This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] google redirect

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

please help me with this nightmare…
below are the logs for mbam, gmer, dds and attach dds
thanks

Malwarebytes' Anti-Malware 1.43
Database version: 3475
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/1/2010 9:06:13 PM
mbam-log-2010-01-01 (21-06-13).txt

Scan type: Quick Scan
Objects scanned: 114052
Time elapsed: 6 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\tdlcmd.dll (Trojan.TDSS) -> Quarantined and deleted successfully.


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-01 21:47:05
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\THEFAM~1\LOCALS~1\Temp\pwtdqpog.sys


—- System - GMER 1.0.15 —-

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xBA0F887E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xBA0F8BFE]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\iaStor \Device\Ide\iaStor0 [B9EA0716] iaStor.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [B9EA0716] iaStor.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\iaStor.sys suspicious modification

—- EOF - GMER 1.0.15 —-



DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:18:09.01 on Fri 01/01/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1564 [GMT -8:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxdncoms.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lexmark 2600 Series\lxdnmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Lexmark 2600 Series\lxdnMsdMon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\hField Technologies, Inc\Wi-Fire Connection Manager\Wi-Fire Connection Manager.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\The Family\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Eee Docking] c:\program files\asus\eee docking\Eee Docking.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe
mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe
mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SynAsusAcpi] c:\program files\synaptics\syntp\SynAsusAcpi.exe
mRun: [lxdnmon.exe] "c:\program files\lexmark 2600 series\lxdnmon.exe"
mRun: [lxdnamon] "c:\program files\lexmark 2600 series\lxdnamon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
StartupFolder: c:\docume~1\thefam~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wi-fir~1.lnk - c:\program files\hfield technologies, inc\wi-fire connection manager\Wi-Fire Connection Manager.exe
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\thefam~1\applic~1\mozilla\firefox\profiles\wqid815o.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R2 FlipShare Service;FlipShare Service;c:\program files\flip video\flipshare\FlipShareService.exe [2009-11-19 455944]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-5-5 54752]
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service –> c:\windows\system32\lxdncoms.exe -service [?]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [2009-5-5 10752]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [2009-4-27 38912]
S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [2009-10-11 98984]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-5-5 1684736]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 m4301a;Linksys Wireless-B USB Network Adapter v4.0 Driver;c:\windows\system32\drivers\m4301A.sys [2004-5-13 83552]
S3 SRS_PremiumSound_Service;SRS Labs Premium Sound;c:\windows\system32\drivers\SRS_PremiumSound_i386.sys [2009-5-5 232872]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [2009-3-16 39040]
S3 ZDCNDIS5;ZDCNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\zdcndis5.sys –> c:\windows\system32\ZDCndis5.SYS [?]

=============== Created Last 30 ================

2010-01-01 21:13 26,624 a——- c:\windows\system32\tdlcmd.dll
2010-01-01 16:06 –d—– c:\program files\Spybot - Search & Destroy
2010-01-01 16:06 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-12-29 17:21 –d—– c:\program files\softendo.com
2009-12-25 07:49 60,032 ac—— c:\windows\system32\dllcache\usbaudio.sys
2009-12-25 07:49 60,032 a——- c:\windows\system32\drivers\USBAUDIO.sys
2009-12-23 21:59 –d—– c:\program files\Vimeo Uploader
2009-12-21 18:43 477,696 a——- c:\windows\system32\drivers\ZD1211BU.sys
2009-12-21 18:43 1,015,808 a——- c:\windows\system32\libeay32.dll
2009-12-21 18:43 348,160 a——- c:\windows\system32\WiFiMan.dll
2009-12-21 18:43 196,608 a——- c:\windows\system32\ssleay32.dll
2009-12-21 18:43 196,608 a——- c:\windows\system32\libssl32.dll
2009-12-21 18:43 21,504 a——- c:\windows\system32\wifimanio.sys
2009-12-21 18:43 21,504 a——- c:\windows\system32\drivers\wifimanio.sys
2009-12-21 18:43 –d—– c:\program files\hField Technologies, Inc
2009-12-10 13:59 1,015 a—-r– C:\logFile.xsl
2009-12-10 11:16 –d—– c:\program files\Flip Video
2009-12-10 10:08 –d—– c:\program files\NCH Software
2009-12-03 21:11 –d—– c:\docume~1\thefam~1\applic~1\vimeo.Duplo.3E2F2984357E7A95AE95C69EF2C5C14640284048.1
2009-12-03 20:23 –d—– c:\program files\3ivx

==================== Find3M ====================

2009-12-30 14:55 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 14:54 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-10-28 23:45 916,480 a——- c:\windows\system32\wininet.dll
2009-10-20 21:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 21:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-13 02:30 270,336 a——- c:\windows\system32\oakley.dll
2009-10-12 05:38 149,504 a——- c:\windows\system32\rastls.dll
2009-10-12 05:38 79,872 a——- c:\windows\system32\raschap.dll
2009-10-11 04:17 411,368 a——- c:\windows\system32\deploytk.dll
2009-09-12 12:55 0 a——- c:\docume~1\thefam~1\applic~1\wklnhst.dat
2009-05-05 08:49 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat
2009-09-12 07:37 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009091220090913\index.dat
2009-09-12 07:37 16,384 a–sh— c:\windows\temp\cookies\index.dat
2009-09-12 07:37 16,384 a–sh— c:\windows\temp\history\history.ie5\index.dat
2009-09-12 07:37 16,384 a–sh— c:\windows\temp\temporary internet files\content.ie5\index.dat

============= FINISH: 22:20:32.28 ===============


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 9/12/2009 8:41:15 AM
System Uptime: 1/1/2010 10:14:22 PM (0 hours ago)

Motherboard: ASUSTeK Computer INC. | | 1005HA
Processor: Intel® Atom™ CPU N270 @ 1.60GHz | PBGA 437 | 1599/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 72 GiB total, 50.744 GiB free.
D: is FIXED (NTFS) - 72 GiB total, 71.982 GiB free.
E: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP16: 10/5/2009 10:12:57 AM - System Checkpoint
RP17: 10/6/2009 10:59:45 AM - System Checkpoint
RP18: 10/7/2009 11:28:46 AM - System Checkpoint
RP19: 10/8/2009 4:21:43 PM - System Checkpoint
RP20: 10/9/2009 5:36:34 PM - System Checkpoint
RP21: 10/10/2009 6:26:09 PM - System Checkpoint
RP22: 10/11/2009 6:46:12 PM - System Checkpoint
RP23: 10/12/2009 7:36:07 PM - System Checkpoint
RP24: 10/12/2009 9:08:27 PM - Software Distribution Service 3.0
RP25: 10/14/2009 9:09:22 AM - System Checkpoint
RP26: 10/15/2009 9:22:50 AM - System Checkpoint
RP27: 10/15/2009 10:34:48 AM - Software Distribution Service 3.0
RP28: 10/16/2009 11:16:02 AM - System Checkpoint
RP29: 10/17/2009 11:55:17 AM - System Checkpoint
RP30: 10/17/2009 9:29:47 PM - Installed QuickTime
RP31: 10/18/2009 10:07:25 PM - System Checkpoint
RP32: 10/19/2009 3:00:38 AM - Software Distribution Service 3.0
RP33: 10/19/2009 10:37:21 PM - Software Distribution Service 3.0
RP34: 10/20/2009 11:09:22 PM - System Checkpoint
RP35: 10/22/2009 9:10:01 AM - System Checkpoint
RP36: 10/23/2009 1:07:09 PM - System Checkpoint
RP37: 10/24/2009 1:43:29 PM - System Checkpoint
RP38: 10/25/2009 7:36:31 PM - System Checkpoint
RP39: 10/26/2009 8:35:36 PM - System Checkpoint
RP40: 10/28/2009 9:39:52 AM - System Checkpoint
RP41: 10/29/2009 10:13:29 AM - System Checkpoint
RP42: 10/30/2009 10:32:28 AM - System Checkpoint
RP43: 10/31/2009 12:11:53 PM - System Checkpoint
RP44: 11/1/2009 7:23:20 PM - System Checkpoint
RP45: 11/2/2009 7:27:02 PM - System Checkpoint
RP46: 11/4/2009 9:16:46 AM - Software Distribution Service 3.0
RP47: 11/5/2009 4:00:16 AM - Software Distribution Service 3.0
RP48: 11/5/2009 4:13:44 PM - Installed Java™ 6 Update 17
RP49: 11/6/2009 4:57:40 PM - System Checkpoint
RP50: 11/7/2009 5:43:49 PM - System Checkpoint
RP51: 11/8/2009 5:32:10 PM - System Checkpoint
RP52: 11/9/2009 6:55:36 PM - System Checkpoint
RP53: 11/11/2009 10:41:32 AM - System Checkpoint
RP54: 11/12/2009 7:20:28 AM - Software Distribution Service 3.0
RP55: 11/13/2009 7:46:04 AM - System Checkpoint
RP56: 11/14/2009 8:40:51 AM - System Checkpoint
RP57: 11/16/2009 9:24:38 AM - System Checkpoint
RP58: 11/17/2009 9:39:22 AM - System Checkpoint
RP59: 11/18/2009 9:51:07 AM - System Checkpoint
RP60: 11/18/2009 10:19:23 AM - Installed DirectX
RP61: 11/19/2009 2:30:40 PM - System Checkpoint
RP62: 11/20/2009 2:54:48 PM - System Checkpoint
RP63: 11/21/2009 3:15:21 PM - System Checkpoint
RP64: 11/23/2009 7:55:56 AM - System Checkpoint
RP65: 11/24/2009 8:29:58 AM - System Checkpoint
RP66: 11/25/2009 11:18:14 AM - System Checkpoint
RP67: 11/26/2009 8:12:43 AM - Software Distribution Service 3.0
RP68: 11/27/2009 3:53:19 PM - System Checkpoint
RP69: 11/29/2009 8:41:05 AM - System Checkpoint
RP70: 11/30/2009 9:06:52 AM - System Checkpoint
RP71: 12/2/2009 8:34:02 AM - System Checkpoint
RP72: 12/3/2009 2:16:25 PM - System Checkpoint
RP73: 12/4/2009 7:42:18 PM - System Checkpoint
RP74: 12/7/2009 6:04:07 PM - System Checkpoint
RP75: 12/8/2009 9:19:19 PM - System Checkpoint
RP76: 12/10/2009 5:46:48 AM - Software Distribution Service 3.0
RP77: 12/11/2009 1:09:29 PM - System Checkpoint
RP78: 12/12/2009 3:31:09 PM - System Checkpoint
RP79: 12/13/2009 4:23:08 PM - System Checkpoint
RP80: 12/14/2009 6:18:07 PM - System Checkpoint
RP81: 12/16/2009 10:09:36 AM - System Checkpoint
RP82: 12/17/2009 11:13:53 AM - System Checkpoint
RP83: 12/18/2009 12:04:52 PM - System Checkpoint
RP84: 12/19/2009 8:20:52 PM - System Checkpoint
RP85: 12/21/2009 11:09:19 AM - System Checkpoint
RP86: 12/21/2009 6:43:52 PM - Installed Wi-Fire Connection Manager
RP87: 12/22/2009 7:05:17 PM - System Checkpoint
RP88: 12/24/2009 8:09:43 AM - System Checkpoint
RP89: 12/26/2009 9:00:52 AM - System Checkpoint
RP90: 12/27/2009 4:06:04 PM - System Checkpoint
RP91: 12/29/2009 11:34:44 AM - System Checkpoint
RP92: 12/29/2009 5:35:46 PM - Removed Skype™ 3.6
RP93: 12/31/2009 9:56:50 AM - System Checkpoint
RP94: 1/1/2010 9:58:54 AM - System Checkpoint
RP95: 1/1/2010 8:29:49 PM - Automatic Restore Point

==== Installed Programs ======================

3ivx MPEG-4 5.0.3 (remove only)
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.3
Apple Application Support
Apple Software Update
Asus ACPI Driver
ASUSUpdate for Eee PC
Atheros Client Installation Program
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
Azurewave Wireless LAN Card
Compatibility Pack for the 2007 Office system
Data Sync
Eee Docking 1.3.1.0
EeePC_1005HA Screen Saver
EeeSplendid
ERUNT 1.1j
EzMessenger
FlipShare
FontResizer
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Intel® Graphics Media Accelerator Driver
Java™ 6 Update 17
JLC's Internet TV
Junk Mail filter update
Lexmark 2600 Series
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works
Mozilla Firefox (3.5.6)
MSVCRT
Prism Video Converter
QuickTime
Realtek High Definition Audio Driver
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953155)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Segoe UI
Spybot - Search & Destroy
Super Hybrid Engine
Synaptics Pointing Device Driver
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Windows Internet Explorer 8 (KB973874)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB898461)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951618-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB953356)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
USB2.0 UVC Camera Device
Vimeo Uploader
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Wi-Fire Connection Manager
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 11

==== Event Viewer Messages From Past Week ========

12/29/2009 5:35:51 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
12/27/2009 7:38:55 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the lxdnCATSCustConnectService service to connect.
12/27/2009 7:38:55 AM, error: Service Control Manager [7000] - The lxdnCATSCustConnectService service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/27/2009 2:32:55 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
12/26/2009 3:04:55 PM, error: Dhcp [1002] - The IP address lease 192.168.0.118 for the Network Card with network address 0025D35F7D25 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
12/25/2009 9:22:58 AM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0025D35F7D25. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
1/1/2010 9:49:01 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Lavasoft Ad-Aware Service service.
1/1/2010 3:28:13 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/1/2010 10:09:07 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the service.

==== End Of File ===========================

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.


Unless informed of in advance, failure to post replies within 5 days will result in this thread being closed.


Hi melissasab

I'm Gary R, I'll be glad to help you with your computer problems.

Before we start: Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to install any new software (other than those I ask you to) until we've got your computer clean.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process. If your defensive programmes warn you about any of those tools, be assured that they are not infected, and are safe to use.
If you can do these things, everything should go smoothly.
  • If you're using XP, you'll need Administrator privileges to perform the fixes. (XP accounts are Administrator by default)
  • If you're using Vista, it will be necessary to right click all tools we use and select —-> Run as Administrator

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


Download ComboFix from one of these locations and save it to your Desktop: (if you already have a copy of Combofix, delete it and use this version)

Link 1
Link 2

IMPORTANT !!! ComboFix.exe must be run from your Desktop

  • Disable your AntiVirus and AntiSpyware applications, they may otherwise interfere with Combofix. There are details for disabling many programmes here.
  • Double click on ComboFix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install Microsoft Windows Recovery Console.

**Please note: If Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

Once Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you.

Please include this log in your next reply. ……… (it can also be found at C:\ComboFix.txt)

IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • If you've lost your Internet connection when Combofix has completely finished, re-start your computer to restore it.
If you have any problems with these instructions, a detailed Tutorial for how to use Combofix is available here.
ok, Gary, here is the log from combofix

ComboFix 10-01-01.05 - The Family 01/02/2010 10:35:14.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1710 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-783013601-2911902795-2016744192-1003
c:\windows\system32\tdlcmd.dll
c:\windows\system32\Thumbs.db

Infected copy of c:\windows\system32\drivers\iaStor.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2009-12-02 to 2010-01-02 )))))))))))))))))))))))))))))))
.

2010-01-02 17:15 . 2010-01-02 17:18 ——– d—–w- c:\documents and settings\The Family\Application Data\ArcSoft
2010-01-02 17:15 . 2010-01-02 17:15 ——– d—–w- c:\program files\My Book
2010-01-02 04:34 . 2010-01-02 04:34 ——– d—–w- c:\program files\ERUNT
2010-01-02 00:06 . 2010-01-02 00:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-02 00:06 . 2010-01-02 00:10 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-01 23:14 . 2010-01-01 23:14 5061520 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-30 01:21 . 2009-12-30 01:35 ——– d—–w- c:\program files\softendo.com
2009-12-25 15:49 . 2008-04-14 08:15 60032 -c–a-w- c:\windows\system32\dllcache\usbaudio.sys
2009-12-25 15:49 . 2008-04-14 08:15 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-12-24 05:59 . 2009-12-24 05:59 ——– d—–w- c:\program files\Vimeo Uploader
2009-12-22 02:43 . 2006-08-24 21:44 477696 —-a-w- c:\windows\system32\drivers\ZD1211BU.sys
2009-12-22 02:43 . 2009-05-18 08:16 21504 —-a-w- c:\windows\system32\wifimanio.sys
2009-12-22 02:43 . 2009-05-18 08:16 21504 —-a-w- c:\windows\system32\drivers\wifimanio.sys
2009-12-22 02:43 . 2009-05-18 08:14 348160 —-a-w- c:\windows\system32\WiFiMan.dll
2009-12-22 02:43 . 2008-06-14 19:05 196608 —-a-w- c:\windows\system32\libssl32.dll
2009-12-22 02:43 . 2007-10-22 04:10 196608 —-a-w- c:\windows\system32\ssleay32.dll
2009-12-22 02:43 . 2007-10-22 04:10 1015808 —-a-w- c:\windows\system32\libeay32.dll
2009-12-22 02:43 . 2009-12-22 02:43 ——– d—–w- c:\program files\hField Technologies, Inc
2009-12-10 19:16 . 2009-12-10 19:16 ——– d—–w- c:\program files\Flip Video
2009-12-10 18:08 . 2009-12-10 18:08 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Software
2009-12-10 18:08 . 2009-12-10 18:08 ——– d—–w- c:\program files\NCH Software
2009-12-04 05:11 . 2009-12-04 05:11 ——– d—–w- c:\documents and settings\The Family\Application Data\vimeo.Duplo.3E2F2984357E7A95AE95C69EF2C5C14640284048.1
2009-12-04 05:06 . 2009-12-04 05:00 38208 —-a-w- c:\documents and settings\The Family\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-04 05:06 . 2009-12-04 05:06 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-04 04:23 . 2009-12-04 04:23 ——– d—–w- c:\program files\3ivx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-02 17:15 . 2009-05-05 16:00 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-02 06:09 . 2009-10-25 03:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-01 23:15 . 2009-10-25 02:57 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-30 22:55 . 2009-10-25 02:57 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 22:54 . 2009-10-25 02:57 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-30 01:35 . 2009-05-05 16:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-12-10 13:49 . 2009-05-05 16:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-02 13:54 . 2009-10-21 04:19 ——– d—–w- c:\documents and settings\The Family\Application Data\U3
2009-11-23 01:14 . 2009-11-23 01:14 ——– d—–w- c:\documents and settings\The Family\Application Data\Lexmark Productivity Studio
2009-11-19 19:14 . 2009-11-19 19:14 4732800 —-a-w- c:\documents and settings\All Users\Application Data\Flip Video\FlipShare\Updates\FirmwareExec_Windows_en-US_83.06_83.07\FlipVideoFWUpdate.exe
2009-11-18 18:20 . 2009-05-05 16:33 ——– d—–w- c:\program files\Windows Live
2009-11-09 03:58 . 2009-09-12 15:42 60664 —-a-w- c:\documents and settings\The Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-05 23:14 . 2009-09-28 20:38 ——– d—–w- c:\program files\Java
2009-11-05 23:13 . 2009-11-05 23:13 152576 —-a-w- c:\documents and settings\The Family\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-10-29 18:38 . 2009-10-29 18:38 93360 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-29 07:45 . 2009-04-28 04:51 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2009-04-28 04:51 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2009-04-28 04:51 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-04-14 00:23 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2009-04-28 04:51 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2009-04-28 04:51 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2009-04-28 04:51 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-11 12:17 . 2009-09-28 20:38 411368 —-a-w- c:\windows\system32\deploytk.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Eee Docking"="c:\program files\ASUS\Eee Docking\Eee Docking.exe" [2009-05-08 395776]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-27 3883856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"RTHDCPL"="RTHDCPL.EXE" [2009-04-27 17881088]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-16 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-16 118784]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-06 1434920]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-03-06 79144]
"lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe" [2009-05-20 660136]
"lxdnamon"="c:\program files\Lexmark 2600 Series\lxdnamon.exe" [2009-05-20 16040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

c:\documents and settings\The Family\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-5-5 376832]
WD Backup Monitor.lnk - c:\program files\My Book\WD Backup\uBBMonitor.exe [2010-1-2 98304]
Wi-Fire Connection Manager.lnk - c:\program files\hField Technologies, Inc\Wi-Fire Connection Manager\Wi-Fire Connection Manager.exe [2009-12-21 425984]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 09:04 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-27 00:44 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\lxdncoms.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdntime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnjswx.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [5/5/2009 8:39 AM 54752]
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service –> c:\windows\system32\lxdncoms.exe -service [?]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [4/27/2009 5:59 PM 38912]
S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [10/11/2009 4:24 PM 98984]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [5/5/2009 8:00 AM 1684736]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
S3 m4301a;Linksys Wireless-B USB Network Adapter v4.0 Driver;c:\windows\system32\drivers\m4301A.sys [5/13/2004 5:31 PM 83552]
S3 SRS_PremiumSound_Service;SRS Labs Premium Sound;c:\windows\system32\drivers\SRS_PremiumSound_i386.sys [5/5/2009 9:16 AM 232872]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [3/16/2009 1:27 PM 39040]
S3 ZDCNDIS5;ZDCNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\ZDCndis5.SYS –> c:\windows\system32\ZDCndis5.SYS [?]
.
Contents of the 'Scheduled Tasks' folder

2009-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\The Family\Application Data\Mozilla\Firefox\Profiles\wqid815o.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-02 10:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(540)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Flip Video\FlipShare\FlipShareService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxdncoms.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\Lexmark 2600 Series\lxdnMsdMon.exe
c:\windows\system32\igfxext.exe
.
**************************************************************************
.
Completion time: 2010-01-02 10:46:07 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-02 18:46

Pre-Run: 54,643,433,472 bytes free
Post-Run: 54,819,053,568 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - EE1C1545BF0DA2D499708DF92C59989D
Looking better, are your Google searches still being re-directed ?

I need you to run another scan for me …..

First

  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.

Next

Please do a scan with ESET Online Scanner
Note: The scan will only work with Internet Explorer
  • Check the box "Yes, I accept the Terms of Use" and click Start
  • Accept the ActiveX by clicking the yellow bar at the top.
  • Install the software when prompted.
  • Read the Welcome notice and then click Start to download the necessary components.
  • When download is complete, make sure Remove found threats stays Unchecked.
  • Click Start to begin the scan.
  • After the scan completes, the Details tab in the Results window will display what was found.
  • A file will also be saved at: C:/Program Files/ESET/ESET Online Scanner /log.txt
  • Please post me the content of that file.
HI, searches are not being re-directed anymore. I am having trouble with the eset online scan. I can only get as far as step 2 of 4 of the Initialization process. After waiting for quite awhile for it to reach 100%, I get the message can not get update. is proxy configured? This has happened twice now. What should I do?
OK I'm not sure why E-Set is giving you problems, let's try a different scanner.

  • Please go to Kaspersky Online Scanner.
  • Read through the requirements and privacy statement and click on the Accept button.
  • It will start downloading and installing the scanner and virus definitions.
    • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they're not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers and other potentially dangerous programs.
    • Archives.
    • Mail databases.
  • Under Scan, click on My Computer.
  • Once the scan is complete, it will display the results.
    • Click on View Scan Report.
  • You will see a list of infected items.
    • Click the Save Report As… button (see red arrow below)

      [external image: Posted Image]
    • In the Save as… prompt, select Desktop
    • In the File name box, name the file KAVScan
    • In the Save as type prompt, select Text file (see below)

      [external image: Posted Image]
    • Copy and paste that information in your next post please.
hi, i am trying the kaspersky scan, but i have a weak internet signal…so it is having a real difficult time just downloading all the components. I will keep at it, just wanted to let you know since it seems to be delaying my reply to you. thanks, i will post the log soon, i hope.
Hi Gary, here is the Kaspersky scan info: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, January 4, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, January 04, 2010 04:58:58 Records in database: 3360302 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 42827 Threats found: 2 Infected objects found: 3 Suspicious objects found: 0 Scan duration: 01:38:03 File name / Threat / Threats count C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\iaStor.sys.vir Infected: Rootkit.Win32.TDSS.u 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\tdlcmd.dll.vir Infected: Packed.Win32.TDSS.z 1 C:\WINDOWS\system32\spool\prtprocs\w32x86\48.tmp Infected: Packed.Win32.TDSS.z 1 Selected area has been scanned.
OK not too much to do, the first 2 files found by Kaspersky are the encrypted backups created by Combofix when it removed your infection, and they can't re-infect you, we'll remove them when we remove Combofix so that they're not detected by any future scans you might run.

The other file needs removing.

Download OTM by Old Timer and save it to your Desktop.
  • Double-click OTM.exe to run it.
  • Copy the lines in the codebox below.
:files
C:\WINDOWS\system32\spool\prtprocs\w32x86\48.tmp
  • Return to OTM, right click in the Paste Instructions for Items to be Moved window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.
  • Close OTM

How is your computer running now ?
computer seems to be running great! ========== FILES ========== C:\WINDOWS\system32\spool\prtprocs\w32x86\48.tmp moved successfully. OTM by OldTimer - Version 3.1.4.0 log created on 01042010_145853
OK, looks like we've got everything, time for a little tidying round and then I'll make a few suggestions about security.

First

Let's clear out Combofix and the files/folders it created
  • Click Start > Run
  • Copy/Paste ComboFix /Uninstall into the Run box.
  • Click OK
  • Combofix will now delete its files and folders and also perform the following function.
  • Clears System Restore cache and creates a new Restore point. This will remove any "malicious" System Restore files, which may have been created whilst your computer was infected.
IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Next

Let's clear out OTM and the files and folders it created. (this will also remove GMER)
  • Double click OTM.exe to launch the programme.
  • Click on the CleanUp! button.
  • OTM will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access.
  • You will be prompted to allow the clean up procedure, click Yes
  • When finished exit out of OTM
  • Now delete OTM.exe (if still present).

Next

Delete DDS.

As far as I can see, your computer looks clear of infection now.

Are you still noticing any problems ?
  • If you are let me know about them.
  • If not it's time to make your computer more secure.

Before I make any recommendations, I'd like to give a simplified overview of how your defensive systems work and what you can do to protect yourself better in future.

The average home computer has approximately 64,000 ports through which it can communicate. By default these ports are open and can be used by any programme which cares to access them, either from within the computer or from without. If you were to go online with a computer in this condition you would quickly be attacked and your computer would be infected.

To prevent this you install a Firewall. A firewall will close all open ports and you then open the ones you need by setting "rules" for them according to the instructions supplied with the Firewall programme. Usually you will have ports open for your Internet Browser, your e-mail client, and the update functions for various programmes.

These "open" ports will not be fully accessible, in that they will only allow a communication if it was instigated from within your computer. Any unsolicited communications from outside are blocked.

However if you are tricked into starting the communication, then as far as your Firewall is concerned it is a legit transaction and it will open the port. So by clicking on malicious links, replying to unsolicited e-mails and attachments, and downloading from unsafe sources, you are effectively bypassing any protection your Firewall supplies.

At this point your Anti-Spyware and Anti-Virus programmes take over. The real-time-protection in these constantly scan the data stream in your open ports looking for things that match with items in the database they have within them. If they find something then they will alert you, or quarantine it, or delete it, according to the rules set within the programme.

However as you can see, if the database does not contain details of the infection that's attacking you, then your Anti-Virus or Anti-Spyware programmes will not protect you. There are new infections (or new variations of old infections) created every day, which is why it's vital to keep your programmes up to date. Even with a fully updated database though, you are still playing catchup, which is why your Firewall, Anti-Virus and Anti-Spyware programmes cannot ever give you 100% protection.

Adding more and more programmes will not give you more and more protection, it's up to you to take some responsibility for your online actions, and modify them to give your programmes the best chance of protecting you.

Be careful what you click on.

  • Don't download anything from a site you do not know and trust. Remember, there's no such thing as a free lunch, if something seems too good to be true it is. Malware purveyors love to offer out freebies as bait knowing full well that one unguarded click is all it takes.
  • Don't reply to unsolicited e-mails.
  • Don't open e-mail attachments (even from friends) without checking with the source to ensure they actually sent them.
  • Don't use P2P file sharing programmes. Even the ones that don't come bundled (and many do) are not safe. By using them you are effectively downloading from an unknown source, with all the dangers described above.


OK, so how do we set about protecting you.

You should definitely have one of each of the following programmes.
  • Firewall
  • Anti-Virus
  • Anti-Spyware
You do not need more than one of each. More than one will cause conflicts, and will not improve your security.

If you don't already have them, then these are links to lists of free programmes.
You'll increase your chances of not getting infected if you don't land on an infected website in the first place.

There are a couple of ways to do this
  • Block access to sites known to spread Malware.
  • Give you clear indication of which they are, so that you can make choices.
To block access to known bad sites we use a Hosts file.

Download HostsXpert and unzip it to your computer, somewhere where you can find it.

  • Double click on HostsXpert.exe to launch the programme.
  • Check to see if top button on left hand side says Make Writable ?
    • If it does. click on it then proceed to next instruction.
    • If not, just proceed to next instruction
  • Click on the Download button (lower left hand side)
    • Click on MVPs Hosts… button.
    • Click on Replace button.
    • Press OK in the box that pops up. (HostsXpert will now download and update your Hosts file)
  • When finished.
    • Click on File Handling button.
    • Click on Make Read Only ? to secure it against infection.
  • Exit the programme.

To give you an indication of which sites may contain bad links or suspect downloads I like to use WebOfTrust (WOT)

Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam, by rating over 21 million websites, helping you avoid the dangerous sites:
  • Green, are OK.
  • Yellow, visit with caution.
  • Red, known to be risky.
WOT has an addon available for both Firefox and IE.

Remove known vulnerabilities
  • Update your Java. I see you're running the latest version and that you don't have any old versions installed. This is important, because not only do they take up space on your computer, but old versions can be exploited even if you're using the latest version. Installing the new versions of Java should now remove the previous version (it was not always so), so all you need to do is keep it up to date.
  • Update Windows and Internet Explorer It is essential you keep your Operating System up to date with all the latest patches. The bad guys watch for the latest exploits, as soon as Microsoft brings out a patch, the bad guys will bring out an infection to exploit that vulnerability. If you don't have all the latest patches your computer is vulnerable. Please go to the windows update site and get the critical updates.
  • Use a "secure" browser Install Internet Explorer 8 or an alternative browser like Firefox or Opera for more secure surfing.
    Please remember that there is no such thing as a totally secure browser. Your browsing habits will be the major factor in determining just how safe you are online. If you visit, Crack/Warez sites, Porn sites, or other sites of a questionable nature, you still run a severe risk of getting infected.
  • Do not use P2P file sharing programmes I'd like you to read the Guidelines for P2P Programs where it's explained why it's not a good idea to have them.

    My recommendation is you go to Control Panel > Add/Remove Programs and uninstall any P2P programs you have installed.
  • Obviously you have already taken care of some of the issues mentioned, but it is important that you read through them, and address any that you may have missed.

Here's links to a few articles which are worth reading
thanks! you have been so very helpful! I appreciate all the time you have spent to help me fix my computer. everything seems to be running just right!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI