This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected desktop with XP please help!

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been having problems getting rid of an unknown infection or infections on my desktop for the last month, it runs the Windows XP OS and I use Microsoft Security Essentials as AV program. I was reading a topic posted by someone with a similar problem so I already completed the tasks that were suggested to them. I downloaded and ran both ATF cleaner and combo fix. I have posted the log from combo fix below, can someone please tell me what to do next? Thanks


Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.112 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\MSN6
c:\documents and settings\All Users\Application Data\MSN6\au.ini
c:\documents and settings\Owner\Application Data\ezLife
c:\documents and settings\Owner\Application Data\Messenger
c:\documents and settings\Owner\Application Data\Messenger\Drivers\Aud32\msgasst84.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\Aud32\msgutil84.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\conf.sys
c:\documents and settings\Owner\Application Data\Messenger\Drivers\IgfxSys.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\MsgUpdate.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\serial.sys
c:\documents and settings\Owner\Application Data\MSN6
c:\documents and settings\Owner\Application Data\MSN6\msndata.dat
c:\documents and settings\Owner\Application Data\Smart-Ads-Solutions
c:\documents and settings\Owner\Application Data\SystemProc
C:\Documents
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
c:\windows\system32\flags.ini
c:\windows\system32\helper32.dll
c:\windows\system32\IS15.exe
c:\windows\system32\kbdsock.dll
c:\windows\system32\mshlps.dll
c:\windows\system32\uses32.dat
c:\windows\system32\warning.html

—– BITS: Possible infected sites —–

hxxp://85.12.18.119
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2009-12-24 to 2010-01-24 )))))))))))))))))))))))))))))))
.

2010-01-22 22:26 . 2010-01-22 22:26 30784 —-a-w- c:\windows\system32\drivers\xfkkyisy.sys
2010-01-22 04:46 . 2010-01-22 05:29 ——– d—–w- c:\documents and settings\Owner\.lincity-ng
2010-01-20 23:10 . 2010-01-20 23:10 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Eastman_Kodak_Company
2010-01-20 23:10 . 2010-01-20 23:10 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Eastman Kodak Company
2010-01-20 02:49 . 2010-01-20 02:49 ——– d—–w- c:\documents and settings\Owner\.lincity
2010-01-20 02:47 . 2010-01-22 04:54 ——– d—–w- c:\program files\LinCity-NG
2010-01-20 02:44 . 2010-01-20 02:44 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-01-19 20:13 . 2010-01-19 20:13 30784 —-a-w- c:\windows\system32\drivers\csofzotk.sys
2010-01-19 20:03 . 2010-01-19 20:03 30784 —-a-w- c:\windows\system32\drivers\rhidanio.sys
2010-01-19 18:28 . 2010-01-19 18:40 ——– d—–w- c:\documents and settings\Owner\Application Data\IObit
2010-01-19 18:28 . 2010-01-20 02:44 ——– d—–w- c:\program files\IObit
2010-01-19 01:45 . 2010-01-19 01:45 ——– d-sh–w- c:\documents and settings\Kayla\PrivacIE
2010-01-17 18:13 . 2010-01-17 18:14 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Google
2010-01-17 16:14 . 2010-01-17 16:14 48285 —-a-w- c:\windows\system32\rybrywrprkzny.exe
2010-01-17 04:19 . 2010-01-17 04:19 ——– d—–w- c:\documents and settings\The Smiths\Local Settings\Application Data\Google
2010-01-17 04:17 . 2010-01-17 04:18 ——– d—–w- c:\documents and settings\The Smiths
2010-01-16 17:43 . 2010-01-16 17:43 30784 —-a-w- c:\windows\system32\drivers\rzirkovx.sys
2010-01-15 06:41 . 2010-01-15 06:41 53788 —ha-w- c:\windows\system32\mlfcache.dat
2010-01-15 06:23 . 2010-01-15 06:24 ——– d—–w- c:\program files\Microsoft Security Essentials
2010-01-13 13:51 . 2010-01-13 13:51 30784 —-a-w- c:\windows\system32\drivers\ijxqeapu.sys
2010-01-12 18:53 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-10 15:02 . 2010-01-14 16:12 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-10 04:43 . 2010-01-10 04:50 ——– d—–w- c:\program files\Windows Live Safety Center
2010-01-10 04:04 . 2010-01-10 04:04 45568 –sh–w- c:\windows\system32\zijaputa.dll
2010-01-10 03:10 . 2010-01-10 03:10 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-10 02:55 . 2010-01-10 02:55 ——– d-sh–w- c:\documents and settings\Owner\.COMMgr
2010-01-08 15:01 . 2010-01-08 15:01 494080 —-a-w- c:\windows\system32\vclenowrbhoxi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-24 05:48 . 2008-06-20 17:18 ——– d—–w- c:\documents and settings\Owner\Application Data\LimeWire
2010-01-24 01:58 . 2008-07-09 14:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-01-22 23:02 . 2008-05-30 02:29 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-01-22 23:02 . 2008-05-30 02:29 96512 —-a-w- c:\windows\system32\drivers\atapi.svs
2010-01-20 17:03 . 2009-07-11 03:42 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-19 20:13 . 2010-01-19 20:13 96512 —-a-w- c:\windows\system32\drivers\atapi.sysFD1A42C6
2010-01-17 18:13 . 2010-01-17 18:13 70960 —-a-w- c:\documents and settings\Kayla\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-17 04:18 . 2010-01-17 04:18 70960 —-a-w- c:\documents and settings\The Smiths\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-14 03:58 . 2008-06-13 03:55 ——– d—–w- c:\program files\Java
2010-01-14 03:43 . 2009-03-17 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-01-10 15:38 . 2008-06-19 19:22 ——– d—–w- c:\program files\Hells Kitchen
2010-01-10 08:11 . 2008-10-13 04:21 ——– d—–w- c:\documents and settings\Owner\Application Data\Yahoo!
2010-01-10 03:38 . 2008-05-31 04:19 70960 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-25 20:15 . 2008-06-24 20:31 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-22 08:00 . 2006-10-28 12:11 63 —-a-w- c:\windows\Fonts\Readme.txt
2009-12-21 19:14 . 2006-06-23 15:33 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-17 02:08 . 2008-05-30 03:47 ——– d—–w- c:\program files\Google
2009-12-13 05:02 . 2008-06-20 17:15 ——– d—–w- c:\program files\LimeWire
2009-11-21 15:51 . 2002-09-03 16:26 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-16 08:42 . 2009-11-16 08:42 286720 —-a-w- c:\windows\system32\thbocwwa.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-31 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-01-06 2335952]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-21 468408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2002-06-19 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2002-06-19 114688]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2008-02-15 1052672]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-06 122368]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-14 149280]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-11-14 1278736]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-6-18 147456]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [1/19/2010 9:44 PM 312592]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [2/28/2008 4:57 PM 18944]
S2 gupdate1c9f2161b370444;Google Update Service (gupdate1c9f2161b370444);c:\program files\Google\Update\GoogleUpdate.exe [6/20/2009 9:13 PM 133104]
S3 MailScan;MailScan;\??\c:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys –> c:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys [?]
S3 TFilter;TFilter;\??\c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys –> c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-01-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-30 06:59]

2010-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-21 02:13]

2010-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-21 02:13]

2010-01-24 c:\windows\Tasks\User_Feed_Synchronization-{F30DD53A-C370-4B8A-9FDA-32233C3929F7}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.centurylink.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: mlb.com\secure
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{02ac71e4-2e16-426e-9c3a-fc0f2f27b08e} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-24 01:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-01-24 01:06:25
ComboFix-quarantined-files.txt 2010-01-24 06:06

Pre-Run: 52,789,854,208 bytes free
Post-Run: 52,784,582,656 bytes free
We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache

Next:

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\drivers\xfkkyisy.sys
c:\windows\system32\drivers\csofzotk.sys
c:\windows\system32\drivers\rhidanio.sys
c:\windows\system32\rybrywrprkzny.exe
c:\windows\system32\drivers\rzirkovx.sys
c:\windows\system32\drivers\ijxqeapu.sys
c:\windows\system32\zijaputa.dll
c:\windows\system32\vclenowrbhoxi.dll
c:\windows\system32\thbocwwa.dll

Driver::
xfkkyisy
csofzotk
rhidanio
rzirkovx
ijxqeapu

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log

Also please describe how your computer behaves at the moment.
I did as you instructed and I noticed nothing different about the computer while running combofix except the disappearance of the desktop icons and taskbar while the scan was being performed. The log is posted below:

ComboFix 10-01-25.02 - Owner 01/25/2010 23:26:24.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.218 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

FILE ::
"c:\windows\system32\drivers\csofzotk.sys"
"c:\windows\system32\drivers\ijxqeapu.sys"
"c:\windows\system32\drivers\rhidanio.sys"
"c:\windows\system32\drivers\rzirkovx.sys"
"c:\windows\system32\drivers\xfkkyisy.sys"
"c:\windows\system32\rybrywrprkzny.exe"
"c:\windows\system32\thbocwwa.dll"
"c:\windows\system32\vclenowrbhoxi.dll"
"c:\windows\system32\zijaputa.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\csofzotk.sys
c:\windows\system32\drivers\ijxqeapu.sys
c:\windows\system32\drivers\rhidanio.sys
c:\windows\system32\drivers\rzirkovx.sys
c:\windows\system32\drivers\xfkkyisy.sys
c:\windows\system32\rybrywrprkzny.exe
c:\windows\system32\thbocwwa.dll
c:\windows\system32\vclenowrbhoxi.dll
c:\windows\system32\zijaputa.dll

.
((((((((((((((((((((((((( Files Created from 2009-12-26 to 2010-01-26 )))))))))))))))))))))))))))))))
.

2010-01-22 04:46 . 2010-01-22 05:29 ——– d—–w- c:\documents and settings\Owner\.lincity-ng
2010-01-20 23:10 . 2010-01-20 23:10 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Eastman_Kodak_Company
2010-01-20 23:10 . 2010-01-20 23:10 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Eastman Kodak Company
2010-01-20 02:49 . 2010-01-20 02:49 ——– d—–w- c:\documents and settings\Owner\.lincity
2010-01-20 02:47 . 2010-01-22 04:54 ——– d—–w- c:\program files\LinCity-NG
2010-01-20 02:44 . 2010-01-20 02:44 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-01-19 18:28 . 2010-01-19 18:40 ——– d—–w- c:\documents and settings\Owner\Application Data\IObit
2010-01-19 18:28 . 2010-01-20 02:44 ——– d—–w- c:\program files\IObit
2010-01-19 01:45 . 2010-01-19 01:45 ——– d-sh–w- c:\documents and settings\Kayla\PrivacIE
2010-01-17 18:13 . 2010-01-17 18:14 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Google
2010-01-17 18:13 . 2010-01-17 18:13 70960 —-a-w- c:\documents and settings\Kayla\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-17 18:13 . 2010-01-17 18:13 ——– d-sh–w- c:\documents and settings\Kayla\IETldCache
2010-01-17 04:19 . 2010-01-17 04:19 ——– d—–w- c:\documents and settings\The Smiths\Local Settings\Application Data\Google
2010-01-17 04:17 . 2010-01-17 04:18 ——– d—–w- c:\documents and settings\The Smiths
2010-01-15 06:41 . 2010-01-15 06:41 53788 —ha-w- c:\windows\system32\mlfcache.dat
2010-01-15 06:23 . 2010-01-15 06:24 ——– d—–w- c:\program files\Microsoft Security Essentials
2010-01-12 18:53 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-10 15:02 . 2010-01-14 16:12 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-10 04:43 . 2010-01-10 04:50 ——– d—–w- c:\program files\Windows Live Safety Center
2010-01-10 03:10 . 2010-01-10 03:10 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-10 02:55 . 2010-01-10 02:55 ——– d-sh–w- c:\documents and settings\Owner\.COMMgr

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-26 04:09 . 2008-06-20 17:18 ——– d—–w- c:\documents and settings\Owner\Application Data\LimeWire
2010-01-25 18:23 . 2008-07-09 14:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-01-22 23:02 . 2008-05-30 02:29 96512 —-a-w- c:\windows\system32\drivers\atapi.svs
2010-01-22 23:02 . 2008-05-30 02:29 96512 ——w- c:\windows\system32\drivers\atapi.sys
2010-01-20 17:03 . 2009-07-11 03:42 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-19 20:13 . 2010-01-19 20:13 96512 —-a-w- c:\windows\system32\drivers\atapi.sysFD1A42C6
2010-01-17 04:18 . 2010-01-17 04:18 70960 —-a-w- c:\documents and settings\The Smiths\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-14 03:58 . 2008-06-13 03:55 ——– d—–w- c:\program files\Java
2010-01-14 03:43 . 2009-03-17 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-01-10 15:38 . 2008-06-19 19:22 ——– d—–w- c:\program files\Hells Kitchen
2010-01-10 08:11 . 2008-10-13 04:21 ——– d—–w- c:\documents and settings\Owner\Application Data\Yahoo!
2010-01-10 03:38 . 2008-05-31 04:19 70960 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-25 20:15 . 2008-06-24 20:31 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-22 08:00 . 2006-10-28 12:11 63 —-a-w- c:\windows\Fonts\Readme.txt
2009-12-21 19:14 . 2006-06-23 15:33 916480 ——w- c:\windows\system32\wininet.dll
2009-12-17 02:08 . 2008-05-30 03:47 ——– d—–w- c:\program files\Google
2009-12-13 05:02 . 2008-06-20 17:15 ——– d—–w- c:\program files\LimeWire
2009-11-21 15:51 . 2002-09-03 16:26 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-01-24_06.00.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-25 22:52 . 2010-01-25 22:52 16384 c:\windows\Temp\Perflib_Perfdata_738.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-31 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-01-06 2335952]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-21 468408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2002-06-19 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2002-06-19 114688]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2008-02-15 1052672]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-06 122368]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-14 149280]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-11-14 1278736]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-6-18 147456]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [1/19/2010 9:44 PM 312592]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [2/28/2008 4:57 PM 18944]
S2 gupdate1c9f2161b370444;Google Update Service (gupdate1c9f2161b370444);c:\program files\Google\Update\GoogleUpdate.exe [6/20/2009 9:13 PM 133104]
S3 MailScan;MailScan;\??\c:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys –> c:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys [?]
S3 TFilter;TFilter;\??\c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys –> c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-01-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-30 06:59]

2010-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-21 02:13]

2010-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-21 02:13]

2010-01-26 c:\windows\Tasks\User_Feed_Synchronization-{F30DD53A-C370-4B8A-9FDA-32233C3929F7}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.centurylink.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: mlb.com\secure
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -

AddRemove-rybrywrprkzny - c:\windows\system32\rybrywrprkzny.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-25 23:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-01-25 23:41:05
ComboFix-quarantined-files.txt 2010-01-26 04:41
ComboFix2.txt 2010-01-24 06:06

Pre-Run: 52,815,073,280 bytes free
Post-Run: 52,859,043,840 bytes free

- - End Of File - - 1F865B0A60A0CCCEAEEA53E9F89D7ACF


What needs to be done next. I appreciate your help Thanks
No, and after my AV program did a sacn last nite, it found no questionable files. That was the first time since this whole thing started that it hasn't had to delete or quarantine a file during the scan. Thanks so much
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    To be on the safe side, I would also change all my passwords.


    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.


I would suggest you read How to Prevent Malware:
I have completed each of the steps you have recommended to me, and I hope this will help my pc to remain virus free. I really and truly am grateful for the help and wonderful advice that you have given me. You are a PC genius sir!!! Thanks again.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI