This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] I think I have a rootkit!

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A friend of a friend brought me a laptop that has been "running slow" for a couple of weeks now. I tried to run malwarebytes on it but it shuts down whenever I try to install it or for late matter whenever I try to go to this or any website dealing with getting it cleaned up. Thanks for the help ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/31 11:33 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP2 ================================================== Drivers ——————- Name: aujasnkj.sys Image Path: C:\DOCUME~1\user\LOCALS~1\Temp\aujasnkj.sys Address: 0xED289000 Size: 84352 File Visible: No Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xEEC64000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7CF3000 Size: 8192 File Visible: No Signed: - Status: - Name: mchInjDrv.sys Image Path: C:\WINDOWS\system32\Drivers\mchInjDrv.sys Address: 0xF7F08000 Size: 2560 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xED7DC000 Size: 49152 File Visible: No Signed: - Status: - SSDT ——————- #: 041 Function Name: NtCreateKey Status: Hooked by "PCTCore.sys" at address 0xf76cd514 #: 047 Function Name: NtCreateProcess Status: Hooked by "PCTCore.sys" at address 0xf76bc282 #: 048 Function Name: NtCreateProcessEx Status: Hooked by "PCTCore.sys" at address 0xf76bc474 #: 063 Function Name: NtDeleteKey Status: Hooked by "PCTCore.sys" at address 0xf76cdd00 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "PCTCore.sys" at address 0xf76cdfb8 #: 119 Function Name: NtOpenKey Status: Hooked by "PCTCore.sys" at address 0xf76cc3fa #: 192 Function Name: NtRenameKey Status: Hooked by "PCTCore.sys" at address 0xf76ce422 #: 247 Function Name: NtSetValueKey Status: Hooked by "PCTCore.sys" at address 0xf76cd7d8 #: 257 Function Name: NtTerminateProcess Status: Hooked by "PCTCore.sys" at address 0xf76bbf32 ==EOF== DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 11:28:30.63 on 08/31/09 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.494.154 [GMT -4:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\brss01a.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\System32\alg.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\WINDOWS\system32\bmwebcfg.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe C:\WINDOWS\system32\lxdicoms.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Common Files\AOL\1171387913\ee\AOLSoftware.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Cingular\Communication Manager\CingularCCM.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\RegistryPC\RegistryPC.exe C:\Program Files\Dell Support\DSAgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\Program Files\America Online 9.0\aoltray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\Program Files\Cingular\Communication Manager\bmctl.exe C:\WINDOWS\system32\wuauclt.exe E:\dds.pif C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: VINMaker: {6b3e26a3-c1e2-4125-8c8f-f1303f748c3a} - c:\windows\system32\kdpini.dll BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - Google Toolbar Notifier BHO BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - Google Dictionary Compression sdch TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No File TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe" uRun: [RegistryPC] c:\program files\registrypc\RegistryPC.exe -boot uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [SunJavaUpdateSched] c:\program files\java\j2re1.4.2_03\bin\jusched.exe mRun: [RecoverFromReboot] c:\windows\temp\RecoverFromReboot.exe mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [PrinTray] c:\windows\system32\spool\drivers\w32x86\3\printray.exe mRun: [mmtask] c:\program files\musicmatch\musicmatch jukebox\mmtask.exe mRun: [lxdimon.exe] "c:\program files\lexmark 3500-4500 series\lxdimon.exe" mRun: [lxdiamon] "c:\program files\lexmark 3500-4500 series\lxdiamon.exe" mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe" mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe mRun: [HostManager] c:\program files\common files\aol\1171387913\ee\AOLSoftware.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [FaxCenterServer] "c:\program files\\lexmark fax solutions\fm3032.exe" /s mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe" mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [Cingular Communication Manager] c:\program files\cingular\communication manager\CingularCCM.exe -a mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe uPolicies-explorer: NoThumbnailCache = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll LSP: bmnet.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126026505890 DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - hxxp://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Notify: cafadcfdabbdece - c:\windows\system32\cafadcfdabbdece.dll Notify: igfxcui - igfxdev.dll Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll ============= SERVICES / DRIVERS =============== R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-6-5 130936] R2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service –> c:\windows\system32\lxdicoms.exe -service [?] R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdiserv.exe [2009-7-31 99248] R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-6-5 348752] R2 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-6-5 1095560] S3 ACGPRS;Sierra Wireless 3G Adapter;c:\windows\system32\drivers\acgprs.sys [2006-1-26 97280] S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys –> c:\windows\system32\drivers\rootrepeal.sys [?] =============== Created Last 30 ================ 2009-08-28 15:13 39,936 a——- c:\windows\system32\02eb90b255815e9067361a3b549c9ff6.sys 2009-08-28 15:13 195,584 a——- c:\windows\system32\kdpini.dll 2009-08-28 10:34 –d—– c:\windows\system32\dllcache\cache 2009-08-28 10:00 a-dshr– C:\cmdcons 2009-08-28 09:54 229,376 a——- c:\windows\PEV.exe 2009-08-28 09:54 161,792 a——- c:\windows\SWREG.exe 2009-08-28 09:54 98,816 a——- c:\windows\sed.exe 2009-08-27 17:41 –d—– c:\docume~1\user\applic~1\Malwarebytes 2009-08-27 17:40 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-27 17:40 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-27 17:40 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-27 17:40 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-27 15:51 3,942,048 a——- C:\mbam-setup.exe 2009-08-27 08:50 –d—– c:\docume~1\user\applic~1\RegistryPC 2009-08-27 08:50 –d—– c:\program files\RegistryPC 2009-08-26 09:26 –d—– C:\TaxCut Business 2008 2009-08-26 08:41 1,089,601 ——– c:\windows\system32\dllcache\ntprint.cat 2009-08-25 11:04 –d—– c:\windows\system32\XPSViewer 2009-08-25 11:02 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-25 11:02 117,760 ——– c:\windows\system32\prntvpt.dll 2009-08-25 11:02 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-25 11:02 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-08-25 11:02 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll 2009-08-25 11:02 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-08-25 11:02 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-25 11:02 –d—– C:\d0c1720f1bcb8be2a9 2009-08-23 11:04 –d—– c:\program files\MSXML 6.0 2009-08-21 22:16 2,060,288 a——- c:\windows\system32\usbaaplrc.dll 2009-08-21 22:16 39,424 a——- c:\windows\system32\drivers\usbaapl.sys 2009-08-20 11:06 –d—– c:\program files\common files\ODBC 2009-08-20 11:02 –d—– c:\windows\ServicePackFiles 2009-08-19 12:41 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx 2009-08-19 12:37 655,872 ——– c:\windows\system32\dllcache\mstscax.dll 2009-08-05 05:11 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll ==================== Find3M ==================== 2009-08-13 11:45 280,064 ——– c:\windows\system32\cafadcfdabbdece.dll 2009-08-05 05:11 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll 2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\cache\mshtml.dll 2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll 2009-07-17 14:55 58,880 a——- c:\windows\system32\atl.dll 2009-07-17 14:55 58,880 ——– c:\windows\system32\dllcache\atl.dll 2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll 2009-07-13 10:08 286,720 ——– c:\windows\system32\dllcache\wmpdxm.dll 2009-07-13 10:08 5,537,792 ——– c:\windows\system32\dllcache\wmp.dll 2009-07-10 09:42 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll 2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-06-29 04:35 634,632 ——– c:\windows\system32\dllcache\iexplore.exe 2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat 2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2009-06-25 04:44 724,480 a——- c:\windows\system32\lsasrv.dll 2009-06-25 04:44 298,496 a——- c:\windows\system32\kerberos.dll 2009-06-25 04:44 168,448 a——- c:\windows\system32\schannel.dll 2009-06-25 04:44 133,632 a——- c:\windows\system32\msv1_0.dll 2009-06-25 04:44 59,392 a——- c:\windows\system32\wdigest.dll 2009-06-25 04:44 56,320 a——- c:\windows\system32\secur32.dll 2009-06-25 04:44 724,480 ——– c:\windows\system32\dllcache\lsasrv.dll 2009-06-25 04:44 298,496 ——– c:\windows\system32\dllcache\kerberos.dll 2009-06-25 04:44 168,448 ——– c:\windows\system32\dllcache\schannel.dll 2009-06-25 04:44 133,632 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-06-25 04:44 59,392 ——– c:\windows\system32\dllcache\wdigest.dll 2009-06-25 04:44 56,320 ——– c:\windows\system32\dllcache\secur32.dll 2009-06-22 07:34 92,544 ——– c:\windows\system32\dllcache\ksecdd.sys 2009-06-16 10:55 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:55 82,432 a——- c:\windows\system32\fontsub.dll 2009-06-16 10:55 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-06-16 10:55 82,432 ——– c:\windows\system32\dllcache\fontsub.dll 2009-06-12 07:50 76,288 a——- c:\windows\system32\telnet.exe 2009-06-12 07:50 76,288 ——– c:\windows\system32\dllcache\telnet.exe 2009-06-10 10:21 84,992 a——- c:\windows\system32\avifil32.dll 2009-06-10 10:21 84,992 ——– c:\windows\system32\dllcache\avifil32.dll 2009-06-10 02:32 132,096 a——- c:\windows\system32\wkssvc.dll 2009-06-10 02:32 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll 2009-06-05 03:42 655,872 a——- c:\windows\system32\mstscax.dll 2009-06-03 15:27 1,290,752 a——- c:\windows\system32\quartz.dll 2009-06-03 15:27 1,290,752 ——– c:\windows\system32\dllcache\quartz.dll 2006-03-22 08:13 259,208 a——- c:\docume~1\user\applic~1\GDIPFONTCACHEV1.DAT 2006-03-14 01:44 6,531 a——- c:\program files\FORM1_NOTICE_FROM_LANDLORD_TO_TENANT.pdf 2005-11-12 22:39 6,841,856 a——- c:\program files\WIA390CANONDRIVERS.exe 2005-09-13 23:04 114,567 a——- c:\program files\le_cbt.exe 2005-08-04 18:44 42,518,640 a——- c:\program files\TaxCut2004CompleteHomeandBusinessD.exe 1998-08-15 22:05 750 a——- c:\program files\2000 Professional Tax System For Windows.LNK ============= FINISH: 11:29:47.04 ===============

Attachments:

Hello Danny Haggard,
Welcome to What the Tech.
My name is OCD, I will be helping you with your log today.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your DDS and RootRepeal logs now, I will post back shortly with instructions.

Hello Danny Haggard,

  • You may want to print out these instructions for reference prior to proceeding.
  • This solution is specifically tailored for this particular problem, please do not attempt to use this solution on another computer.
  • If you have any questions, or are uncertain about any steps please ask 'before' proceeding.
- - - - - Next - - - - -

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad".
This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself.

- - - - - Next - - - - -

Please go to Start Menu > Control Panel > Add/ Remove Programs
Scroll Down and locate the following programs:
  • My Way Search Assistant
  • Viewpoint Media Player / Viewpoint Manager / Viewpoint
Select each one of the programs, then select remove.
(if the program is not listed don't be alarmed, just continue with the list)

Exit the Control Panel when finished.

- - - - - Next - - - - -

There is one file I am not sure about so I would like for you to submit it to be analyzed

Submit this File (le_cbt.exe) For Analysis
  • Please visit Jotti at http://virusscan.jotti.org/
  • Click on Browse… and navigate to the following file: c:\program files\le_cbt.exe
  • Click Open
  • Please post back the results of this scan.
If Jotti is too busy please try Virustotal at http://www.virustotal.com/

- - - - - Next - - - - -

Please download ComboFix from one of these locations:

Link 1
Link 2

A guide can be found here

* IMPORTANT : Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
*Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.
When finished, it will produce a log for you. The log will be located here C:\ComboFix.txt (Provided 'C' is your root directory)
Notes:
  • Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it at least 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • Results from the Jotti scan
  • ComboFix.txt
  • Tell me how your computer is running at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI