 a——- c:\windows\system32\mmcndmgr.dll 2009-07-09 22:47 –d—– c:\windows\system32\EventProviders 2009-07-09 08:40 –d—– c:\programdata\ATI 2009-07-05 08:15 2,569 a——- c:\windows\system32\GamParse.INI 2009-06-30 13:37 –d—– C:\Temp 2009-06-29 19:48 –d—– c:\program files\Everquest 2009-06-29 19:46 –d—– c:\windows\system32\Skins 2009-06-29 19:46 969 a——- c:\windows\system32\eqp_config.xml 2009-06-29 13:28 4,608 a——- c:\windows\system32\W95Inf32.DLL 2009-06-29 13:28 2,272 a——- c:\windows\system32\W95Inf16.DLL 2009-06-29 13:10 –d—– c:\users\travis\appdata\roaming\CoreFTP ==================== Find3M ==================== 2009-07-09 23:04 86,016 a——- c:\windows\inf\infstor.dat 2009-07-09 23:04 51,200 a——- c:\windows\inf\infpub.dat 2009-07-09 23:04 143,360 a——- c:\windows\inf\infstrng.dat 2009-07-09 22:58 665,600 a——- c:\windows\inf\drvindex.dat 2009-05-15 20:24 442,368 a——- c:\windows\system32\ATIDEMGX.dll 2009-05-15 20:24 335,872 a——- c:\windows\system32\atieclxx.exe 2009-05-15 20:23 176,128 a——- c:\windows\system32\atiesrxx.exe 2009-05-15 20:22 159,744 a——- c:\windows\system32\atitmmxx.dll 2009-05-15 20:22 356,352 a——- c:\windows\system32\atipdlxx.dll 2009-05-15 20:22 278,528 a——- c:\windows\system32\Oemdspif.dll 2009-05-15 20:22 11,776 a——- c:\windows\system32\atimuixx.dll 2009-05-15 20:22 43,520 a——- c:\windows\system32\ati2edxx.dll 2009-05-15 20:19 2,411,008 a——- c:\windows\system32\atidxx32.dll 2009-05-15 20:08 3,064,832 a——- c:\windows\system32\atiumdag.dll 2009-05-15 19:53 2,847,744 a——- c:\windows\system32\atiumdva.dll 2009-05-15 19:42 51,712 a——- c:\windows\system32\atimpc32.dll 2009-05-15 19:42 51,712 a——- c:\windows\system32\amdpcom32.dll 2009-05-15 19:41 172,032 a——- c:\windows\system32\atiadlxx.dll 2009-05-15 19:40 11,376,640 a——- c:\windows\system32\atioglxx.dll 2009-05-15 19:00 53,248 a——- c:\windows\system32\aticalrt.dll 2009-05-15 19:00 53,248 a——- c:\windows\system32\aticalcl.dll 2009-05-15 18:59 3,174,400 a——- c:\windows\system32\aticaldd.dll 2009-05-05 12:33 118,784 a——- c:\windows\system32\atibtmon.exe 2009-04-28 02:47 499,712 a——- c:\windows\system32\msvcp71.dll 2009-04-28 02:47 348,160 a——- c:\windows\system32\msvcr71.dll 2008-10-23 21:17 174 a–sh— c:\program files\desktop.ini 2006-11-02 05:40 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 05:40 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 05:40 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 05:40 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 13:05:10.56 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft® Windows Vista™ Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 10/20/2008 12:59:17 PM System Uptime: 7/24/2009 7:37:26 AM (6 hours ago) Motherboard: ASUSTeK Computer INC. | | P5Q-PRO Processor: Intel® Core™2 Duo CPU E8500 @ 3.16GHz | LGA 775 | 3166/333mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 466 GiB total, 396.02 GiB free. D: is FIXED (NTFS) - 74 GiB total, 47.987 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== ==== Installed Programs ====================== AccessDiver v4.402 Acrobat.com Ad-Aware Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.1 Adobe Shockwave Player 11.5 AGEIA PhysX v7.09.13 Apple Mobile Device Support Apple Software Update Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver ATI Catalyst Install Manager ATI Catalyst Registration Bonjour Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center HydraVision Full Catalyst Control Center InstallProxy ccc-core-static ccc-utility CCC Help English CCleaner (remove only) Darkfall DivX Codec DivX Web Player EPU-6 Engine GamParse GIMP 2.6.3 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) iTunes Java™ 6 Update 13 Malwarebytes' Anti-Malware Microsoft .NET Framework 3.5 SP1 Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Ultimate 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2008 Management Objects Microsoft SQL Server Compact 3.5 SP1 Design Tools English Microsoft SQL Server Compact 3.5 SP1 English Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 mIRC Mozilla Firefox (3.0.12) QuickHitFootball QuickTime Realtek High Definition Audio Driver Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office Word 2007 (KB969604) Skype™ 3.8 SQL Server System CLR Types Trillian Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB969907) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (kb971933) VC80CRTRedist - 8.0.50727.762 Ventrilo Client VLC media player 0.9.8a WinRAR archiver World of Warcraft FREE Trial ==== End Of File =========================== As far as the system running. I haven't occured any problems this morning, but I was still getting random reboots and crashes and music ads randomly coming through my speakers last night. I haven't touched anything but the scans you told me to do, so those problems should still be in force I would assume.
LoCoELF, 1) Since we last touched base, how's the computer been performing? Have you encountered anymore crashing, any strange music, or anything else? 2) Are you experiencing any issues within Firefox or IE? 3) Run a full scan in MBAM, making sure to remove all (if any) items found, and post the log.
Everything seems to be running a'okay. No crashes, haven't heard any music ads the last couple days. Although I haven't really tested the computer out fully, with games and such to see if it's still causing me to crash. Firefox and IE both seem to be working fine, I haven't had problems with them since the first time I ran malwarebytes. Malwarebytes' Anti-Malware 1.39 Database version: 2488 Windows 6.0.6002 Service Pack 2 7/26/2009 7:49:31 AM mbam-log-2009-07-26 (07-49-27).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 220416 Time elapsed: 38 minute(s), 58 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Qoobox\quarantine\C\Windows\System32\UACbnqvxnpmvm.dll.vir (Trojan.TDSS) -> No action taken. c:\Qoobox\quarantine\C\Windows\System32\UACtbeaivotis.dll.vir (Trojan.TDSS) -> No action taken. BTW, I still have this Qoobox folder in my C drive which seems to be holding the problem.
Ok then, everything's looking all clean. :thumbup:

Time for some housekeeping
  • Click START then RUN
  • Now type Combo-fix /u in the runbox and click OK
The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix. This will remove the Qoobox folder too, which contains the old infections that are showing up now.

Combofix - Not an everyday tool, not to be used without supervision
DDS - Delete this
GMER - Delete this
MBAM - Can be run weekly :)

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    1. Change the Download signed ActiveX controls to Prompt
    2. Change the Download unsigned ActiveX controls to Disable
    3. Change the Initialize and script ActiveX controls not marked as safe to Disable
    4. Change the Installation of desktop items to Prompt
    5. Change the Launching programs and files in an IFRAME to Prompt
    6. Change the Navigate sub-frames across different domains to Prompt
    7. When all these settings have been made, click on the OK button.
    8. If it prompts you as to whether or not you want to save the settings, press the Yes button.
    9. Next press the Apply button and then the OK to exit the Internet Properties page.
2. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here

Do not install more than one firewall program because they will conflict with each other

4. Make sure you keep your Windows OS current by using Windows Update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
Important! Windows Vista requires special instructions for a custom Hosts file. Please see here

6. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

7. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.

8. Finally, I strongly recommend that you read Miekiemoses' good advice - How to prevent Malware

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI