This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Antispyware pro hijacked my computer

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi SweetTech,
I'm sorry, I have been away for the past week and haven't had a chance to reply to my original thread at: http://forums.whatthetech.com/Antispyware_…270#entry614270

Anyway, I followed your instructions, here is what I have:

My Copy.bat log:

1 file(s) copied.
1 file(s) copied.
1 file(s) copied.

My Avenger Log:

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File move operation "C:\atapi.sys|C:\WINDOWS\system32\drivers\atapi.sys" completed successfully.
File move operation "c:\atapidll\atapi.sys|C:\WINDOWS\system32\dllcache\atapi.sys" completed successfully.

Completed script processing.

*******************

Finished! Terminate.

My system look log:

SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 13:41 on 13/12/2009 by Sameer (Administrator - Elevation successful)

========== filefind ==========

Searching for "*atapi.sys"
C:\atapibak\atapi.sys –a— 95360 bytes [18:31 13/12/2009] [03:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\i386\atapi.sys –a–c 95360 bytes [20:11 02/11/2005] [03:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\erdnt\cache\atapi.sys –a— 95360 bytes [04:02 02/12/2009] [03:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys —— 96512 bytes [14:56 13/06/2009] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\dllcache\atapi.sys –a— 96512 bytes [00:39 21/05/2009] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\atapi.sys –a— 96512 bytes [00:39 21/05/2009] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys –a–c 95360 bytes [14:44 20/10/2005] [03:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51

-=End Of File=-


My computer has been running very good, probably even better than before I was infected. It starts up really fast, which it never had done previously.

Thanks.
Hello smp182, I've gone ahead and asked that this thread be merged with your previous thread, and that your original thread re-opened. In the future, if you plan on being away for longer than 5 days, please let me know, so that I don't close your thread thinking you abandoned me. We still have some work to do. I'll get back to you shortly. Thanks, SweetTech.
Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Re-Scanning with DDS
Please re-run DDS by sUBs.
Make sure to pay attention to the directions below:
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by doing the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Please make sure you include the following items in your next post:
1. The log that was produced after running MalwareBytes' Anti-Malware.
2. The log that was produced after running the ESET Online Scan.
3. The logs that were produced after running DDS. (DDS.txt & Attach.txt)
4. Any outstanding issues that you may be experiencing with your computer.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Hi SweetTech, 1) My Malwarebytes log: Malwarebytes' Anti-Malware 1.42 Database version: 3289 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 12/16/2009 9:28:10 PM mbam-log-2009-12-16 (21-28-10).txt Scan type: Quick Scan Objects scanned: 128391 Time elapsed: 15 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) 2) My ESET log: C:\Documents and Settings\Sameer\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.12262 Win32/TrojanDownloader.PurityScan.NAK trojan C:\Documents and Settings\Sameer\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.15731 Win32/Adware.Virtumonde.NEO application C:\Documents and Settings\Sameer\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.29860 Win32/Adware.Virtumonde.NEO application C:\Documents and Settings\Sameer\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.35361 Win32/Adware.Virtumonde.NEO application C:\Documents and Settings\Sameer\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.37031 Win32/TrojanDownloader.Agent.BLS trojan C:\Documents and Settings\Sameer\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.52156 Win32/Adware.Virtumonde.NEO application C:\Documents and Settings\Sameer\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.80044 Win32/TrojanDownloader.Agent.BLS trojan C:\Documents and Settings\Sameer\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.80800 Win32/Adware.Virtumonde.NEO application C:\Documents and Settings\Sameer\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.96231 Win32/TrojanDownloader.PurityScan.EG trojan C:\Documents and Settings\Sameer\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.98564 Win32/Adware.Virtumonde.NEO application C:\Documents and Settings\Sameer\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-30d5aac8-56712370.class Java/TrojanDownloader.OpenStream.NAC trojan C:\Documents and Settings\Sameer\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-59045a6-1f5cc2c3.class Java/TrojanDownloader.OpenStream.NAC trojan C:\Documents and Settings\Sameer\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms03011.jar-fc9eb36-2129bd08.zip multiple threats C:\Documents and Settings\Sameer\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-51de10e-5ce03f03.zip Java/TrojanDownloader.OpenStream.NAB trojan C:\Documents and Settings\Sameer\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-64f01ec-74d9733e.zip Java/TrojanDownloader.OpenStream.NAB trojan C:\Program Files\RSSoft\RSEDNClient.exe probably a variant of Win32/Adware.Agent application C:\QooBox\Quarantine\C\Documents and Settings\Sameer\Local Settings\Application Data\ngontc\brxcsysguard.exe.vir a variant of Win32/Kryptik.AVN trojan C:\QooBox\Quarantine\C\WINDOWS\default.htm.vir Win32/TrojanDownloader.FakeAlert.AV trojan C:\QooBox\Quarantine\C\WINDOWS\system32\L5DEC.tmp.vir Win32/Adware.ISM application C:\QooBox\Quarantine\C\WINDOWS\system32\L909.tmp.vir Win32/TrojanDownloader.Small.IAW trojan C:\QooBox\Quarantine\C\WINDOWS\system32\LB0FA.tmp.vir Win32/Adware.ISM application C:\QooBox\Quarantine\C\WINDOWS\system32\LCED6.tmp.vir Win32/TrojanDownloader.Small.IAW trojan C:\QooBox\Quarantine\C\WINDOWS\system32\lhkiynof.ini.vir Win32/Adware.Virtumonde.NEO application C:\QooBox\Quarantine\C\WINDOWS\system32\rbhwgbyi.dll.vir Win32/Adware.AdMedia application C:\QooBox\Quarantine\C\WINDOWS\system32\tuinwuxs.dll.vir Win32/Adware.AdMedia application C:\QooBox\Quarantine\C\WINDOWS\system32\wxityumo.dll.vir Win32/Adware.AdMedia application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102802.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102807.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102808.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102810.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102811.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102812.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102814.DLL Win32/FunWeb application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102815.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102816.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102817.SCR Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102818.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102819.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102820.EXE Win32/Adware.FunWeb application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102821.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102824.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102825.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102826.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102827.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102828.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102829.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102831.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102832.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102833.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102835.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102836.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102837.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102838.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102839.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102840.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102847.exe probably a variant of Win32/TrojanClicker.Delf trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102848.exe Win32/TrojanClicker.Delf.NBD trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102849.exe probably a variant of Win32/TrojanClicker.Delf trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102850.exe probably a variant of Win32/TrojanClicker.Delf trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0102851.dll Win32/Small.NDR trojan C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP658\A0103019.exe a variant of Win32/Kryptik.AVN trojan 3) My DDS.txt log (below) and Attach.txt log (attached) DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 23:08:16.56 on Wed 12/16/2009 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.162 [GMT -5:00] AV: Norton Internet Security *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\AskBarDis\bar\bin\AskService.exe C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wdfmgr.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\hphmon04.exe C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\BitTorrent_DNA\dna.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\America Online 9.0\aoltray.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe C:\Documents and Settings\Sameer\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ mURLSearchHooks: H - No File BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: PCTools Site Guard: {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - c:\progra~1\spywar~1\tools\iesdsg.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aim toolbar 5.0\aoltb.dll BHO: CNisExtBho Class: {9ecb9560-04f9-4bbc-943d-298ddf1699e1} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll BHO: PCTools Browser Monitor: {b56a7d7d-6927-48c8-a975-17df180c71ac} - c:\progra~1\spywar~1\tools\iesdpb.dll BHO: CNavExtBho Class: {bdf3e430-b101-42ad-a544-fadc6b084872} - c:\program files\norton internet security\norton antivirus\NavShExt.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Norton Internet Security: {0b53eac3-8d69-4b9e-9b19-a37c9a5676a7} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton internet security\norton antivirus\NavShExt.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: AIM Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll uRun: [Red Swoosh EDN Client] c:\program files\rssoft\RSEDNClient.exe uRun: [EA Core] c:\program files\electronic arts\ea downloader\Core.exe -silent uRun: [DNA] "c:\program files\bittorrent_dna\dna.exe" uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe mRun: [CTSysVol] c:\program files\creative\sound blaster live! 24-bit\surround mixer\CTSysVol.exe /r mRun: [P17Helper] Rundll32 P17.dll,P17Helper mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe" mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [Symantec NetDriver Monitor] c:\progra~1\symnet~1\SNDMon.exe /Consumer mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe mRun: [HPHmon04] c:\windows\system32\hphmon04.exe mRun: [HPHUPD04] "c:\program files\hp photosmart 11\hphinstall\unipatch\hphupd04.exe" mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-us\local\search.html IE: &Search IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - {A1EDC4A1-940F-48E0-8DFD-E38F1D501021} - c:\progra~1\spywar~1\tools\iesdpb.dll IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll Trusted Zone: turbotax.com DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://download.macromedia.com/pub/shockwave/cabs/authorware/awswax70.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www1.snapfish.com/SnapfishActivia.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: igfxcui - igfxdev.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R1 ikhfile;File Security Kernel Anti-Spyware Driver;c:\windows\system32\drivers\ikhfile.sys [2006-4-14 30688] R1 ikhlayer;Kernel Anti-Spyware Driver;c:\windows\system32\drivers\ikhlayer.sys [2006-4-14 51456] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2006-10-10 5632] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2007-2-27 32256] R1 SAVRTPEL;SAVRTPEL;c:\program files\norton internet security\norton antivirus\SAVRTPEL.SYS [2005-3-15 53896] R2 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-12-14 464264] R2 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2009-12-14 234888] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCEVTMGR.EXE [2005-3-15 185704] R2 ccProxy;Symantec Network Proxy;c:\program files\common files\symantec shared\CCPROXY.EXE [2005-3-15 239264] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSETMGR.EXE [2005-3-15 177512] R2 navapsvc;Norton AntiVirus Auto-Protect Service;c:\program files\norton internet security\norton antivirus\NAVAPSVC.exe [2005-3-15 128160] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-11-14 24652] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20061213.022\NAVENG.Sys [2006-12-13 79240] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20061213.022\NavEx15.Sys [2006-12-13 831880] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096] R3 SAVRT;SAVRT;c:\program files\norton internet security\norton antivirus\SAVRT.SYS [2005-3-15 334984] S2 SBService;ScriptBlocking Service;c:\progra~1\common~1\symant~1\script~1\SBServ.exe [2005-3-11 67184] S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\CCPWDSVC.EXE [2005-3-15 83304] S3 SAVScan;SAVScan;c:\program files\norton internet security\norton antivirus\SAVSCAN.EXE [2005-3-15 198368] =============== Created Last 30 ================ 2009-12-17 02:36:34 0 d—–w- c:\program files\ESET 2009-12-17 02:04:18 1940 —-a-w- C:\Catalog.LiveSubscribe 2009-12-14 13:29:04 0 d—–w- c:\program files\AskBarDis 2009-12-13 18:31:42 0 d—–w- C:\atapidll 2009-12-13 18:31:42 0 d—–w- C:\atapibak 2009-12-05 16:52:59 0 d—–w- C:\ComboFix 2009-12-02 03:19:59 0 d-sha-r- C:\cmdcons 2009-12-02 03:18:37 98816 —-a-w- c:\windows\sed.exe 2009-12-02 03:18:37 77312 —-a-w- c:\windows\MBR.exe 2009-12-02 03:18:37 260608 —-a-w- c:\windows\PEV.exe 2009-12-02 03:18:37 161792 —-a-w- c:\windows\SWREG.exe 2009-11-29 21:22:48 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-11-29 21:22:45 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-11-29 19:41:54 0 d—–w- c:\program files\Trend Micro ==================== Find3M ==================== 2009-10-27 11:06:22 18432 —-a-w- c:\windows\system32\dllcache\iedw.exe 2009-10-21 06:00:55 75776 —-a-w- c:\windows\system32\strmfilt.dll 2009-10-21 06:00:55 75776 ——w- c:\windows\system32\dllcache\strmfilt.dll 2009-10-21 06:00:55 25088 —-a-w- c:\windows\system32\httpapi.dll 2009-10-21 06:00:55 25088 ——w- c:\windows\system32\dllcache\httpapi.dll 2009-10-20 14:58:48 263552 —-a-w- c:\windows\system32\drivers\http.sys 2009-10-20 14:58:48 263552 ——w- c:\windows\system32\dllcache\http.sys 2009-10-13 10:53:29 266752 —-a-w- c:\windows\system32\oakley.dll 2009-10-13 10:53:29 266752 ——w- c:\windows\system32\dllcache\oakley.dll 2009-10-12 13:54:17 69632 —-a-w- c:\windows\system32\raschap.dll 2009-10-12 13:54:17 69632 ——w- c:\windows\system32\dllcache\raschap.dll 2009-10-12 13:54:17 112128 —-a-w- c:\windows\system32\rastls.dll 2009-10-12 13:54:17 112128 ——w- c:\windows\system32\dllcache\rastls.dll 2009-09-25 05:56:35 473600 —-a-w- c:\windows\system32\dllcache\shlwapi.dll 2009-09-25 05:56:32 81920 —-a-w- c:\windows\system32\ieencode.dll 2009-09-25 05:56:32 81920 —-a-w- c:\windows\system32\dllcache\ieencode.dll 2009-09-25 05:56:32 1054208 —-a-w- c:\windows\system32\dllcache\danim.dll ============= FINISH: 23:08:52.81 =============== 📎Attach.txt 4) My computer is running very well, don't have any current issues. Thanks.
Questions:
According to your logs you are currently running Norton Internet Security. Your logs also show me that it is outdated. Is your subscription with Norton Internet Security still current?

Java Outdated
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 17. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the drop-down menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader
Alternative Option: after uninstalling Adobe Reader, you could try installing Foxit Reader from >here< Foxit Reader has fewer add-ons therefore loads more quickly.

Remove Program
We need to remove a program. To do this please do the following:
  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present):
  • ESET Online Scanner v3
  • Kaspersky On-line Scanner
Time for some housekeeping
The following will implement some cleanup procedures as well as reset System Restore points:
[external image: Posted Image]
Click Start > Run and copy/paste the following bolded text into the Run box and click OK: ComboFix /Uninstall

Please make sure you include the following items in your next post:
1. A response to my questions that I asked you under the question section regarding your Norton Internet Security Subscription.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Hi SweetTech, I ran through everything you listed. To answer your question: 1) Yes, my Norton Antivirus is out of date. I do need to re-subscribe. My computer has been running great. I can't thank you enough for your help!!
It's never a good idea to be running your system with no active anti-virus subscription. This can leave you wide open to a sleuth of viruses and other baddies that your system will be susceptible to getting re-infected. If you can't upgrade your Norton subscription at this time, then you should consider uninstalling Norton for the time being and installing a free anti-virus program like Avira or Avast. I've included links for both Avira and Avast.

  • Avira AntiVir Personal - Free anti-virus software for Windows. Detects and removes more than 50000 viruses. Free support.
  • avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
Clean-Up Time
Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.
All Clean Speech

===> Make sure you've re-enabled any Security Programs that we may have disabled during the malware removal process. <===

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at: http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE
  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from Here
    • If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
      • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI