You have Limewire & BitTorrent, P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.
References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm
I would recommend that you uninstall Limewire & BitTorrent, however that choice is up to you.
Please go to Start Menu > Control Panel > Add/ Remove Programs
Scroll Down and locate the following programs:
BitTorrent
Limewire 4.18.8
Select each one of the programs, then select remove. (if the program is not listed don't be alarmed, just continue with the list)
Exit the Control Panel when finished.
================================
[external image: Posted Image]Your Java is out of date. Java™ 6 Update (10) can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.
================================
Please do a scan with the Kaspersky Online Scanner
As you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan. The scan will not work if you do not do this. Please ensure you close your browser after completion.
Click on the Accept button and install any components it needs.
The program will install and then begin downloading the latest definition
files.
After the files have been downloaded on the left side of the page in the Scan section select My Computer.
This will start the program and scan your system.
The scan will take a long time, so be patient and let it run. (At times it may appear to stall)
Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
Once the scan is complete, click on View scan report
To obtain the report:
Click on Save Report As
In the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select Text file [*.txt]
Click Save
(Note for Internet Explorer users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75%. Once the license has been accepted, reset to 100%.)
In your next reply post: Kaspersky log
New DDS log taken after the above scan has run
How the computer is performing now
LoCoELF,
1) Since we last touched base, how's the computer been performing? Have you encountered anymore crashing, any strange music, or anything else?
2) Are you experiencing any issues within Firefox or IE?
3) Run a full scan in MBAM, making sure to remove all (if any) items found, and post the log.
Everything seems to be running a'okay.
No crashes, haven't heard any music ads the last couple days. Although I haven't really tested the computer out fully, with games and such to see if it's still causing me to crash.
Firefox and IE both seem to be working fine, I haven't had problems with them since the first time I ran malwarebytes.
Malwarebytes' Anti-Malware 1.39
Database version: 2488
Windows 6.0.6002 Service Pack 2
7/26/2009 7:49:31 AM
mbam-log-2009-07-26 (07-49-27).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 220416
Time elapsed: 38 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Qoobox\quarantine\C\Windows\System32\UACbnqvxnpmvm.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\Windows\System32\UACtbeaivotis.dll.vir (Trojan.TDSS) -> No action taken.
BTW, I still have this Qoobox folder in my C drive which seems to be holding the problem.
The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix. This will remove the Qoobox folder too, which contains the old infections that are showing up now.
Combofix - Not an everyday tool, not to be used without supervision DDS - Delete this GMER - Delete this MBAM - Can be run weekly
Here are some tips to reduce the potential for spyware infection in the future:
1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
2. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.
3. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here
Do not install more than one firewall program because they will conflict with each other
4. Make sure you keep your Windows OS current by using Windows Update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.
5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file. Important! Windows Vista requires special instructions for a custom Hosts file. Please see here
6. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
7. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.
8. Finally, I strongly recommend that you read Miekiemoses' good advice - How to prevent Malware
Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI