This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] OMG... MALWARE DEFENDER INFECTION

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

SO THE PROBLEM STARTED LATE LAST NIGHT… WITH A POP UP SAYING THAT I WAS INFECTED… AND THEN THIS PROGRAM NAMED MALWARE DEFENDER STARTED INSTALLING ITSELF ON MY COMPUTER… I IMMEDIATELY TRIED TO RUN MALWARE BYTES HOWEVER I WAS UNABLE TO… NO MATTER WHAT I DID I COULDNT RUN IT.. I EVEN TRIED TO UNINSTALL/REINSTALL MALWAREBYTES BUT TO NO AVAIL…. I AM ABLE TO RUN HIJACKTHIS.. BUT OTHER THAN THAT I AM UNALBE TO DO ANYTHING ELSE… AND NOW ABOUT EVERY MIN OR SO I GET A POP UP THAT SAYS INTERNET EXPLORER HAS ENCOUNTERED A PROBLEM AND NEEDS TO CLOSE… IF I DONT CLICK THE SEND/DONT SEND BUTTON… I CAN KEEP USING IE WITH NO PROBLEM… HOWEVER THIS POP UP WARNING MESSAGE CONTINUES TO KEEP POPPING UP… AND SO AFTER ABOUT 20 MINS I HAVE ABOUT 20 OF THESE LITTLE POP UPS ALL OVER THE PLACE ON MY SCREEN… PLEASE PLEASE HELP… ITS VERY FRUSTRATING SINCE I DO MOST OF MY WORK ONLINE AND MY COMPUTER IS BASICALLY HOW I MAKE MY LIVING … THANKS SO MUCH… SHAWNA
[external image: Posted Image]

Please don't type with the CAPS on.


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


Now see if MBAM will run
THANK YOU SO MUCH FOR A PROMPT RESPONSE… HERE IS A COPY OF THE LOG…. I AM GOING TO SEE IF MALWAREBYTES WILL RUN NOW.. AND POST A SECOND REPLY…
DURRRR…. I GUESS IT WOULD HELP IF I ACTUALLY ADDED THE LOG.. LOL… HERE IT IS… exeHelper by Raktor Build 20091220 Run at 17:56:50 on 01/10/10 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished–
Download Combofix from any of the links below but rename it to ABCD.exe before saving it to your desktop.

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Link 1
Link 2


Double click on the ABCD.exe ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
sorry about the caps… force of habit…. i ran combofix…. after saving it to my desktop and saving it as abcd.exe and this is the report it gave me… also it said that it dectected the following problems before restarting the first time…
c:\windows\system32\drivers\H8SRTppisrujdul.sys
c:\windows\system32\H8SRThtkiphhbqv.dll
c:\windows\system32\H8SRTngshtilrol.dat
c:\windows\system32\H8SRTvhxmbbqakd.dll
c:\windows\system32\H8SRTwkaeyxlloy.dll
c:\windows\system32\H8SRTlurjkymycd.dll

here is a copy of the report it gave me after it was finished:
ComboFix 10-01-04.01 - MONA 01/10/2010 18:14:58.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.789 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ABCD.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\MONA\LOCALS~1\Temp\wscsvc32.exe
C:\install.exe
c:\windows\system32\drivers\H8SRTppisrujdul.sys
c:\windows\system32\H8SRThtkiphhbqv.dll
c:\windows\system32\h8srtkrl32mainweq.dll
c:\windows\system32\H8SRTlurjkymycd.dll
c:\windows\system32\H8SRTngsntilrlo.dat
c:\windows\system32\h8srtshsyst.dll
c:\windows\system32\H8SRTvhxmbbqakd.dll
c:\windows\system32\H8SRTwkaeyxlloy.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_H8SRTd.sys
——-\Legacy_H8SRTd.sys


((((((((((((((((((((((((( Files Created from 2009-12-11 to 2010-01-11 )))))))))))))))))))))))))))))))
.

2010-01-11 01:12 . 2010-01-08 00:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-11 01:12 . 2010-01-11 01:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-11 01:12 . 2010-01-08 00:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-08 10:22 . 2010-01-08 10:22 ——– d—–w- c:\program files\MSXML 6.0
2009-12-26 07:22 . 2009-12-24 03:07 52224 —-a-w- c:\documents and settings\MONA\Application Data\Mozilla\Firefox\Profiles\s8owchhj.default\extensions\{69d1a568-ffdf-4ef5-8919-7003582e0ee8}\components\FFExternalAlert.dll
2009-12-26 07:22 . 2009-12-24 03:07 101376 —-a-w- c:\documents and settings\MONA\Application Data\Mozilla\Firefox\Profiles\s8owchhj.default\extensions\{69d1a568-ffdf-4ef5-8919-7003582e0ee8}\components\RadioWMPCore.dll
2009-12-26 00:15 . 2010-01-03 20:53 ——– d—–w- c:\documents and settings\MONA\Local Settings\Application Data\Digital Concepts Image Manager
2009-12-26 00:15 . 2009-12-26 00:15 ——– d—–w- c:\documents and settings\All Users\Application Data\DigitalConcepts
2009-12-26 00:15 . 2009-12-26 00:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Digital Concepts Image Manager
2009-12-26 00:14 . 2009-12-26 00:14 ——– d—–w- c:\program files\Haali
2009-12-26 00:13 . 2010-01-03 20:53 ——– d—–w- c:\program files\Digital Concepts Image Manager
2009-12-17 02:07 . 2006-02-28 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-12-12 02:41 . 2009-12-12 02:41 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-12-12 02:41 . 2009-12-30 00:03 ——– d—–w- c:\documents and settings\MONA\Application Data\skypePM
2009-12-12 02:39 . 2010-01-11 02:24 ——– d—–w- c:\documents and settings\MONA\Application Data\Skype
2009-12-12 02:38 . 2009-12-12 02:38 ——– d—–w- c:\program files\Common Files\Skype
2009-12-12 02:38 . 2009-12-12 02:39 ——– d—–r- c:\program files\Skype
2009-12-12 02:38 . 2009-12-12 02:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-10 08:00 . 2009-11-24 04:21 ——– d—–w- c:\program files\PokerStars
2010-01-10 02:27 . 2009-11-28 18:10 20 —h–w- c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
2010-01-10 02:26 . 2009-11-28 18:05 20 —h–w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-12-20 20:33 . 2009-11-24 04:22 ——– d—–w- c:\program files\Full Tilt Poker
2009-12-19 23:31 . 2009-12-05 11:39 ——– d—–w- c:\program files\Absolute Poker
2009-12-19 07:46 . 2009-11-30 05:06 79488 —-a-w- c:\documents and settings\MONA\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-05 11:41 . 2009-12-05 11:41 147456 —-a-w- c:\documents and settings\MONA\Application Data\Absolute Poker\DownLoadInst\liveupdate.exe
2009-12-05 11:41 . 2009-12-05 11:39 ——– d—–w- c:\documents and settings\MONA\Application Data\Absolute Poker
2009-12-05 11:39 . 2009-12-05 11:39 ——– d—–w- c:\program files\_uninstallation_info
2009-12-02 17:53 . 2009-12-02 17:52 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-30 05:07 . 2009-11-30 05:07 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-30 05:07 . 2009-11-30 05:07 ——– d—–w- c:\program files\Java
2009-11-30 05:06 . 2009-11-30 05:06 152576 —-a-w- c:\documents and settings\MONA\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-28 18:38 . 2009-11-28 18:22 ——– d—–w- c:\documents and settings\MONA\Application Data\Nikon
2009-11-28 18:22 . 2009-11-28 18:06 ——– d—–w- c:\program files\Common Files\Nikon
2009-11-28 18:11 . 2009-11-28 18:11 57344 —-a-r- c:\documents and settings\MONA\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2009-11-28 18:10 . 2009-11-28 18:05 ——– d—–w- c:\program files\Nikon
2009-11-28 18:10 . 2009-11-28 18:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Ultima_T15
2009-11-28 18:10 . 2009-11-28 18:05 ——– d—–w- c:\documents and settings\All Users\Application Data\EnterNHelp
2009-11-28 18:07 . 2009-11-28 18:07 49152 —-a-r- c:\documents and settings\MONA\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
2009-11-28 18:07 . 2009-11-28 18:07 335872 —-a-r- c:\documents and settings\MONA\Application Data\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe
2009-11-28 18:06 . 2009-11-28 18:06 ——– d—–w- c:\program files\Common Files\muvee Technologies
2009-11-28 18:06 . 2009-11-28 18:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Nikon
2009-11-28 18:05 . 2009-11-24 00:24 ——– d—–w- c:\program files\Common Files\InstallShield
2009-11-28 18:02 . 2009-11-28 18:02 ——– d—–w- c:\program files\ArcSoft
2009-11-28 18:02 . 2009-11-24 00:25 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-11-28 10:05 . 2009-11-28 10:05 ——– d—–w- c:\documents and settings\MONA\Application Data\Yahoo!
2009-11-28 09:56 . 2009-11-28 09:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-11-28 09:56 . 2009-11-28 09:54 ——– d—–w- c:\program files\Yahoo!
2009-11-28 08:22 . 2009-11-28 08:22 0 —-a-w- c:\windows\nsreg.dat
2009-11-28 08:10 . 2009-11-23 23:42 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-28 02:55 . 2009-11-28 02:55 ——– d—–w- c:\program files\Trend Micro
2009-11-28 02:53 . 2009-11-28 02:53 ——– d—–w- c:\documents and settings\MONA\Application Data\Malwarebytes
2009-11-28 02:53 . 2009-11-28 02:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-26 19:46 . 2009-11-26 19:46 ——– d—–w- c:\program files\MSXML 4.0
2009-11-24 07:04 . 2009-11-24 07:04 12328 —-a-w- c:\documents and settings\MONA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-24 07:04 . 2009-11-24 07:04 127 —-a-w- c:\documents and settings\MONA\Local Settings\Application Data\fusioncache.dat
2009-11-24 06:56 . 2009-11-24 06:43 104253 —-a-w- c:\windows\hpoins04.dat
2009-11-24 06:55 . 2009-11-24 06:44 ——– d—–w- c:\program files\HP
2009-11-24 06:52 . 2009-11-24 06:52 ——– d—–w- c:\program files\Common Files\HP
2009-11-24 06:50 . 2009-11-24 06:50 ——– d—–w- c:\program files\Hewlett-Packard
2009-11-24 06:50 . 2009-11-24 06:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-11-24 06:50 . 2009-11-24 06:50 45056 —-a-r- c:\documents and settings\MONA\Application Data\Microsoft\Installer\{457791C5-D702-4143-A7B2-2744BE9573F2}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2009-11-24 06:48 . 2009-11-24 06:48 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2009-11-24 00:25 . 2009-11-24 00:25 ——– d—–w- c:\program files\Realtek AC97
2009-11-23 23:43 . 2009-11-23 23:43 ——– d—–w- c:\program files\microsoft frontpage
2009-11-23 23:39 . 2009-11-23 23:39 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-11-10 22:39 . 2009-11-28 09:56 607472 —-a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-10-29 05:48 . 2006-02-28 12:00 662016 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 06:00 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2006-02-28 12:00 263552 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:53 . 2006-02-28 12:00 266752 —-a-w- c:\windows\system32\oakley.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2008-09-30 485208]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-30 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"VX6000"="c:\windows\vVX6000.exe" [2009-06-27 759296]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [6/26/2009 5:21 PM 2069504]
.
.
——- Supplementary Scan ——-
.
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - c:\documents and settings\MONA\Application Data\Mozilla\Firefox\Profiles\s8owchhj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2464976&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Playdom Customized Web Search
FF - component: c:\documents and settings\MONA\Application Data\Mozilla\Firefox\Profiles\s8owchhj.default\extensions\{69d1a568-ffdf-4ef5-8919-7003582e0ee8}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\MONA\Application Data\Mozilla\Firefox\Profiles\s8owchhj.default\extensions\{69d1a568-ffdf-4ef5-8919-7003582e0ee8}\components\RadioWMPCore.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-10 18:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-583907252-854245398-1801674531-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\progra~1\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2010-01-10 18:27:43 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-11 02:27

Pre-Run: 106,392,903,680 bytes free
Post-Run: 106,652,360,704 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 06AA77FD5C1D019D30719B0454F1EC83
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\ezsidmv.dat

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"=-

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log


Also please describe how your computer behaves at the moment.
done….. and here is a copy of the new log…. and at the moment… the computer is not doing the annoying internet explorer pop ups… yay… because that was super annoying… at any rate.. here is a copy of the log… and i am only doing what you ask… so i have not tried to run malwarebytes or anything else for that matter… so far so good tho… i know that whenever i come here i can always count on getting my pc back to running order… i really appreciate your effort and time in helping me…

ComboFix 10-01-04.01 - MONA 01/10/2010 18:53:47.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.693 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ABCD.exe
Command switches used :: c:\documents and settings\MONA\Desktop\CFScript.txt

FILE ::
"c:\windows\system32\ezsidmv.dat"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ezsidmv.dat

.
((((((((((((((((((((((((( Files Created from 2009-12-11 to 2010-01-11 )))))))))))))))))))))))))))))))
.

2010-01-11 01:12 . 2010-01-08 00:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-11 01:12 . 2010-01-11 01:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-11 01:12 . 2010-01-08 00:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-08 10:22 . 2010-01-08 10:22 ——– d—–w- c:\program files\MSXML 6.0
2009-12-26 07:22 . 2009-12-24 03:07 52224 —-a-w- c:\documents and settings\MONA\Application Data\Mozilla\Firefox\Profiles\s8owchhj.default\extensions\{69d1a568-ffdf-4ef5-8919-7003582e0ee8}\components\FFExternalAlert.dll
2009-12-26 07:22 . 2009-12-24 03:07 101376 —-a-w- c:\documents and settings\MONA\Application Data\Mozilla\Firefox\Profiles\s8owchhj.default\extensions\{69d1a568-ffdf-4ef5-8919-7003582e0ee8}\components\RadioWMPCore.dll
2009-12-26 00:15 . 2010-01-03 20:53 ——– d—–w- c:\documents and settings\MONA\Local Settings\Application Data\Digital Concepts Image Manager
2009-12-26 00:15 . 2009-12-26 00:15 ——– d—–w- c:\documents and settings\All Users\Application Data\DigitalConcepts
2009-12-26 00:15 . 2009-12-26 00:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Digital Concepts Image Manager
2009-12-26 00:14 . 2009-12-26 00:14 ——– d—–w- c:\program files\Haali
2009-12-26 00:13 . 2010-01-03 20:53 ——– d—–w- c:\program files\Digital Concepts Image Manager
2009-12-17 02:07 . 2006-02-28 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-11 02:24 . 2009-12-12 02:39 ——– d—–w- c:\documents and settings\MONA\Application Data\Skype
2010-01-10 08:00 . 2009-11-24 04:21 ——– d—–w- c:\program files\PokerStars
2010-01-10 02:27 . 2009-11-28 18:10 20 —h–w- c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
2010-01-10 02:26 . 2009-11-28 18:05 20 —h–w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-12-30 00:03 . 2009-12-12 02:41 ——– d—–w- c:\documents and settings\MONA\Application Data\skypePM
2009-12-20 20:33 . 2009-11-24 04:22 ——– d—–w- c:\program files\Full Tilt Poker
2009-12-19 23:31 . 2009-12-05 11:39 ——– d—–w- c:\program files\Absolute Poker
2009-12-19 07:46 . 2009-11-30 05:06 79488 —-a-w- c:\documents and settings\MONA\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-12 02:39 . 2009-12-12 02:38 ——– d—–r- c:\program files\Skype
2009-12-12 02:38 . 2009-12-12 02:38 ——– d—–w- c:\program files\Common Files\Skype
2009-12-12 02:38 . 2009-12-12 02:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-12-05 11:41 . 2009-12-05 11:41 147456 —-a-w- c:\documents and settings\MONA\Application Data\Absolute Poker\DownLoadInst\liveupdate.exe
2009-12-05 11:41 . 2009-12-05 11:39 ——– d—–w- c:\documents and settings\MONA\Application Data\Absolute Poker
2009-12-05 11:39 . 2009-12-05 11:39 ——– d—–w- c:\program files\_uninstallation_info
2009-12-02 17:53 . 2009-12-02 17:52 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-30 05:07 . 2009-11-30 05:07 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-30 05:07 . 2009-11-30 05:07 ——– d—–w- c:\program files\Java
2009-11-30 05:06 . 2009-11-30 05:06 152576 —-a-w- c:\documents and settings\MONA\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-28 18:38 . 2009-11-28 18:22 ——– d—–w- c:\documents and settings\MONA\Application Data\Nikon
2009-11-28 18:22 . 2009-11-28 18:06 ——– d—–w- c:\program files\Common Files\Nikon
2009-11-28 18:11 . 2009-11-28 18:11 57344 —-a-r- c:\documents and settings\MONA\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2009-11-28 18:10 . 2009-11-28 18:05 ——– d—–w- c:\program files\Nikon
2009-11-28 18:10 . 2009-11-28 18:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Ultima_T15
2009-11-28 18:10 . 2009-11-28 18:05 ——– d—–w- c:\documents and settings\All Users\Application Data\EnterNHelp
2009-11-28 18:07 . 2009-11-28 18:07 49152 —-a-r- c:\documents and settings\MONA\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
2009-11-28 18:07 . 2009-11-28 18:07 335872 —-a-r- c:\documents and settings\MONA\Application Data\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe
2009-11-28 18:06 . 2009-11-28 18:06 ——– d—–w- c:\program files\Common Files\muvee Technologies
2009-11-28 18:06 . 2009-11-28 18:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Nikon
2009-11-28 18:05 . 2009-11-24 00:24 ——– d—–w- c:\program files\Common Files\InstallShield
2009-11-28 18:02 . 2009-11-28 18:02 ——– d—–w- c:\program files\ArcSoft
2009-11-28 18:02 . 2009-11-24 00:25 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-11-28 10:05 . 2009-11-28 10:05 ——– d—–w- c:\documents and settings\MONA\Application Data\Yahoo!
2009-11-28 09:56 . 2009-11-28 09:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-11-28 09:56 . 2009-11-28 09:54 ——– d—–w- c:\program files\Yahoo!
2009-11-28 08:22 . 2009-11-28 08:22 0 —-a-w- c:\windows\nsreg.dat
2009-11-28 08:10 . 2009-11-23 23:42 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-28 02:55 . 2009-11-28 02:55 ——– d—–w- c:\program files\Trend Micro
2009-11-28 02:53 . 2009-11-28 02:53 ——– d—–w- c:\documents and settings\MONA\Application Data\Malwarebytes
2009-11-28 02:53 . 2009-11-28 02:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-26 19:46 . 2009-11-26 19:46 ——– d—–w- c:\program files\MSXML 4.0
2009-11-24 07:04 . 2009-11-24 07:04 12328 —-a-w- c:\documents and settings\MONA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-24 07:04 . 2009-11-24 07:04 127 —-a-w- c:\documents and settings\MONA\Local Settings\Application Data\fusioncache.dat
2009-11-24 06:56 . 2009-11-24 06:43 104253 —-a-w- c:\windows\hpoins04.dat
2009-11-24 06:55 . 2009-11-24 06:44 ——– d—–w- c:\program files\HP
2009-11-24 06:52 . 2009-11-24 06:52 ——– d—–w- c:\program files\Common Files\HP
2009-11-24 06:50 . 2009-11-24 06:50 ——– d—–w- c:\program files\Hewlett-Packard
2009-11-24 06:50 . 2009-11-24 06:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-11-24 06:50 . 2009-11-24 06:50 45056 —-a-r- c:\documents and settings\MONA\Application Data\Microsoft\Installer\{457791C5-D702-4143-A7B2-2744BE9573F2}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2009-11-24 06:48 . 2009-11-24 06:48 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2009-11-24 00:25 . 2009-11-24 00:25 ——– d—–w- c:\program files\Realtek AC97
2009-11-23 23:43 . 2009-11-23 23:43 ——– d—–w- c:\program files\microsoft frontpage
2009-11-23 23:39 . 2009-11-23 23:39 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-11-10 22:39 . 2009-11-28 09:56 607472 —-a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-10-29 05:48 . 2006-02-28 12:00 662016 ——w- c:\windows\system32\wininet.dll
2009-10-21 06:00 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2006-02-28 12:00 263552 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:53 . 2006-02-28 12:00 266752 —-a-w- c:\windows\system32\oakley.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2008-09-30 485208]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-30 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"VX6000"="c:\windows\vVX6000.exe" [2009-06-27 759296]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [6/26/2009 5:21 PM 2069504]
.
.
——- Supplementary Scan ——-
.
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - c:\documents and settings\MONA\Application Data\Mozilla\Firefox\Profiles\s8owchhj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2464976&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Playdom Customized Web Search
FF - component: c:\documents and settings\MONA\Application Data\Mozilla\Firefox\Profiles\s8owchhj.default\extensions\{69d1a568-ffdf-4ef5-8919-7003582e0ee8}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\MONA\Application Data\Mozilla\Firefox\Profiles\s8owchhj.default\extensions\{69d1a568-ffdf-4ef5-8919-7003582e0ee8}\components\RadioWMPCore.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-10 18:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-583907252-854245398-1801674531-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2010-01-10 18:59:40
ComboFix-quarantined-files.txt 2010-01-11 02:59
ComboFix2.txt 2010-01-11 02:27

Pre-Run: 106,651,824,128 bytes free
Post-Run: 106,646,982,656 bytes free

- - End Of File - - 866D3CDD1A7D323574A84330411DB82A

jumps up and down for joy… it works… yay!!! i am running a full scan right now… is there anything i need to do after that?

You didn't need to run the FULL scan. The quick one will work.
When it's finished post the scan results.

We're not finished yet.
k…. i ran malware bytes… here is a copy of the log… also plz note that it said no malicious files were found~~ Malwarebytes' Anti-Malware 1.44 Database version: 3510 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 1/10/2010 7:18:57 PM mbam-log-2010-01-10 (19-18-57).txt Scan type: Quick Scan Objects scanned: 101587 Time elapsed: 5 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    To be on the safe side, I would also change all my passwords.


    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.


I would suggest you read How to Prevent Malware:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI