This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Your computer is Infected background. False antispyware pro

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I can recommend a program for you to run on your computer to help remove programs from running at start up. I will provide you with this program in my All Clean Speech.

The rundll error that you received after running the CF Script was perfectly normal. It was just letting you know that it couldn't locate those two files that were suppose to be executed at start up.

If you are on a secure website you will notice that in your URL bar it will say https rather than http. The https means that it's a secure connection. I'm not too familiar with Safari, but I know in Firefox there is a padlock in the status bar that displays when you are on a secure website. Before entering any sensitive data onto a website you should make sure that the site in the URL is in fact the website you are on, and making sure that the website is secure.


ComboFix Script
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Your_computer_Infected_background_False_antispyware_programs_t108974.html&view=findpost&p=620560#entry620560
Collect::
c:\windows\system32\bofavoju.dll
c:\windows\system32\jadebaji.dll
c:\windows\system32\vizisida.dll
c:\windows\system32\yekikewa.dll

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.
**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT



Uploading ComboFix Quarantined Files
Please visit this site & follow the instructions for uploading the >>Zip<< file.
Copy/paste the contents of the Code Box below into the Link to topic where this file was requested: box:
http://forums.whatthetech.com/Your_computer_Infected_background_False_antispyware_programs_t108974.html&view=findpost&p=620188#entry620188
Click Browse & navigate to C:\Qoobox\Quarantine\[4]-Submit_2009-12-27_23.31.42.zip. Click Open then Send File.



NEXT



ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]

Please make sure you include the following items in your next post:
1. A confirmation that you upload that file successfully to BleepingComputer.
2. The log that was produced after running ComboFix.
3. The log that was produced after running ESET Online Virus Scanner.
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Hello nashisthepower! It's been several days since I last posted instructions for you to complete. Do you still require assistance in getting your computer cleaned up? Thanks, SweetTech.
I apologize. I am still in need of your assistance. Work has delayed me. I believe this is what you asked for.

ComboFix 09-12-29.06 - HP_Administrator 12/30/2009 20:34:21.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.601 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

file zipped: c:\windows\system32\bofavoju.dll
file zipped: c:\windows\system32\jadebaji.dll
file zipped: c:\windows\system32\vizisida.dll
file zipped: c:\windows\system32\yekikewa.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\windows\system32\bofavoju.dll
c:\windows\system32\jadebaji.dll
c:\windows\system32\vizisida.dll
c:\windows\system32\yekikewa.dll

.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-31 )))))))))))))))))))))))))))))))
.

2009-12-26 06:09 . 2009-12-28 04:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-23 03:49 . 2009-12-23 03:49 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2009-12-23 03:49 . 2009-12-23 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-19 20:55 . 2009-12-19 20:55 0 —-a-w- c:\documents and settings\HP_Administrator\settings.dat
2009-12-19 20:49 . 2009-12-19 20:50 ——– d—–w- c:\program files\ERUNT
2009-12-19 20:33 . 2009-12-29 20:52 52224 —-a-w- c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-11 23:03 . 2009-12-29 20:34 ——– d—–w- c:\program files\Norton Security Scan
2009-12-09 09:00 . 2009-12-09 09:00 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 01:41 . 2008-10-17 19:51 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\DNA
2009-12-29 20:52 . 2009-06-11 22:49 117760 —-a-w- c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-29 20:48 . 2008-10-17 19:51 ——– d—–w- c:\program files\DNA
2009-12-29 20:34 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-12-29 20:34 . 2006-07-31 23:52 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-12-24 23:57 . 2007-02-06 22:01 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\BitTorrent
2009-12-11 23:03 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-09 08:11 . 2008-08-29 20:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-29 07:45 . 2004-08-10 04:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 04:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 04:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-10 04:00 265728 ——w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-10 04:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 04:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 04:00 79872 —-a-w- c:\windows\system32\raschap.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-12-09 323392]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"ftutil2"="ftutil2.dll" [2004-06-07 106496]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 16239616]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-31 180269]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-02-25 2799760]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-7-31 36903]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-10-25 23:58 282624 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\a-squared Anti-Malware\\a2guard.exe"=
"c:\\hp\\KBD\\kbd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 9:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 9:05 AM 72944]
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared Anti-Malware\a2service.exe [3/14/2009 11:54 PM 425080]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 9:05 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-12-31 c:\windows\Tasks\User_Feed_Synchronization-{84B2B653-5DBF-4B0E-A1A8-9B78EA3FD5EE}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-30 20:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(768)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2009-12-30 20:43:45
ComboFix-quarantined-files.txt 2009-12-31 01:43
ComboFix2.txt 2009-12-29 20:59
ComboFix3.txt 2009-12-28 05:03
ComboFix4.txt 2009-12-25 17:30
ComboFix5.txt 2009-12-31 01:33

Pre-Run: 26,259,488,768 bytes free
Post-Run: 26,219,847,680 bytes free

- - End Of File - - E4944793F291A3FCB4F124C183A15208
Upload was successful

C:\hp\bin\wbug\HPPavillion_Spring06.exe a variant of Win32/Toolbar.MyWebSearch application
C:\Qoobox\Quarantine\[4]-Submit_2009-12-27_23.31.42.zip multiple threats
C:\Qoobox\Quarantine\[4]-Submit_2009-12-30_20.34.14.zip multiple threats
C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\protect.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\ChkDisk.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\Documents and Settings\LocalService\protect.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\protect.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\Program Files\InternetSecurity2010\IS2010.exe.vir Win32/Adware.AdvancedVirusRemover.B application
C:\Qoobox\Quarantine\C\WINDOWS\system32\292.exe.vir a variant of Win32/Kryptik.AZD trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\2995.exe.vir a variant of Win32/Kryptik.AZD trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\autochk.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\critical_warning.html.vir Win32/TrojanDownloader.FakeAlert.AED virus
C:\Qoobox\Quarantine\C\WINDOWS\system32\dezuwabi.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\foyugujo.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\kivihude.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\mohugeze.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\pagapobo.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\voyutepu.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\winlogon86.exe.vir Win32/TrojanDownloader.FakeAlert.AED trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\winupdate86.exe.vir Win32/TrojanDownloader.FakeAlert.AED trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\zupijulo.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\_logon_.exe.zip a variant of Win32/Kryptik.BNH trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\protect.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Win32/Olmarik.SJ virus
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1004\A0069360.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1004\A0070356.exe a variant of Win32/Kryptik.BNH trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1005\A0073375.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1005\A0074377.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0074383.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075551.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075686.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075687.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075689.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075690.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075691.exe a variant of Win32/Kryptik.BLS trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075706.exe a variant of Win32/Kryptik.AZD trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075717.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075719.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075720.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075726.dll a variant of Win32/Kryptik.AQY trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075727.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1009\A0077126.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1009\A0077133.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1009\A0077135.exe Win32/Adware.AdvancedVirusRemover.B application
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078128.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078320.exe Win32/Adware.AdvancedVirusRemover.B application
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078332.exe a variant of Win32/Kryptik.AZD trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078341.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078342.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078344.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1011\A0078574.dll a variant of Win32/Kryptik.BOQ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1013\A0078704.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1013\A0078705.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1013\A0078706.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1013\A0078709.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1013\A0078713.dll a variant of Win32/Kryptik.BOP trojan
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Desktop.htt Win32/TrojanDownloader.FakeAlert.AED virus
D:\I386\APPS\APP23880\src\CompaqPresario_Spring06.exe a variant of Win32/Toolbar.MyWebSearch application
D:\I386\APPS\APP23880\src\HPPavillion_Spring06.exe a variant of Win32/Toolbar.MyWebSearch application

Computer is running well but I couldn't tell you at this point if there is a threat. I've submitted the file you asked me to send. I appreciate your continued assistance, time, and patience.
Questions:
What are the issues you are experiencing with MalwareBytes' Anti-Malware. Is it still installed on your computer? If it is installed have you attempted to run it? What happens when you attempt to run the MalwareBytes' Anti-Malware removal tool?


NEXT


Please do the following:

Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c del /f/a/q "C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Desktop.htt"


Please respond to the questions posed to you above as well as any outstanding issues you are experiencing with your computer.
Got Mal to work. Here is the log. If you are going to say everything is ok, please give me an idea of what browser I should use. I hear Firefox is great and Chrome is suppose to be too. Those two free programs you suggested, should I use both or just one? Which do you suggest if just one? Thank you again. Malwarebytes' Anti-Malware 1.43 Database version: 3492 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/4/2010 3:03:52 PM mbam-log-2010-01-04 (15-03-52).txt Scan type: Quick Scan Objects scanned: 123679 Time elapsed: 5 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
A while back you mentioned an issue you were having with Internet Explorer. Where your sessions weren't being shut down correctly. I said that I would come back to these issue later on. Are you still experiencing these issues with Internet Explorer?

Those two free programs you suggested, should I use both or just one? Which do you suggest if just one?

You should use just one. I'd recommend either one. They are both great programs for detecting and removing viruses.

please give me an idea of what browser I should use. I hear Firefox is great and Chrome is suppose to be too.

Firefox and Chrome are both excellent Internet Browsers. I use Firefox daily and on occassion use Chrome.


I can recommend a program for you to run on your computer to help remove programs from running at start up. I will provide you with this program in my All Clean Speech.

You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve performance.


NEXT


Java Outdated
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 17. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the drop-down menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader
Alternative Option: after uninstalling Adobe Reader, you could try installing Foxit Reader from >here< Foxit Reader has fewer add-ons therefore loads more quickly.


NEXT


Re-Scanning with DDS
Please re-run DDS by sUBs.
Make sure to pay attention to the directions below:
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by doing the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

NEXT


Please include the logs that were produced after running DDS. (DDS.txt & Attach.txt)
Hello nashisthepower! It's been several days since I last posted instructions for you to complete. Do you still require assistance in getting your computer cleaned up? Thanks, SweetTech.
The DDS report that you asked for, I can't figure out how to get it. I'll do it immediately after I comeback here. THanks again. And the computer has no visible issues at this time.
Instructions for DDS are given below.

Scanning with DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.
[external image: Posted Image]
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by doing the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Post the logs that are produced after running DDS.
Is this correct? DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 14:46:41.53 on Sun 01/10/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.235 [GMT -5:00] AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255} FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\DNA\btdna.exe C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\a-squared Anti-Malware\a2service.exe C:\WINDOWS\arservice.exe C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\WINDOWS\system32\nvsvc32.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe svchost.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Java\jre6\bin\jqs.exe c:\windows\system\hpsysdrv.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\DISC\DISCover.exe C:\Program Files\DISC\DiscUpdMgr.exe C:\Program Files\DISC\DiscStreamHub.exe C:\WINDOWS\explorer.exe C:\Program Files\Safari\Safari.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\HP_Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode mRun: [RTHDCPL] RTHDCPL.EXE mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE mRun: [DMAScheduler] "c:\program files\hp digitalmedia archive\DMAScheduler.exe" mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll" mRun: [a-squared] "c:\program files\a-squared anti-malware\a2guard.exe" /d=60 mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\hp_adm~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000 IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {25365FF3-2746-4230-9DA7-163CCA318309} - hxxp://inst.c-wss.com/n028p/EN/install/gtdownlr.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944] R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared anti-malware\a2service.exe [2009-3-14 425080] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408] =============== Created Last 30 ================ 2010-01-06 05:57:49 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-01-05 04:19:17 411368 —-a-w- c:\windows\system32\deploytk.dll 2010-01-04 19:15:38 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-04 19:15:36 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-01-04 02:44:16 21504 —-a-w- c:\windows\system32\hidserv.dll 2010-01-04 02:44:16 21504 —-a-w- c:\windows\system32\dllcache\hidserv.dll 2010-01-04 02:44:02 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys 2010-01-04 02:44:02 60032 —-a-w- c:\windows\system32\dllcache\usbaudio.sys 2009-12-31 20:38:19 0 d—–w- c:\program files\ESET 2009-12-27 05:13:24 18944 —-a-w- c:\documents and settings\hp_administrator\n 2009-12-26 06:09:00 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-12-23 03:49:31 0 d—–w- c:\docume~1\hp_adm~1\applic~1\Malwarebytes 2009-12-23 03:49:24 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-12-22 04:21:36 77312 —-a-w- c:\windows\MBR.exe 2009-12-22 04:21:36 261632 —-a-w- c:\windows\PEV.exe 2009-12-19 20:55:32 0 —-a-w- c:\documents and settings\hp_administrator\settings.dat 2009-12-18 20:54:41 0 —-a-w- c:\windows\Textart.INI 2009-12-11 23:03:13 0 d—–w- c:\program files\Norton Security Scan ==================== Find3M ==================== 2010-01-05 23:32:19 9396 —-a-w- c:\docume~1\hp_adm~1\applic~1\wklnhst.dat 2009-10-28 14:40:47 173056 ——w- c:\windows\system32\dllcache\ie4uinit.exe 2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll 2009-10-21 05:38:36 75776 ——w- c:\windows\system32\dllcache\strmfilt.dll 2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll 2009-10-21 05:38:36 25088 ——w- c:\windows\system32\dllcache\httpapi.dll 2009-10-20 16:20:16 265728 ——w- c:\windows\system32\dllcache\http.sys 2009-10-13 10:30:16 270336 —-a-w- c:\windows\system32\oakley.dll 2009-10-13 10:30:16 270336 ——w- c:\windows\system32\dllcache\oakley.dll ============= FINISH: 14:48:02.09 ===============

Attachments:

Time for some housekeeping
The following will implement some cleanup procedures as well as reset System Restore points:
[external image: Posted Image]
Click Start > Run and copy/paste the following bolded text into the Run box and click OK: ComboFix /Uninstall


Next:


Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.
Next:


Please remove any additional logs or tools that are left over on your desktop.

All Clean Speech

===> Make sure you've re-enabled any Security Programs that we may have disabled during the malware removal process. <===

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at: http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE
  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from Here
    • If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
      • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI