Spyware / Malware / Virus Removal
[Closed] "Your System is Infected" Background
7 min read
SarahU
Topic Starter
The back ground has appeared as well as caused my computer to have random pop-ups saying my system is infected with some sort of spyware. Also if i hit ctrl-alt-del then I get the pop-up also if i try to open certian programs. There is also a red circle with a white x in the right hand corner that randomly pops up with messages saying windows has detected spyware and blah blah. I have run avast and am now running malwarebytes. If anyone could help me get this off my computer i'd greatly appreciate it.
SweetTech
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
This may cause a delay, but I will do my best to keep it as short as possible.
I am checking over your log , I will post back shortly with instructions.
- Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
- Please make sure to carefully read any instruction that I give you.
Reading too lightly will cause you to miss important steps, which could have destructive effects. - If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
- These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
- Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
- If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
- I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together
Because of this, you must reply within five days. I will post a reminder should you seem to fail to do this, however, if you fail to reply within five days then,
unless I have been notified of your absence in advance, the topic shall be closed! - Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
This may cause a delay, but I will do my best to keep it as short as possible.
I am checking over your log , I will post back shortly with instructions.
SarahU
Umm ok thank you i'll wait for your reply
SweetTech
Scanning with DDS
Please download DDS by sUBs from one of the following links and save it to your desktop.
[external image: Posted Image]
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Please make sure you include the following items in your next post:
1. The logs that were produced after running DDS. (DDS.txt & Attach.txt)
2. The log that was produced after running GMER.
Please download DDS by sUBs from one of the following links and save it to your desktop.
[external image: Posted Image]
- DDS.scr
- DDS.pif
- Disable any script blocking protection (How to Disable your Security Programs)
- Double click DDS icon to run the tool (may take up to 3 minutes to run)
- When done, DDS.txt will open.
- After a few moments, attach.txt will open in a second window.
- Save both reports to your desktop.
- Post the contents of the DDS.txt report in your next reply
- Attach the Attach.txt report to your post by doing the following:
- Under the reply panel is the Attachments Panel
- Browse for the attachment file you want to upload, then click the green Upload button
- Once it has uploaded, click the Manage Current Attachments drop down box
- Click on [external image: Posted Image] to insert the attachment into your post
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image]
Click the image to enlarge it
- In the right panel, you will see several boxes that have been checked. Uncheck the following …
- Sections
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and attach it in your reply.
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Please make sure you include the following items in your next post:
1. The logs that were produced after running DDS. (DDS.txt & Attach.txt)
2. The log that was produced after running GMER.
SarahU
GMER.txtAttach.txtDDS (Ver_09-11-29.01) - NTFSx86
Run by [removed] at 22:29:02.31 on Mon 30/11/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.367 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: avast! antivirus 4.8.1368 [VPS 091130-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Linksys\WMP110\gtwpssrv.exe
C:\Program Files\iWin Games\iWinTrusted.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Linksys\WMP110\WLSngS.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\Explorer.EXE
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Linksys\WMP110\WMP110.exe
C:\Program Files\Motorola\Software Update\mumservice.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\System32\mshta.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\mshta.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\System32\mshta.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\danny\Local Settings\Temporary Internet Files\Content.IE5\JHC5SRDJ\dds[1].scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uSearch Bar =
uSearch Page =
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearchAssistant =
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: P2P Energy Toolbar: {2bae58c2-79f9-45d1-a286-81f911301c3a} - c:\program files\p2p_energy\tbP2P1.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: BrowserHelper Class: {8a9d74f9-560b-4fe7-abeb-3b2e638e5cd6} - c:\program files\sgpsa\SearchAssistant.dll
BHO: IEHlprObj Class: {8ca5ed52-f3fb-4414-a105-2e3491156990} - c:\program files\iwin games\iWinGamesHookIE.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Search Assistant: {f0626a63-410b-45e2-99a1-3f2475b2d695} - c:\program files\sgpsa\BHO.dll
BHO: Fast Browser Search Toolbar Helper: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\fast browser search\ie\FBStoolbar.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn2\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll
TB: P2P Energy Toolbar: {2bae58c2-79f9-45d1-a286-81f911301c3a} - c:\program files\p2p_energy\tbP2P1.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: Fast Browser Search Toolbar: {1bb22d38-a411-4b13-a746-c2a4f4ec7344} - c:\program files\fast browser search\ie\FBStoolbar.dll
TB: {E738F11F-B0F3-4E0D-A5CA-6ED7B0BD4F5D} - No File
TB: {8A784E73-8794-4B0B-817D-671CDDD1D230} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [Google Update] "c:\documents and settings\danny\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [NBJ] "c:\program files\ahead\nero backitup\NBJ.exe"
uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-AU
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [WMP110] c:\program files\linksys\wmp110\WMP110.exe
mRun: [mumservice] c:\program files\motorola\software update\mumservice.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Monitor] c:\windows\pixart\pac207\Monitor.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
StartupFolder: c:\docume~1\danny\startm~1\programs\startup\frostw~1.lnk - c:\program files\frostwire\FrostWire.exe
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
dPolicies-system: DisableTaskMgr = 1 (0x1)
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB}
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228321686531
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: 5875fe14593 - c:\windows\system32\dpcdll32.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
AppInit_DLLs: c:\windows\system32\wshiph6.dll,c:\windows\system32\dpcdll32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 70.38.19.201 www.review.2009softwarereviews.com
Hosts: 70.38.19.201 review.2009softwarereviews.com
Hosts: 70.38.19.201 a1.review.zdnet.com
Hosts: 70.38.19.201 www.d1.reviews.cnet.com
Hosts: 70.38.19.201 www.reviews.toptenreviews.com
Note: multiple HOSTS entries found. Please refer to Attach.txt
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-11-28 114768]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-30 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-30 108552]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-28 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-11-28 138680]
R2 GTWPSService;GTWPSSRV;c:\program files\linksys\wmp110\gtwpssrv.exe [2009-7-12 34816]
R2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2009-11-9 78104]
R2 WLSng Service;WLSng Service;c:\program files\linksys\wmp110\WLSngS.exe [2009-7-12 233472]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2009-7-12 57344]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-11-28 38224]
R3 PAC207;Basic Webcam;c:\windows\system32\drivers\PFC027.SYS [2006-11-20 506112]
R3 WMP110;Linksys WMP110 RangePlus Wireless PCI Adapter Service;c:\windows\system32\drivers\WMP110.sys [2009-1-22 1299520]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-30 327688]
S2 MotoConnect Service;MotoConnect Service;c:\program files\motorola\motoconnectservice\MotoConnectService.exe [2009-7-25 91392]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-11-28 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-11-28 352920]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\linksys\wmp110\jswpsapi.exe [2009-7-12 352338]
S3 kvpndev;Kerio VPN adapter;c:\windows\system32\drivers\kvpndrv.sys [2008-6-24 65024]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer; [x]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys –> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys –> c:\windows\system32\drivers\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys –> c:\windows\system32\drivers\motodrv.sys [?]
S4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-6-30 906520]
S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-30 298776]
S4 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service –> c:\windows\system32\lxdncoms.exe -service [?]
S4 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [2009-1-22 98984]
S4 MyWebSearchService;My Web Search Service;c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe –> c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe [?]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-1-22 24652]
=============== Created Last 30 ================
2009-12-01 02:33:02 0 —-a-w- c:\windows\system32\23281.exe
2009-12-01 02:12:50 0 —-a-w- c:\windows\system32\28145.exe
2009-12-01 01:52:41 0 —-a-w- c:\windows\system32\5705.exe
2009-11-30 22:11:04 0 d—–w- c:\docume~1\danny\applic~1\MSNInstaller
2009-11-30 21:14:59 0 —-a-w- c:\windows\system32\24464.exe
2009-11-30 20:54:50 0 —-a-w- c:\windows\system32\26962.exe
2009-11-30 20:34:40 0 —-a-w- c:\windows\system32\29358.exe
2009-11-30 20:14:31 0 —-a-w- c:\windows\system32\11478.exe
2009-11-30 19:54:22 0 —-a-w- c:\windows\system32\15724.exe
2009-11-30 19:34:12 0 —-a-w- c:\windows\system32\19169.exe
2009-11-30 19:14:02 0 —-a-w- c:\windows\system32\26500.exe
2009-11-30 18:53:53 0 —-a-w- c:\windows\system32\6334.exe
2009-11-30 18:33:43 0 —-a-w- c:\windows\system32\18467.exe
2009-11-30 18:13:23 0 —-a-w- c:\windows\system32\AVR10.exe
2009-11-30 18:13:22 0 —-a-w- c:\windows\system32\winhelper86.dll
2009-11-30 18:13:14 27136 —-a-w- c:\windows\system32\winlogon86.exe
2009-11-30 18:13:11 27136 —-a-w- c:\windows\system32\emp.exe
2009-11-29 05:42:44 0 d—–w- c:\program files\SecondLife
2009-11-29 02:24:52 0 d—–w- c:\docume~1\danny\applic~1\Malwarebytes
2009-11-29 02:24:45 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-29 02:24:44 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 02:24:44 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-29 02:24:44 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-11-27 01:29:38 7680 –sha-w- c:\windows\Thumbs.db
2009-11-24 23:00:29 30532 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-18 04:51:25 0 d—–w- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-14 21:59:52 0 d—–w- c:\docume~1\danny\applic~1\iWin
2009-11-14 11:18:07 0 d—–w- c:\program files\iWin.com
2009-11-14 10:52:28 0 d—–w- c:\program files\iWin Games
2009-11-14 10:13:25 433 -c–a-w- C:\2.js
2009-11-12 22:48:40 0 d—–w- c:\docume~1\danny\applic~1\Microsoft Games
2009-11-12 22:48:40 0 d—–w- c:\docume~1\alluse~1\applic~1\Microsoft Games
2009-11-12 22:44:34 0 d—–w- c:\program files\Microsoft Games
2009-11-11 03:44:33 58880 -c—-w- c:\windows\system32\dllcache\msasn1.dll
2009-11-11 01:10:13 0 d—–w- c:\program files\common files\Software Update Utility
2009-11-11 01:09:45 0 d—–w- c:\docume~1\alluse~1\applic~1\AIM
2009-11-11 01:09:28 0 d—–w- c:\program files\AIM
2009-11-10 22:36:19 0 d—–w- c:\windows\system32\wbem\Repository
2009-11-10 22:33:41 0 d—–w- c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2009-11-10 22:33:40 0 d—–w- c:\windows\system32\drivers\Avg
2009-11-10 22:33:40 0 d—–w- c:\docume~1\danny\applic~1\AVGTOOLBAR
2009-11-10 22:26:37 0 d—–w- c:\program files\CCleaner
2009-11-10 22:26:25 0 d—–w- c:\program files\Winferno
2009-11-10 22:12:43 0 d—–w- c:\program files\ExcellentAdDisplay
2009-11-10 22:12:28 0 d—–w- c:\program files\SGPSA
2009-11-10 22:12:28 0 d—–w- c:\program files\Fast Browser Search
2009-11-09 02:46:50 0 dc—-w- C:\SafetyCenter
2009-11-01 22:51:54 0 d—–w- c:\program files\CyberDefender
==================== Find3M ====================
2009-10-22 09:19:04 5939712 —-a-w- c:\windows\system32\mshtml(2).dll
2009-09-27 08:38:44 862 -c–a-w- C:\xcrashdump.dat
2009-09-11 14:18:39 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39 136192 —-a-w- c:\windows\system32\msv1_0(2)(3).dll
2009-09-04 21:03:36 58880 —-a-w- c:\windows\system32\msasn1.dll
2009-09-04 21:03:36 58880 —-a-w- c:\windows\system32\msasn1(2)(2).dll
2009-01-22 23:03:59 1525024 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-01-22 23:03:59 37408 –sha-w- c:\windows\system32\drivers\fidbox2.dat
============= FINISH: 22:31:45.21 ===============
SweetTech
[external image: Posted Image] One or more of the identified infections is a backdoor trojan and password stealer.
I highly suggest you take a look at the two links provided below:
1. How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?
2. When should I re-format? How should I reinstall?
If you still wish to continue please proceed:
Multiple Anti-Virus Programs
Your currently running multiple Anti-Virus programs. This will cause your Anti-Virus programs to conflict with each other and will cause more problems than it will prevent. Before you continue with this fix you MUST pick one Anti-Virus program that you will keep updated and use and then uninstall the other(s).
Remove Programs
We need to remove a few program(s). To do this please do the following:
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[external image: Posted Image]
[external image: Posted Image]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Please make sure you include the following items in your next post:
1. The log that was produced after running ComboFix.
2. An update on how your computer is currently running.
This type of infection allows hackers to access and remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it contains any other sensitive information, then from a clean computer, change all passwords where applicable.
It would also be wise to contact those same financial institutions to appraise them of your situation.
I highly suggest you take a look at the two links provided below:
1. How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?
2. When should I re-format? How should I reinstall?
If you still wish to continue please proceed:
Multiple Anti-Virus Programs
Your currently running multiple Anti-Virus programs. This will cause your Anti-Virus programs to conflict with each other and will cause more problems than it will prevent. Before you continue with this fix you MUST pick one Anti-Virus program that you will keep updated and use and then uninstall the other(s).
- Click Start
- Go to Control Panel
- Go to Add/Remove Programs
- Find and click Remove for the following (if present):
- AVG 8.0 or Avast (pick which one you want to keep and uninstall the other.)
Remove Programs
We need to remove a few program(s). To do this please do the following:
- Click Start
- Go to Control Panel
- Go to Add/Remove Programs
- Find and click Remove for the following (if present):
- Fast Browser Search (My Web Tattoo)
- P2P_Energy Toolbar
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
- Double click on ComboFix.exe & follow the prompts.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
[external image: Posted Image]
- Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
- Click on Yes, to continue scanning for malware.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Please make sure you include the following items in your next post:
1. The log that was produced after running ComboFix.
2. An update on how your computer is currently running.
SweetTech
Hello SarahU!
It's been several days since I last posted instructions for you to complete. Do you still require assistance in getting your computer cleaned up?
Thanks,
SweetTech.
oldman960
Due to inactivity this topic will be closed.
If you need help please start a new thread.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI