Personal Antivirus started appearing on the computer. I ran Malwarebytes and it found and removed Personal AV but there appears to be an entry that can not be removed, I have attached the Malware Bytes Log. This virus seems to have affected the network connection, when I try to connect to a webpage it can't resolve the host name ex: www.google.com I can however ping the IP of google. I have included DDS and RootRepeal logs, when I attempted to run rootrepeal it locks up on hidden services so I don't have that part of the log. It appears to be scanning but I let it run for several hours with no results.
DDS Log:
DDS (Ver_09-06-26.01) - NTFSx86 NETWORK
Run by [removed] at 15:39:58.01 on Tue 09/01/2009
Internet Explorer: 8.0.6001.18813
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1982.1262 [GMT -5:00]
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Windows\Explorer.EXE
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
E:\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
BHO: ElnkBhoGuard Class: {00000000-0000-0000-0000-000000000002} - c:\program files\peoplepc\toolbar\ScamGrd.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: ElnkScamBHO Class: {15f4d456-5baa-4076-8486-eecb38cd3e57} - c:\program files\peoplepc\toolbar\ScamGrd.dll
BHO: Accelerator Plugin: {656ec4b7-072b-4698-b504-2a414c1f0037} - c:\progra~1\people~1\PRPL_I~1.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
uRun: [WMPNSCFG] "c:\program files\windows media player\WMPNSCFG.exe"
uRun: [SpybotSD TeaTimer] "c:\program files\spybot - search & destroy\TeaTimer.exe"
uRun: [HPADVISOR] "c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe" autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [NvSvc] "RUNDLL32.EXE" c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] "RUNDLL32.EXE" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe"
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0\bin\jusched.exe"
mRun: [snp2uvc] c:\windows\vsnp2uvc.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] "c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe" /Start
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IS CfgWiz] "c:\program files\common files\symantec shared\opc\{31011d49-d90c-4da0-878b-78d28ad507af}\cltUIStb.exe" /MODULE CfgWiz /GUID {BC8D3EAF-F864-4d4b-AB4D-B3D0C32E2840} /MODE CfgWiz /CMDLINE "REBOOT"
mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [HP Health Check Scheduler] "c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe"
mRun: [Bart Station] "c:\program files\peoplepc\isp7000\bin\PPCOLink.exe" -STATION
mRun: [AppleSyncNotifier] "c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe"
mRun: [SpySweeper] "c:\program files\webroot\spy sweeper\SpySweeperUI.exe" /startintray
mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\fixit.exe" /runcleanupscript
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\eventr~1.lnk - c:\program files\printmaster silver 17\Remind.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: WRNotifier - WRLogonNTF.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R0 AFS;AFS;c:\windows\system32\drivers\AFS.SYS [2008-6-28 79052]
R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\Ndisrd.sys [2009-8-26 22016]
S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-8-5 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-8-5 74480]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-8-31 1153368]
S3 Ndisrd;WinpkFilter Service;c:\windows\system32\drivers\Ndisrd.sys [2009-8-26 22016]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-8-5 7408]
=============== Created Last 30 ================
2009-09-01 15:08 61,440 a——- c:\windows\system32\drivers\doafo.sys
2009-09-01 10:25 –d—– c:\programdata\SUPERAntiSpyware.com
2009-09-01 10:25 –d—– c:\progra~2\SUPERAntiSpyware.com
2009-09-01 10:25 –d—– c:\users\rains\appdata\roaming\SUPERAntiSpyware.com
2009-09-01 10:25 –d—– c:\program files\SUPERAntiSpyware
2009-09-01 10:19 –d—– c:\program files\common files\Wise Installation Wizard
2009-09-01 08:59 387,167,881 a——- c:\windows\MEMORY.DMP
2009-09-01 07:11 –d—– c:\users\rains\appdata\roaming\Malwarebytes
2009-08-31 21:56 1,905 a——- c:\windows\diagwrn.xml
2009-08-31 21:56 1,905 a——- c:\windows\diagerr.xml
2009-08-31 20:59 –d—– c:\program files\Trend Micro
2009-08-31 20:24 13,025 a——- c:\users\rains\appdata\roaming\nvModes.dat
2009-08-31 20:03 –d—– c:\programdata\Spybot - Search & Destroy
2009-08-31 20:03 –d—– c:\program files\Spybot - Search & Destroy
2009-08-31 20:03 –d—– c:\progra~2\Spybot - Search & Destroy
2009-08-31 19:32 –d—– c:\users\rains\Bluetooth Software
2009-08-31 19:32 –d—– c:\users\rains\appdata\roaming\Webroot
2009-08-31 19:06 –d—– c:\users\Rains
2009-08-31 13:50 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-31 13:50 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-31 13:50 –d—– c:\programdata\Malwarebytes
2009-08-31 13:50 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-31 13:50 –d—– c:\progra~2\Malwarebytes
2009-08-26 19:39 61,440 a——- c:\windows\system32\ndisapi.dll
2009-08-26 19:39 22,016 a——- c:\windows\system32\drivers\Ndisrd.sys
2009-08-26 19:39 13,312 a——- c:\windows\system32\drivers\snetcfg.exe
2009-08-26 18:34 –d—– c:\program files\common files\Uninstall
2009-08-19 22:43 107,368 a——- c:\windows\system32\GEARAspi.dll
2009-08-19 22:43 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-08-19 22:43 –d—– c:\program files\iPod
2009-08-19 22:43 –d—– c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-19 22:43 –d—– c:\program files\iTunes
2009-08-19 22:43 –d—– c:\progra~2\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-13 10:44 71,680 a——- c:\windows\system32\atl.dll
2009-08-13 10:44 160,256 a——- c:\windows\system32\wkssvc.dll
2009-08-13 10:44 2,066,432 a——- c:\windows\system32\mstscax.dll
2009-08-13 10:44 91,136 a——- c:\windows\system32\avifil32.dll
2009-08-13 10:44 499,712 a——- c:\windows\system32\kerberos.dll
2009-08-13 10:44 270,848 a——- c:\windows\system32\schannel.dll
2009-08-13 10:44 218,624 a——- c:\windows\system32\msv1_0.dll
2009-08-13 10:44 175,104 a——- c:\windows\system32\wdigest.dll
2009-08-13 10:44 1,259,008 a——- c:\windows\system32\lsasrv.dll
2009-08-13 10:44 439,864 a——- c:\windows\system32\drivers\ksecdd.sys
2009-08-13 10:44 72,704 a——- c:\windows\system32\secur32.dll
2009-08-13 10:44 9,728 a——- c:\windows\system32\lsass.exe
2009-08-13 10:43 313,344 a——- c:\windows\system32\wmpdxm.dll
2009-08-13 10:43 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-08-13 10:43 7,680 a——- c:\windows\system32\spwmp.dll
2009-08-13 10:43 4,096 a——- c:\windows\system32\msdxm.ocx
2009-08-13 10:43 4,096 a——- c:\windows\system32\dxmasf.dll
2009-08-13 10:43 43,520 a——- c:\windows\system32\msdxm.tlb
2009-08-13 10:43 18,432 a——- c:\windows\system32\amcompat.tlb
==================== Find3M ====================
2009-09-01 08:53 20,284,348 a——- c:\program files\PROCESSLIST.DB
2009-09-01 08:52 1,221,434 a——- c:\program files\PROCESSLISTRELATED.DB
2009-08-31 21:38 143,360 a——- c:\windows\inf\infstrng.dat
2009-08-31 21:38 51,200 a——- c:\windows\inf\infpub.dat
2009-08-31 21:38 86,016 a——- c:\windows\inf\infstor.dat
2009-07-21 16:52 915,456 a——- c:\windows\system32\wininet.dll
2009-07-21 16:47 109,056 a——- c:\windows\system32\iesysprep.dll
2009-07-21 16:47 71,680 a——- c:\windows\system32\iesetup.dll
2009-07-21 15:13 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-07-14 05:53 665,600 a——- c:\windows\inf\drvindex.dat
2009-06-15 09:53 156,672 a——- c:\windows\system32\t2embed.dll
2009-06-15 09:52 23,552 a——- c:\windows\system32\lpk.dll
2009-06-15 09:52 72,704 a——- c:\windows\system32\fontsub.dll
2009-06-15 09:51 10,240 a——- c:\windows\system32\dciman32.dll
2009-06-15 07:42 289,792 a——- c:\windows\system32\atmfd.dll
2009-01-11 01:00 174 a–sh— c:\program files\desktop.ini
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2007-08-30 20:07 22 a–sh— c:\windows\sminst\HPCD.sys
============= FINISH: 15:41:29.84 ===============
DDS Log:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/02 06:43
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
——————-
Name: dump_diskdump.sys
Image Path: C:\Windows\System32\Drivers\dump_diskdump.sys
Address: 0x91175000 Size: 40960 File Visible: No Signed: -
Status: -
Name: dump_nvstor.sys
Image Path: C:\Windows\System32\Drivers\dump_nvstor.sys
Address: 0x9117F000 Size: 53248 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0xAB83D000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1324 Status: Locked to the Windows API!
==EOF==
MalwareBytes Log:
Malwarebytes' Anti-Malware 1.40
Database version: 2551
Windows 6.0.6002 Service Pack 2
9/1/2009 8:57:51 AM
mbam-log-2009-09-01 (08-44-08).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 287610
Time elapsed: 51 minute(s), 40 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 2
Registry Keys Infected: 4
Registry Values Infected: 3
Registry Data Items Infected: 1
Folders Infected: 2
Files Infected: 6
Memory Processes Infected:
C:\Program Files\PersonalAV\PAV.exe (Rogue.PersonalAntiVirus) -> No action taken.
Memory Modules Infected:
\\?\globalroot\systemroot\System32\UACnqrqeisevc.dll (Rogue.Agent) -> No action taken.
C:\Windows\System32\msxmlm.dll (Trojan.FakeAlert) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.BHO.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.BHO.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) -> No action taken.
HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msdrv (Trojan.Agent) -> No action taken.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
Folders Infected:
C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) -> No action taken.
C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) -> No action taken.
Files Infected:
C:\Windows\System32\msxmlm.dll (Trojan.BHO.H) -> No action taken.
\\?\globalroot\systemroot\System32\UACnqrqeisevc.dll (Rogue.Agent) -> No action taken.
C:\Program Files\PersonalAV\PAV.exe (Rogue.PersonalAntiVirus) -> No action taken.
C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) -> No action taken.
C:\Windows\system32\uacinit.dll (Trojan.Agent) -> No action taken.
C:\Windows\System32\NetFilter.exe (Trojan.Agent) -> No action taken.
Hi,
Please do the following:
Download
Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————–
IMPORTANT -
Disable your AntiVirus and AntiSpyware applications ,
McAfee, Windows Defender and Adwatch, (usually via a right click on the System Tray icon.) They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
here
——————————————————————–
Double click on
ComboFix.exe & follow the prompts.
When finished, it will produce a report for you. Please post the C:\ComboFix.txt for further review.
Thanks for the reply, below is the ComboFix log:
ComboFix 09-09-03.02 - owner 09/03/2009 17:32.1.2 - NTFSx86
MicrosoftÆ Windows Vistaô Home Premium 6.0.6002.2.1252.1.1033.18.1982.1259 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2363746086-1690789789-852912484-500
c:\$recycle.bin\S-1-5-21-3151259665-1138395727-835149201-500
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\ndisrd.sys
c:\windows\system32\drivers\snetcfg.exe
c:\windows\system32\drivers\UACvaecpqyxcx.sys
c:\windows\system32\ndisapi.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACnqrqeisevc.dll
c:\windows\system32\UACpfrdxoptvk.dll
c:\windows\system32\UACtcmvavqqrh.dat
c:\windows\system32\UACxsjbotqlvq.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
——-\Legacy_UACd.sys
——-\Service_Ndisrd
——-\Service_NdisrdMP
((((((((((((((((((((((((( Files Created from 2009-08-03 to 2009-09-03 )))))))))))))))))))))))))))))))
.
2009-09-03 22:40 . 2009-09-03 22:42 ——– d—–w- c:\users\owner\AppData\Local\temp
2009-09-03 02:17 . 2009-09-03 11:34 ——– d—–w- c:\users\owner\AppData\Local\MigWiz
2009-09-03 02:15 . 2009-09-03 02:15 ——– d—–w- c:\users\owner\AppData\Local\Apple
2009-09-03 02:11 . 2009-09-03 02:11 ——– d—–w- c:\users\owner\AppData\Roaming\Spearit
2009-09-03 02:11 . 2009-09-03 02:11 ——– d—–w- c:\programdata\Spearit
2009-09-03 02:11 . 2009-09-03 02:11 ——– d—–w- c:\program files\Spearit
2009-09-03 02:10 . 2009-09-03 02:10 ——– d—–w- c:\users\Rains\AppData\Local\MigWiz
2009-09-01 20:37 . 2009-09-01 20:38 ——– d—–w- c:\program files\ERUNT
2009-09-01 20:15 . 2009-09-01 20:15 680 —-a-w- c:\users\Rains\AppData\Local\d3d9caps.dat
2009-09-01 16:56 . 2009-09-01 16:56 ——– d—–w- c:\users\owner\AppData\Local\Apple Computer
2009-09-01 15:26 . 2009-09-01 15:26 ——– d—–w- c:\users\Rains\AppData\Local\Apple Computer
2009-09-01 15:25 . 2009-09-01 15:25 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2009-09-01 15:25 . 2009-09-01 15:25 ——– d—–w- c:\users\Rains\AppData\Roaming\SUPERAntiSpyware.com
2009-09-01 15:25 . 2009-09-01 15:25 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-09-01 15:19 . 2009-09-01 15:19 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-09-01 12:11 . 2009-09-01 12:11 ——– d—–w- c:\users\Rains\AppData\Roaming\Malwarebytes
2009-09-01 01:59 . 2009-09-01 01:59 ——– d—–w- c:\program files\Trend Micro
2009-09-01 01:03 . 2009-09-01 15:25 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2009-09-01 01:03 . 2009-09-01 12:51 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-09-01 00:32 . 2009-09-01 00:32 255248 —-a-w- c:\users\Rains\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-01 00:32 . 2009-09-01 00:32 ——– d—–w- c:\users\Rains\Bluetooth Software
2009-09-01 00:32 . 2009-09-01 00:32 ——– d—–w- c:\users\Rains\AppData\Roaming\Webroot
2009-09-01 00:31 . 2009-09-01 00:31 ——– d—–w- c:\users\Rains\AppData\Local\QuickPlay
2009-09-01 00:07 . 2009-09-01 00:07 ——– d—–w- c:\users\Rains\AppData\Roaming\hewlett-packard
2009-09-01 00:07 . 2009-09-01 00:07 ——– d—–w- c:\users\Rains\AppData\Local\Hewlett-Packard
2009-08-31 18:51 . 2009-08-31 18:51 ——– d—–w- c:\users\owner\AppData\Roaming\Malwarebytes
2009-08-31 18:50 . 2009-08-03 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-31 18:50 . 2009-09-01 12:11 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-31 18:50 . 2009-08-31 18:50 ——– d—–w- c:\programdata\Malwarebytes
2009-08-31 18:50 . 2009-08-03 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-27 01:26 . 2009-08-27 01:28 ——– d—–w- c:\users\owner\AppData\Roaming\U3
2009-08-26 23:34 . 2009-09-01 13:58 ——– d—–w- c:\program files\Common Files\Uninstall
2009-08-20 03:43 . 2009-03-19 21:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-08-20 03:43 . 2008-04-17 17:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-08-20 03:43 . 2009-08-20 03:43 ——– d—–w- c:\program files\iPod
2009-08-20 03:43 . 2009-08-20 03:43 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-20 03:43 . 2009-08-20 03:43 ——– d—–w- c:\program files\iTunes
2009-08-20 03:40 . 2009-08-20 03:40 ——– d—–w- c:\program files\QuickTime
2009-08-13 15:44 . 2009-07-17 13:54 71680 —-a-w- c:\windows\system32\atl.dll
2009-08-13 15:44 . 2009-06-10 11:42 160256 —-a-w- c:\windows\system32\wkssvc.dll
2009-08-13 15:44 . 2009-06-04 12:07 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-08-13 15:44 . 2009-06-10 11:38 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-08-13 15:44 . 2009-06-15 14:52 499712 —-a-w- c:\windows\system32\kerberos.dll
2009-08-13 15:44 . 2009-06-15 14:54 175104 —-a-w- c:\windows\system32\wdigest.dll
2009-08-13 15:44 . 2009-06-15 14:53 270848 —-a-w- c:\windows\system32\schannel.dll
2009-08-13 15:44 . 2009-06-15 14:53 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-08-13 15:44 . 2009-06-15 23:15 439864 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-13 15:44 . 2009-06-15 14:52 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2009-08-13 15:44 . 2009-06-15 14:53 72704 —-a-w- c:\windows\system32\secur32.dll
2009-08-13 15:44 . 2009-06-15 12:48 9728 —-a-w- c:\windows\system32\lsass.exe
2009-08-13 15:43 . 2009-07-15 12:39 313344 —-a-w- c:\windows\system32\wmpdxm.dll
2009-08-13 15:43 . 2009-07-15 12:40 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-08-13 15:43 . 2009-07-15 12:39 4096 —-a-w- c:\windows\system32\dxmasf.dll
2009-08-13 15:43 . 2009-07-15 12:39 7680 —-a-w- c:\windows\system32\spwmp.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-03 02:34 . 2007-06-20 10:11 12 —-a-w- c:\windows\bthservsdp.dat
2009-09-03 02:10 . 2007-08-30 18:53 13025 —-a-w- c:\users\owner\AppData\Roaming\nvModes.dat
2009-09-01 13:53 . 2009-09-01 17:46 20284348 —-a-w- c:\program files\PROCESSLIST.DB
2009-09-01 13:52 . 2009-09-01 17:46 1221434 —-a-w- c:\program files\PROCESSLISTRELATED.DB
2009-09-01 01:24 . 2009-09-01 01:24 13025 —-a-w- c:\users\Rains\AppData\Roaming\nvModes.dat
2009-09-01 00:00 . 2007-06-20 11:19 ——– d—–w- c:\program files\Yahoo!
2009-08-31 23:59 . 2007-06-20 10:45 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-31 21:12 . 2007-06-20 10:45 ——– d—–w- c:\programdata\Symantec
2009-08-20 03:59 . 2009-03-21 23:39 ——– d—–w- c:\program files\Safari
2009-08-20 03:43 . 2009-01-11 06:43 ——– d—–w- c:\program files\Common Files\Apple
2009-08-13 23:56 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-08-04 02:23 . 2009-01-10 18:16 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-23 20:15 . 2008-03-08 03:06 13025 —-a-w- c:\users\Guest\AppData\Roaming\nvModes.dat
2009-07-23 19:07 . 2007-06-20 11:20 ——– d—–w- c:\programdata\WildTangent
2009-07-21 21:52 . 2009-07-29 14:27 915456 —-a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 14:27 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 14:27 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 14:27 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration
2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2009-07-14 10:54 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2009-07-13 02:35 . 2008-03-08 02:49 255248 —-a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-10 23:56 . 2007-08-31 08:07 255248 —-a-w- c:\users\owner\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-10 02:11 . 2007-06-20 10:29 ——– d—–w- c:\program files\Hewlett-Packard
2009-07-10 02:06 . 2007-06-20 10:34 ——– d—–w- c:\program files\Hp
2009-06-15 14:53 . 2009-07-14 19:23 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-06-15 14:52 . 2009-07-14 19:23 23552 —-a-w- c:\windows\system32\lpk.dll
2009-06-15 14:52 . 2009-07-14 19:23 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-06-15 14:51 . 2009-07-14 19:23 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:42 . 2009-07-14 19:23 289792 —-a-w- c:\windows\system32\atmfd.dll
2009-06-09 22:16 . 2009-06-09 22:16 3482240 —-a-w- c:\windows\system32\drivers\snp2uvc.sys
2007-08-31 01:07 . 2007-08-31 01:07 22 –sha-w- c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Event Reminder.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Event Reminder.lnk
backup=c:\windows\pss\Event Reminder.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Vongo Tray.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Vongo Tray.lnk
backup=c:\windows\pss\Vongo Tray.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(
:D1,60,c1,c4,72,04,ca,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{903D2643-8BCB-40A5-BCBC-0BAA7899536C}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{8F0E44E2-228C-4322-87E9-A60E072285C4}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0743DDAB-782A-46C8-B4FC-14CE0125125E}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{A37AFBF8-CCC0-4FC4-A385-4C0C3FCCACC5}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{D0C19CFF-DD0D-4E71-AE61-F2D33F28F32E}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{7947CEE0-1A68-47AD-9AD0-A2864363AEA1}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{46E3107F-0D0E-4393-87DF-A48E4C82FD16}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{BC4F7140-2C20-4017-AFD1-B2B6D2A3ACC8}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{9E0473AA-CF07-428B-A6B8-93CDA6C2379B}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{D25DAFD3-D062-4831-82E3-FF5112B1E418}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{FB48B738-2CD5-476D-B375-DFDEFAB2783A}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{321E0879-F174-47F8-AC97-4E634A9634E1}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{835EFC0F-3352-424E-B487-DCA96EC9DA8A}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{4215757C-1B60-4807-B7F9-D5C75EC61030}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{90FCA9CA-BA60-45A1-A7F0-966B4018C02C}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{46FFAA76-4CBE-490F-9EE3-502F2196F0A7}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{50ED27AA-B40F-4829-89A2-4AFED960A90A}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{D16EF4C1-EAA4-455D-A096-EB016CB3F218}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{4A0977C0-A4D3-4315-8D91-636822919DFB}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{1FB0D87C-D350-466F-91E4-9E207D2D2A5B}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{8708DC2B-1063-4E88-9B5C-1C8D93C157D9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{DFA7956D-BA38-409A-923C-C5B88C527AC5}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R0 AFS;AFS;c:\windows\System32\drivers\AFS.SYS [6/28/2008 3:44 PM 79052]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408]
S4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [8/31/2009 8:03 PM 1153368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-17 c:\windows\Tasks\HPCeeScheduleForowner.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-06-20 21:23]
2009-09-03 c:\windows\Tasks\User_Feed_Synchronization-{7A6B1F41-074D-41BD-94F3-12E3C100F706}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=73&bd;=Pavilion&pf;=laptop
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: {198759B9-65A0-4E64-9998-BD9876674CAA} = 10.0.1.1
.
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(1940)
c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
.
Completion time: 2009-09-03 17:47 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-03 22:47
Pre-Run: 119,972,802,560 bytes free
Post-Run: 119,631,060,992 bytes free
244 — E O F — 2009-08-20 17:55
After running the ComboFix I now receive the message "Illegal operation attempted on a registry key that has been marked for deletion" when trying to run any program. I had to copy the ComboFix log to another computer before I could open it.
Hi,
Reboot your system a couple of times and that will get rid of that message.
Please do the following:
Please open your MalwareBytes AntiMalware Program Click the Update Tab and search for updates If an update is found, it will download and install the latest version. Once the program has loaded, select "Perform Quick Scan" , then click Scan. The scan may take some time to finish, so please be patient. When the scan is complete, click OK , then Show Results to view the results. Make sure that everything is checked, and click Remove Selected . <– very important When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note) The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. Copy&Paste the entire report in your next reply.
NEXT
**Vista users - right click on the IE icon and run as administrator
Run an on-line scan with Kaspersky
Using Internet Explorer or Firefox, visit
Kaspersky On-line Scanner
1. Click
Accept , when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
Close any open programs Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click
Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan. Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it. Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined. Click View scan report at the bottom.
[external image: Posted Image]
Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
In your next reply please include
MalwareBytes Log
Malwarebytes' Anti-Malware 1.40
Database version: 2743
Windows 6.0.6000
9/4/2009 6:19:59 PM
mbam-log-2009-09-04 (18-19-59).txt
Scan type: Quick Scan
Objects scanned: 95031
Time elapsed: 3 minute(s), 19 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Kaspersky Log
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, September 6, 2009
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit (build 6000)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, September 05, 2009 16:59:46
Records in database: 2749780
Scan settings
scan using the following database extended
Scan archives yes
Scan e-mail databases yes
Scan area My Computer
C:\
D:\
E:\
F:\
Scan statistics
Objects scanned 209675
Threats found 1
Infected objects found 1
Suspicious objects found 0
Scan duration 03:23:46
File name Threat Threats count
F:\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\C6KLTY9Q\Antivirus-9091c_2024-1[1].exe Infected: Packed.Win32.Katusha.e 1
Selected area has been scanned.
Hi,
run this program to get rid of your temp files,
then post a fresh DDS and Attach.txt and describe how your computer is running now and if there are any outstanding issues.
Download
TFC to your
desktop
Close any open windows. Double click the TFC icon to run the program TFC will close all open programs itself in order to run, Click the Start button to begin the process. Allow TFC to run uninterrupted. The program should not take long to finish it's job Once its finished it should automatically reboot your machine, if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.
Due to inactivity this topic will be closed.
If you need help please start a new thread.