This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] "Your System is Infected" Background

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The back ground has appeared as well as caused my computer to have random pop-ups saying my system is infected with some sort of spyware. Also if i hit ctrl-alt-del then I get the pop-up also if i try to open certian programs. There is also a red circle with a white x in the right hand corner that randomly pops up with messages saying windows has detected spyware and blah blah. I have run avast and am now running malwarebytes. If anyone could help me get this off my computer i'd greatly appreciate it.
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
  • Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within five days
    . I will post a reminder should you seem to fail to do this, however, if you fail to reply within five days then,
    unless I have been notified of your absence in advance, the topic shall be closed!
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your log , I will post back shortly with instructions.
Scanning with DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.
[external image: Posted Image]
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by doing the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Scanning with GMER
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please make sure you include the following items in your next post:
1. The logs that were produced after running DDS. (DDS.txt & Attach.txt)
2. The log that was produced after running GMER.
📎GMER.txt📎Attach.txtDDS (Ver_09-11-29.01) - NTFSx86 Run by [removed] at 22:29:02.31 on Mon 30/11/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.367 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: avast! antivirus 4.8.1368 [VPS 091130-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Linksys\WMP110\gtwpssrv.exe C:\Program Files\iWin Games\iWinTrusted.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Linksys\WMP110\WLSngS.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\Explorer.EXE C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe C:\Program Files\Linksys\WMP110\WMP110.exe C:\Program Files\Motorola\Software Update\mumservice.exe C:\WINDOWS\PixArt\PAC207\Monitor.exe C:\Program Files\iTunes\iTunesHelper.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AIM\aim.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\mshta.exe C:\WINDOWS\System32\mshta.exe C:\WINDOWS\System32\mshta.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\WINDOWS\System32\mshta.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\WINDOWS\System32\mshta.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\danny\Local Settings\Temporary Internet Files\Content.IE5\JHC5SRDJ\dds[1].scr ============== Pseudo HJT Report =============== uStart Page = about:blank uSearch Bar = uSearch Page = mDefault_Page_URL = hxxp://www.yahoo.com/ mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com mStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com mSearchAssistant = uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: P2P Energy Toolbar: {2bae58c2-79f9-45d1-a286-81f911301c3a} - c:\program files\p2p_energy\tbP2P1.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: BrowserHelper Class: {8a9d74f9-560b-4fe7-abeb-3b2e638e5cd6} - c:\program files\sgpsa\SearchAssistant.dll BHO: IEHlprObj Class: {8ca5ed52-f3fb-4414-a105-2e3491156990} - c:\program files\iwin games\iWinGamesHookIE.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: Search Assistant: {f0626a63-410b-45e2-99a1-3f2475b2d695} - c:\program files\sgpsa\BHO.dll BHO: Fast Browser Search Toolbar Helper: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\fast browser search\ie\FBStoolbar.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn2\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll TB: P2P Energy Toolbar: {2bae58c2-79f9-45d1-a286-81f911301c3a} - c:\program files\p2p_energy\tbP2P1.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: Fast Browser Search Toolbar: {1bb22d38-a411-4b13-a746-c2a4f4ec7344} - c:\program files\fast browser search\ie\FBStoolbar.dll TB: {E738F11F-B0F3-4E0D-A5CA-6ED7B0BD4F5D} - No File TB: {8A784E73-8794-4B0B-817D-671CDDD1D230} - No File TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe uRun: [Google Update] "c:\documents and settings\danny\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [NBJ] "c:\program files\ahead\nero backitup\NBJ.exe" uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-AU uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe" mRun: [WMP110] c:\program files\linksys\wmp110\WMP110.exe mRun: [mumservice] c:\program files\motorola\software update\mumservice.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Monitor] c:\windows\pixart\pac207\Monitor.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe StartupFolder: c:\docume~1\danny\startm~1\programs\startup\frostw~1.lnk - c:\program files\frostwire\FrostWire.exe dPolicies-explorer: NoSetActiveDesktop = 1 (0x1) dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) dPolicies-system: DisableTaskMgr = 1 (0x1) IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB} IE: {925DAB62-F9AC-4221-806A-057BFB1014AA} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228321686531 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: 5875fe14593 - c:\windows\system32\dpcdll32.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxsrvc.dll AppInit_DLLs: c:\windows\system32\wshiph6.dll,c:\windows\system32\dpcdll32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll Hosts: 70.38.19.201 www.review.2009softwarereviews.com Hosts: 70.38.19.201 review.2009softwarereviews.com Hosts: 70.38.19.201 a1.review.zdnet.com Hosts: 70.38.19.201 www.d1.reviews.cnet.com Hosts: 70.38.19.201 www.reviews.toptenreviews.com Note: multiple HOSTS entries found. Please refer to Attach.txt ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-11-28 114768] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-30 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-30 108552] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-28 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-11-28 138680] R2 GTWPSService;GTWPSSRV;c:\program files\linksys\wmp110\gtwpssrv.exe [2009-7-12 34816] R2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2009-11-9 78104] R2 WLSng Service;WLSng Service;c:\program files\linksys\wmp110\WLSngS.exe [2009-7-12 233472] R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2009-7-12 57344] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-11-28 38224] R3 PAC207;Basic Webcam;c:\windows\system32\drivers\PFC027.SYS [2006-11-20 506112] R3 WMP110;Linksys WMP110 RangePlus Wireless PCI Adapter Service;c:\windows\system32\drivers\WMP110.sys [2009-1-22 1299520] S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-30 327688] S2 MotoConnect Service;MotoConnect Service;c:\program files\motorola\motoconnectservice\MotoConnectService.exe [2009-7-25 91392] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-11-28 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-11-28 352920] S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\linksys\wmp110\jswpsapi.exe [2009-7-12 352338] S3 kvpndev;Kerio VPN adapter;c:\windows\system32\drivers\kvpndrv.sys [2008-6-24 65024] S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer; [x] S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys –> c:\windows\system32\drivers\motccgp.sys [?] S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys –> c:\windows\system32\drivers\motccgpfl.sys [?] S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys –> c:\windows\system32\drivers\motodrv.sys [?] S4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-6-30 906520] S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-30 298776] S4 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service –> c:\windows\system32\lxdncoms.exe -service [?] S4 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [2009-1-22 98984] S4 MyWebSearchService;My Web Search Service;c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe –> c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe [?] S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-1-22 24652] =============== Created Last 30 ================ 2009-12-01 02:33:02 0 —-a-w- c:\windows\system32\23281.exe 2009-12-01 02:12:50 0 —-a-w- c:\windows\system32\28145.exe 2009-12-01 01:52:41 0 —-a-w- c:\windows\system32\5705.exe 2009-11-30 22:11:04 0 d—–w- c:\docume~1\danny\applic~1\MSNInstaller 2009-11-30 21:14:59 0 —-a-w- c:\windows\system32\24464.exe 2009-11-30 20:54:50 0 —-a-w- c:\windows\system32\26962.exe 2009-11-30 20:34:40 0 —-a-w- c:\windows\system32\29358.exe 2009-11-30 20:14:31 0 —-a-w- c:\windows\system32\11478.exe 2009-11-30 19:54:22 0 —-a-w- c:\windows\system32\15724.exe 2009-11-30 19:34:12 0 —-a-w- c:\windows\system32\19169.exe 2009-11-30 19:14:02 0 —-a-w- c:\windows\system32\26500.exe 2009-11-30 18:53:53 0 —-a-w- c:\windows\system32\6334.exe 2009-11-30 18:33:43 0 —-a-w- c:\windows\system32\18467.exe 2009-11-30 18:13:23 0 —-a-w- c:\windows\system32\AVR10.exe 2009-11-30 18:13:22 0 —-a-w- c:\windows\system32\winhelper86.dll 2009-11-30 18:13:14 27136 —-a-w- c:\windows\system32\winlogon86.exe 2009-11-30 18:13:11 27136 —-a-w- c:\windows\system32\emp.exe 2009-11-29 05:42:44 0 d—–w- c:\program files\SecondLife 2009-11-29 02:24:52 0 d—–w- c:\docume~1\danny\applic~1\Malwarebytes 2009-11-29 02:24:45 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-11-29 02:24:44 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-11-29 02:24:44 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-11-29 02:24:44 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-11-27 01:29:38 7680 –sha-w- c:\windows\Thumbs.db 2009-11-24 23:00:29 30532 —ha-w- c:\windows\system32\mlfcache.dat 2009-11-18 04:51:25 0 d—–w- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-11-14 21:59:52 0 d—–w- c:\docume~1\danny\applic~1\iWin 2009-11-14 11:18:07 0 d—–w- c:\program files\iWin.com 2009-11-14 10:52:28 0 d—–w- c:\program files\iWin Games 2009-11-14 10:13:25 433 -c–a-w- C:\2.js 2009-11-12 22:48:40 0 d—–w- c:\docume~1\danny\applic~1\Microsoft Games 2009-11-12 22:48:40 0 d—–w- c:\docume~1\alluse~1\applic~1\Microsoft Games 2009-11-12 22:44:34 0 d—–w- c:\program files\Microsoft Games 2009-11-11 03:44:33 58880 -c—-w- c:\windows\system32\dllcache\msasn1.dll 2009-11-11 01:10:13 0 d—–w- c:\program files\common files\Software Update Utility 2009-11-11 01:09:45 0 d—–w- c:\docume~1\alluse~1\applic~1\AIM 2009-11-11 01:09:28 0 d—–w- c:\program files\AIM 2009-11-10 22:36:19 0 d—–w- c:\windows\system32\wbem\Repository 2009-11-10 22:33:41 0 d—–w- c:\docume~1\alluse~1\applic~1\AVG Security Toolbar 2009-11-10 22:33:40 0 d—–w- c:\windows\system32\drivers\Avg 2009-11-10 22:33:40 0 d—–w- c:\docume~1\danny\applic~1\AVGTOOLBAR 2009-11-10 22:26:37 0 d—–w- c:\program files\CCleaner 2009-11-10 22:26:25 0 d—–w- c:\program files\Winferno 2009-11-10 22:12:43 0 d—–w- c:\program files\ExcellentAdDisplay 2009-11-10 22:12:28 0 d—–w- c:\program files\SGPSA 2009-11-10 22:12:28 0 d—–w- c:\program files\Fast Browser Search 2009-11-09 02:46:50 0 dc—-w- C:\SafetyCenter 2009-11-01 22:51:54 0 d—–w- c:\program files\CyberDefender ==================== Find3M ==================== 2009-10-22 09:19:04 5939712 —-a-w- c:\windows\system32\mshtml(2).dll 2009-09-27 08:38:44 862 -c–a-w- C:\xcrashdump.dat 2009-09-11 14:18:39 136192 —-a-w- c:\windows\system32\msv1_0.dll 2009-09-11 14:18:39 136192 —-a-w- c:\windows\system32\msv1_0(2)(3).dll 2009-09-04 21:03:36 58880 —-a-w- c:\windows\system32\msasn1.dll 2009-09-04 21:03:36 58880 —-a-w- c:\windows\system32\msasn1(2)(2).dll 2009-01-22 23:03:59 1525024 –sha-w- c:\windows\system32\drivers\fidbox.dat 2009-01-22 23:03:59 37408 –sha-w- c:\windows\system32\drivers\fidbox2.dat ============= FINISH: 22:31:45.21 ===============
[external image: Posted Image] One or more of the identified infections is a backdoor trojan and password stealer.

This type of infection allows hackers to access and remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it contains any other sensitive information, then from a clean computer, change all passwords where applicable.
It would also be wise to contact those same financial institutions to appraise them of your situation.


I highly suggest you take a look at the two links provided below:
1. How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?
2. When should I re-format? How should I reinstall?

If you still wish to continue please proceed:

Multiple Anti-Virus Programs
Your currently running multiple Anti-Virus programs. This will cause your Anti-Virus programs to conflict with each other and will cause more problems than it will prevent. Before you continue with this fix you MUST pick one Anti-Virus program that you will keep updated and use and then uninstall the other(s).

  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present):
  • AVG 8.0 or Avast (pick which one you want to keep and uninstall the other.)

Remove Programs
We need to remove a few program(s). To do this please do the following:
  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present):
  • Fast Browser Search (My Web Tattoo)
  • P2P_Energy Toolbar
Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the following items in your next post:
1. The log that was produced after running ComboFix.
2. An update on how your computer is currently running.
Hello SarahU! It's been several days since I last posted instructions for you to complete. Do you still require assistance in getting your computer cleaned up? Thanks, SweetTech.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI