This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Personal AV removal and more

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Personal Antivirus started appearing on the computer. I ran Malwarebytes and it found and removed Personal AV but there appears to be an entry that can not be removed, I have attached the Malware Bytes Log. This virus seems to have affected the network connection, when I try to connect to a webpage it can't resolve the host name ex: www.google.com I can however ping the IP of google. I have included DDS and RootRepeal logs, when I attempted to run rootrepeal it locks up on hidden services so I don't have that part of the log. It appears to be scanning but I let it run for several hours with no results. DDS Log: DDS (Ver_09-06-26.01) - NTFSx86 NETWORK Run by [removed] at 15:39:58.01 on Tue 09/01/2009 Internet Explorer: 8.0.6001.18813 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1982.1262 [GMT -5:00] SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Windows\Explorer.EXE C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe E:\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop BHO: ElnkBhoGuard Class: {00000000-0000-0000-0000-000000000002} - c:\program files\peoplepc\toolbar\ScamGrd.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: ElnkScamBHO Class: {15f4d456-5baa-4076-8486-eecb38cd3e57} - c:\program files\peoplepc\toolbar\ScamGrd.dll BHO: Accelerator Plugin: {656ec4b7-072b-4698-b504-2a414c1f0037} - c:\progra~1\people~1\PRPL_I~1.DLL BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll uRun: [WMPNSCFG] "c:\program files\windows media player\WMPNSCFG.exe" uRun: [SpybotSD TeaTimer] "c:\program files\spybot - search & destroy\TeaTimer.exe" uRun: [HPADVISOR] "c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe" autoRun uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [NvSvc] "RUNDLL32.EXE" c:\windows\system32\nvsvc.dll,nvsvcStart mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] "RUNDLL32.EXE" c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe" mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll" mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0\bin\jusched.exe" mRun: [snp2uvc] c:\windows\vsnp2uvc.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [QlbCtrl] "c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe" /Start mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [IS CfgWiz] "c:\program files\common files\symantec shared\opc\{31011d49-d90c-4da0-878b-78d28ad507af}\cltUIStb.exe" /MODULE CfgWiz /GUID {BC8D3EAF-F864-4d4b-AB4D-B3D0C32E2840} /MODE CfgWiz /CMDLINE "REBOOT" mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe" mRun: [HP Health Check Scheduler] "c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe" mRun: [Bart Station] "c:\program files\peoplepc\isp7000\bin\PPCOLink.exe" -STATION mRun: [AppleSyncNotifier] "c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe" mRun: [SpySweeper] "c:\program files\webroot\spy sweeper\SpySweeperUI.exe" /startintray mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\fixit.exe" /runcleanupscript StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\eventr~1.lnk - c:\program files\printmaster silver 17\Remind.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: WRNotifier - WRLogonNTF.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R0 AFS;AFS;c:\windows\system32\drivers\AFS.SYS [2008-6-28 79052] R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\Ndisrd.sys [2009-8-26 22016] S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-8-5 9968] S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-8-5 74480] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-8-31 1153368] S3 Ndisrd;WinpkFilter Service;c:\windows\system32\drivers\Ndisrd.sys [2009-8-26 22016] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-8-5 7408] =============== Created Last 30 ================ 2009-09-01 15:08 61,440 a——- c:\windows\system32\drivers\doafo.sys 2009-09-01 10:25 –d—– c:\programdata\SUPERAntiSpyware.com 2009-09-01 10:25 –d—– c:\progra~2\SUPERAntiSpyware.com 2009-09-01 10:25 –d—– c:\users\rains\appdata\roaming\SUPERAntiSpyware.com 2009-09-01 10:25 –d—– c:\program files\SUPERAntiSpyware 2009-09-01 10:19 –d—– c:\program files\common files\Wise Installation Wizard 2009-09-01 08:59 387,167,881 a——- c:\windows\MEMORY.DMP 2009-09-01 07:11 –d—– c:\users\rains\appdata\roaming\Malwarebytes 2009-08-31 21:56 1,905 a——- c:\windows\diagwrn.xml 2009-08-31 21:56 1,905 a——- c:\windows\diagerr.xml 2009-08-31 20:59 –d—– c:\program files\Trend Micro 2009-08-31 20:24 13,025 a——- c:\users\rains\appdata\roaming\nvModes.dat 2009-08-31 20:03 –d—– c:\programdata\Spybot - Search & Destroy 2009-08-31 20:03 –d—– c:\program files\Spybot - Search & Destroy 2009-08-31 20:03 –d—– c:\progra~2\Spybot - Search & Destroy 2009-08-31 19:32 –d—– c:\users\rains\Bluetooth Software 2009-08-31 19:32 –d—– c:\users\rains\appdata\roaming\Webroot 2009-08-31 19:06 –d—– c:\users\Rains 2009-08-31 13:50 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-31 13:50 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-31 13:50 –d—– c:\programdata\Malwarebytes 2009-08-31 13:50 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-31 13:50 –d—– c:\progra~2\Malwarebytes 2009-08-26 19:39 61,440 a——- c:\windows\system32\ndisapi.dll 2009-08-26 19:39 22,016 a——- c:\windows\system32\drivers\Ndisrd.sys 2009-08-26 19:39 13,312 a——- c:\windows\system32\drivers\snetcfg.exe 2009-08-26 18:34 –d—– c:\program files\common files\Uninstall 2009-08-19 22:43 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-08-19 22:43 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-08-19 22:43 –d—– c:\program files\iPod 2009-08-19 22:43 –d—– c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-08-19 22:43 –d—– c:\program files\iTunes 2009-08-19 22:43 –d—– c:\progra~2\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-08-13 10:44 71,680 a——- c:\windows\system32\atl.dll 2009-08-13 10:44 160,256 a——- c:\windows\system32\wkssvc.dll 2009-08-13 10:44 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-08-13 10:44 91,136 a——- c:\windows\system32\avifil32.dll 2009-08-13 10:44 499,712 a——- c:\windows\system32\kerberos.dll 2009-08-13 10:44 270,848 a——- c:\windows\system32\schannel.dll 2009-08-13 10:44 218,624 a——- c:\windows\system32\msv1_0.dll 2009-08-13 10:44 175,104 a——- c:\windows\system32\wdigest.dll 2009-08-13 10:44 1,259,008 a——- c:\windows\system32\lsasrv.dll 2009-08-13 10:44 439,864 a——- c:\windows\system32\drivers\ksecdd.sys 2009-08-13 10:44 72,704 a——- c:\windows\system32\secur32.dll 2009-08-13 10:44 9,728 a——- c:\windows\system32\lsass.exe 2009-08-13 10:43 313,344 a——- c:\windows\system32\wmpdxm.dll 2009-08-13 10:43 8,147,456 a——- c:\windows\system32\wmploc.DLL 2009-08-13 10:43 7,680 a——- c:\windows\system32\spwmp.dll 2009-08-13 10:43 4,096 a——- c:\windows\system32\msdxm.ocx 2009-08-13 10:43 4,096 a——- c:\windows\system32\dxmasf.dll 2009-08-13 10:43 43,520 a——- c:\windows\system32\msdxm.tlb 2009-08-13 10:43 18,432 a——- c:\windows\system32\amcompat.tlb ==================== Find3M ==================== 2009-09-01 08:53 20,284,348 a——- c:\program files\PROCESSLIST.DB 2009-09-01 08:52 1,221,434 a——- c:\program files\PROCESSLISTRELATED.DB 2009-08-31 21:38 143,360 a——- c:\windows\inf\infstrng.dat 2009-08-31 21:38 51,200 a——- c:\windows\inf\infpub.dat 2009-08-31 21:38 86,016 a——- c:\windows\inf\infstor.dat 2009-07-21 16:52 915,456 a——- c:\windows\system32\wininet.dll 2009-07-21 16:47 109,056 a——- c:\windows\system32\iesysprep.dll 2009-07-21 16:47 71,680 a——- c:\windows\system32\iesetup.dll 2009-07-21 15:13 133,632 a——- c:\windows\system32\ieUnatt.exe 2009-07-14 05:53 665,600 a——- c:\windows\inf\drvindex.dat 2009-06-15 09:53 156,672 a——- c:\windows\system32\t2embed.dll 2009-06-15 09:52 23,552 a——- c:\windows\system32\lpk.dll 2009-06-15 09:52 72,704 a——- c:\windows\system32\fontsub.dll 2009-06-15 09:51 10,240 a——- c:\windows\system32\dciman32.dll 2009-06-15 07:42 289,792 a——- c:\windows\system32\atmfd.dll 2009-01-11 01:00 174 a–sh— c:\program files\desktop.ini 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2007-08-30 20:07 22 a–sh— c:\windows\sminst\HPCD.sys ============= FINISH: 15:41:29.84 =============== DDS Log: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/09/02 06:43 Program Version: Version 1.3.5.0 Windows Version: Windows Vista SP2 ================================================== Drivers ——————- Name: dump_diskdump.sys Image Path: C:\Windows\System32\Drivers\dump_diskdump.sys Address: 0x91175000 Size: 40960 File Visible: No Signed: - Status: - Name: dump_nvstor.sys Image Path: C:\Windows\System32\Drivers\dump_nvstor.sys Address: 0x9117F000 Size: 53248 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\Windows\system32\drivers\rootrepeal.sys Address: 0xAB83D000 Size: 49152 File Visible: No Signed: - Status: - Processes ——————- Path: System PID: 4 Status: Locked to the Windows API! Path: C:\Windows\System32\audiodg.exe PID: 1324 Status: Locked to the Windows API! ==EOF== MalwareBytes Log: Malwarebytes' Anti-Malware 1.40 Database version: 2551 Windows 6.0.6002 Service Pack 2 9/1/2009 8:57:51 AM mbam-log-2009-09-01 (08-44-08).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 287610 Time elapsed: 51 minute(s), 40 second(s) Memory Processes Infected: 1 Memory Modules Infected: 2 Registry Keys Infected: 4 Registry Values Infected: 3 Registry Data Items Infected: 1 Folders Infected: 2 Files Infected: 6 Memory Processes Infected: C:\Program Files\PersonalAV\PAV.exe (Rogue.PersonalAntiVirus) -> No action taken. Memory Modules Infected: \\?\globalroot\systemroot\System32\UACnqrqeisevc.dll (Rogue.Agent) -> No action taken. C:\Windows\System32\msxmlm.dll (Trojan.FakeAlert) -> No action taken. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.BHO.H) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.BHO.H) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> No action taken. Registry Values Infected: HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) -> No action taken. HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msdrv (Trojan.Agent) -> No action taken. Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken. Folders Infected: C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) -> No action taken. C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) -> No action taken. Files Infected: C:\Windows\System32\msxmlm.dll (Trojan.BHO.H) -> No action taken. \\?\globalroot\systemroot\System32\UACnqrqeisevc.dll (Rogue.Agent) -> No action taken. C:\Program Files\PersonalAV\PAV.exe (Rogue.PersonalAntiVirus) -> No action taken. C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) -> No action taken. C:\Windows\system32\uacinit.dll (Trojan.Agent) -> No action taken. C:\Windows\System32\NetFilter.exe (Trojan.Agent) -> No action taken.
Hi,

Please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications,McAfee, Windows Defender and Adwatch, (usually via a right click on the System Tray icon.) They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Thanks for the reply, below is the ComboFix log: ComboFix 09-09-03.02 - owner 09/03/2009 17:32.1.2 - NTFSx86 MicrosoftÆ Windows Vistaô Home Premium 6.0.6002.2.1252.1.1033.18.1982.1259 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-2363746086-1690789789-852912484-500 c:\$recycle.bin\S-1-5-21-3151259665-1138395727-835149201-500 c:\windows\system32\AutoRun.inf c:\windows\system32\drivers\ndisrd.sys c:\windows\system32\drivers\snetcfg.exe c:\windows\system32\drivers\UACvaecpqyxcx.sys c:\windows\system32\ndisapi.dll c:\windows\system32\uacinit.dll c:\windows\system32\UACnqrqeisevc.dll c:\windows\system32\UACpfrdxoptvk.dll c:\windows\system32\UACtcmvavqqrh.dat c:\windows\system32\UACxsjbotqlvq.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Service_UACd.sys ——-\Legacy_UACd.sys ——-\Service_Ndisrd ——-\Service_NdisrdMP ((((((((((((((((((((((((( Files Created from 2009-08-03 to 2009-09-03 ))))))))))))))))))))))))))))))) . 2009-09-03 22:40 . 2009-09-03 22:42 ——– d—–w- c:\users\owner\AppData\Local\temp 2009-09-03 02:17 . 2009-09-03 11:34 ——– d—–w- c:\users\owner\AppData\Local\MigWiz 2009-09-03 02:15 . 2009-09-03 02:15 ——– d—–w- c:\users\owner\AppData\Local\Apple 2009-09-03 02:11 . 2009-09-03 02:11 ——– d—–w- c:\users\owner\AppData\Roaming\Spearit 2009-09-03 02:11 . 2009-09-03 02:11 ——– d—–w- c:\programdata\Spearit 2009-09-03 02:11 . 2009-09-03 02:11 ——– d—–w- c:\program files\Spearit 2009-09-03 02:10 . 2009-09-03 02:10 ——– d—–w- c:\users\Rains\AppData\Local\MigWiz 2009-09-01 20:37 . 2009-09-01 20:38 ——– d—–w- c:\program files\ERUNT 2009-09-01 20:15 . 2009-09-01 20:15 680 —-a-w- c:\users\Rains\AppData\Local\d3d9caps.dat 2009-09-01 16:56 . 2009-09-01 16:56 ——– d—–w- c:\users\owner\AppData\Local\Apple Computer 2009-09-01 15:26 . 2009-09-01 15:26 ——– d—–w- c:\users\Rains\AppData\Local\Apple Computer 2009-09-01 15:25 . 2009-09-01 15:25 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2009-09-01 15:25 . 2009-09-01 15:25 ——– d—–w- c:\users\Rains\AppData\Roaming\SUPERAntiSpyware.com 2009-09-01 15:25 . 2009-09-01 15:25 ——– d—–w- c:\program files\SUPERAntiSpyware 2009-09-01 15:19 . 2009-09-01 15:19 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard 2009-09-01 12:11 . 2009-09-01 12:11 ——– d—–w- c:\users\Rains\AppData\Roaming\Malwarebytes 2009-09-01 01:59 . 2009-09-01 01:59 ——– d—–w- c:\program files\Trend Micro 2009-09-01 01:03 . 2009-09-01 15:25 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2009-09-01 01:03 . 2009-09-01 12:51 ——– d—–w- c:\program files\Spybot - Search & Destroy 2009-09-01 00:32 . 2009-09-01 00:32 255248 —-a-w- c:\users\Rains\AppData\Local\GDIPFONTCACHEV1.DAT 2009-09-01 00:32 . 2009-09-01 00:32 ——– d—–w- c:\users\Rains\Bluetooth Software 2009-09-01 00:32 . 2009-09-01 00:32 ——– d—–w- c:\users\Rains\AppData\Roaming\Webroot 2009-09-01 00:31 . 2009-09-01 00:31 ——– d—–w- c:\users\Rains\AppData\Local\QuickPlay 2009-09-01 00:07 . 2009-09-01 00:07 ——– d—–w- c:\users\Rains\AppData\Roaming\hewlett-packard 2009-09-01 00:07 . 2009-09-01 00:07 ——– d—–w- c:\users\Rains\AppData\Local\Hewlett-Packard 2009-08-31 18:51 . 2009-08-31 18:51 ——– d—–w- c:\users\owner\AppData\Roaming\Malwarebytes 2009-08-31 18:50 . 2009-08-03 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-31 18:50 . 2009-09-01 12:11 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-08-31 18:50 . 2009-08-31 18:50 ——– d—–w- c:\programdata\Malwarebytes 2009-08-31 18:50 . 2009-08-03 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-08-27 01:26 . 2009-08-27 01:28 ——– d—–w- c:\users\owner\AppData\Roaming\U3 2009-08-26 23:34 . 2009-09-01 13:58 ——– d—–w- c:\program files\Common Files\Uninstall 2009-08-20 03:43 . 2009-03-19 21:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-08-20 03:43 . 2008-04-17 17:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll 2009-08-20 03:43 . 2009-08-20 03:43 ——– d—–w- c:\program files\iPod 2009-08-20 03:43 . 2009-08-20 03:43 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-08-20 03:43 . 2009-08-20 03:43 ——– d—–w- c:\program files\iTunes 2009-08-20 03:40 . 2009-08-20 03:40 ——– d—–w- c:\program files\QuickTime 2009-08-13 15:44 . 2009-07-17 13:54 71680 —-a-w- c:\windows\system32\atl.dll 2009-08-13 15:44 . 2009-06-10 11:42 160256 —-a-w- c:\windows\system32\wkssvc.dll 2009-08-13 15:44 . 2009-06-04 12:07 2066432 —-a-w- c:\windows\system32\mstscax.dll 2009-08-13 15:44 . 2009-06-10 11:38 91136 —-a-w- c:\windows\system32\avifil32.dll 2009-08-13 15:44 . 2009-06-15 14:52 499712 —-a-w- c:\windows\system32\kerberos.dll 2009-08-13 15:44 . 2009-06-15 14:54 175104 —-a-w- c:\windows\system32\wdigest.dll 2009-08-13 15:44 . 2009-06-15 14:53 270848 —-a-w- c:\windows\system32\schannel.dll 2009-08-13 15:44 . 2009-06-15 14:53 218624 —-a-w- c:\windows\system32\msv1_0.dll 2009-08-13 15:44 . 2009-06-15 23:15 439864 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2009-08-13 15:44 . 2009-06-15 14:52 1259008 —-a-w- c:\windows\system32\lsasrv.dll 2009-08-13 15:44 . 2009-06-15 14:53 72704 —-a-w- c:\windows\system32\secur32.dll 2009-08-13 15:44 . 2009-06-15 12:48 9728 —-a-w- c:\windows\system32\lsass.exe 2009-08-13 15:43 . 2009-07-15 12:39 313344 —-a-w- c:\windows\system32\wmpdxm.dll 2009-08-13 15:43 . 2009-07-15 12:40 8147456 —-a-w- c:\windows\system32\wmploc.DLL 2009-08-13 15:43 . 2009-07-15 12:39 4096 —-a-w- c:\windows\system32\dxmasf.dll 2009-08-13 15:43 . 2009-07-15 12:39 7680 —-a-w- c:\windows\system32\spwmp.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-09-03 02:34 . 2007-06-20 10:11 12 —-a-w- c:\windows\bthservsdp.dat 2009-09-03 02:10 . 2007-08-30 18:53 13025 —-a-w- c:\users\owner\AppData\Roaming\nvModes.dat 2009-09-01 13:53 . 2009-09-01 17:46 20284348 —-a-w- c:\program files\PROCESSLIST.DB 2009-09-01 13:52 . 2009-09-01 17:46 1221434 —-a-w- c:\program files\PROCESSLISTRELATED.DB 2009-09-01 01:24 . 2009-09-01 01:24 13025 —-a-w- c:\users\Rains\AppData\Roaming\nvModes.dat 2009-09-01 00:00 . 2007-06-20 11:19 ——– d—–w- c:\program files\Yahoo! 2009-08-31 23:59 . 2007-06-20 10:45 ——– d—–w- c:\program files\Common Files\Symantec Shared 2009-08-31 21:12 . 2007-06-20 10:45 ——– d—–w- c:\programdata\Symantec 2009-08-20 03:59 . 2009-03-21 23:39 ——– d—–w- c:\program files\Safari 2009-08-20 03:43 . 2009-01-11 06:43 ——– d—–w- c:\program files\Common Files\Apple 2009-08-13 23:56 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2009-08-04 02:23 . 2009-01-10 18:16 ——– d—–w- c:\program files\Microsoft Silverlight 2009-07-23 20:15 . 2008-03-08 03:06 13025 —-a-w- c:\users\Guest\AppData\Roaming\nvModes.dat 2009-07-23 19:07 . 2007-06-20 11:20 ——– d—–w- c:\programdata\WildTangent 2009-07-21 21:52 . 2009-07-29 14:27 915456 —-a-w- c:\windows\system32\wininet.dll 2009-07-21 21:47 . 2009-07-29 14:27 109056 —-a-w- c:\windows\system32\iesysprep.dll 2009-07-21 21:47 . 2009-07-29 14:27 71680 —-a-w- c:\windows\system32\iesetup.dll 2009-07-21 20:13 . 2009-07-29 14:27 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar 2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar 2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal 2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration 2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery 2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender 2009-07-13 02:35 . 2008-03-08 02:49 255248 —-a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT 2009-07-10 23:56 . 2007-08-31 08:07 255248 —-a-w- c:\users\owner\AppData\Local\GDIPFONTCACHEV1.DAT 2009-07-10 02:11 . 2007-06-20 10:29 ——– d—–w- c:\program files\Hewlett-Packard 2009-07-10 02:06 . 2007-06-20 10:34 ——– d—–w- c:\program files\Hp 2009-06-15 14:53 . 2009-07-14 19:23 156672 —-a-w- c:\windows\system32\t2embed.dll 2009-06-15 14:52 . 2009-07-14 19:23 23552 —-a-w- c:\windows\system32\lpk.dll 2009-06-15 14:52 . 2009-07-14 19:23 72704 —-a-w- c:\windows\system32\fontsub.dll 2009-06-15 14:51 . 2009-07-14 19:23 10240 —-a-w- c:\windows\system32\dciman32.dll 2009-06-15 12:42 . 2009-07-14 19:23 289792 —-a-w- c:\windows\system32\atmfd.dll 2009-06-09 22:16 . 2009-06-09 22:16 3482240 —-a-w- c:\windows\system32\drivers\snp2uvc.sys 2007-08-31 01:07 . 2007-08-31 01:07 22 –sha-w- c:\windows\SMINST\HPCD.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 17:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup backupExtension=.CommonStartup [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk backup=c:\windows\pss\Bluetooth.lnk.CommonStartup backupExtension=.CommonStartup [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Event Reminder.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Event Reminder.lnk backup=c:\windows\pss\Event Reminder.lnk.CommonStartup backupExtension=.CommonStartup [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup backupExtension=.CommonStartup [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Vongo Tray.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Vongo Tray.lnk backup=c:\windows\pss\Vongo Tray.lnk.CommonStartup backupExtension=.CommonStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(B):D1,60,c1,c4,72,04,ca,01 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{903D2643-8BCB-40A5-BCBC-0BAA7899536C}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{8F0E44E2-228C-4322-87E9-A60E072285C4}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{0743DDAB-782A-46C8-B4FC-14CE0125125E}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play "{A37AFBF8-CCC0-4FC4-A385-4C0C3FCCACC5}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program "{D0C19CFF-DD0D-4E71-AE61-F2D33F28F32E}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{7947CEE0-1A68-47AD-9AD0-A2864363AEA1}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{46E3107F-0D0E-4393-87DF-A48E4C82FD16}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{BC4F7140-2C20-4017-AFD1-B2B6D2A3ACC8}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{9E0473AA-CF07-428B-A6B8-93CDA6C2379B}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{D25DAFD3-D062-4831-82E3-FF5112B1E418}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl "{FB48B738-2CD5-476D-B375-DFDEFAB2783A}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{321E0879-F174-47F8-AC97-4E634A9634E1}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{835EFC0F-3352-424E-B487-DCA96EC9DA8A}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{4215757C-1B60-4807-B7F9-D5C75EC61030}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{90FCA9CA-BA60-45A1-A7F0-966B4018C02C}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{46FFAA76-4CBE-490F-9EE3-502F2196F0A7}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "TCP Query User{50ED27AA-B40F-4829-89A2-4AFED960A90A}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire "UDP Query User{D16EF4C1-EAA4-455D-A096-EB016CB3F218}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire "{4A0977C0-A4D3-4315-8D91-636822919DFB}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{1FB0D87C-D350-466F-91E4-9E207D2D2A5B}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "{8708DC2B-1063-4E88-9B5C-1C8D93C157D9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{DFA7956D-BA38-409A-923C-C5B88C527AC5}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List] "c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink R0 AFS;AFS;c:\windows\System32\drivers\AFS.SYS [6/28/2008 3:44 PM 79052] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408] S4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [8/31/2009 8:03 PM 1153368] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-08-17 c:\windows\Tasks\HPCeeScheduleForowner.job - c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-06-20 21:23] 2009-09-03 c:\windows\Tasks\User_Feed_Synchronization-{7A6B1F41-074D-41BD-94F3-12E3C100F706}.job - c:\windows\system32\msfeedssync.exe [2009-07-29 20:13] . . ——- Supplementary Scan ——- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: {198759B9-65A0-4E64-9998-BD9876674CAA} = 10.0.1.1 . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'Explorer.exe'(1940) c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll . Completion time: 2009-09-03 17:47 - machine was rebooted ComboFix-quarantined-files.txt 2009-09-03 22:47 Pre-Run: 119,972,802,560 bytes free Post-Run: 119,631,060,992 bytes free 244 — E O F — 2009-08-20 17:55
After running the ComboFix I now receive the message "Illegal operation attempted on a registry key that has been marked for deletion" when trying to run any program. I had to copy the ComboFix log to another computer before I could open it.
Hi,

Reboot your system a couple of times and that will get rid of that message.

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.


NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
MalwareBytes Log Malwarebytes' Anti-Malware 1.40 Database version: 2743 Windows 6.0.6000 9/4/2009 6:19:59 PM mbam-log-2009-09-04 (18-19-59).txt Scan type: Quick Scan Objects scanned: 95031 Time elapsed: 3 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Kaspersky Log KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, September 6, 2009 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit (build 6000) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Saturday, September 05, 2009 16:59:46 Records in database: 2749780 Scan settings scan using the following database extended Scan archives yes Scan e-mail databases yes Scan area My Computer C:\ D:\ E:\ F:\ Scan statistics Objects scanned 209675 Threats found 1 Infected objects found 1 Suspicious objects found 0 Scan duration 03:23:46 File name Threat Threats count F:\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\C6KLTY9Q\Antivirus-9091c_2024-1[1].exe Infected: Packed.Win32.Katusha.e 1 Selected area has been scanned.
Hi,

run this program to get rid of your temp files,

then post a fresh DDS and Attach.txt and describe how your computer is running now and if there are any outstanding issues.


Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI