This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] your system is infected wallpaper

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am running windows xp and seem to have the same problem as a previos post but you mentioned not to follow someone elses problem. so here it goes:

  • . when system starts up "Spyware Alert" Security Warning! Worm.Win32.Netsky detected on your machine… message comes up.
  • . WARNING; Application cannot be executed. The file is infected
  • . logon.exe error message " Windows cannot find logon.exe. make sure you typed name correctly…
  • . wallpaper has changed to " your system is infected"… screen and it will not allow me to change in the settings
  • . bottom right corner has a red circle with white x
  • . warning sign that says "Attention! Sysem detected a potential hazard (TrojanSPM/LX) on you computer…
  • . There was another one that was called "Advanced Virus Remover" (AVR) but finally somehow got rid of it (maybe)
I hope you can help. Thank you in advance.
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
  • Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within five days
    . I will post a reminder should you seem to fail to do this, however, if you fail to reply within five days then,
    unless I have been notified of your absence in advance, the topic shall be closed!
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your log, I will post back shortly with instructions.
I know i should've done this first but i am following the steps for NEW MEMBERs. I am on step 2 "download DDS" and i did but when i double click on the icon to run, the Commant prompt opens then closes. A message pops up "Warning: Application cannot be executed. The file is infected. Please acivate you antivirus software. And yes i disabled all security programs. Now i dont know what to do! I will wait for your instructions
Sorry for the delay.

Please do the following:

Please download SmitfraudFix

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

Please post the log that is produced after running SmitfraudFix.
I cannot install. Warning message: Application cannot be executed. the file is infected. please activate your antivirus software. as i was typing this a comand prompt came up( C:/windows/system32/19169.exe) but it will not allow me to do anything with it
Run exeHelper
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

Delete the copy of SmitFraudFix you have on your computer.

Running SmitFraudFix
Please download SmitfraudFix

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

Post the logs that are produced after running exeHelper and SmitFraudFix.
exeHelper by Raktor Build 20091122 Run at 13:49:39 on 12/03/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Killed process winupdate86.exe Checking for bad files… Deleting file C:\WINDOWS\system32\41.exe Deleting file C:\WINDOWS\system32\critical_warning.html Deleting file C:\WINDOWS\system32\winupdate86.exe Checking for bad registry entries… Removing HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Advanced Virus Remover Deleting file C:\Program Files\AdvancedVirusRemover\AVR.exe Error deleting C:\Program Files\AdvancedVirusRemover\AVR.exe - Set for removal on reboot - PLEASE REBOOT Removing HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate86.exe Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– SmitFraudFix v2.424 Scan done at 13:55:50.82, Thu 12/03/2009 Run from C:\Documents and Settings\JERN\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Microsoft Security Essentials\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\System32\snmp.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\Canon\CAL\CALMAIN.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\Explorer.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Microsoft Security Essentials\msseces.exe C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe C:\Program Files\DellSupport\DSAgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AdvancedVirusRemover\AVR.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\JERN\Desktop\SmitfraudFix\Policies.exe C:\Documents and Settings\JERN\Desktop\SmitfraudFix\Policies.exe C:\Documents and Settings\JERN\Desktop\SmitfraudFix\Policies.exe C:\Documents and Settings\JERN\Desktop\SmitfraudFix\Policies.exe C:\Documents and Settings\JERN\Desktop\SmitfraudFix\Policies.exe C:\Documents and Settings\JERN\Desktop\SmitfraudFix\Policies.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Documents and Settings\JERN\Desktop\SmitfraudFix\Policies.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\notepad.exe C:\Documents and Settings\JERN\Desktop\SmitfraudFix\Policies.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\JERN »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\JERN\LOCALS~1\Temp »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\JERN\Application Data C:\Documents and Settings\JERN\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Start Menu C:\DOCUME~1\JERN\STARTM~1\Advanced Virus Remover.lnk FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\JERN\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop C:\DOCUME~1\JERN\Desktop\Advanced Virus Remover.lnk FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\AdvancedVirusRemover\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» o4Patch !!!Attention, following keys are not inevitably infected!!! o4Patch Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» IEDFix !!!Attention, following keys are not inevitably infected!!! IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix !!!Attention, following keys are not inevitably infected!!! Agent.OMZ.Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» VACFix !!!Attention, following keys are not inevitably infected!!! VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» 404Fix !!!Attention, following keys are not inevitably infected!!! 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{50f55a99-9ddb-4907-950b-610f998387aa}"="mujuzedij" [HKEY_CLASSES_ROOT\CLSID\{50f55a99-9ddb-4907-950b-610f998387aa}\InProcServer32] @="c:\windows\system32\norupeze.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{50f55a99-9ddb-4907-950b-610f998387aa}\InProcServer32] @="c:\windows\system32\norupeze.dll" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="kosagiti.dll c:\\windows\\system32\\norupeze.dll" "LoadAppInit_DLLs"=dword:00000001 »»»»»»»»»»»»»»»»»»»»»»»» Winlogon !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"="C:\\WINDOWS\\system32\\userinit.exe," »»»»»»»»»»»»»»»»»»»»»»»» RK [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Intel® PRO/100 VE Network Connection - Packet Scheduler Miniport DNS Server Search Order: 192.168.1.254 HKLM\SYSTEM\CCS\Services\Tcpip\..\{8CDBB704-4D3F-4215-816B-F0C87D749BDF}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\..\{D7F27905-7902-457E-B690-E3B8CB5AA723}: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CS1\Services\Tcpip\..\{8CDBB704-4D3F-4215-816B-F0C87D749BDF}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{D7F27905-7902-457E-B690-E3B8CB5AA723}: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CS2\Services\Tcpip\..\{8CDBB704-4D3F-4215-816B-F0C87D749BDF}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{D7F27905-7902-457E-B690-E3B8CB5AA723}: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Running SmitFraudFix
You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

1. Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer.
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually.
  • Instead of Windows loading as normal, a menu with options should appear.
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
2. Once in Safe Mode
  • Double-click SmitfraudFix.exe
  • Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
  • You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter".

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply. The report can also be found at C:\rapport.txt.

Warning: running option #2 on a non infected computer will remove your Desktop background.

Scanning with MalwareBytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

Scanning with DDS
Before continuing please delete the version of DDS that you have on your computer. We need to download a fresh copy.

Please download DDS by sUBs from one of the following links and save it to your desktop.
[external image: Posted Image]
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by doing the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Please make sure you include the following items in your next post:
1. The log that was produced after running SmitFraudFix Option 2.
2. The log that was produced after running MalwareBytes' Anti-Malware.
3. The logs that were produced after running DDS. (DDS.txt & Attach.txt)
4. An update on how your computer is running.
I tried to restart in safe mode but received the blue error screen message saying: A problem has been detected and windows has been shut down to prevent damage to your computer If this is the first time you've seen this stop error screen, restart your computer. If this screen appears again, follow these steps: Check for viruses on your computer. Remove any newly installed hard drives or hard drive controllers………………..and so on…. So i tried again and same thing happened.
Please go ahead and skip the instructions for SmitFraudFix and continue with the MalwareBytes' Anti-Malware scan and the DDS Scan. Make sure you include the logs that are produced after running the scans as well as an update on how your computer is running.
I could not launch the Malwarebytes. After setup was complete error message:

Setup
Unable to execute file: c:\ProgramFiles\Malwarebytes'Anti-Malware\mbam.exe

CreateProcess failed; code 2.
The system cannot find the file specified.


I then double clicked on icon and received Missing Shortcut error message. But i did run the DDS


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 16:21:17.09 on Thu 12/03/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.102 [GMT -8:00]

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\JERN\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uWindow Title = Microsoft Internet Explorer presented by Comcast
uDefault_Page_URL = hxxp://www.yahoo.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mWindow Title = Microsoft Internet Explorer presented by Comcast
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearchAssistant =
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {3192b808-ec27-4332-b6c6-97f82692cad5} - No File
BHO: Yahoo! IE Suggest: {5a263cf7-56a6-4d68-a8cf-345be45bc911} - c:\program files\yahoo!\searchsuggest\YSearchSuggest.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
{6022635f-7197-4ced-b066-5e46d0a696a0}
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: {C06B1E9D-AC66-42E1-9992-71147245A3F7} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {e21c1631-27ba-4527-815a-39ace2fb4914}: {4194bf2e-ca93-a518-7254-ab721361c12e}
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {F8C5B5C9-3AC5-4C8C-A984-1C4B71C2E69B} - No File
BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No File
TB: {3192b808-ec27-4332-b6c6-97f82692cad5} - No File
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
mRun: [McAfee Backup] "c:\program files\mcafee\mbk\McAfeeDataBackup.exe"
mRun: [jidopijen] Rundll32.exe "c:\windows\system32\norupeze.dll",a
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/
IE: {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/
IE: {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\pokerstars.net\PokerStarsUpdate.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper20073151.dll
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxdev.dll
Notify: ssqPfcde - ssqPfcde.dll
AppInit_DLLs: kosagiti.dll c:\windows\system32\norupeze.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: hakorumit - {1a309fd0-8200-4ac7-94e2-2927ed48df52} - No File
SSODL: hewolalum - {50f55a99-9ddb-4907-950b-610f998387aa} - c:\windows\system32\norupeze.dll
STS: mujuzedij: {50f55a99-9ddb-4907-950b-610f998387aa} - c:\windows\system32\norupeze.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\awtsPJBT
LSA: Notification Packages = scecli dorulelo.dll

============= SERVICES / DRIVERS ===============

R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-3-9 214664]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-3-9 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2008-3-9 144704]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-3-9 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-3-9 35272]
S3 dump_wmimmc;dump_wmimmc;\??\c:\nexon\maplestory\gameguard\dump_wmimmc.sys –> c:\nexon\maplestory\gameguard\dump_wmimmc.sys [?]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-3-9 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-3-9 40552]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2008-3-9 606736]

=============== Created Last 30 ================

2009-12-04 00:19:36 0 d—–w- c:\docume~1\jern\applic~1\Malwarebytes
2009-12-04 00:13:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13:36 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-04 00:13:36 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-04 00:13:35 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-03 21:56:12 3750 —-a-w- c:\windows\system32\tmp.reg
2009-12-03 04:02:45 0 d—–w- c:\program files\AdvancedVirusRemover
2009-12-02 03:31:17 0 d—–w- c:\windows\system32\drivers\NSS
2009-12-02 03:31:16 0 d—–w- c:\program files\Norton Security Scan
2009-12-02 03:31:15 0 d—–w- c:\docume~1\alluse~1\applic~1\Norton
2009-12-02 03:30:40 0 d—–w- c:\program files\NortonInstaller
2009-12-02 03:30:40 0 d—–w- c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-12-01 00:31:39 0 d—–w- C:\828be51ece8d9c1b7c7ec5
2009-11-30 23:41:52 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-11-30 23:28:39 0 d—–w- c:\program files\Microsoft Security Essentials
2009-11-30 23:28:33 274288 —-a-w- c:\windows\system32\mucltui.dll
2009-11-30 23:28:33 215920 —-a-w- c:\windows\system32\muweb.dll
2009-11-30 23:28:33 16736 —-a-w- c:\windows\system32\mucltui.dll.mui
2009-11-30 22:50:16 0 d—–w- C:\ProgramData
2009-11-30 22:50:16 0 d—–w- c:\program files\Angle Interactive
2009-11-30 22:18:02 0 —-a-w- c:\windows\system32\5436.exe
2009-11-30 21:57:58 0 —-a-w- c:\windows\system32\4827.exe
2009-11-30 21:37:58 0 —-a-w- c:\windows\system32\11942.exe
2009-11-30 21:17:57 0 —-a-w- c:\windows\system32\2995.exe
2009-11-30 20:57:56 0 —-a-w- c:\windows\system32\491.exe
2009-11-30 20:37:56 0 —-a-w- c:\windows\system32\9961.exe
2009-11-30 20:17:55 0 —-a-w- c:\windows\system32\16827.exe
2009-11-30 19:57:55 0 —-a-w- c:\windows\system32\23281.exe
2009-11-30 19:37:54 0 —-a-w- c:\windows\system32\28145.exe
2009-11-30 02:27:44 0 —-a-w- c:\windows\system32\5705.exe
2009-11-30 02:07:43 0 —-a-w- c:\windows\system32\24464.exe
2009-11-30 01:47:43 0 —-a-w- c:\windows\system32\26962.exe
2009-11-30 01:27:42 0 —-a-w- c:\windows\system32\29358.exe
2009-11-30 01:07:41 0 —-a-w- c:\windows\system32\11478.exe
2009-11-30 00:47:40 0 —-a-w- c:\windows\system32\15724.exe
2009-11-30 00:27:39 193 —-a-w- c:\windows\system32\19169.exe
2009-11-30 00:07:37 0 —-a-w- c:\windows\system32\26500.exe
2009-11-29 23:32:36 0 d—–w- c:\program files\common files\Scanner
2009-11-29 23:32:32 0 d—–w- c:\program files\CA Yahoo! Anti-Spy
2009-11-29 19:40:05 0 —-a-w- c:\windows\system32\6334.exe
2009-11-29 18:46:37 0 —-a-w- c:\windows\system32\18467.exe
2009-11-29 18:25:29 18944 —-a-w- c:\windows\system32\winlogon86.exe
2009-11-28 00:13:57 0 d—–w- c:\program files\Conduit
2009-11-06 23:48:37 73728 —-a-w- c:\windows\system32\javacpl.cpl

==================== Find3M ====================

2009-11-30 22:02:21 11094 —-a-w- c:\docume~1\jern\applic~1\wklnhst.dat
2009-11-11 01:32:42 55792 —ha-w- c:\windows\system32\mlfcache.dat
2009-10-22 09:19:04 5939712 —-a-w- c:\windows\system32\dllcache\mshtml.dll
2009-10-11 12:17:27 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-09-11 14:18:39 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39 136192 ——w- c:\windows\system32\dllcache\msv1_0.dll
2005-12-16 03:42:22 390396 –sha-w- c:\windows\system32\dfhkj.bak2
2005-12-16 19:51:27 391830 –sha-w- c:\windows\system32\dfhkj.ini2
2009-08-30 15:52:46 52224 –sha-w- c:\windows\system32\dorulelo.dll
2009-01-20 22:51:03 1684345 –sha-w- c:\windows\system32\eKRsYcdd.ini2
2009-09-03 01:56:07 92672 –sha-w- c:\windows\system32\fibanana.dll
2009-08-30 15:52:46 52224 –sha-w- c:\windows\system32\kobitaka.dll
2009-09-03 15:39:30 38400 –sha-w- c:\windows\system32\kogonubo.dll
2009-08-30 15:52:46 52224 –sha-w- c:\windows\system32\kosagiti.dll
2009-09-03 15:39:30 92160 –sha-w- c:\windows\system32\norupeze.dll
2009-09-01 03:52:21 38912 –sha-w- c:\windows\system32\relereni.dll
2009-09-03 01:56:07 38400 –sha-w- c:\windows\system32\sezulono.dll
2009-01-22 23:19:54 1053066 –sha-w- c:\windows\system32\TBJPstwa.ini2
2009-01-17 07:22:01 1658367 –sha-w- c:\windows\system32\TtCIOXyb.ini2
2009-08-30 15:52:08 52224 –sha-w- c:\windows\system32\tukideka.dll
2009-09-02 03:01:07 39424 –sha-w- c:\windows\system32\wolayuga.dll

============= FINISH: 16:22:32.56 ===============

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI