This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] [Infected] TrojanDownloader:Win32/Renos.IO

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, everyone. This is my first post here after reading numerous topics on virus removal. Anyway, I am using a Windows XP and one day, I discovered a pop-up by Windows Defender stating that the virus "Trojan Downloader:Win32/Renos.IO" has been found in my system. I clicked on the "Remove" button and carried on as per usual. However, it struck again numerous times. It has almost been a week. I tried to remove it again, but it is popping up again. Since then my Internet Explorer and Firefox are both working in a weird manner and I'm unable to download some anti, virus, spyware, and maleware programs. Only a few things on my desktop will work and when I try to open other programs like my "SpyEraser", they will not open (I have clicked on the icons and nothing will come up) and I had have a couple of crashes. I have also tried system restore and that would not work either. Plus there is times where I hear clicking noises(When I'm not clicking) and certain kinds of music(Music I'm not playing). I know there has been previous cases, but please note that I'm running Windows XP, not Vista and I don't know where to start and how to get the logs. Can you please help me out here and check if my computer is completely clean and free of viruses, etc.. I appreciate all help, Thanks.
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.


Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hello CatByte, thank you for attending to my problem. Here are the logs you requested. *GMER Rootkit Scanner is not opening (Is there anything else?)* uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\4.1.509.5470\swg.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn1\YTSingleInstance.dll TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - No File TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File uRun: [Uniblue SpeedUpMyPC] c:\program files\uniblue\speedupmypc 3\SpeedUpMyPC.exe -s uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Cognac] c:\docume~1\hp_adm~1\locals~1\temp\b.exe uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe mRun: [] mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe" mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe" mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [Share-to-Web Namespace Daemon] c:\program files\hp\hp share-to-web\hpgs2wnd.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\hp_adm~1\startm~1\programs\startup\vzacce~1.lnk - c:\program files\verizon wireless\vzaccess manager\VZAccess Manager.exe StartupFolder: c:\docume~1\hp_adm~1\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll IE: {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - c:\program files\eltima software\flash decompiler trillix\saveflash\iebt.dll LSP: c:\windows\system32\VetRedir.dll Trusted Zone: trymedia.com DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro2.cce.hp.com/ChatEntry/downloads/sysinfo.cab DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab TCP: {F02C8FC6-CB69-4326-9C2E-8BF277702CB4} = 66.174.95.44 69.78.96.14 Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: !SABWinLogon - c:\program files\superadblocker.com\super ad blocker\SABWINLO.DLL Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\hp_adm~1\applic~1\mozilla\firefox\profiles\f6ektngu.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p= FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-7 114768] R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2008-1-8 26352] R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2008-1-8 21104] R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2008-1-8 880560] R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\vetfddnt.sys [2008-1-8 21488] R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2008-1-8 32240] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-7 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-12-7 138680] R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2008-1-4 144696] R2 lxbm_device;lxbm_device;c:\windows\system32\lxbmcoms.exe -service –> c:\windows\system32\lxbmcoms.exe -service [?] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-8-30 210216] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 VETMSGNT;VET Message Service;c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe [2008-1-4 251120] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-12-7 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-12-7 352920] R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2008-5-9 174336] R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2008-1-8 108368] S1 rxp;rxp;\??\c:\windows\system32\drivers\rxp.sys –> c:\windows\system32\drivers\rxp.sys [?] S1 SABKUTIL;SABKUTIL;\??\c:\program files\superadblocker.com\super ad blocker\sabkutil.sys –> c:\program files\superadblocker.com\super ad blocker\SABKUTIL.sys [?] S2 Abel;Abel; [x] S2 gupdate1c9c85185c857fc;Google Update Service (gupdate1c9c85185c857fc);c:\program files\google\update\GoogleUpdate.exe [2009-4-28 133104] S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter;\??\c:\windows\system32\drivers\nsdriver.sys –> c:\windows\system32\drivers\NSDriver.sys [?] S3 RkHit;RkHit;\??\c:\windows\system32\drivers\rkhit.sys –> c:\windows\system32\drivers\RKHit.sys [?] S3 UBWipRFBMLg;UBWipRFBMLg;\??\c:\downloads\windows\downloads\mhs\gnfdq –> c:\downloads\windows\downloads\mhs\GNFDQ [?] =============== Created Last 30 ================ 2009-07-22 21:14 137,732 a——- c:\windows\msb.exe 2009-07-22 01:03 143,360 a——- c:\windows\msa.exe 2009-07-22 01:02 142,852 ——– c:\windows\system32\msxml71.dll 2009-07-17 21:48 21,504 a——- c:\windows\system32\hidserv.dll 2009-07-17 21:48 21,504 a——- c:\windows\system32\dllcache\hidserv.dll 2009-07-17 21:48 14,848 a——- c:\windows\system32\drivers\kbdhid.sys 2009-07-17 21:48 14,848 a——- c:\windows\system32\dllcache\kbdhid.sys 2009-07-01 19:47 29,953 a——- C:\_70879-L.JPG 2009-07-01 19:00 –d—– c:\windows\system32\wbem\Repository ==================== Find3M ==================== 2009-07-22 23:50 94,208 a——- c:\windows\DUMP8f11.tmp 2009-06-10 21:23 44,944 ——– c:\windows\system32\drivers\pxhelp20.sys 2009-06-10 21:23 9,200 ——– c:\windows\system32\drivers\cdralw2k.sys 2009-06-10 21:23 9,072 ——– c:\windows\system32\drivers\cdr4_xp.sys 2009-04-04 01:16 1,140 ac—— c:\docume~1\hp_adm~1\applic~1\wklnhst.dat 2006-09-23 23:25 167 ac–h— c:\documents and settings\hp_administrator\hpothb07.dat 2008-05-16 17:04 848 a–sh— c:\windows\system32\KGyGaAvL.sys ============= FINISH: 18:08:21.86 ===============

Attachments:

Hi,


The front part of the DDS log "running processes" has been cut off - if you could repost it…should start with: DDS (Ver_09-06-26.01) - NTFSx86


Try renaming GMER to REMG.exe and run it, or run it in safe mode. if it still will not run, continue on to step 3 - run Root Repeal
Alright, I think I have the full log now. Sorry about that. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 20:39:08.50 on Thu 07/23/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.200 [GMT -5:00] AV: CA Anti-Virus *On-access scanning enabled* (Outdated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} AV: avast! antivirus 4.8.1335 [VPS 090723-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe C:\WINDOWS\arservice.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe C:\WINDOWS\system32\drivers\dcfssvc.exe C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\HP\HP Share-to-Web\hpgs2wnf.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Webshots\webshots.scr C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\lxbmcoms.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\b.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Internet Explorer\Iexplore.exe C:\Program Files\Internet Explorer\Iexplore.exe C:\Documents and Settings\HP_Administrator\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8 uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uWindow Title = Windows Internet Explorer provided by Yahoo! uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html mDefault_Page_URL = hxxp://www.yahoo.com/ mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com mStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uInternet Connection Wizard,ShellNext = hxxp://www.callwave.com/iam/DemoIntro.html?u=0f5ab0f3e201a2176ba63427dc04bc729318fe15fe61a8ad81d3e2d0bb7349025c&Ver=3.09.7.0&OS=WinNT:5.1.2600SP:2.0&co=0 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\4.1.509.5470\swg.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn1\YTSingleInstance.dll TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - No File TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File uRun: [Uniblue SpeedUpMyPC] c:\program files\uniblue\speedupmypc 3\SpeedUpMyPC.exe -s uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Cognac] c:\docume~1\hp_adm~1\locals~1\temp\b.exe uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe mRun: [] mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe" mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe" mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [Share-to-Web Namespace Daemon] c:\program files\hp\hp share-to-web\hpgs2wnd.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\hp_adm~1\startm~1\programs\startup\vzacce~1.lnk - c:\program files\verizon wireless\vzaccess manager\VZAccess Manager.exe StartupFolder: c:\docume~1\hp_adm~1\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll IE: {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - c:\program files\eltima software\flash decompiler trillix\saveflash\iebt.dll LSP: c:\windows\system32\VetRedir.dll Trusted Zone: trymedia.com DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {49232000-16E4-426C-A231-62846947304B} - hxxps://wimpro2.cce.hp.com/ChatEntry/downloads/sysinfo.cab DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab TCP: {F02C8FC6-CB69-4326-9C2E-8BF277702CB4} = 66.174.95.44 69.78.96.14 Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: !SABWinLogon - c:\program files\superadblocker.com\super ad blocker\SABWINLO.DLL Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\hp_adm~1\applic~1\mozilla\firefox\profiles\f6ektngu.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p= FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-7 114768] R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2008-1-8 26352] R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2008-1-8 21104] R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2008-1-8 880560] R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\vetfddnt.sys [2008-1-8 21488] R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2008-1-8 32240] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-7 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-12-7 138680] R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2008-1-4 144696] R2 lxbm_device;lxbm_device;c:\windows\system32\lxbmcoms.exe -service –> c:\windows\system32\lxbmcoms.exe -service [?] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-8-30 210216] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 VETMSGNT;VET Message Service;c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe [2008-1-4 251120] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-12-7 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-12-7 352920] R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2008-5-9 174336] R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2008-1-8 108368] S1 rxp;rxp;\??\c:\windows\system32\drivers\rxp.sys –> c:\windows\system32\drivers\rxp.sys [?] S1 SABKUTIL;SABKUTIL;\??\c:\program files\superadblocker.com\super ad blocker\sabkutil.sys –> c:\program files\superadblocker.com\super ad blocker\SABKUTIL.sys [?] S2 Abel;Abel; [x] S2 gupdate1c9c85185c857fc;Google Update Service (gupdate1c9c85185c857fc);c:\program files\google\update\GoogleUpdate.exe [2009-4-28 133104] S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter;\??\c:\windows\system32\drivers\nsdriver.sys –> c:\windows\system32\drivers\NSDriver.sys [?] S3 RkHit;RkHit;\??\c:\windows\system32\drivers\rkhit.sys –> c:\windows\system32\drivers\RKHit.sys [?] S3 UBWipRFBMLg;UBWipRFBMLg;\??\c:\downloads\windows\downloads\mhs\gnfdq –> c:\downloads\windows\downloads\mhs\GNFDQ [?] =============== Created Last 30 ================ 2009-07-22 21:14 137,732 a——- c:\windows\msb.exe 2009-07-22 01:03 143,360 a——- c:\windows\msa.exe 2009-07-22 01:02 142,852 ——– c:\windows\system32\msxml71.dll 2009-07-17 21:48 21,504 a——- c:\windows\system32\hidserv.dll 2009-07-17 21:48 21,504 a——- c:\windows\system32\dllcache\hidserv.dll 2009-07-17 21:48 14,848 a——- c:\windows\system32\drivers\kbdhid.sys 2009-07-17 21:48 14,848 a——- c:\windows\system32\dllcache\kbdhid.sys 2009-07-01 19:47 29,953 a——- C:\_70879-L.JPG 2009-07-01 19:00 –d—– c:\windows\system32\wbem\Repository ==================== Find3M ==================== 2009-07-22 23:50 94,208 a——- c:\windows\DUMP8f11.tmp 2009-06-10 21:23 44,944 ——– c:\windows\system32\drivers\pxhelp20.sys 2009-06-10 21:23 9,200 ——– c:\windows\system32\drivers\cdralw2k.sys 2009-06-10 21:23 9,072 ——– c:\windows\system32\drivers\cdr4_xp.sys 2009-04-04 01:16 1,140 ac—— c:\docume~1\hp_adm~1\applic~1\wklnhst.dat 2006-09-23 23:25 167 ac–h— c:\documents and settings\hp_administrator\hpothb07.dat 2008-05-16 17:04 848 a–sh— c:\windows\system32\KGyGaAvL.sys ============= FINISH: 20:40:41.81 ===============
OK, but there is a few difficulties. I'm receiving warnings. "Could not read the boot sector. Try adjusting the Disk Access Level in the Options dialog." "Could not find module file on disk" Is this going to interfere with process and should I just keep continuing?
Yes, it's running, but there were several warnings during the process. Here is the report from RootRepeal. ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/07/23 22:38 Program Version: Version 1.3.2.0 Windows Version: Windows XP Media Center Edition SP2 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF1AF0000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7A86000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xEE286000 Size: 49152 File Visible: No Signed: - Status: - Stealth Objects ——————- Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: winlogon.exe (PID: 820) Address: 0x00930000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: winlogon.exe (PID: 820) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: services.exe (PID: 896) Address: 0x00a30000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: services.exe (PID: 896) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: lsass.exe (PID: 916) Address: 0x00ad0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: lsass.exe (PID: 916) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: Ati2evxx.exe (PID: 1084) Address: 0x00e30000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: Ati2evxx.exe (PID: 1084) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACltrmhcedav.dll] Process: svchost.exe (PID: 1100) Address: 0x00720000 Address: 77824 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: svchost.exe (PID: 1100) Address: 0x00a10000 Address: 45056 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: svchost.exe (PID: 1100) Address: 0x00a40000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: svchost.exe (PID: 1100) Address: 0x00ad0000 Address: 49152 Object: Hidden Module [Name: UACeaemcwruem.dll] Process: svchost.exe (PID: 1100) Address: 0x00b70000 Address: 73728 Object: Hidden Module [Name: UACroyiltnanu.dll] Process: svchost.exe (PID: 1100) Address: 0x00ec0000 Address: 217088 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: svchost.exe (PID: 1100) Address: 0x02cc0000 Address: 49152 Object: Hidden Module [Name: UACa1cb.tmpltnanu.dll] Process: svchost.exe (PID: 1100) Address: 0x10000000 Address: 217088 Object: Hidden Module [Name: UACltrmhcedav.dll] Process: svchost.exe (PID: 1212) Address: 0x00720000 Address: 77824 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: svchost.exe (PID: 1212) Address: 0x00a40000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: svchost.exe (PID: 1212) Address: 0x00ad0000 Address: 49152 Object: Hidden Module [Name: UACa1cb.tmpltnanu.dll] Process: svchost.exe (PID: 1212) Address: 0x10000000 Address: 217088 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: MsMpEng.exe (PID: 1252) Address: 0x00a40000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: MsMpEng.exe (PID: 1252) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACltrmhcedav.dll] Process: svchost.exe (PID: 1296) Address: 0x00720000 Address: 77824 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: svchost.exe (PID: 1296) Address: 0x00a40000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: svchost.exe (PID: 1296) Address: 0x00ad0000 Address: 49152 Object: Hidden Module [Name: UACa1cb.tmpltnanu.dll] Process: svchost.exe (PID: 1296) Address: 0x10000000 Address: 217088 Object: Hidden Module [Name: UACltrmhcedav.dll] Process: svchost.exe (PID: 1348) Address: 0x00720000 Address: 77824 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: svchost.exe (PID: 1348) Address: 0x00a40000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: svchost.exe (PID: 1348) Address: 0x00ad0000 Address: 49152 Object: Hidden Module [Name: UACa1cb.tmpltnanu.dll] Process: svchost.exe (PID: 1348) Address: 0x10000000 Address: 217088 Object: Hidden Module [Name: UACltrmhcedav.dll] Process: svchost.exe (PID: 1492) Address: 0x00720000 Address: 77824 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: svchost.exe (PID: 1492) Address: 0x00a40000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: svchost.exe (PID: 1492) Address: 0x00ad0000 Address: 49152 Object: Hidden Module [Name: UACa1cb.tmpltnanu.dll] Process: svchost.exe (PID: 1492) Address: 0x10000000 Address: 217088 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: aswUpdSv.exe (PID: 1652) Address: 0x00de0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: aswUpdSv.exe (PID: 1652) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: Ati2evxx.exe (PID: 1732) Address: 0x00e30000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: Ati2evxx.exe (PID: 1732) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: ashServ.exe (PID: 1820) Address: 0x00df0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: ashServ.exe (PID: 1820) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: Explorer.EXE (PID: 1876) Address: 0x00d00000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: Explorer.EXE (PID: 1876) Address: 0x00db0000 Address: 49152 Object: Hidden Module [Name: UACltrmhcedav.dll] Process: Explorer.EXE (PID: 1876) Address: 0x10000000 Address: 77824 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: spoolsv.exe (PID: 404) Address: 0x00d30000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: spoolsv.exe (PID: 404) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: PhotoshopElementsFileAgent.exe (PID: 640) Address: 0x00b90000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: PhotoshopElementsFileAgent.exe (PID: 640) Address: 0x00680000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: arservice.exe (PID: 772) Address: 0x00cd0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: arservice.exe (PID: 772) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: b.exe (PID: 800) Address: 0x00e20000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: b.exe (PID: 800) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: ISafe.exe (PID: 1768) Address: 0x003b0000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: ISafe.exe (PID: 1768) Address: 0x00e10000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: dcfssvc.exe (PID: 416) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: dcfssvc.exe (PID: 416) Address: 0x00e10000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: cctray.exe (PID: 1336) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: cctray.exe (PID: 1336) Address: 0x00de0000 Address: 49152 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: CAVRID.exe (PID: 1384) Address: 0x00df0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: CAVRID.exe (PID: 1384) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: MSASCui.exe (PID: 968) Address: 0x00e40000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: MSASCui.exe (PID: 968) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: ashDisp.exe (PID: 1568) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: ashDisp.exe (PID: 1568) Address: 0x00df0000 Address: 49152 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: hpgs2wnd.exe (PID: 1516) Address: 0x00df0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: hpgs2wnd.exe (PID: 1516) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: realsched.exe (PID: 1456) Address: 0x00e10000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: realsched.exe (PID: 1456) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: SpeedUpMyPC.exe (PID: 1208) Address: 0x016c0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: SpeedUpMyPC.exe (PID: 1208) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: ctfmon.exe (PID: 2112) Address: 0x00d40000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: ctfmon.exe (PID: 2112) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: hpgs2wnf.exe (PID: 2180) Address: 0x00df0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: hpgs2wnf.exe (PID: 2180) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: msmsgs.exe (PID: 2200) Address: 0x00ce0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: msmsgs.exe (PID: 2200) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: GoogleToolbarNotifier.exe (PID: 2268) Address: 0x00dc0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: GoogleToolbarNotifier.exe (PID: 2268) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: ctfmon.exe (PID: 2288) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: ctfmon.exe (PID: 2288) Address: 0x00d40000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: VZAccess Manager.exe (PID: 2468) Address: 0x00d40000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: VZAccess Manager.exe (PID: 2468) Address: 0x01030000 Address: 49152 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: webshots.scr (PID: 2528) Address: 0x00ff0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: webshots.scr (PID: 2528) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: LSSrvc.exe (PID: 2896) Address: 0x00b70000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: LSSrvc.exe (PID: 2896) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: lxbmcoms.exe (PID: 2940) Address: 0x00e60000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: lxbmcoms.exe (PID: 2940) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: McSACore.exe (PID: 2992) Address: 0x00e20000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: McSACore.exe (PID: 2992) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: MDM.EXE (PID: 3052) Address: 0x00e20000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: MDM.EXE (PID: 3052) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACltrmhcedav.dll] Process: svchost.exe (PID: 3156) Address: 0x00720000 Address: 77824 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: svchost.exe (PID: 3156) Address: 0x00a40000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: svchost.exe (PID: 3156) Address: 0x00ad0000 Address: 49152 Object: Hidden Module [Name: UACa1cb.tmpltnanu.dll] Process: svchost.exe (PID: 3156) Address: 0x10000000 Address: 217088 Object: Hidden Module [Name: UACltrmhcedav.dll] Process: svchost.exe (PID: 3184) Address: 0x00720000 Address: 77824 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: svchost.exe (PID: 3184) Address: 0x00a40000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: svchost.exe (PID: 3184) Address: 0x00ad0000 Address: 49152 Object: Hidden Module [Name: UACa1cb.tmpltnanu.dll] Process: svchost.exe (PID: 3184) Address: 0x10000000 Address: 217088 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: VetMsg.exe (PID: 3216) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: VetMsg.exe (PID: 3216) Address: 0x00e00000 Address: 49152 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: YahooAUService.exe (PID: 3356) Address: 0x00d50000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: YahooAUService.exe (PID: 3356) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: mcrdsvc.exe (PID: 3528) Address: 0x009f0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: mcrdsvc.exe (PID: 3528) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: ashMaiSv.exe (PID: 672) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: ashMaiSv.exe (PID: 672) Address: 0x00e10000 Address: 49152 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: ashWebSv.exe (PID: 2284) Address: 0x00e30000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: ashWebSv.exe (PID: 2284) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: ccprovsp.exe (PID: 2788) Address: 0x00b70000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: ccprovsp.exe (PID: 2788) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: alg.exe (PID: 3088) Address: 0x00ab0000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: alg.exe (PID: 3088) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: ymsgr_tray.exe (PID: 3964) Address: 0x00f40000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: ymsgr_tray.exe (PID: 3964) Address: 0x10000000 Address: 45056 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: firefox.exe (PID: 888) Address: 0x00b90000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: firefox.exe (PID: 888) Address: 0x01020000 Address: 49152 Object: Hidden Module [Name: UACa1cb.tmpltnanu.dll] Process: firefox.exe (PID: 888) Address: 0x10000000 Address: 217088 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: Iexplore.exe (PID: 3272) Address: 0x00b20000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: Iexplore.exe (PID: 3272) Address: 0x00f80000 Address: 49152 Object: Hidden Module [Name: UACroyiltnanu.dll] Process: Iexplore.exe (PID: 3272) Address: 0x10000000 Address: 217088 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: Iexplore.exe (PID: 664) Address: 0x00b20000 Address: 45056 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: Iexplore.exe (PID: 664) Address: 0x00fa0000 Address: 49152 Object: Hidden Module [Name: UACroyiltnanu.dll] Process: Iexplore.exe (PID: 664) Address: 0x10000000 Address: 217088 Object: Hidden Module [Name: UACiwvakbkvrb.dll] Process: RootRepeal.exe (PID: 2820) Address: 0x00f70000 Address: 49152 Object: Hidden Module [Name: UACwamoqdnpnk.dll] Process: RootRepeal.exe (PID: 2820) Address: 0x10000000 Address: 45056 ==EOF==
OK,

Please do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

OK, it's completed. Here is the log from the Combo-fix.

ComboFix 09-07-23.02 - HP_Administrator 07/23/2009 23:20.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.447 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1335 [VPS 090723-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: CA Anti-Virus *On-access scanning enabled* (Outdated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
c:\program files\smbols~1
c:\recycler\S-1-5-21-2856212118-2892828900-201305014-1008
c:\recycler\S-1-5-21-3329523479-2079964671-2664348731-1009
c:\recycler\S-1-5-21-3381561272-153511819-2455406854-1008
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\temp\tn3
c:\temp\tn3\cache.dsk
c:\windows\cookies.ini
c:\windows\IA
c:\windows\Installer\105d6cb.msi
c:\windows\Installer\1076632.msi
c:\windows\Installer\10e6cd.msi
c:\windows\Installer\11b71.msp
c:\windows\Installer\11b7a.msi
c:\windows\Installer\11d7c1.msp
c:\windows\Installer\1348c57.msi
c:\windows\Installer\148acf.msi
c:\windows\Installer\148ada.msi
c:\windows\Installer\14c4ae7.msp
c:\windows\Installer\14dd945.msi
c:\windows\Installer\15c88c.msi
c:\windows\Installer\1618639.msp
c:\windows\Installer\17d215.msi
c:\windows\Installer\17e3e75.msp
c:\windows\Installer\17e3e87.msp
c:\windows\Installer\17e3e9a.msp
c:\windows\Installer\187f5fc.msp
c:\windows\Installer\19339f5.msp
c:\windows\Installer\19c185.msi
c:\windows\Installer\1b06473.msp
c:\windows\Installer\1b06486.msp
c:\windows\Installer\1b06499.msp
c:\windows\Installer\1b064ac.msp
c:\windows\Installer\1b064bf.msp
c:\windows\Installer\1ce613c.msi
c:\windows\Installer\1d5fea.msi
c:\windows\Installer\1d79fb.msi
c:\windows\Installer\1e352ea.msi
c:\windows\Installer\1e353c8.msi
c:\windows\Installer\1e67af2.msp
c:\windows\Installer\1eeda16.msi
c:\windows\Installer\1f14133.msi
c:\windows\Installer\1fcd9d4.msi
c:\windows\Installer\1fcd9e6.msp
c:\windows\Installer\1fcd9fa.msp
c:\windows\Installer\1fcda0d.msp
c:\windows\Installer\1fcda20.msp
c:\windows\Installer\1fcda33.msp
c:\windows\Installer\1fcda46.msp
c:\windows\Installer\21179ee.msi
c:\windows\Installer\211ebcb.msp
c:\windows\Installer\220bb4c.msp
c:\windows\Installer\23391.msi
c:\windows\Installer\25547ec.msi
c:\windows\Installer\25547f2.msi
c:\windows\Installer\25547fc.msi
c:\windows\Installer\2554808.msi
c:\windows\Installer\256cd4.msi
c:\windows\Installer\2646581.msp
c:\windows\Installer\26e1241.msp
c:\windows\Installer\272212.msp
c:\windows\Installer\299eed.msi
c:\windows\Installer\2a18823.msp
c:\windows\Installer\2ac5f5.msi
c:\windows\Installer\2ac5f8.msi
c:\windows\Installer\2d36ce.msi
c:\windows\Installer\2d370f.msi
c:\windows\Installer\2d3713.msi
c:\windows\Installer\313354b.msi
c:\windows\Installer\313355e.msp
c:\windows\Installer\3133571.msp
c:\windows\Installer\3328bf.msp
c:\windows\Installer\3328d2.msp
c:\windows\Installer\3328e5.msp
c:\windows\Installer\3328f9.msp
c:\windows\Installer\33290c.msp
c:\windows\Installer\33291f.msp
c:\windows\Installer\332932.msp
c:\windows\Installer\36876e.msi
c:\windows\Installer\36e474.msp
c:\windows\Installer\36e48a.msp
c:\windows\Installer\36e49e.msp
c:\windows\Installer\4065795.msp
c:\windows\Installer\40657a8.msp
c:\windows\Installer\40657bb.msp
c:\windows\Installer\40657d8.msp
c:\windows\Installer\40657eb.msp
c:\windows\Installer\40657fd.msp
c:\windows\Installer\40fb163.msi
c:\windows\Installer\4165ebb.msp
c:\windows\Installer\4165ece.msp
c:\windows\Installer\432f8a3.msi
c:\windows\Installer\460be.msi
c:\windows\Installer\4667655.msp
c:\windows\Installer\4bcbb.msi
c:\windows\Installer\4ee94e.msi
c:\windows\Installer\51db26a.msp
c:\windows\Installer\5367142.msp
c:\windows\Installer\5367156.msp
c:\windows\Installer\54799d.msp
c:\windows\Installer\5479b0.msp
c:\windows\Installer\5479c3.msp
c:\windows\Installer\5b6e6ef.msp
c:\windows\Installer\5b6e6f8.msi
c:\windows\Installer\5b6e70a.msp
c:\windows\Installer\5cebf0.msp
c:\windows\Installer\5cebf1.msp
c:\windows\Installer\60ade2.msi
c:\windows\Installer\68aea8.msi
c:\windows\Installer\693f03.msi
c:\windows\Installer\72189.msi
c:\windows\Installer\7218b.msi
c:\windows\Installer\7218c.msi
c:\windows\Installer\72193.msi
c:\windows\Installer\78659a.msp
c:\windows\Installer\7865ae.msp
c:\windows\Installer\791035.msi
c:\windows\Installer\79559.msp
c:\windows\Installer\813b3.msi
c:\windows\Installer\81644.msi
c:\windows\Installer\880e4.msi
c:\windows\Installer\888ee0.msp
c:\windows\Installer\888ef2.msp
c:\windows\Installer\8898ff.msp
c:\windows\Installer\889912.msp
c:\windows\Installer\88992f.msp
c:\windows\Installer\9d7a88.msi
c:\windows\Installer\a76cd8.msp
c:\windows\Installer\a9c30e.msp
c:\windows\Installer\ac5f97.msi
c:\windows\Installer\b6a9b.msi
c:\windows\Installer\b7cf9f.msi
c:\windows\Installer\c1c338.msi
c:\windows\Installer\c768e3.msi
c:\windows\Installer\cab8c1.msp
c:\windows\Installer\cc17b3.msi
c:\windows\Installer\cc17bb.msi
c:\windows\Installer\cc17c2.msi
c:\windows\Installer\cc17cc.msi
c:\windows\Installer\cc17dc.msi
c:\windows\Installer\cc17f1.msi
c:\windows\Installer\cc17f9.msi
c:\windows\Installer\cc180f.msi
c:\windows\Installer\cc1858.msi
c:\windows\Installer\cc185e.msi
c:\windows\Installer\cc1864.msi
c:\windows\Installer\cc186a.msi
c:\windows\Installer\ce28f.msi
c:\windows\Installer\d3e95.msi
c:\windows\Installer\ec9148.msp
c:\windows\Installer\f3ad8d.msi
c:\windows\Installer\f3eea9.msp
c:\windows\Installer\f3eebc.msp
c:\windows\Installer\f3eed4.msp
c:\windows\Installer\f559b2.msp
c:\windows\Installer\f8c5cb.msp
c:\windows\Installer\f8c5de.msp
c:\windows\Installer\f8c5f1.msp
c:\windows\Installer\f8c604.msp
c:\windows\Installer\f8c617.msp
c:\windows\Installer\f8c62a.msp
c:\windows\Installer\f8c63c.msp
c:\windows\Installer\fbb477.msp
c:\windows\Installer\fbb48b.msp
c:\windows\Installer\fbb538.msp
c:\windows\Installer\fc8a26.msp
c:\windows\Installer\fcdbb.msi
c:\windows\kb913800.exe
c:\windows\msa.exe
c:\windows\pppatc~1
c:\windows\system32\cpmsky-uninst.exe
c:\windows\system32\drivers\UACnnodstbvuk.sys
c:\windows\system32\msxml71.dll
c:\windows\system32\UACdihqhfnytk.db
c:\windows\system32\UACeaemcwruem.dll
c:\windows\system32\UAChblbfmbaka.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiwvakbkvrb.dll
c:\windows\system32\UACltrmhcedav.dll
c:\windows\system32\UACroyiltnanu.dll
c:\windows\system32\UACwamoqdnpnk.dll
c:\windows\winhelp.ini
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_ABEL
——-\Legacy_NPF
——-\Service_Abel
——-\Service_RkHit


((((((((((((((((((((((((( Files Created from 2009-06-24 to 2009-07-24 )))))))))))))))))))))))))))))))
.

2009-07-23 06:08 . 2009-07-23 06:08 ——– d—–w- c:\program files\ERUNT
2009-07-23 02:14 . 2009-07-23 02:14 137732 —-a-w- c:\windows\msb.exe
2009-07-22 07:26 . 2009-07-22 07:26 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-19 23:55 . 2009-07-19 23:55 ——– d—–w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Installer3660
2009-07-18 19:48 . 2009-07-18 19:49 ——– d—–w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Temp
2009-07-18 02:48 . 2004-08-04 05:56 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-07-18 02:48 . 2004-08-04 05:56 21504 —-a-w- c:\windows\system32\dllcache\hidserv.dll
2009-07-18 02:48 . 2004-08-04 03:58 14848 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2009-07-18 02:48 . 2004-08-04 03:58 14848 —-a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-07-02 00:00 . 2009-07-02 00:00 ——– d—–w- c:\windows\system32\wbem\Repository

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-24 04:20 . 2005-11-11 00:59 ——– d—–w- c:\program files\Google
2009-07-23 07:32 . 2008-08-30 08:09 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-07-23 04:50 . 2008-01-09 02:27 94208 —-a-w- c:\windows\DUMP8f11.tmp
2009-07-23 04:46 . 2008-06-29 16:01 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-23 04:46 . 2008-06-29 16:01 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-07-23 00:23 . 2007-12-30 05:13 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Google Updater
2009-07-23 00:22 . 2007-02-16 18:42 ——– d—–w- c:\program files\Windows Media Connect 2
2009-07-23 00:22 . 2006-12-14 02:58 ——– d—–w- c:\program files\Smilebox
2009-07-23 00:22 . 2006-06-10 14:36 ——– d—–w- c:\program files\Sierra On-Line
2009-07-23 00:22 . 2005-11-11 00:46 ——– d—a-w- c:\program files\TurboTax Online
2009-07-23 00:22 . 2006-11-13 02:37 ——– d—–w- c:\program files\Scrapbook Designer
2009-07-23 00:22 . 2005-11-11 00:31 ——– d—–w- c:\program files\Rhapsody
2009-07-23 00:22 . 2006-06-10 22:29 ——– d—–w- c:\program files\LimeWire
2009-07-23 00:22 . 2006-07-03 20:26 ——– d—–w- c:\program files\Hemera Products
2009-07-23 00:22 . 2005-11-11 00:40 ——– d—a-w- c:\program files\IntelliMoverDemo
2009-07-23 00:22 . 2008-07-01 00:28 ——– d—–w- c:\program files\FinePixViewer
2009-07-23 00:22 . 2006-02-07 01:02 ——– d—–w- c:\program files\CallWave
2009-07-22 15:31 . 2008-08-21 06:25 ——– d—–w- c:\program files\IEPro
2009-07-22 15:30 . 2008-11-30 00:30 ——– d—–w- c:\program files\UnicodeImageMaker
2009-07-19 20:57 . 2008-02-02 22:47 1367 —-a-w- c:\windows\system32\HPA.DAT
2009-07-17 20:21 . 2008-01-09 02:37 334352 —-a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-01 03:45 . 2008-03-21 01:43 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\LimeWire
2009-06-18 04:29 . 2008-07-19 20:42 ——– d—–w- c:\program files\RegCure
2009-06-18 04:29 . 2005-11-11 00:54 ——– d—–w- c:\program files\PC-Doctor 5 for Windows
2009-06-18 04:29 . 2005-11-11 00:30 ——– d—–w- c:\program files\MSN Encarta Standard
2009-06-16 16:28 . 2009-06-16 16:28 390664 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-11 06:28 . 2008-10-03 15:11 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2009-06-11 05:56 . 2009-06-11 05:56 ——– d—–w- c:\program files\VersalSoft
2009-06-11 05:56 . 2009-06-11 05:56 ——– d—–w- c:\program files\Universal
2009-06-11 02:23 . 2009-06-11 02:23 9200 ——w- c:\windows\system32\drivers\cdralw2k.sys
2009-06-11 02:23 . 2009-06-11 02:23 9072 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2009-06-11 02:23 . 2005-04-25 17:03 44944 ——w- c:\windows\system32\drivers\pxhelp20.sys
2009-06-08 19:00 . 2009-06-15 05:03 110592 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\f6ektngu.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
2009-05-30 21:19 . 2009-05-30 21:14 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\U3
2009-05-03 00:40 . 2009-03-09 23:17 82380 —-a-w- c:\windows\system32\drivers\AFS2K.SYS
2009-04-28 22:24 . 2009-04-28 22:24 8552 —-a-w- c:\windows\system32\drivers\asctrm.sys
2009-07-23 02:06 . 2008-10-17 19:05 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2008-05-16 22:04 . 2008-05-16 22:03 848 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Uniblue SpeedUpMyPC"="c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" [2007-12-07 9479448]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-30 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2008-08-02 181488]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-06-14 234736]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Share-to-Web Namespace Daemon"="c:\program files\HP\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 69632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-28 198160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
VZAccess Manager.lnk - c:\program files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe [2009-3-2 1787184]
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2006-2-9 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SABWinLogon]
2008-04-07 02:50 176128 —-a-w- c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\CallWave\\IAM.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\lxbmcoms.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56642:TCP"= 56642:TCP:Pando P2P TCP Listening Port
"56642:UDP"= 56642:UDP:Pando P2P UDP Listening Port

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [12/7/2008 12:01 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/7/2008 12:01 AM 20560]
R2 lxbm_device;lxbm_device;c:\windows\system32\lxbmcoms.exe -service –> c:\windows\system32\lxbmcoms.exe -service [?]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [8/30/2008 3:07 AM 210216]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [5/9/2008 11:08 AM 174336]
S1 rxp;rxp;\??\c:\windows\system32\drivers\rxp.sys –> c:\windows\system32\drivers\rxp.sys [?]
S1 SABKUTIL;SABKUTIL;\??\c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys –> c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys [?]
S3 UBWipRFBMLg;UBWipRFBMLg;\??\c:\downloads\Windows\Downloads\MHS\GNFDQ –> c:\downloads\Windows\Downloads\MHS\GNFDQ [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q106&bd;=pavilion&pf;=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.callwave.com/iam/DemoIntro.html?u=0f5ab0f3e201a2176ba63427dc04bc729318fe15fe61a8ad81d3e2d0bb7349025c&Ver;=3.09.7.0&OS;=WinNT:5.1.2600SP:2.0&co;=0
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949}
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: trymedia.com
FF - ProfilePath - c:\docume~1\HP_ADM~1\APPLIC~1\Mozilla\Firefox\Profiles\f6ektngu.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p;=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-23 23:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UBWipRFBMLg]
"ImagePath"="\??\c:\downloads\Windows\Downloads\MHS\GNFDQ"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3329523479-2079964671-2664348731-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
@SACL=

[HKEY_USERS\S-1-5-21-3329523479-2079964671-2664348731-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ò*k*"\OpenWithList]
@Class="Shell"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(744)
c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(820)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll

- - - - - - - > 'explorer.exe'(3824)
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
c:\windows\arservice.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
c:\windows\system32\drivers\dcfssvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\lxbmcoms.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\HP Share-to-Web\hpgs2wnf.exe
c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
c:\progra~1\Webshots\webshots.scr
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-07-24 23:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-24 04:48

Pre-Run: 99,542,085,632 bytes free
Post-Run: 99,543,715,840 bytes free

405 — E O F — 2008-08-12 22:51
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Infected_TrojanDownloader_Win32_Renos_IO_t105464.html&view=findpost&p=581339#entry581339

Collect::
c:\windows\msb.exe
c:\windows\DUMP8f11.tmp

KillAll::

Folder::
c:\downloads\Windows\Downloads\MHS\GNFDQ

Driver::
UBWipRFBMLg

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
Here is the Malwarebyte's Report. Do you want the new ComboFix report as well? *I'm unable to "accept" the Kaspersky scan* Malwarebytes' Anti-Malware 1.39 Database version: 2493 Windows 5.1.2600 Service Pack 2 7/24/2009 9:12:16 AM mbam-log-2009-07-24 (09-12-16).txt Scan type: Quick Scan Objects scanned: 109612 Time elapsed: 7 minute(s), 31 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 95 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\Typelib\{e24211b3-a78a-c6a9-d317-70979ace5058} (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\system32\WhoisCL.exe (Adware.BHO) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\0122_saginaw.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\0616_lovitz.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\adult-ramblings_aez-anastacia-hw.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\akatype_akadora.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\angst_pimp.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\artsylady_al-cinderella.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\author.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\B046-brooklyn_kid.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\barrer.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\billy-argel_ginga.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\billy-argel_olho-de-boi.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\blackadd.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\bmug_asianfont.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\bombhaus-digital-foundry_breastbomb.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\burnstow.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\calligr0.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\calligraph.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\callisv2.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\casady-and-greene_calligraphyflf.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\casady-and-greene_regencyscriptflf.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\casady-and-greene_slendergoldflf.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\celesr.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\chanmd.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\char1b.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\charming.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\chillymoe.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\christophe-beaumale_cursif.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\chr_card.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\chyld.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\civilian.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\co.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\colourba.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\crumble.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\david-rakowski_beachman-script.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\david-rakowski_rechtman.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\defaced_dingle-berries.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\dieter-steffmann_brock-script.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\dieter-steffmann_chopin-script.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\digital-graphics-labs_ils-script.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\diogene_chopinscript.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\divide-by-zero_tommys-first-alphabet.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\dos.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\dow.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\dragor.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\echei.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\edward-leach_zachary.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\efflores.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\emboss_el.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\emboss_el2.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\eurofctt.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\filxgirl.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\font-environment_tpf-senseless-strokes.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\fontasyland_fl-sesame-street.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\fonte.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\gad.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\girlsare.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\goodfish.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\gorillablu_precious-moments.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\hansa.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\inkwell.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\invitati.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\jean-douteau_ecolier.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\jennaspopsicles.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\kill.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\last-soundtrack_chic-decay.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\ldsscrp.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\libewn.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\loki_cola.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\lothar.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\maharlik.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\mischa-hof_witched.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\nancy-lorenz_elven-common-speak.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\nancy-lorenz_marigold-wild.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\niewcmn.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\niteclub.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\oakwood.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\oktoberfest.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\papercut.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\partridg.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\philippe-tassel_ducahier.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\pinecasu.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\rick-mueller_brandy.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\rina.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\roger-white_hanford-script.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\script9.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\shangril.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\steven-l-wood_msdwt-manuscript.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\subway.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\the-devil-in-jason-ramirez_one-fell-swoop.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\typo5_oil.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\unicorn.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\velvet.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\vianta.zip (Worm.Archive) -> Quarantined and deleted successfully. c:\WINDOWS\Fonts\xtraflex.zip (Worm.Archive) -> Quarantined and deleted successfully.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI