This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Strange Popups in browsers

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I tried to set the system back and it failed. Got a windows update yesterday morning and every time I open a browser (Firefox or Chrome) it opens up about a dozen or so strange tabs. Every time I navigate somewhere it does it again and if there are popups it does it for every popup. Help. Edit: I am using IE to post this, Neither Firefox nor Chrome were open when I did these logs or posted them. ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/12/02 05:02 Program Version: Version 1.3.5.0 Windows Version: Windows XP Media Center Edition SP3 ================================================== Drivers ——————- Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0x9FBA3000 Size: 49152 File Visible: No Signed: - Status: - SSDT ——————- #: 041 Function Name: NtCreateKey Status: Hooked by "Lbd.sys" at address 0xba8f887e #: 247 Function Name: NtSetValueKey Status: Hooked by "Lbd.sys" at address 0xba8f8bfe ==EOF== DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 5:10:59.89 on Wed 12/02/2009 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1226 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\stsystra.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Documents and Settings\George Hall\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Documents and Settings\George Hall\Desktop\RootRepeal.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\George Hall\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll EB: {8BCB5337-EC01-4E38-840C-A964F174255B} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [cdloader] "c:\documents and settings\george hall\application data\mjusbsp\cdloader2.exe" MAGICJACK uRun: [qrocfjpv] c:\documents and settings\george hall\local settings\application data\gvvpls\gkkhsysguard.exe uRun: [Google Update] "c:\documents and settings\george hall\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [qrocfjpv] c:\documents and settings\george hall\local settings\application data\gvvpls\gkkhsysguard.exe mRun: [adhgmqan] c:\documents and settings\george hall\local settings\application data\xbxmjm\wsxpsysguard.exe StartupFolder: c:\docume~1\george~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258497653373 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: avgrsstarter - avgrsstx.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\george~1\applic~1\mozilla\firefox\profiles\d2nrwydv.default\ FF - prefs.js: browser.startup.homepage - hxxp://george-hall.net FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll FF - plugin: c:\documents and settings\george hall\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-12-1 64288] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-10-25 333192] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-10-25 28424] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-10-25 360584] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-10-25 906520] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-10-25 285392] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1184912] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-24 135664] =============== Created Last 30 ================ 2009-12-01 09:09 15,880 a——- c:\windows\system32\lsdelete.exe 2009-12-01 06:58 64,288 a——- c:\windows\system32\drivers\Lbd.sys 2009-12-01 06:58 93,360 a——- c:\windows\system32\drivers\SBREDrv.sys 2009-12-01 06:56 -cd-h— c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} 2009-12-01 06:56 –d—– c:\program files\Lavasoft 2009-12-01 06:21 –d—– c:\program files\Spybot - Search & Destroy 2009-12-01 06:21 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-11-29 19:45 36 a——- c:\windows\webica.ini 2009-11-29 19:45 –d—– c:\docume~1\george~1\applic~1\ICAClient 2009-11-29 19:44 –d—– c:\program files\Citrix 2009-11-27 22:45 411,368 a——- c:\windows\system32\deploytk.dll 2009-11-27 22:45 73,728 a——- c:\windows\system32\javacpl.cpl 2009-11-21 23:19 –d—– c:\program files\jZip 2009-11-21 20:44 376 a——- c:\windows\ODBC.INI 2009-11-21 20:43 –d—– c:\program files\common files\L&H 2009-11-21 20:43 –d—– c:\program files\Microsoft ActiveSync 2009-11-20 18:01 –d—– c:\program files\common files\Symantec Shared 2009-11-17 19:08 274,288 a——- c:\windows\system32\mucltui.dll 2009-11-17 19:08 16,736 a——- c:\windows\system32\mucltui.dll.mui 2009-11-17 17:41 15,064 a——- c:\windows\system32\wuapi.dll.mui 2009-11-07 04:28 –d—– c:\program files\iPod 2009-11-07 04:28 –d—– c:\program files\iTunes 2009-11-04 05:47 2,752 a——- c:\windows\system32\PerfStringBackup.TMP 2009-11-04 05:42 –d—– c:\windows\system32\wbem\Repository 2009-11-04 05:40 –d—– c:\windows\system32\drivers\NSS 2009-11-04 05:40 –d—– c:\program files\Norton Security Scan 2009-11-04 05:40 –d—– c:\program files\NortonInstaller 2009-11-04 05:33 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-11-04 05:33 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-11-03 17:28 –d—– c:\program files\iPod(2) 2009-11-03 17:28 –d—– c:\program files\iTunes(2) 2009-11-02 18:47 –d—– c:\program files\DivX ==================== Find3M ==================== 2009-11-29 20:33 96,512 a——- c:\windows\system32\drivers\atapi.sys 2009-11-11 09:25 360,584 a——- c:\windows\system32\drivers\avgtdix.sys 2009-10-29 19:29 2,146,304 a——- c:\windows\system32\GPhotos.scr 2009-10-25 04:38 93,074,728 a——- C:\iTunesSetup(2).exe 2009-10-25 03:54 12,464 a——- c:\windows\system32\avgrsstx.dll 2009-10-25 03:54 333,192 a——- c:\windows\system32\drivers\avgldx86.sys 2009-10-25 03:35 87,747 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-10-25 03:01 21,640 a——- c:\windows\system32\emptyregdb.dat 2009-09-25 00:37 667,136 a——- c:\windows\system32\wininet.dll 2009-09-25 00:37 81,920 a——- c:\windows\system32\ieencode.dll 2009-09-11 09:18 136,192 a——- c:\windows\system32\msv1_0.dll 2009-09-04 16:03 58,880 a——- c:\windows\system32\msasn1.dll ============= FINISH: 5:12:28.82 ===============
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)

Please post the exeHelper log, and a new DDS log.
Thank you very much for your assistance, as per your instructions here are your requests. exeHelper by Raktor Build 20091204 Run at 04:24:38 on 12/04/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Removing HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\adhgmqan Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 4:27:34.50 on Fri 12/04/2009 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1052 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\stsystra.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Documents and Settings\George Hall\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\notepad.exe C:\Documents and Settings\George Hall\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll EB: {8BCB5337-EC01-4E38-840C-A964F174255B} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [cdloader] "c:\documents and settings\george hall\application data\mjusbsp\cdloader2.exe" MAGICJACK uRun: [qrocfjpv] c:\documents and settings\george hall\local settings\application data\gvvpls\gkkhsysguard.exe uRun: [Google Update] "c:\documents and settings\george hall\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [qrocfjpv] c:\documents and settings\george hall\local settings\application data\gvvpls\gkkhsysguard.exe StartupFolder: c:\docume~1\george~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258497653373 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: avgrsstarter - avgrsstx.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\george~1\applic~1\mozilla\firefox\profiles\d2nrwydv.default\ FF - prefs.js: browser.startup.homepage - hxxp://george-hall.net FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll FF - plugin: c:\documents and settings\george hall\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-12-1 64288] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-10-25 333192] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-10-25 28424] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-10-25 360584] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-10-25 906520] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-10-25 285392] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1184912] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-24 135664] =============== Created Last 30 ================ 2009-12-01 09:09 15,880 a——- c:\windows\system32\lsdelete.exe 2009-12-01 06:58 64,288 a——- c:\windows\system32\drivers\Lbd.sys 2009-12-01 06:58 93,360 a——- c:\windows\system32\drivers\SBREDrv.sys 2009-12-01 06:56 -cd-h— c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} 2009-12-01 06:56 –d—– c:\program files\Lavasoft 2009-12-01 06:21 –d—– c:\program files\Spybot - Search & Destroy 2009-12-01 06:21 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-11-29 19:45 36 a——- c:\windows\webica.ini 2009-11-29 19:45 –d—– c:\docume~1\george~1\applic~1\ICAClient 2009-11-29 19:44 –d—– c:\program files\Citrix 2009-11-27 22:45 411,368 a——- c:\windows\system32\deploytk.dll 2009-11-27 22:45 73,728 a——- c:\windows\system32\javacpl.cpl 2009-11-21 23:19 –d—– c:\program files\jZip 2009-11-21 20:44 376 a——- c:\windows\ODBC.INI 2009-11-21 20:43 –d—– c:\program files\common files\L&H 2009-11-21 20:43 –d—– c:\program files\Microsoft ActiveSync 2009-11-20 18:01 –d—– c:\program files\common files\Symantec Shared 2009-11-17 19:08 274,288 a——- c:\windows\system32\mucltui.dll 2009-11-17 19:08 16,736 a——- c:\windows\system32\mucltui.dll.mui 2009-11-17 17:41 15,064 a——- c:\windows\system32\wuapi.dll.mui 2009-11-07 04:28 –d—– c:\program files\iPod 2009-11-07 04:28 –d—– c:\program files\iTunes 2009-11-04 05:47 2,752 a——- c:\windows\system32\PerfStringBackup.TMP 2009-11-04 05:42 –d—– c:\windows\system32\wbem\Repository 2009-11-04 05:40 –d—– c:\windows\system32\drivers\NSS 2009-11-04 05:40 –d—– c:\program files\Norton Security Scan 2009-11-04 05:40 –d—– c:\program files\NortonInstaller 2009-11-04 05:33 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-11-04 05:33 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes ==================== Find3M ==================== 2009-12-02 21:57 96,512 a——- c:\windows\system32\drivers\atapi.sys 2009-11-11 09:25 360,584 a——- c:\windows\system32\drivers\avgtdix.sys 2009-10-29 19:29 2,146,304 a——- c:\windows\system32\GPhotos.scr 2009-10-25 04:38 93,074,728 a——- C:\iTunesSetup(2).exe 2009-10-25 03:54 12,464 a——- c:\windows\system32\avgrsstx.dll 2009-10-25 03:54 333,192 a——- c:\windows\system32\drivers\avgldx86.sys 2009-10-25 03:35 87,747 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-10-25 03:01 21,640 a——- c:\windows\system32\emptyregdb.dat 2009-09-25 00:37 667,136 a——- c:\windows\system32\wininet.dll 2009-09-25 00:37 81,920 a——- c:\windows\system32\ieencode.dll 2009-09-11 09:18 136,192 a——- c:\windows\system32\msv1_0.dll ============= FINISH: 4:28:51.14 ===============
Download Combofix to your desktop from any of the links below.

Link 1
Link 2


==================================

Disable any antivirus programs you are running, then double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
It appeared to be fine, the AVG did something where it had to ber restarted. Once I restarted the same problem happened again and I ran the exehelper again and it stopped the problem again. Then I ran combo fix.


ComboFix 09-12-03.06 - George Hall 12/04/2009 18:00.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1439 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\kb913800.exe

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2009-11-04 to 2009-12-04 )))))))))))))))))))))))))))))))
.

2009-12-04 10:05 . 2009-12-04 10:05 ——– d—–w- c:\program files\ElcomSoft
2009-12-01 22:36 . 2009-08-01 16:16 6256600 —ha-w- c:\documents and settings\George Hall\Application Data\mjusbsp\in00000\setup.exe
2009-12-01 22:36 . 2009-08-01 16:12 728600 —ha-w- c:\documents and settings\George Hall\Application Data\mjusbsp\ar00000\install.exe
2009-12-01 22:36 . 2008-02-29 12:42 386496 —-a-w- c:\documents and settings\George Hall\Application Data\mjusbsp\ar00000\magicJackSplash.exe
2009-12-01 14:09 . 2009-12-01 11:58 15880 —-a-w- c:\windows\system32\lsdelete.exe
2009-12-01 11:56 . 2009-12-01 22:34 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-12-01 11:56 . 2009-10-03 08:15 2924848 -c–a-w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-12-01 11:56 . 2009-12-01 11:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-01 11:56 . 2009-12-01 11:56 ——– d—–w- c:\program files\Lavasoft
2009-12-01 11:21 . 2009-12-01 11:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-01 11:21 . 2009-12-01 11:24 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-11-30 00:45 . 2009-11-30 00:47 ——– d—–w- c:\documents and settings\George Hall\Application Data\ICAClient
2009-11-30 00:44 . 2009-11-30 00:44 ——– d—–w- c:\program files\Citrix
2009-11-28 03:46 . 2009-11-28 03:46 ——– d—–w- c:\windows\Sun
2009-11-28 03:45 . 2009-11-28 03:45 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-28 03:45 . 2009-11-28 03:45 ——– d—–w- c:\program files\Java
2009-11-28 03:45 . 2009-11-28 03:45 152576 —-a-w- c:\documents and settings\George Hall\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-28 03:45 . 2009-11-28 03:45 79488 —-a-w- c:\documents and settings\George Hall\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-24 23:42 . 2009-11-24 23:42 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-11-24 23:37 . 2009-11-24 23:37 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-11-24 23:36 . 2009-11-25 00:50 ——– d—–w- c:\program files\Google
2009-11-22 04:19 . 2009-11-22 04:19 ——– d—–w- c:\documents and settings\George Hall\Local Settings\Application Data\jZip
2009-11-22 04:19 . 2009-11-22 04:20 ——– d—–w- c:\program files\jZip
2009-11-22 01:43 . 2009-11-22 01:43 ——– d—–w- c:\program files\Common Files\L&H;
2009-11-22 01:43 . 2009-11-22 01:43 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-11-21 21:45 . 2009-11-24 23:38 ——– d—–w- c:\documents and settings\George Hall\Local Settings\Application Data\Temp
2009-11-21 21:45 . 2009-11-25 00:51 ——– d—–w- c:\documents and settings\George Hall\Local Settings\Application Data\Google
2009-11-20 23:01 . 2009-11-29 23:00 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-11-18 04:02 . 2009-11-18 04:02 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2009-11-18 00:08 . 2009-08-07 00:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2009-11-16 10:38 . 2009-11-18 17:00 ——– d—–w- c:\documents and settings\George Hall\Local Settings\Application Data\xbxmjm
2009-11-12 14:44 . 2009-11-11 14:25 4026136 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-11-12 14:44 . 2009-11-12 14:43 3963648 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-12 14:44 . 2009-11-12 14:43 497944 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchjwx.dll
2009-11-12 14:44 . 2009-11-11 14:25 2016536 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-11-12 14:44 . 2009-11-11 14:25 1257240 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2009-11-10 10:42 . 2009-11-11 15:27 ——– d—–w- c:\documents and settings\George Hall\Local Settings\Application Data\gvvpls
2009-11-07 09:28 . 2009-11-07 09:28 ——– d—–w- c:\program files\iPod
2009-11-07 09:28 . 2009-11-07 09:29 ——– d—–w- c:\program files\iTunes
2009-11-07 09:24 . 2009-11-07 09:24 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-04 22:14 . 2009-10-25 08:54 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2009-12-04 22:04 . 2009-10-25 15:44 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-12-04 21:06 . 2009-10-25 10:21 0 —-a-w- c:\documents and settings\George Hall\Local Settings\Application Data\prvlcl.dat
2009-12-03 02:57 . 2004-08-10 11:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2009-12-02 09:54 . 2009-11-04 10:26 ——– d—–w- c:\program files\ERUNT
2009-12-01 22:37 . 2009-10-25 09:10 ——– d—–w- c:\documents and settings\George Hall\Application Data\mjusbsp
2009-12-01 10:08 . 2009-10-25 09:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-01 10:07 . 2009-10-25 09:04 ——– d—–w- c:\program files\Microsoft Works
2009-11-30 01:13 . 2009-10-25 09:56 ——– d—–w- c:\documents and settings\George Hall\Application Data\FileZilla
2009-11-22 16:05 . 2009-10-25 08:29 70792 —-a-w- c:\documents and settings\George Hall\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-22 03:46 . 2009-10-25 09:56 ——– d—–w- c:\program files\FileZilla FTP Client
2009-11-11 14:25 . 2009-10-25 08:54 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-11 14:24 . 2009-10-25 10:08 1657112 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2009-11-07 09:28 . 2009-10-25 09:39 ——– d—–w- c:\program files\Common Files\Apple
2009-11-04 10:47 . 2009-11-04 10:47 2752 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2009-11-04 10:41 . 2009-11-02 23:47 ——– d—–w- c:\program files\DivX
2009-11-04 10:41 . 2009-11-03 22:28 ——– d—–w- c:\program files\iPod(2)
2009-11-04 10:41 . 2009-11-03 22:28 ——– d—–w- c:\program files\iTunes(2)
2009-11-04 10:40 . 2009-11-04 10:40 ——– d—–w- c:\program files\Norton Security Scan
2009-11-04 10:40 . 2009-11-04 10:40 ——– d—–w- c:\program files\NortonInstaller
2009-11-04 10:40 . 2009-11-04 10:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-04 10:33 . 2009-11-04 10:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-04 09:58 . 2009-10-31 17:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-10-31 17:12 . 2009-10-31 17:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-31 17:12 . 2009-10-31 17:12 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-10-31 16:52 . 2009-10-31 16:52 ——– d—–w- c:\program files\Microsoft Silverlight
2009-10-30 10:36 . 2009-10-30 10:36 ——– d—–w- c:\program files\AnalogX
2009-10-30 00:29 . 2009-10-30 00:29 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-10-28 16:07 . 2009-10-25 08:14 ——– d—–w- c:\program files\DIGStream
2009-10-25 22:46 . 2009-10-25 22:46 ——– d—–w- c:\documents and settings\George Hall\Application Data\AdobeUM
2009-10-25 22:46 . 2009-10-25 22:45 ——– d—–w- c:\program files\Common Files\Adobe
2009-10-25 22:42 . 2009-10-25 22:36 ——– d—–w- c:\program files\Macromedia
2009-10-25 22:42 . 2009-10-25 08:33 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-10-25 22:40 . 2009-10-25 22:37 ——– d—–w- c:\program files\Common Files\Macromedia
2009-10-25 21:28 . 2009-10-25 21:24 ——– d—–w- c:\documents and settings\George Hall\Application Data\Apple Computer
2009-10-25 21:23 . 2009-10-25 21:23 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-25 21:23 . 2009-10-25 09:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-25 15:44 . 2009-10-25 15:44 ——– d—–w- c:\documents and settings\George Hall\Application Data\Thunderbird
2009-10-25 10:17 . 2009-10-25 09:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-10-25 09:41 . 2009-10-25 09:41 ——– d—–w- c:\program files\Bonjour
2009-10-25 09:40 . 2009-10-25 09:40 ——– d—–w- c:\program files\QuickTime
2009-10-25 09:40 . 2009-10-25 09:40 ——– d—–w- c:\program files\Apple Software Update
2009-10-25 09:38 . 2009-10-25 10:19 93074728 —-a-w- C:\iTunesSetup(2).exe
2009-10-25 09:27 . 2009-10-25 09:27 ——– d—–w- c:\program files\ACDSee32
2009-10-25 09:04 . 2009-10-25 09:04 ——– d—–w- c:\program files\MSBuild
2009-10-25 09:03 . 2009-10-25 09:03 ——– d—–w- c:\program files\Microsoft.NET
2009-10-25 08:54 . 2009-10-25 08:54 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-10-25 08:54 . 2009-10-25 08:54 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-25 08:54 . 2009-10-25 08:54 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-25 08:54 . 2009-10-25 08:54 ——– d—–w- c:\program files\AVG
2009-10-25 08:35 . 2009-10-25 08:04 87747 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-25 08:35 . 2009-10-25 08:35 ——– d—–w- c:\program files\SigmaTel
2009-10-25 08:35 . 2009-10-25 08:30 ——– d—–w- c:\program files\Common Files\InstallShield
2009-10-25 08:33 . 2009-10-25 08:33 ——– d—–w- c:\program files\ATI Technologies
2009-10-25 08:31 . 2009-10-25 08:31 ——– d—–w- c:\program files\Intel
2009-10-25 08:31 . 2009-10-25 08:31 ——– d—–w- c:\program files\Dell
2009-10-25 08:16 . 2009-10-25 08:16 ——– d—–w- c:\program files\RGB
2009-10-25 08:14 . 2009-10-25 08:14 ——– d—–w- c:\program files\ESPNMotion
2009-10-25 08:14 . 2009-10-25 08:14 ——– d—–w- c:\documents and settings\All Users\Application Data\DIGStream
2009-10-25 08:14 . 2009-10-25 08:14 134 —-a-w- c:\documents and settings\George Hall\Local Settings\Application Data\fusioncache.dat
2009-10-25 08:14 . 2009-10-25 08:14 ——– d—–w- c:\program files\GemMaster
2009-10-25 08:14 . 2009-10-25 08:14 ——– d—–w- c:\program files\EnglishOtto
2009-10-25 08:05 . 2009-10-25 08:05 ——– d—–w- c:\program files\microsoft frontpage
2009-10-25 08:01 . 2009-10-25 08:01 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-10-25 08:00 . 2009-10-25 08:00 ——– d—–w- c:\program files\Windows Plus
2009-10-25 07:43 . 2009-10-25 07:43 0 —-a-w- c:\windows\nsreg.dat
2009-09-25 05:37 . 2004-08-10 11:00 667136 —-a-w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2004-08-10 11:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-09-23 12:55 . 2009-12-01 11:58 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-09-11 14:18 . 2004-08-10 11:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\George Hall\Application Data\mjusbsp\cdloader2.exe MAGICJACK" [X]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Google Update"="c:\documents and settings\George Hall\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-21 135664]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-12 2020120]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-22 339968]

c:\documents and settings\George Hall\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-25 08:54 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Macromedia\\Flash MX\\Flash.exe"=
"c:\\Documents and Settings\\George Hall\\Application Data\\mjusbsp\\magicJack.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12/1/2009 6:58 AM 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/25/2009 3:54 AM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/25/2009 3:54 AM 360584]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [10/25/2009 3:54 AM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/25/2009 3:54 AM 285392]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 6:17 AM 1184912]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/24/2009 6:37 PM 135664]
.
Contents of the 'Scheduled Tasks' folder

2009-12-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 11:58]

2009-12-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-24 21:45]

2009-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-24 21:45]

2009-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1801674531-682003330-1003Core.job
- c:\documents and settings\George Hall\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-21 21:45]

2009-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1801674531-682003330-1003UA.job
- c:\documents and settings\George Hall\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-21 21:45]

2009-12-02 c:\windows\Tasks\Norton Security Scan for George Hall.job
- c:\program files\Norton Security Scan\Engine\2.3.0.44\Nss.exe [2009-10-31 23:58]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\George Hall\Application Data\Mozilla\Firefox\Profiles\d2nrwydv.default\
FF - prefs.js: browser.startup.homepage - hxxp://george-hall.net
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\George Hall\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-qrocfjpv - c:\documents and settings\George Hall\Local Settings\Application Data\gvvpls\gkkhsysguard.exe
HKLM-Run-qrocfjpv - c:\documents and settings\George Hall\Local Settings\Application Data\gvvpls\gkkhsysguard.exe
AddRemove-Ad-Aware - c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe REMOVE=TRUE MODIFY=FALSE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-04 18:10
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-12-04 18:11
ComboFix-quarantined-files.txt 2009-12-04 23:11

Pre-Run: 360,710,119,424 bytes free
Post-Run: 361,341,628,416 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - 69907B0968D13F57E69A49BADE7D2A9A
1) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

2) ESET
You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

3) What You Will Need To Post:
  • MBAM log
  • ESET log
  • How your computer is performing now
Just ran both processes and here is the log files. Other than when the problem re-introduced itself on bootup yesterday (I ran your file to stop it and have not rebooted since) it appears to be running OK for the time being. I'll keep checking back in the next 24-36 hours to see if there are any further instructions before confirming it is OK. Thank You. Malwarebytes' Anti-Malware 1.42 Database version: 3299 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 12/5/2009 4:46:33 AM mbam-log-2009-12-05 (04-46-33).txt Scan type: Quick Scan Objects scanned: 105166 Time elapsed: 3 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Smart-Shopper (Adware.SmartShopper) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=6.00.2900.5512 (xpsp.080413-2105) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=c724d4095dd2ef43a03f8c3e2fcdc98d # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-12-05 02:13:14 # local_time=2009-12-05 09:13:14 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1024 16777175 100 0 2624355 2624355 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=165871 # found=2 # cleaned=0 # scan_time=15590 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmartShopper5.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Win32/Olmarik.RF virus 00000000000000000000000000000000 I
Looking all clean. :)

The following will implement some cleanup procedures as well as reset System Restore points:

  • Please press the Windows Key and R on your keyboard. This will bring up the Run… command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
    🖼Click to load external image (Posted Image)
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.

You can remove any other programs or logs from this fix, except MBAM. Keep that, and scan/update weekly.

How to reduce your chances of infection in the future

Web Browsers
Internet Explorer does come pre-installed with all Windows machines - but this doesn't necessarily mean you have to use it! Because it is the most widely used browser, it is targeted by more malware writers, making you more susceptible to infection. There are many other free alternatives out there that offer better security, take one of these for a spin and see if it takes your fancy.
Mozilla Firefox
Google Chrome
Opera

WOT - Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for Firefox, Google Chrome and Internet Explorer.

If you would prefer to keep using Internet Explorer, follow these additional steps to make the browser more secure.
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Additional Security Measures
Keep your software up-to-date - You should be manually performing updates of your software once a week to ensure that you are current with anti-virus definitions and patched for any security vulnerabilities. This does not just apply to your anti-virus/anti-malware software; malware authors rely on exploiting commonly used software such as Java and Adobe Reader, which need to be kept up to date as well.

Keep Windows up-to-date - Use Windows Update regularly to stay current with security patches and service packs.

MVPS Hosts File - This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.

Firewalls - Without a firewall your computer is susceptible to being hacked and taken over. If you use the Windows Firewall you might think that's sufficient - but it only controls one way of the traffic (inbound). Simply using a Firewall in its default configuration can lower your risk greatly.

What Not To Do
The Perils of P2P File Sharing - Even if a P2P application is on the 'safe' list, malware can still be downloaded through infected files - executables, zip files and even MP3s. It is just not worth the risk.

Fake Security/Optimization Software - Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Additional Reading
How to prevent Malware - I strongly recommend that you read Miekiemoses' good advice

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI