This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] IE Redirect, Win32.nestsky popup, Internet Security 2010 Po

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
First I want to thank you guys in advance for providing this site. It's awesome!! I believe I was infected from a crack/keygen (I allowed it to run even though warned by AV). Norton AV 2009 unable to clean after infected. Before familiarizing myself with the rules of posting, my computer had/has the symtoms described in the title and description. I have followed the steps in the 'Are you infected' section. However SysRestorePoint would not launch but I was able use the Windows Wizard. Further, GMER caused a Windows error but I saved the log at that time - may be incomplete. Ran GMER a second time (without reboot) and got the windows shutdown blue screen. After finishing the steps outlined in the 'Are you infected' section, pop-ups seem to be gone, task manager is enabled, ieaskie32.dll add on is no longer visable. I have not tested the safe mode yet. Your advise is greatly appreciated :notworthy:

Here are the logs:

Malwarebytes' Anti-Malware 1.42
Database version: 3439
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/27/2009 11:40:47 AM
mbam-log-2009-12-27 (11-40-29).txt

Scan type: Quick Scan
Objects scanned: 135706
Time elapsed: 4 minute(s), 23 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 4
Registry Keys Infected: 6
Registry Values Infected: 2
Registry Data Items Infected: 12
Folders Infected: 2
Files Infected: 31

Memory Processes Infected:
C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.Installer) -> No action taken.
C:\WINDOWS\system32\winupdate86.exe (Trojan.FakeAlert) -> No action taken.

Memory Modules Infected:
C:\WINDOWS\system32\icwdial32.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\2C9.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c0046212.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c00C9112.dat (Trojan.Agent) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.BHO.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.BHO.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cb1f7a0720 (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.Tracur) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0f3f5df4-b7a9-48c4-9b4e-7a691ab4e84f} (Trojan.Tracur) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0046212 (Trojan.Agent) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security 2010 (Rogue.Installer) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate86.exe (Trojan.Downloader) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: c:\windows\system32\icwdial32.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: system32\icwdial32.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\winlogon86.exe) Good: (Userinit.exe) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
C:\WINDOWS\system32\SysWoW32 (Worm.Archive) -> No action taken.
C:\Program Files\InternetSecurity2010 (Rogue.InternetSecurity2010) -> No action taken.

Files Infected:
C:\WINDOWS\system32\ieaksie32.dll (Trojan.BHO.H) -> No action taken.
C:\WINDOWS\system32\icwdial32.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\2C9.tmp (Trojan.Agent) -> No action taken.
C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.Installer) -> No action taken.
C:\WINDOWS\system32\1.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\winhelper86.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mi1458286074v4.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mi1458286074v6.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mi1458286074v7.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mu1458286074v5 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\mu1458286074v5.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v0 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v0.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v1 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v1.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v2 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v2.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v3 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\wu1458286074v3.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v0 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v1 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v2 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SysWoW32\_u1458286074v3 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\__c0046212.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c00B843E.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\__c00C9112.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\GnuHashes.ini (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\winupdate86.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\41.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\Winlogon86.exe (Trojan.FakeAlert) -> No action taken.


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-27 11:50:33
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\DUANEP~1\LOCALS~1\Temp\pwldapog.sys


—- System - GMER 1.0.15 —-

SSDT 8900A6A0 ZwAlertResumeThread
SSDT 89027EF0 ZwAlertThread
SSDT 890326D8 ZwAllocateVirtualMemory
SSDT 8900E0C0 ZwAssignProcessToJobObject
SSDT 89113A08 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA8A01130]
SSDT 890274E0 ZwCreateMutant
SSDT 8900D100 ZwCreateSymbolicLinkObject
SSDT 890150C0 ZwCreateThread
SSDT 8900E1A0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA8A013B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA8A01910]
SSDT 890006D0 ZwDuplicateObject
SSDT 88FFD6B0 ZwFreeVirtualMemory
SSDT 890275B0 ZwImpersonateAnonymousToken
SSDT 88FDC7D8 ZwImpersonateThread
SSDT 897D4648 ZwLoadDriver
SSDT 88FD5870 ZwMapViewOfSection
SSDT 8900F1A0 ZwOpenEvent
SSDT 89010710 ZwOpenProcess
SSDT 89010650 ZwOpenProcessToken
SSDT 890101E0 ZwOpenSection
SSDT 890007A0 ZwOpenThread
SSDT 8900D1D0 ZwProtectVirtualMemory
SSDT 89048E88 ZwResumeThread
SSDT 89031660 ZwSetContextThread
SSDT 89031740 ZwSetInformationProcess
SSDT 89010098 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA8A01B60]
SSDT 8900F0C0 ZwSuspendProcess
SSDT 89027FD0 ZwSuspendThread
SSDT 88FD7658 ZwTerminateProcess
SSDT 88FDC2D8 ZwTerminateThread
SSDT 88FDA6A8 ZwUnmapViewOfSection
SSDT 88FFD7A0 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] on Sun 12/27/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1579 [GMT -6:00]


============== Running Processes ===============

C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Quicken\Online Backup\OnlineBackup.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Duane Pankhurst\Desktop\whatthetech\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.live.com
uStart Page = hxxp://my.att.net/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\norton antivirus\engine\16.7.2.11\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [@BackupScheduler] c:\program files\quicken\online backup\OnlineBackup.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1007020.00b\SymEFA.sys [2009-11-27 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1007020.00b\BHDrvx86.sys [2009-11-27 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1007020.00b\cchpx86.sys [2009-11-27 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20091217.002\IDSXpx86.sys [2009-12-18 329592]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-12-18 155648]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\norton antivirus\engine\16.7.2.11\ccSvcHst.exe [2009-11-27 117640]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-12-23 102448]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
S3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20091226.025\NAVENG.SYS [2009-12-27 84912]
S3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20091226.025\NAVEX15.SYS [2009-12-27 1323568]

=============== Created Last 30 ================

2009-12-27 11:33 –d—– c:\docume~1\duanep~1\applic~1\Malwarebytes
2009-12-27 11:33 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-27 11:33 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-27 11:33 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-12-27 11:33 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-12-27 08:29 0 a——- c:\windows\system32\18467.exe
2009-12-23 20:18 35 a——- c:\windows\system32\5c31f0a7
2009-12-23 19:50 1,254 a–sh— c:\windows\system32\1558292464
2009-12-23 19:50 817 a——- c:\windows\system32\212989856
2009-12-23 19:49 –d—– c:\windows\system32\1048809671
2009-12-23 19:49 203,776 —sh— c:\windows\system32\unrar.exe
2009-12-23 19:36 –d—– c:\docume~1\duanep~1\applic~1\LimeWire
2009-12-17 19:30 –d—– c:\docume~1\duanep~1\applic~1\Final Draft
2009-12-17 19:25 1,073,152 a—-r– c:\windows\system32\cdintf210.dll
2009-12-17 19:25 –d—– c:\docume~1\alluse~1\applic~1\Final Draft
2009-12-17 19:24 –d—– c:\program files\Final Draft Tagger
2009-12-17 19:24 –d—– c:\program files\Final Draft 7
2009-12-17 19:24 –d—– c:\program files\common files\Wise Installation Wizard
2009-12-01 18:56 –d—– C:\UBCD4Win
2009-12-01 18:37 –d—– C:\xpcd
2009-12-01 17:49 –d—– C:\vista cd
2009-12-01 17:48 1,905 a——- c:\windows\diagwrn.xml
2009-12-01 17:48 1,905 a——- c:\windows\diagerr.xml
2009-11-29 08:10 –d—– C:\Intel
2009-11-28 08:29 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys

==================== Find3M ====================

2009-11-27 16:02 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-11-27 16:02 60,808 a——- c:\windows\system32\S32EVNT1.DLL
2009-11-27 16:02 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2009-11-27 16:02 806 a——- c:\windows\system32\drivers\SYMEVENT.INF
2009-10-29 01:45 916,480 a——- c:\windows\system32\wininet.dll
2009-10-27 20:21 614 a——- c:\docume~1\duanep~1\applic~1\wklnhst.dat
2009-10-20 23:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 23:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-13 04:30 270,336 a——- c:\windows\system32\oakley.dll
2009-10-12 07:38 149,504 a——- c:\windows\system32\rastls.dll
2009-10-12 07:38 79,872 a——- c:\windows\system32\raschap.dll
2009-10-09 17:54 77,824 a——- c:\windows\setpwr32.exe
2009-10-09 15:08 410,984 a——- c:\windows\system32\deploytk.dll
2009-10-09 15:01 87,263 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat

============= FINISH: 11:56:28.06 ===============

Attachments:

Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi,

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT



Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


NEXT

Please advise how your computer is running now and if there are any outstanding issues:
OK here's the logs (+attachment). So far so good. It looks like all is working normally. :thumbup: Malwarebytes' Anti-Malware 1.42 Database version: 3441 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/27/2009 2:45:28 PM mbam-log-2009-12-27 (14-45-28).txt Scan type: Quick Scan Objects scanned: 135688 Time elapsed: 2 minute(s), 38 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Attachments:

Hi,

Please do the following:

  • Go to Start->Run and type in notepad and hit OK.
  • Then copy and paste the content of the following codebox into Notepad:

    @echo off 
    if exist "%temp%\log.txt" del "%temp%\log.txt"
    
    for %%g in ( 
    "C:\Documents and Settings\Duane Pankhurst\My Documents\downloads\technical software\hampson russell\(100% works for all versions) hampson russell pc universal crack from FOFF.zip"
    "C:\Documents and Settings\Duane Pankhurst\My Documents\downloads\technical software\hampson russell\cracks\patch.FOFF.exe"
    "C:\Documents and Settings\Duane Pankhurst\My Documents\downloads\technical software\hampson russell\cracks2\patch.[lucid].exe"
    "C:\Documents and Settings\Duane Pankhurst\My Documents\downloads\technical software\hampson russell\keygens.nl presents hampson russell pc crack + patch 100% working new fixed version by lucid.zip"
    "C:\Documents and Settings\Duane Pankhurst\old cee drive\My Documents\Business and Post Cards\archive.pst"
    ) do (
    del /a/f/q %%g >nul 2>&1
    if exist %%g echo.%%g>>"%temp%\log.txt"
    )
    if exist "%temp%\log.txt" ( start notepad "%temp%\log.txt"
    ) else echo.Deleted Successfully !!
    pause
    del %0
  • Save the file to your DESKTOP as "find.bat". Make sure to save it with the quotes.
  • Once saved, the icon to click should look like this on your desktop:

    [external image: Posted Image]
  • Double click find.bat. to run it. A small black box should open and close - this is normal.
  • Let me know if it deletes successfully.


Also, one of your emails is infected.
Unfortunately Kaspersky is unable to identify which, so delete anything with attachments or from anyone you don't know.

C:\Documents and Settings\xxx\old cee drive\Documents and Settings\xxx\Local Settings\Application Data\Microsoft\Outlook\outlook.pst Infected: Hoax.Win16.BadJoke.Stupid.a


NEXT

Please post a fresh DDS and Attach.txt and advise if there are any outstanding issues.
One more log. BTW, your team is great!! ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Dell\DellDock\DockLogin.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files\Canon\MyPrinter\BJMyPrt.exe C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Quicken\Online Backup\OnlineBackup.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\cidaemon.exe C:\Documents and Settings\Duane Pankhurst\Desktop\whatthetech\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://my.att.net/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\norton antivirus\engine\16.7.2.11\IPSBHO.DLL BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File uRun: [@BackupScheduler] c:\program files\quicken\online backup\OnlineBackup.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [RTHDCPL] RTHDCPL.EXE mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe" mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe" mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.EXE mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Notify: igfxcui - igfxdev.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1007020.00b\SymEFA.sys [2009-11-27 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1007020.00b\BHDrvx86.sys [2009-11-27 259632] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1007020.00b\cchpx86.sys [2009-11-27 482432] R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20091217.002\IDSXpx86.sys [2009-12-18 329592] R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312] R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-12-18 155648] R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\norton antivirus\engine\16.7.2.11\ccSvcHst.exe [2009-11-27 117640] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-12-23 102448] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20091227.004\NAVENG.SYS [2009-12-27 84912] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20091227.004\NAVEX15.SYS [2009-12-27 1323568] S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680] =============== Created Last 30 ================ 2009-12-27 14:04 a-dshr– C:\cmdcons 2009-12-27 14:02 261,632 a——- c:\windows\PEV.exe 2009-12-27 14:02 161,792 a——- c:\windows\SWREG.exe 2009-12-27 14:02 98,816 a——- c:\windows\sed.exe 2009-12-27 14:02 77,312 a——- c:\windows\MBR.exe 2009-12-27 11:33 –d—– c:\docume~1\duanep~1\applic~1\Malwarebytes 2009-12-27 11:33 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-27 11:33 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-12-27 11:33 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-12-27 11:33 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-12-23 20:18 35 a——- c:\windows\system32\5c31f0a7 2009-12-23 19:50 1,254 a–sh— c:\windows\system32\1558292464 2009-12-23 19:50 817 a——- c:\windows\system32\212989856 2009-12-23 19:36 –d—– c:\docume~1\duanep~1\applic~1\LimeWire 2009-12-17 19:30 –d—– c:\docume~1\duanep~1\applic~1\Final Draft 2009-12-17 19:25 1,073,152 a—-r– c:\windows\system32\cdintf210.dll 2009-12-17 19:25 –d—– c:\docume~1\alluse~1\applic~1\Final Draft 2009-12-17 19:24 –d—– c:\program files\Final Draft Tagger 2009-12-17 19:24 –d—– c:\program files\Final Draft 7 2009-12-17 19:24 –d—– c:\program files\common files\Wise Installation Wizard 2009-12-01 18:56 –d—– C:\UBCD4Win 2009-12-01 18:37 –d—– C:\xpcd 2009-12-01 17:49 –d—– C:\vista cd 2009-12-01 17:48 1,905 a——- c:\windows\diagwrn.xml 2009-12-01 17:48 1,905 a——- c:\windows\diagerr.xml 2009-11-29 08:10 –d—– C:\Intel 2009-11-28 08:29 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys ==================== Find3M ==================== 2009-11-27 16:02 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-11-27 16:02 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2009-11-27 16:02 7,456 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-11-27 16:02 806 a——- c:\windows\system32\drivers\SYMEVENT.INF 2009-10-29 01:45 916,480 ——– c:\windows\system32\wininet.dll 2009-10-27 20:21 614 a——- c:\docume~1\duanep~1\applic~1\wklnhst.dat 2009-10-20 23:38 75,776 a——- c:\windows\system32\strmfilt.dll 2009-10-20 23:38 25,088 a——- c:\windows\system32\httpapi.dll 2009-10-13 04:30 270,336 a——- c:\windows\system32\oakley.dll 2009-10-12 07:38 149,504 a——- c:\windows\system32\rastls.dll 2009-10-12 07:38 79,872 a——- c:\windows\system32\raschap.dll 2009-10-09 17:54 77,824 a——- c:\windows\setpwr32.exe 2009-10-09 15:08 410,984 a——- c:\windows\system32\deploytk.dll 2009-10-09 15:01 87,263 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat ============= FINISH: 18:39:37.57 ===============

Attachments:

Hi,

Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\windows\system32\5c31f0a7

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Please do the same for the following files:

c:\windows\system32\1558292464
c:\windows\system32\212989856
Three more logs. When I donate, is it to a large group or can I specify you personally? This level of help is simply unprecedented. Thank-you very much!!

VirSCAN.org Scanned Report :
Scanned time : 2009/12/28 09:29:13 (CST)
Scanner results: Scanners did not find malware!
File Name : 5c31f0a7
File Size : 35 byte
File Type : data
MD5 : f4b042e1752c41b9d89df79702a1da14
SHA1 : 23aa7a4f574e5a672b131498f5366fafc02b8efe
Online report : http://virscan.org/report/94b5ca48efd86271…6f7fee9eef.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091228020243 2009-12-28 4.22 -
AhnLab V3 2009.12.26.00 2009.12.26 2009-12-26 1.00 -
AntiVir 8.2.1.122 7.10.2.75 2009-12-26 0.13 -
Antiy 2.0.18 20091225.3525327 2009-12-25 0.12 -
Arcavir 2009 200912270015 2009-12-27 0.02 -
Authentium 5.1.1 200912271908 2009-12-27 1.23 -
AVAST! 4.7.4 091227-1 2009-12-27 0.00 -
AVG 8.5.288 270.14.121/2589 2009-12-27 0.30 -
BitDefender 7.81008.4789804 7.29643 2009-12-28 4.17 -
CA (VET) 35.1.0 7197 2009-12-24 7.09 -
ClamAV 0.95.2 10225 2009-12-27 0.00 -
Comodo 3.13 3389 2009-12-27 0.90 -
CP Secure 1.3.0.5 2009.12.28 2009-12-28 0.00 -
Dr.Web 4.44.0.9170 2009.12.27 2009-12-27 8.03 -
F-Prot 4.4.4.56 20091227 2009-12-27 1.21 -
F-Secure 7.02.73807 2009.12.28.03 2009-12-28 0.07 -
Fortinet 11.315- 11.315 2009-12-27 0.17 -
GData 19.9578/19.647 20091228 2009-12-28 5.76 -
ViRobot 20091226 2009.12.26 2009-12-26 0.41 -
Ikarus T3.1.01.79 2009.12.27.74844 2009-12-27 4.19 -
JiangMin 13.0.900 2009.12.27 2009-12-27 7.68 -
Kaspersky 5.5.10 2009.12.27 2009-12-27 0.03 -
KingSoft 2009.2.5.15 2009.12.27.22 2009-12-27 0.56 -
McAfee 5.3.00 5844 2009-12-27 3.31 -
Microsoft 1.5302 2009.12.28 2009-12-28 6.87 -
Norman 6.01.09 6.01.00 2009-12-26 4.01 -
Panda 9.05.01 2009.12.27 2009-12-27 1.87 -
Trend Micro 9.000-1003 6.724.07 2009-12-28 0.02 -
Quick Heal 10.00 2009.12.26 2009-12-26 1.28 -
Rising 20.0 22.27.06.04 2009-12-27 0.26 -
Sophos 3.03.0 4.49 2009-12-28 2.73 -
Sunbelt 3.9.2388.2 5584 2009-12-27 2.19 -
Symantec 1.3.0.24 20091227.004 2009-12-27 0.06 -
nProtect 20091227.01 6720647 2009-12-27 3.94 -
The Hacker [removed] v00113 2009-12-26 0.68 -
VBA32 3.12.12.0 20091225.2239 2009-12-25 2.29 -
VirusBuster 4.5.11.10 10.118.11/2003832 2009-12-27 2.35 -

VirSCAN.org Scanned Report :
Scanned time : 2009/12/28 09:33:12 (CST)
Scanner results: Scanners did not find malware!
File Name : 1558292464
File Size : 1254 byte
File Type : ASCII text, with CRLF line terminators
MD5 : 82a5290bc48aac385b4742893aa5aa97
SHA1 : 03881134a13a79400d6062e614952b38e3513ae2
Online report : http://virscan.org/report/7e0f374ce21d0ba2…d560863978.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091228020243 2009-12-28 4.10 -
AhnLab V3 2009.12.26.00 2009.12.26 2009-12-26 1.07 -
AntiVir 8.2.1.122 7.10.2.75 2009-12-26 0.25 -
Antiy 2.0.18 20091225.3525327 2009-12-25 0.12 -
Arcavir 2009 200912270015 2009-12-27 0.02 -
Authentium 5.1.1 200912271908 2009-12-27 1.27 -
AVAST! 4.7.4 091227-1 2009-12-27 0.00 -
AVG 8.5.288 270.14.121/2589 2009-12-27 0.31 -
BitDefender 7.81008.4789804 7.29643 2009-12-28 4.12 -
CA (VET) 35.1.0 7197 2009-12-24 7.64 -
ClamAV 0.95.2 10225 2009-12-27 0.01 -
Comodo 3.13 3389 2009-12-27 1.01 -
CP Secure 1.3.0.5 2009.12.28 2009-12-28 0.01 -
Dr.Web 4.44.0.9170 2009.12.27 2009-12-27 8.16 -
F-Prot 4.4.4.56 20091227 2009-12-27 1.25 -
F-Secure 7.02.73807 2009.12.28.03 2009-12-28 9.41 -
Fortinet 11.315- 11.315 2009-12-27 0.18 -
GData 19.9578/19.647 20091228 2009-12-28 7.49 -
ViRobot 20091226 2009.12.26 2009-12-26 0.43 -
Ikarus T3.1.01.79 2009.12.27.74844 2009-12-27 4.12 -
JiangMin 13.0.900 2009.12.27 2009-12-27 4.97 -
Kaspersky 5.5.10 2009.12.27 2009-12-27 0.03 -
KingSoft 2009.2.5.15 2009.12.27.22 2009-12-27 0.52 -
McAfee 5.3.00 5844 2009-12-27 3.29 -
Microsoft 1.5302 2009.12.28 2009-12-28 7.06 -
Norman 6.01.09 6.01.00 2009-12-26 4.01 -
Panda 9.05.01 2009.12.27 2009-12-27 2.05 -
Trend Micro 9.000-1003 6.724.07 2009-12-28 0.02 -
Quick Heal 10.00 2009.12.26 2009-12-26 1.26 -
Rising 20.0 22.27.06.04 2009-12-27 0.24 -
Sophos 3.03.0 4.49 2009-12-28 2.75 -
Sunbelt 3.9.2388.2 5584 2009-12-27 2.15 -
Symantec 1.3.0.24 20091227.004 2009-12-27 0.29 -
nProtect 20091227.01 6720647 2009-12-27 4.91 -
The Hacker [removed] v00113 2009-12-26 0.97 -
VBA32 3.12.12.0 20091225.2239 2009-12-25 2.25 -
VirusBuster 4.5.11.10 10.118.11/2003832 2009-12-27 2.33 -


VirSCAN.org Scanned Report :
Scanned time : 2009/12/28 09:36:45 (CST)
Scanner results: Scanners did not find malware!
File Name : 212989856
File Size : 817 byte
File Type : data
MD5 : fa9f38e50945e0d4936f48eadf493432
SHA1 : d3066358374e5c02b97ad0cc421a9ebaed27234c
Online report : http://virscan.org/report/327cb311276e0cc1…bafa06b1b5.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091228020243 2009-12-28 4.18 -
AhnLab V3 2009.12.26.00 2009.12.26 2009-12-26 0.98 -
AntiVir 8.2.1.122 7.10.2.75 2009-12-26 0.47 -
Antiy 2.0.18 20091225.3525327 2009-12-25 0.12 -
Arcavir 2009 200912270015 2009-12-27 0.02 -
Authentium 5.1.1 200912271908 2009-12-27 1.23 -
AVAST! 4.7.4 091227-1 2009-12-27 0.00 -
AVG 8.5.288 270.14.121/2589 2009-12-27 0.31 -
BitDefender 7.81008.4789804 7.29643 2009-12-28 4.15 -
CA (VET) 35.1.0 7197 2009-12-24 8.00 -
ClamAV 0.95.2 10225 2009-12-27 0.00 -
Comodo 3.13 3389 2009-12-27 0.89 -
CP Secure 1.3.0.5 2009.12.28 2009-12-28 0.00 -
Dr.Web 4.44.0.9170 2009.12.27 2009-12-27 8.01 -
F-Prot 4.4.4.56 20091227 2009-12-27 1.22 -
F-Secure 7.02.73807 2009.12.28.03 2009-12-28 9.39 -
Fortinet 11.315- 11.315 2009-12-27 0.15 -
GData 19.9578/19.647 20091228 2009-12-28 5.74 -
ViRobot 20091226 2009.12.26 2009-12-26 0.41 -
Ikarus T3.1.01.79 2009.12.27.74844 2009-12-27 4.21 -
JiangMin 13.0.900 2009.12.27 2009-12-27 4.68 -
Kaspersky 5.5.10 2009.12.27 2009-12-27 0.03 -
KingSoft 2009.2.5.15 2009.12.27.22 2009-12-27 0.55 -
McAfee 5.3.00 5844 2009-12-27 3.29 -
Microsoft 1.5302 2009.12.28 2009-12-28 6.71 -
Norman 6.01.09 6.01.00 2009-12-26 4.01 -
Panda 9.05.01 2009.12.27 2009-12-27 1.85 -
Trend Micro 9.000-1003 6.724.07 2009-12-28 0.02 -
Quick Heal 10.00 2009.12.26 2009-12-26 1.31 -
Rising 20.0 22.27.06.04 2009-12-27 0.28 -
Sophos 3.03.0 4.49 2009-12-28 2.74 -
Sunbelt 3.9.2388.2 5584 2009-12-27 2.07 -
Symantec 1.3.0.24 20091227.004 2009-12-27 0.23 -
nProtect 20091227.01 6720647 2009-12-27 3.99 -
The Hacker [removed] v00113 2009-12-26 0.74 -
VBA32 3.12.12.0 20091225.2239 2009-12-25 2.25 -
VirusBuster 4.5.11.10 10.118.11/2003832 2009-12-27 2.33 -
Hi,

You are clean,

Now we can clean up our tools,

Please do the following:

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 13 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


NEXT


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
If any other logs remain > right click and delete them.

NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

When I donate, is it to a large group or can I specify you personally? This level of help is simply unprecedented. Thank-you very much!!


haha, the paypal in my sig goes directly to me, but please don't feel obliged to donate, my help is always free, my thanks is helping you get your computer totally clean.

You are welcome.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI