This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Your computer is Infected background. False antispyware pro

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm not sure what this is but it lags my computer and denies me access to my real antispyware, my task manager, and the DDS report asked of me here. It says file infected when I attempt these. It stopped rootrepeal as well. I get redirected from websites and the false antispyware is Internet Security 2010. It also mentions a virus named SPM/LX. I'd like to know how I got this if at all possible. What else can I do for you guys to help me?
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
  • Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within five days
    . I will post a reminder should you seem to fail to do this, however, if you fail to reply within five days then,
    unless I have been notified of your absence in advance, the topic shall be closed!
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your log, I will post back shortly with instructions.

I'd like to know how I got this if at all possible.

The most common method of infection for Internet Security 2010 is through websites that contain malicious code. The majority of the time you will be presented with a pop-up window that includes a warning message that your computer is infected. This infection has also been known to spread through e-mail, Facebook, and Myspace.

What else can I do for you guys to help me?

We are going to need to run a few additional scans. This will enable me to get a better view at what else we might be dealing with. I will post the instructions for this programs as well as the links to download this programs.

Let's continue.

Run exeHelper
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

Scanning with DDS
Delete the current copy of DDS that you have on your computer and please download a fresh copy from one of the following links. Please make sure that you save it to your desktop.
[external image: Posted Image]
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by doing the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Scanning with GMER
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please make sure you include the following items in your next post:
1. The log that was produced after running exeHelper.
2. The log that was produced after running DDS. (DDS.txt & Attach.txt)
3. The log that was produced after running GMER.
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Hi. Thanks for the quick response. I'm sorry if the log is incomplete. It stopped very soon after it started because of this issue i'm having. I'll cooperate as best as possible.
I really tried this entire time to get all the things you requested. Gmer would never finish. It was ultra slow and the computer would always reset. I got as much as possible. If you could possibly help me free up some system resources so I can run things more smoothly, I could try again. Let me know if I need to do anything else. I checked my task manager processes. That is what told me my CPU usage was 100%. This one svchost was like 54k. Not sure if that makes a difference.
Hi again. I ran Gmer for over five hours and it didn't finish but I got a little more out of it. and my critical warning changed. It now says Active desktop recovery. Here is new gmer file.

Attachments:

Ok. Thanks for providing me with the latest GMER log. For the time being hold up on doing anything else. I should have a new set of instructions for you to complete shortly. Thanks, SweetTech.
Questions:
It would be extremely helpful if you could please post the logs instead of attaching them. If I ask for a specific log to be attached then that's fine, but it's a lot easier to work with the logs when they are posted to this thread instead of being attached.

If you could possibly help me free up some system resources so I can run things more smoothly, I could try again.

You have provided me with enough information to work with for right now. In regards to your system running slowly this is mostly likely attributed to you running quite a few Security Software programs at once. Your currently running Ad-Aware, Norton, McAfee, a-squared Anti-Malware, and SUPERAntiSpyware. This leads me into a few questions for you in regards to your security software.

You have or at one point had the following security programs installed on your computer: a-squared Anti-Malware, McAfee, and Norton. I'm seeing your McAfee outdated. Is your subscription to McAfee still active or has it recently expired? I would also like you to comment on whether or not you still use Norton.

Do you use Ad-Aware regularly or was this a program that you installed onto your computer in an effort to remove the infections? I also have the same question regarding SUPERAntiSpyware.

Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Please make sure you include the following items in your next post:
1. An answer to my questions that were posed to you under the questions section.
2. The log that was produced after running ComboFix.
3. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Hi. Sorry about the attachments. I thought that was what I should do. I got confused somewhere. My system came with mcafee but it expired and I switched to norton. I ran that for awhile and then switched back to mcafee. No real reason why. I was then told mcafee is not big on spyware so I got ad aware which I have used before with good results. I was told later that ad aware isn't all encompassing for spyware so I got A-squared/super antispyware too. I do run the last two quite often but I let mcafee lapse because of the cost. Is that clear?

ComboFix 09-12-21.02 - HP_Administrator 12/21/2009 23:31:50.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.456 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll
c:\documents and settings\HP_Administrator\protect.dll
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\ChkDisk.dll
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\ChkDisk.lnk
c:\documents and settings\LocalService\protect.dll
c:\documents and settings\NetworkService\protect.dll
c:\program files\InternetSecurity2010
c:\program files\InternetSecurity2010\IS2010.exe
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\kb913800.exe
c:\windows\system32\11478.exe
c:\windows\system32\11942.exe
c:\windows\system32\14604.exe
c:\windows\system32\153.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\32391.exe
c:\windows\system32\3902.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5436.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
c:\windows\system32\autochk.dll
c:\windows\system32\BSTIEPrintCtl1.dll
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll
c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.lnk
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\winhelper86.dll
c:\windows\system32\winlogon86.exe
c:\windows\system32\wpcap.dll
D:\Autorun.inf

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2009-11-22 to 2009-12-22 )))))))))))))))))))))))))))))))
.

2009-12-19 20:55 . 2009-12-19 20:55 0 —-a-w- c:\documents and settings\HP_Administrator\settings.dat
2009-12-19 20:49 . 2009-12-19 20:50 ——– d—–w- c:\program files\ERUNT
2009-12-19 17:42 . 2009-12-19 17:42 34308 —-a-w- c:\windows\system32\logon.exe.vir
2009-12-11 23:03 . 2009-12-11 23:03 ——– d—–w- c:\windows\system32\drivers\NSS
2009-12-11 23:03 . 2009-12-11 23:03 ——– d—–w- c:\program files\Norton Security Scan
2009-12-09 09:00 . 2009-12-09 09:00 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-22 04:49 . 2008-10-17 19:51 ——– d—–w- c:\program files\DNA
2009-12-22 04:49 . 2008-10-17 19:51 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\DNA
2009-12-19 20:27 . 2006-07-31 23:52 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-12-19 16:43 . 2009-03-15 19:49 ——– d—–w- c:\program files\McAfee
2009-12-17 23:06 . 2007-02-06 22:01 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\BitTorrent
2009-12-11 23:03 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-12-11 23:03 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-09 08:11 . 2008-08-29 20:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-29 07:45 . 2004-08-10 04:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 04:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 04:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-10 04:00 265728 ——w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-10 04:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 04:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 04:00 79872 —-a-w- c:\windows\system32\raschap.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-12-09 323392]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"ftutil2"="ftutil2.dll" [2004-06-07 106496]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 16239616]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-31 180269]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-02-25 2799760]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
MEMonitor.lnk - c:\program files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-2-22 947544]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-7-31 36903]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-10-25 23:58 282624 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 9:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 9:05 AM 72944]
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared Anti-Malware\a2service.exe [3/14/2009 11:54 PM 425080]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [3/15/2009 2:55 PM 93320]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 9:05 AM 7408]
S2 Kfwaev;Kfwaev;c:\windows\System32\svchost.exe -k netsvcs [8/9/2004 11:00 PM 14336]
S2 Kmuyqewi;Kmuyqewi;c:\windows\System32\svchost.exe -k netsvcs [8/9/2004 11:00 PM 14336]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Kfwaev
Kmuyqewi
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=64&bd;=PAVILION&pf;=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=64&bd;=PAVILION&pf;=desktop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: trymedia.com
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Mp4 Player - c:\program files\Mp4 Player\Mp4Player.exe
HKCU-Run-Uniblue RegistryBooster2 - c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKCU-Run-Internet Security 2010 - c:\program files\InternetSecurity2010\IS2010.exe
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\UninstFl.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-21 23:54
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(776)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(2636)
c:\windows\system32\WININET.dll
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Common Files\Microsoft Shared\OFFICE12\MSOXEV.DLL
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\arservice.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\hp\KBD\KBD.EXE
.
**************************************************************************
.
Completion time: 2009-12-22 00:03:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-22 05:03

Pre-Run: 25,880,719,360 bytes free
Post-Run: 26,876,608,512 bytes free

- - End Of File - - 2C244ED82F25C0E70D994E5EF456F06C

My computer is as fast as it has ever been. I get no more spam pop ups from fake security systems. My background image is as it was. I am immensely grateful. Is there anything else I need to do?
Questions:
Unfortunately, I'm still unsure of your anti-virus situation, and whether or not you have a anti-virus program that is up-to date as well if it has a current subscription., In your last post you did not make mention of a-squared. If you could please comment on that as well as the other questions posed above in your next reply.

Peer to Peer Program
While reviewing your logs I noticed that you currently have Peer to Peer program(s) installed on your computer.

You currently have the following P2P programs installed:
  • BitTorrent
Most of the infections that we see today are through P2P file sharing. By uninstalling the programs that I mentioned above you will be doing yourself a favor. It's impossible to trust the source of what is being downloaded from them and a file may or may not be what it appears to be.

Should you decide to keep these programs installed on your computer PLEASE do not use these programs while we are getting your P.C. cleaned up.

How to Uninstall the P2P Programs:
  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present):
  • BitTorrent
PLEASE NOTE: When your uninstalling the P2P Program(s) some questions are worded in various ways to try and deceive you and keep you from uninstalling their Program.

ComboFix Script
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::
File::
c:\windows\system32\logon.exe.vir

Driver::
Kfwaev
Kmuyqewi

NetSvc::
Kfwaev
Kmuyqewi

DDS::
Trusted Zone: trymedia.com

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Scanning with MalwareBytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

Kaspersky Online Scanner
I'd like for you to run this next online scan to check for remnants or anything that might be hidden.
The below scan can take up to an hour or longer, please be patient.

Note:
It is recommended to disable on board Anti-Virus program and Anti-Spyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident Anti-Virus protection along with whatever Anti-Spyware app you use.



Please do a scan with Kaspersky Online Scanner or from Here.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.
Please make sure you include the following items in your next post:
1. An answer to the question I asked you under the question section.

2. The log that was produced after running ComboFix.
3. The log that was produced after running MalwareBytes' Anti-Malware.
4. The log that was produced after running the Kaspersky Online Scanner.
5. An outstanding issues you may be experiencing with your computer.
It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Here is Combo fix

ComboFix 09-12-25.01 - HP_Administrator 12/25/2009 11:53:44.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.470 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

FILE ::
"c:\windows\system32\logon.exe.vir"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\HP_Administrator\Desktop\Internet Security 2010.lnk
c:\documents and settings\HP_Administrator\Start Menu\Internet Security 2010.lnk
c:\program files\InternetSecurity2010
c:\program files\InternetSecurity2010\IS2010.exe
c:\windows\system32\11478.exe
c:\windows\system32\11942.exe
c:\windows\system32\14604.exe
c:\windows\system32\153.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\17421.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\32391.exe
c:\windows\system32\3902.exe
c:\windows\system32\41.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5436.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
c:\windows\system32\bokiluve.dll
c:\windows\system32\critical_warning.html
c:\windows\system32\fesorega.dll.tmp
c:\windows\system32\kivihude.dll
c:\windows\system32\logon.exe
c:\windows\system32\pagapobo.dll
c:\windows\system32\pajuwojo.dll.tmp
c:\windows\system32\winhelper86.dll
c:\windows\system32\winlogon86.exe
c:\windows\system32\winupdate86.exe
c:\windows\system32\yevazani.dll.tmp
c:\windows\Tasks\yobkergo.job

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_KFWAEV
——-\Legacy_KMUYQEWI
——-\Service_Kfwaev
——-\Service_Kmuyqewi


((((((((((((((((((((((((( Files Created from 2009-11-25 to 2009-12-25 )))))))))))))))))))))))))))))))
.

2009-12-23 03:49 . 2009-12-23 03:49 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2009-12-23 03:49 . 2009-12-03 21:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-23 03:49 . 2009-12-23 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-23 03:49 . 2009-12-03 21:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-23 03:49 . 2009-12-24 17:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-19 20:55 . 2009-12-19 20:55 0 —-a-w- c:\documents and settings\HP_Administrator\settings.dat
2009-12-19 20:49 . 2009-12-19 20:50 ——– d—–w- c:\program files\ERUNT
2009-12-11 23:03 . 2009-12-11 23:03 ——– d—–w- c:\windows\system32\drivers\NSS
2009-12-11 23:03 . 2009-12-11 23:03 ——– d—–w- c:\program files\Norton Security Scan
2009-12-09 09:00 . 2009-12-09 09:00 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-25 17:08 . 2008-10-17 19:51 ——– d—–w- c:\program files\DNA
2009-12-25 17:08 . 2008-10-17 19:51 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\DNA
2009-12-24 23:57 . 2007-02-06 22:01 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\BitTorrent
2009-12-23 19:59 . 2006-07-31 23:52 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-12-19 16:43 . 2009-03-15 19:49 ——– d—–w- c:\program files\McAfee
2009-12-11 23:03 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-12-11 23:03 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-09 08:11 . 2008-08-29 20:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-29 07:45 . 2004-08-10 04:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 04:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 04:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-10 04:00 265728 ——w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-10 04:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 04:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 04:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-09-24 17:18 . 2009-09-24 17:18 39424 –sha-w- c:\windows\system32\begadosi.dll
2009-09-24 17:18 . 2009-09-24 17:18 93184 –sha-w- c:\windows\system32\niyihifi.dll
2009-09-25 05:59 . 2009-09-25 05:59 61440 –sha-w- c:\windows\system32\rutijatu.dll
2009-09-25 05:59 . 2009-09-25 05:59 51712 –sha-w- c:\windows\system32\wahewuvu.dll
2009-09-25 05:59 . 2009-09-25 05:59 39424 –sha-w- c:\windows\system32\yesukeje.dll
2009-09-25 05:59 . 2009-09-25 05:59 51712 –sha-w- c:\windows\system32\yonolafo.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b992e213-b57e-4bf3-825e-851698a93f60}]
2009-09-25 05:59 51712 –sha-w- c:\windows\system32\wahewuvu.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-12-09 323392]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]
"Internet Security 2010"="c:\program files\InternetSecurity2010\IS2010.exe" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"ftutil2"="ftutil2.dll" [2004-06-07 106496]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 16239616]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-31 180269]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-02-25 2799760]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-7-31 36903]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-10-25 23:58 282624 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\a-squared Anti-Malware\\a2guard.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 9:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 9:05 AM 72944]
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared Anti-Malware\a2service.exe [3/14/2009 11:54 PM 425080]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [3/15/2009 2:55 PM 93320]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 9:05 AM 7408]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=64&bd;=PAVILION&pf;=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=64&bd;=PAVILION&pf;=desktop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-migekehuv - c:\windows\system32\bokiluve.dll
HKLM-Run-palozozole - kivihude.dll
SharedTaskScheduler-{c7525c5d-7134-49fd-bb9c-8d21deaf723c} - c:\windows\system32\bokiluve.dll
SSODL-savevijuz-{c7525c5d-7134-49fd-bb9c-8d21deaf723c} - c:\windows\system32\bokiluve.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-25 12:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(776)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3792)
c:\windows\system32\WININET.dll
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Common Files\Microsoft Shared\OFFICE12\MSOXEV.DLL
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\arservice.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\windows\system32\msiexec.exe
c:\hp\KBD\KBD.EXE
.
**************************************************************************
.
Completion time: 2009-12-25 12:30:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-25 17:29
ComboFix2.txt 2009-12-23 03:10
ComboFix3.txt 2009-12-22 05:03

Pre-Run: 26,286,223,360 bytes free
Post-Run: 26,304,675,840 bytes free

- - End Of File - - B9502B5FFEC235263396BB768459F597

Malwarebytes downloads but then says it can't find the shortcut to .exe. I tried to remove the program and download again but it does not completely uninstall it.

Kaspersky was a ten hour scan that decided to shut down after 99%. Should I try again? It found over 13 infected files. I just never got the log.

I get occasional pop ups from browsing. The reboot on my computer is slow. I use Internet explorer and Safari. What browser do you suggest is safest? Should I try my antispyware programs again?
I have not forgotten about your issues with MalwareBytes' Anti-Malware and the Kaspersky Scan. I will address those issues a little later in the post.

Questions:
Unfortunately, I'm still unsure of your anti-virus situation, and whether or not you have a anti-virus program that is up-to date as well if it has a current subscription., In your last post you did not make mention of a-squared. If you could please comment on that as well as the other questions posed above in your next reply.

Do the pop-ups occur on a particular website or is it something that occurs randomly? I will give you my suggestions on what internet browser I suggest in my All-Clean post to you. For the time being hold up on doing anything with your anti-spyware programs. Only exception being if you need to disable them.

ComboFix Script
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Your_computer_Infected_background_False_antispyware_programs_t108974.html&view=findpost&p=619783#entry619783
Collect::
c:\windows\system32\begadosi.dll
c:\windows\system32\niyihifi.dll
c:\windows\system32\rutijatu.dll
c:\windows\system32\wahewuvu.dll
c:\windows\system32\yesukeje.dll
c:\windows\system32\yonolafo.dll

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Internet Security 2010"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b992e213-b57e-4bf3-825e-851698a93f60}]

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

In regards to the MalwareBytes issue try this:
MalwareBytes' Anti-Malware Uninstall
1. Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel.
2. Restart your computer (very important).
3. Download and run this utility. http://www.malwarebytes.org/mbam-clean.exe
4. It will ask to restart your computer (please allow it to).

Scanning with MalwareBytes' Anti-Malware
After the computer restarts please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
1. An answer to the questions posed to you under the Questions section.
2. The log that was produced after running the ComboFix scan.
3. The log that was produced after running the MalwareBytes' Anti-Malware Scan.
4. The log that was produced after running the ESET Online Virus Scanner
5. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Ok first off, McAfee keeps prompting me with this problem where an unwanted program is trying to run. Something like tool-nircd. Itried to copy and paste but that didn't work. That clean up for malwarebytes gave me an SHGetValue with error code 0 message.

Anytime I try to start up IE, it says my session shut down incorrectly, would I like to continue. I tried it just once and it brought up some office suite download page. It's any time I'm browsing I get pop-ups, not any particular site. I was being redirected at a point but that has changed. I have not ran ANY antispyware program and I disable them everytime my computer restarts.

The super anti spyware was my final addition to my defenses. I was told ad-aware does not always catch everything, so I thought a second program would cover the other half.

ComboFix 09-12-26.05 - HP_Administrator 12/27/2009 23:31:52.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.601 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

file zipped: c:\windows\system32\begadosi.dll
file zipped: c:\windows\system32\niyihifi.dll
file zipped: c:\windows\system32\rutijatu.dll
file zipped: c:\windows\system32\wahewuvu.dll
file zipped: c:\windows\system32\yesukeje.dll
file zipped: c:\windows\system32\yonolafo.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\begadosi.dll
c:\windows\system32\dezuwabi.dll
c:\windows\system32\foyugujo.dll
c:\windows\system32\mohugeze.dll
c:\windows\system32\niyihifi.dll
c:\windows\system32\rutijatu.dll
c:\windows\system32\voyutepu.dll
c:\windows\system32\wahewuvu.dll
c:\windows\system32\yesukeje.dll
c:\windows\system32\yonolafo.dll
c:\windows\system32\zupijulo.dll
c:\windows\Tasks\gtyihebo.job
c:\windows\unins000.dat
c:\windows\unins000.exe

.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-28 )))))))))))))))))))))))))))))))
.

2009-12-26 06:09 . 2009-12-28 04:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-23 03:49 . 2009-12-23 03:49 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2009-12-23 03:49 . 2009-12-23 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-19 20:55 . 2009-12-19 20:55 0 —-a-w- c:\documents and settings\HP_Administrator\settings.dat
2009-12-19 20:49 . 2009-12-19 20:50 ——– d—–w- c:\program files\ERUNT
2009-12-11 23:03 . 2009-12-11 23:03 ——– d—–w- c:\windows\system32\drivers\NSS
2009-12-11 23:03 . 2009-12-11 23:03 ——– d—–w- c:\program files\Norton Security Scan
2009-12-09 09:00 . 2009-12-09 09:00 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-28 04:44 . 2008-10-17 19:51 ——– d—–w- c:\program files\DNA
2009-12-28 04:44 . 2008-10-17 19:51 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\DNA
2009-12-27 19:59 . 2006-07-31 23:52 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-12-24 23:57 . 2007-02-06 22:01 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\BitTorrent
2009-12-19 16:43 . 2009-03-15 19:49 ——– d—–w- c:\program files\McAfee
2009-12-11 23:03 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-12-11 23:03 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-09 08:11 . 2008-08-29 20:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-29 07:45 . 2004-08-10 04:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 04:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 04:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-10 04:00 265728 ——w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-10 04:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 04:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 04:00 79872 —-a-w- c:\windows\system32\raschap.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-12-09 323392]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"ftutil2"="ftutil2.dll" [2004-06-07 106496]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 16239616]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-31 180269]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-02-25 2799760]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"migekehuv"="c:\windows\system32\mohugeze.dll" [BU]
"palozozole"="kivihude.dll" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-7-31 36903]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-10-25 23:58 282624 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\a-squared Anti-Malware\\a2guard.exe"=
"c:\\hp\\KBD\\kbd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 9:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 9:05 AM 72944]
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared Anti-Malware\a2service.exe [3/14/2009 11:54 PM 425080]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [3/15/2009 2:55 PM 93320]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 9:05 AM 7408]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

SharedTaskScheduler-{50d5fa88-bc08-4102-8b9c-bc709bc85704} - c:\windows\system32\mohugeze.dll
SSODL-guleriseb-{50d5fa88-bc08-4102-8b9c-bc709bc85704} - c:\windows\system32\mohugeze.dll
AddRemove-MyITLab ActiveX Installer_is1 - c:\windows\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-27 23:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(768)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(1288)
c:\windows\system32\WININET.dll
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Common Files\Microsoft Shared\OFFICE12\MSOXEV.DLL
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\arservice.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\dllhost.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\hp\KBD\KBD.EXE
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-12-28 00:03:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-28 05:03
ComboFix2.txt 2009-12-25 17:30
ComboFix3.txt 2009-12-23 03:10
ComboFix4.txt 2009-12-22 05:03

Pre-Run: 26,062,897,152 bytes free
Post-Run: 26,049,167,360 bytes free

- - End Of File - - 109165ED7D5633BF4D1A51D29C214693

Since Malwarebytes is not working I did not do Eset scan because I am trying to do things in the specific order you have laid out. I can do it still if you want. I await your advice. My computer is running well enough right now. I have no slow down and I only notice the pop ups. I can tell there is something still lurking here. Thanks again for your help.
The Tool-NirCD alert that you are receiving from McAfee is related to a false positive related to ComboFix. We will come back to the MalwareBytes Anti-Malware error later.

I'd like to come back to your Internet Explorer issue. Lets see if this issue clears up on it's own after we get you cleaned up. If it doesn't then we can cross that bridge later. If for some reason I forget about this issue please remind me.

No security program will catch everything.

If I'm understanding everything correctly your subscription to McAfee is currently outdated. If so, are you using a-squared Anti-Malware 4.0 as an Anti-Virus and Anti-Spyware program?

If McAfee is in fact outdated then I suggest you uninstall it. There isn't a point in having an outdated security program still installed on your computer when the only thing it is doing is taking up space and resources.

I'm going to provide you with instructions for removing McAfee and Norton. As these programs seem to be outdated, it's suggested that you use the removal tools to remove these two programs from your computer.

If your subscription to McAfee is outdated and you don't plan on updating your subscription, then I suggest you uninstall it:

Remove McAfee Tool
Please download the McAfee removal tool from HERE
  • Save it to your desktop
  • Make sure all McAfee application windows are closed.
  • Double-click MCPR.exe and the removal tool will start automatically.
  • Note: Windows Vista users must right-click and select Run as Administrator.
    Once the removal tool is finished, you will be prompted to restart your computer. If you choose to restart later, your McAfee product will not be fully removed until you do.
  • Wait for the computer to restart.
Remove Norton Tool

ONLY if you don't have an active subscription, use below link to uninstall Norton.

Please click HERE and follow the instructions to download and run the Norton Removal Tool for your own version.

It is strongly recommended that you run only one anti-virus program at a time. Having more than one anti-virus program active in memory uses additional resources and can result in program conflicts and false virus alerts.

If a-squared anti-malware is not what your using for an Anti-Virus program, then I can provide you with some great free alternatives.

1) Antivir PersonalEdition Classic - Free anti-virus software for Windows. Detects and removes more than 50,000 viruses. Free support.
2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.If a-squared Anti-Malware is not your If Anti-Virus

ComboFix Script
**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download.

Download ComboFix from one of the following locations:
Link 1
Link 2
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
c:\windows\system32\kivihude.dll
c:\windows\system32\mohugeze.dll
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"migekehuv"=-
"palozozole"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Grabbing ComboFix Quarantined Files
Click Start > Run then copy/paste the following single-line command into the Run box and click OK:

C:\Qoobox\ComboFix-quarantined-files.txt

A text file should open. Post the contents of that file in your next reply.

Please make sure you include the following items in your next post:
1. An answer to the questions that I've asked in this post.
2. The log that was produced after running the ComboFix scan. (ComboFix.txt)
3. The log that was produced after running the run command. (ComboFix-quarantined-files.txt)
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
I have a preference for ad-aware. I feel it is a superior product. I appreciate the free programs you offered and will look into using them. Here are both logs you asked for.

ComboFix 09-12-29.03 - HP_Administrator 12/29/2009 15:38:45.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.603 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

FILE ::
"c:\windows\system32\kivihude.dll"
"c:\windows\system32\mohugeze.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Administrator\Local Settings\temp\IadHide5.dll

.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.

2009-12-26 06:09 . 2009-12-28 04:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-23 03:49 . 2009-12-23 03:49 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2009-12-23 03:49 . 2009-12-23 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-19 20:55 . 2009-12-19 20:55 0 —-a-w- c:\documents and settings\HP_Administrator\settings.dat
2009-12-19 20:49 . 2009-12-19 20:50 ——– d—–w- c:\program files\ERUNT
2009-12-11 23:03 . 2009-12-29 20:34 ——– d—–w- c:\program files\Norton Security Scan
2009-12-09 09:00 . 2009-12-09 09:00 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 20:48 . 2008-10-17 19:51 ——– d—–w- c:\program files\DNA
2009-12-29 20:48 . 2008-10-17 19:51 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\DNA
2009-12-29 20:34 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-12-29 20:34 . 2006-07-31 23:52 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-12-24 23:57 . 2007-02-06 22:01 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\BitTorrent
2009-12-11 23:03 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-09 08:11 . 2008-08-29 20:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-29 07:45 . 2004-08-10 04:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 04:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 04:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-10 04:00 265728 ——w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-10 04:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 04:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 04:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-09-27 05:12 . 2009-09-27 05:12 91648 –sha-w- c:\windows\system32\bofavoju.dll
2009-09-26 17:11 . 2009-09-26 17:11 61440 –sha-w- c:\windows\system32\jadebaji.dll
2009-09-26 05:11 . 2009-09-26 05:11 92160 –sha-w- c:\windows\system32\vizisida.dll
2009-09-26 17:11 . 2009-09-26 17:11 92672 –sha-w- c:\windows\system32\yekikewa.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-12-09 323392]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"ftutil2"="ftutil2.dll" [2004-06-07 106496]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 16239616]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-31 180269]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-02-25 2799760]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-7-31 36903]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-10-25 23:58 282624 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\a-squared Anti-Malware\\a2guard.exe"=
"c:\\hp\\KBD\\kbd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 9:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 9:05 AM 72944]
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared Anti-Malware\a2service.exe [3/14/2009 11:54 PM 425080]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 9:05 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-12-29 c:\windows\Tasks\User_Feed_Synchronization-{84B2B653-5DBF-4B0E-A1A8-9B78EA3FD5EE}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-29 15:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(768)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(2412)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Common Files\Microsoft Shared\OFFICE12\MSOXEV.DLL
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\arservice.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\hp\KBD\KBD.EXE
.
**************************************************************************
.
Completion time: 2009-12-29 15:59:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-29 20:59
ComboFix2.txt 2009-12-28 05:03
ComboFix3.txt 2009-12-25 17:30
ComboFix4.txt 2009-12-23 03:10
ComboFix5.txt 2009-12-29 20:37

Pre-Run: 26,251,939,840 bytes free
Post-Run: 26,319,462,400 bytes free

- - End Of File - - AE9445C2AAEA0A3E4AADFB7EC9EF8EC0


2009-12-29 20:48:45 . 2006-07-31 23:35:09 24,613 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\LOCALS~1\temp\IadHide5.dll.vir
2009-12-29 20:38:43 . 2009-12-29 20:38:43 0 —-a-w- C:\Qoobox\Quarantine\catchme.txt
2009-12-28 05:02:02 . 2009-12-28 05:02:02 1,424 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-MyITLab ActiveX Installer_is1.reg.dat
2009-12-28 05:01:46 . 2009-12-28 05:01:46 373 —-a-w- C:\Qoobox\Quarantine\Registry_backups\SSODL-guleriseb-{50d5fa88-bc08-4102-8b9c-bc709bc85704}.reg.dat
2009-12-28 05:01:44 . 2009-12-28 05:01:44 374 —-a-w- C:\Qoobox\Quarantine\Registry_backups\SharedTaskScheduler-{50d5fa88-bc08-4102-8b9c-bc709bc85704}.reg.dat
2009-12-28 04:31:49 . 2009-12-28 04:31:49 298,812 —-a-w- C:\Qoobox\Quarantine\[4]-Submit_2009-12-27_23.31.42.zip
2009-12-26 17:11:48 . 2009-12-28 04:00:00 316 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\gtyihebo.job.vir
2009-12-25 17:25:59 . 2009-12-25 17:25:59 373 —-a-w- C:\Qoobox\Quarantine\Registry_backups\SSODL-savevijuz-{c7525c5d-7134-49fd-bb9c-8d21deaf723c}.reg.dat
2009-12-25 17:25:57 . 2009-12-25 17:25:57 374 —-a-w- C:\Qoobox\Quarantine\Registry_backups\SharedTaskScheduler-{c7525c5d-7134-49fd-bb9c-8d21deaf723c}.reg.dat
2009-12-25 17:25:51 . 2009-12-25 17:25:51 128 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-palozozole.reg.dat
2009-12-25 17:25:51 . 2009-12-25 17:25:51 150 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-migekehuv.reg.dat
2009-12-25 17:04:46 . 2009-12-25 17:04:46 25,530 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_logon_.exe.zip
2009-12-25 17:04:03 . 2009-12-25 17:04:03 3,164 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_Kmuyqewi.reg.dat
2009-12-25 17:04:02 . 2009-12-25 17:04:02 3,520 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_Kfwaev.reg.dat
2009-12-25 17:04:02 . 2009-12-25 17:04:02 1,038 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_KMUYQEWI.reg.dat
2009-12-25 17:04:02 . 2009-12-25 17:04:02 1,014 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_KFWAEV.reg.dat
2009-12-25 14:55:28 . 2009-12-25 14:55:28 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\17421.exe.vir
2009-12-25 13:55:22 . 2009-12-25 13:55:22 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\153.exe.vir
2009-12-25 13:35:21 . 2009-12-25 13:35:21 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\3902.exe.vir
2009-12-25 13:15:21 . 2009-12-25 13:15:21 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\14604.exe.vir
2009-12-25 12:55:20 . 2009-12-25 12:55:20 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\32391.exe.vir
2009-12-25 12:35:20 . 2009-12-25 12:35:20 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\5436.exe.vir
2009-12-25 12:15:19 . 2009-12-25 12:15:19 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\4827.exe.vir
2009-12-25 11:55:19 . 2009-12-25 11:55:19 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\11942.exe.vir
2009-12-25 11:35:17 . 2009-12-25 11:35:18 110,592 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\2995.exe.vir
2009-12-25 11:15:16 . 2009-12-25 11:15:16 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\491.exe.vir
2009-12-25 10:55:16 . 2009-12-25 10:55:16 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\9961.exe.vir
2009-12-25 10:35:15 . 2009-12-25 10:35:15 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\16827.exe.vir
2009-12-25 10:15:15 . 2009-12-25 10:15:15 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\23281.exe.vir
2009-12-25 09:55:14 . 2009-12-25 09:55:14 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\28145.exe.vir
2009-12-25 09:35:14 . 2009-12-25 09:35:14 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\5705.exe.vir
2009-12-25 09:15:13 . 2009-12-25 09:15:13 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\24464.exe.vir
2009-12-25 08:55:12 . 2009-12-25 08:55:12 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\26962.exe.vir
2009-12-25 08:35:12 . 2009-12-25 08:35:12 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\29358.exe.vir
2009-12-25 08:15:12 . 2009-12-25 08:15:12 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\11478.exe.vir
2009-12-25 07:55:11 . 2009-12-25 16:43:02 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\15724.exe.vir
2009-12-25 07:35:10 . 2009-12-25 16:22:57 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\19169.exe.vir
2009-12-25 07:15:10 . 2009-12-25 16:02:56 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\26500.exe.vir
2009-12-25 06:55:09 . 2009-12-25 15:42:55 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\6334.exe.vir
2009-12-25 06:35:09 . 2009-12-25 15:22:55 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\18467.exe.vir
2009-12-25 06:16:32 . 2009-12-25 06:16:32 767 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\Start Menu\Internet Security 2010.lnk.vir
2009-12-25 06:16:32 . 2009-12-25 06:16:32 767 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\Desktop\Internet Security 2010.lnk.vir
2009-12-25 06:15:15 . 2009-12-25 06:15:07 915,968 —-a-w- C:\Qoobox\Quarantine\C\Program Files\InternetSecurity2010\IS2010.exe.vir
2009-12-25 05:59:09 . 2009-12-25 16:00:00 296 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\yobkergo.job.vir
2009-12-25 04:48:38 . 2009-12-25 15:02:54 0 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\41.exe.vir
2009-12-25 04:48:24 . 2009-12-25 06:14:58 16,896 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\winhelper86.dll.vir
2009-12-25 04:48:13 . 2009-12-25 14:59:43 2,854 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\critical_warning.html.vir
2009-12-25 04:48:11 . 2009-12-25 04:48:08 22,016 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\winlogon86.exe.vir
2009-12-25 04:48:11 . 2009-12-25 04:48:08 22,016 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\winupdate86.exe.vir
2009-12-24 17:13:28 . 2009-12-24 17:13:25 34,308 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\logon.exe.vir
2009-12-22 05:02:54 . 2009-12-22 05:02:54 1,312 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-ShockwaveFlash.reg.dat
2009-12-22 05:00:53 . 2009-12-22 05:00:53 159 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-Internet Security 2010.reg.dat
2009-12-22 05:00:53 . 2009-12-22 05:00:53 179 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-Uniblue RegistryBooster2.reg.dat
2009-12-22 05:00:53 . 2009-12-22 05:00:53 148 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-Mp4 Player.reg.dat
2009-12-22 04:49:10 . 2004-04-30 05:01:14 53 —-a-w- C:\Qoobox\Quarantine\D\Autorun.inf.vir
2009-12-22 04:42:33 . 2009-12-22 04:42:33 2,404 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_NPF.reg.dat
2009-12-22 04:42:33 . 2009-12-22 04:42:33 1,312 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_NPF.reg.dat
2009-12-22 04:42:15 . 2009-12-29 20:45:36 7,565 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2009-12-22 04:09:30 . 2009-12-29 20:37:20 818 —-a-w- C:\Qoobox\Quarantine\catchme.log
2009-12-20 06:46:33 . 2009-12-20 06:46:33 81,920 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll.vir
2009-12-20 04:32:31 . 2009-12-20 04:32:32 110,592 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\292.exe.vir
2009-12-19 17:42:07 . 2009-12-19 17:42:07 24,064 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll.vir
2009-12-19 17:42:07 . 2009-12-19 17:42:07 651 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.lnk.vir
2009-12-19 17:42:07 . 2009-12-19 17:42:07 24,064 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\protect.dll.vir
2009-09-27 17:12:03 . 2009-09-27 17:12:03 92,160 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\mohugeze.dll.vir
2009-09-27 17:12:03 . 2009-09-27 17:12:03 38,912 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\foyugujo.dll.vir
2009-09-27 05:12:01 . 2009-09-27 05:12:01 38,912 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\zupijulo.dll.vir
2009-09-26 17:11:47 . 2009-09-26 17:11:47 38,400 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\voyutepu.dll.vir
2009-09-26 05:11:33 . 2009-09-26 05:11:33 38,400 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\dezuwabi.dll.vir
2009-09-25 05:59:19 . 2009-09-25 05:59:19 51,712 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\kivihude.dll.vir
2009-09-25 05:59:19 . 2009-09-25 05:59:19 51,712 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\pagapobo.dll.vir
2009-09-25 05:59:19 . 2009-09-25 05:59:19 51,712 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\wahewuvu.dll.vir
2009-09-25 05:59:06 . 2009-09-25 05:59:06 93,696 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\bokiluve.dll.vir
2009-09-25 05:59:06 . 2009-09-25 05:59:06 61,440 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\rutijatu.dll.vir
2009-09-25 05:59:06 . 2009-09-25 05:59:06 39,424 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\yesukeje.dll.vir
2009-09-25 05:59:06 . 2009-09-25 05:59:06 51,712 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\yonolafo.dll.vir
2009-09-24 17:18:29 . 2009-09-24 17:18:29 39,424 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\begadosi.dll.vir
2009-09-24 17:18:29 . 2009-09-24 17:18:29 93,184 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\niyihifi.dll.vir
2009-09-24 17:13:11 . 2009-09-24 17:13:11 52,224 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\fesorega.dll.tmp.vir
2009-09-24 17:13:11 . 2009-09-24 17:13:11 52,224 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\pajuwojo.dll.tmp.vir
2009-09-24 17:13:11 . 2009-09-24 17:13:11 52,224 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\yevazani.dll.tmp.vir
2009-04-06 15:43:12 . 2009-04-06 15:43:12 24,064 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\protect.dll.vir
2009-04-05 10:51:40 . 2009-04-05 10:51:40 24,064 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\LocalService\protect.dll.vir
2009-04-05 00:55:06 . 2009-04-05 00:55:12 24,064 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\ChkDisk.dll.vir
2009-04-05 00:55:06 . 2009-05-01 05:00:02 651 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\ChkDisk.lnk.vir
2009-04-05 00:55:03 . 2009-04-05 00:55:03 24,064 -c–a-w- C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\protect.dll.vir
2009-04-05 00:55:02 . 2009-12-22 04:25:54 24,064 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\autochk.dll.vir
2008-08-29 21:27:14 . 2008-08-29 21:27:10 683,801 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\unins000.exe.vir
2008-08-29 21:27:14 . 2008-08-29 21:27:15 1,074 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\unins000.dat.vir
2008-02-23 03:03:39 . 2008-02-23 03:03:39 883 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\MEMonitor.lnk.vir
2007-02-04 08:04:11 . 2006-03-21 03:23:12 23,040 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\kb913800.exe.vir
2005-08-02 21:24:02 . 2005-08-02 21:24:02 14,336 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\pthreadVC.dll.vir
2005-08-02 21:18:46 . 2005-08-02 21:18:46 93,696 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\wpcap.dll.vir
2005-08-02 21:10:14 . 2005-08-02 21:10:14 32,512 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\npf.sys.vir
2005-08-02 21:08:10 . 2005-08-02 21:08:10 29,696 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\Packet.dll.vir
2005-08-02 21:08:08 . 2005-08-02 21:08:08 24,064 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\WanPacket.dll.vir
2004-08-18 19:47:58 . 2004-08-18 19:47:58 241 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\Downloaded Program Files\popcaploader.inf.vir
2004-08-11 18:28:04 . 2004-08-11 18:28:04 393,216 -c–a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\BSTIEPrintCtl1.dll.vir
2004-08-10 04:00:00 . 2008-04-13 18:40:30 96,512 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir
2004-08-10 04:00:00 . 2008-04-13 18:40:30 96,512 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir_


I'm currently using safari as my browser. The computer seems to run fine but start up takes a little longer than usual. I try to minimize my start up programs. There is actually nothing I need to have appear on start up. The restart before this one displayed a rundll error for the first two programs you had me insert for the CFScript, kivihud and mohugeze. I don't understand why that happened but it did not occur again. I have a question. Is it safe to browse and insert personal information, such as credit cards, into sites that are suppose to be secure? I purchase a lot from e-bay and online stores. If I missed any questions, please reask. I do not leave them unanswered on purpose. Thank you again for all the time you have spent with me.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI