This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] can't update security ............

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

karpersky and DDS logs below ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, February 17, 2010 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, February 16, 2010 14:44:05 Records in database: 3518612 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Objects scanned: 215201 Threats found: 5 Infected objects found: 7 Suspicious objects found: 7 Scan duration: 04:49:46 File name / Threat / Threats count C:\Program Files\Adobe\Photoshop 7.0\Samples\Droplets\Photoshop Droplets\Aged Photo.exe Infected: Trojan-Downloader.Win32.Agent.dcnp 1 C:\Documents and Settings\pete\Local Settings\Application Data\Identities\{A145BF2C-2882-4706-9C1B-53BDB71A5844}\Microsoft\Outlook Express\Deleted Items.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 2 C:\Documents and Settings\kate\Desktop\songz for bart\usher uturn.mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1 C:\Documents and Settings\kate\Application Data\Sun\Java\Deployment\cache\6.0\52\2d46f834-6ee6ef74 Infected: Trojan.Java.Binny.a 2 C:\Documents and Settings\kate\Application Data\Sun\Java\Deployment\cache\6.0\52\2d46f834-3b451848 Infected: Trojan.Java.Binny.a 2 C:\Documents and Settings\lucy\Application Data\Sun\Java\Deployment\cache\6.0\22\d1ed7d6-3d62f534 Infected: Trojan-Downloader.Java.OpenConnection.at 1 C:\Documents and Settings\gillian\Local Settings\Application Data\Identities\{D603AC8E-7ED3-415F-A971-DF3F9471DCC6}\Microsoft\Outlook Express\Deleted Items.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 5 Selected area has been scanned. DDS (Ver_09-06-26.01) - FAT32x86 Run by [removed] at 9:44:59.81 on 17/02/2010 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_18 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.216 [GMT 0:00] AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch SVCHOST.EXE C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup SVCHOST.EXE SVCHOST.EXE C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe SVCHOST.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\sistray.EXE C:\Program Files\Multimedia Keyboard\PS2USBKbdDrv.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\System32\PAStiSvc.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Opera\opera.exe C:\Documents and Settings\pete\My Documents\dds.scr ============== Pseudo HJT Report =============== uDefault_Search_URL = uStart Page = hxxp://www.google.co.uk/ mStart Page = Ze2 mSearch Bar = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = 127.0.0.1 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/keyword/%s BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: ST: {9394ede7-c8b5-483e-8773-474bf36af6e4} - c:\program files\msn apps\st\01.03.0000.1005\en-xu\stmain.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: MSNToolBandBHO: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: MSN: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File mRun: [SiSUSBRG] c:\windows\SiSUSBrg.exe mRun: [SiS Tray] c:\windows\system32\sistray.EXE mRun: [SiS Windows KeyHook] c:\windows\system32\keyhook.exe mRun: [WireLessKeyboard] c:\program files\multimedia keyboard\PS2USBKbdDrv.exe mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [D-Link D-Link Wireless N DWA-140] c:\program files\d-link\d-link wireless n dwa-140\AirNCFG.exe mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\pete\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe IE: &Search IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe Trusted Zone: moove.com DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {00000161-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} - hxxp://musicmix.messenger.msn.com/Medialogic.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab AppInit_DLLs: c:\windows\system32\guard32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\pete\applic~1\mozilla\firefox\profiles\7be4294a.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.bbc.co.uk/ FF - prefs.js: network.proxy.type - 4 FF - component: c:\documents and settings\pete\application data\mozilla\firefox\profiles\7be4294a.default\extensions\[removed]\components\coolirisstub.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess"); c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess"); c:\program files\mozilla firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess"); ============= SERVICES / DRIVERS =============== R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-2-5 162512] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-8-24 134344] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-8-24 25160] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-2-5 19024] R2 GenPort;GenPort;c:\windows\system32\drivers\genport.sys [2005-4-20 4832] R2 MapMem;MapMem;c:\windows\system32\drivers\MAPMEM.SYS [2005-4-20 6816] R2 NTRemap;NTRemap;c:\windows\system32\drivers\NTREMAP.SYS [2005-4-20 6336] S1 SiSEsc;SISLIB_ESC;c:\windows\system32\sisesc.sys [2005-4-4 28416] S2 https;https;\??\c:\windows\system32\drivers\https.sys –> c:\windows\system32\drivers\https.sys [?] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-12-21 13224] S3 iMSPQMn;iMSPQMn;\??\c:\docume~1\pete\locals~1\temp\imspqmn.sys –> c:\docume~1\pete\locals~1\temp\iMSPQMn.sys [?] S3 MadgeTRN;Madge Token-Ring Adapter NDIS5 Driver;c:\windows\system32\drivers\mdgndis5.sys [2006-9-11 164586] S3 PAC207;SoC PC-Camer@;c:\windows\system32\drivers\pfc027.sys –> c:\windows\system32\drivers\pfc027.sys [?] S3 RegGuard;RegGuard;c:\windows\system32\drivers\regguard.sys [2007-3-9 25773] S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2010-1-24 476416] S3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;c:\windows\system32\drivers\usbscan.sys [2005-5-5 15104] S3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\drivers\s816bus.sys [2009-8-11 81832] S3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;c:\windows\system32\drivers\s816mdfl.sys [2009-8-11 13864] S3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;c:\windows\system32\drivers\s816mdm.sys [2009-8-11 107304] S3 s816mgmt;Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s816mgmt.sys [2009-8-11 99112] S3 s816nd5;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS);c:\windows\system32\drivers\s816nd5.sys [2009-8-11 21928] S3 s816obex;Sony Ericsson Device 816 USB WMC OBEX Interface;c:\windows\system32\drivers\s816obex.sys [2009-8-11 97320] S3 s816unic;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM);c:\windows\system32\drivers\s816unic.sys [2009-8-11 97704] S3 usb2vcom;USB Data Cable;c:\windows\system32\drivers\usb2vcom.sys [2006-8-2 29152] =============== Created Last 30 ================ 2010-02-15 19:59 411,368 a——- c:\windows\system32\deploytk.dll 2010-02-15 19:59 73,728 a——- c:\windows\system32\javacpl.cpl 2010-02-12 21:35 –dsh— C:\Recycled 2010-02-12 12:03 a-dshr– C:\cmdcons 2010-02-12 12:02 261,632 a——- c:\windows\PEV.exe 2010-02-12 12:02 161,792 a——- c:\windows\SWREG.exe 2010-02-12 12:02 98,816 a——- c:\windows\sed.exe 2010-02-12 12:02 77,312 a——- c:\windows\MBR.exe 2010-02-11 19:14 –d—– C:\FOUND.071 2010-02-09 14:30 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-09 14:30 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-02-09 14:30 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-02-09 11:18 –d—– C:\FOUND.070 2010-02-08 17:10 –d—– c:\program files\YouTube Downloader 2010-02-07 21:21 –d—– c:\docume~1\pete\applic~1\Malwarebytes 2010-02-07 21:18 –d—– c:\docume~1\alluse~1.win\applic~1\Malwarebytes 2010-02-05 20:11 –d—– c:\docume~1\alluse~1.win\applic~1\Alwil Software 2010-01-26 18:39 3,284 a——- c:\windows\system32\ANIWZCS{962B5B47-5E88-4350-A0CB-F717AC6E0D10} 2010-01-25 12:52 –d—– C:\FOUND.069 2010-01-24 19:47 5 a——- c:\windows\system32\ANIWZCSUSERNAME{962B5B47-5E88-4350-A0CB-F717AC6E0D10} 2010-01-24 19:47 1,327,189 a——- c:\windows\system32\odSupp_M.dll 2010-01-24 19:47 249,856 a——- c:\windows\system32\wnicapi.dll 2010-01-24 19:47 225,280 a——- c:\windows\system32\WlanApp.dll 2010-01-24 19:47 204,800 a——- c:\windows\system32\aIPH.dll 2010-01-24 19:47 49,152 a——- c:\windows\system32\JJAKEn.dll 2010-01-24 19:47 667,648 a——- c:\windows\system32\ANIWZCS2.dll 2010-01-24 19:47 49,152 a——- c:\windows\system32\AQCKGen.dll 2010-01-24 19:47 45,115 a——- c:\windows\system32\ANICtl.dll 2010-01-24 19:46 48,128 a——- c:\windows\system32\ANIO64.sys 2010-01-24 19:46 36,864 a——- c:\windows\system32\ANIOApi.dll 2010-01-24 19:46 28,195 a——- c:\windows\system32\ANIO.sys 2010-01-24 19:46 16,997 a——- c:\windows\system32\ANIO.VXD 2010-01-24 19:46 11,904 a——- c:\windows\system32\anio4.sys 2010-01-24 19:46 –d—– c:\program files\ANI 2010-01-24 19:45 –d—– c:\program files\D-Link 2010-01-24 19:43 476,416 a——- c:\windows\system32\drivers\rt2870.sys 2010-01-23 12:20 –d—– C:\FOUND.068 ==================== Find3M ==================== 2010-02-02 15:51 171,552 a——- c:\windows\system32\guard32.dll 2010-02-02 15:51 134,344 a——- c:\windows\system32\drivers\cmdguard.sys 2010-01-31 21:11 25,160 a——- c:\windows\system32\drivers\cmdhlp.sys 2009-12-31 16:14 352,640 a——- c:\windows\system32\drivers\srv.sys 2009-12-31 16:14 352,640 ——– c:\windows\system32\dllcache\srv.sys 2009-12-21 22:01 0 a—h— c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf 2009-12-21 22:01 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf 2009-12-21 21:55 1,112,288 a——- c:\windows\system32\WdfCoInstaller01007.dll 2009-12-21 21:55 25,512 a——- c:\windows\system32\drivers\ggsemc.sys 2009-12-21 21:55 13,224 a——- c:\windows\system32\drivers\ggflt.sys 2009-12-16 12:58 343,040 a——- c:\windows\system32\mspaint.exe 2009-12-16 12:58 343,040 ——– c:\windows\system32\dllcache\mspaint.exe 2009-12-16 12:57 18,432 ——– c:\windows\system32\dllcache\iedw.exe 2009-12-08 18:55 2,180,352 ——– c:\windows\system32\dllcache\ntoskrnl.exe 2009-12-08 18:53 2,136,064 ——– c:\windows\system32\ntoskrnl.exe 2009-12-08 18:53 2,136,064 ——– c:\windows\system32\dllcache\ntkrnlmp.exe 2009-12-08 18:19 2,057,728 ——– c:\windows\system32\dllcache\ntkrnlpa.exe 2009-12-08 18:19 2,015,744 ——– c:\windows\system32\ntkrnlpa.exe 2009-12-08 18:19 2,015,744 ——– c:\windows\system32\dllcache\ntkrpamp.exe 2009-12-08 09:13 474,112 ——– c:\windows\system32\dllcache\shlwapi.dll 2009-12-04 14:41 453,760 ——– c:\windows\system32\dllcache\mrxsmb.sys 2009-11-27 17:33 1,291,264 a——- c:\windows\system32\quartz.dll 2009-11-27 17:33 17,920 a——- c:\windows\system32\msyuv.dll 2009-11-27 17:33 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-11-27 17:33 17,920 ——– c:\windows\system32\dllcache\msyuv.dll 2009-11-27 16:37 84,992 a——- c:\windows\system32\avifil32.dll 2009-11-27 16:37 48,128 a——- c:\windows\system32\iyuv_32.dll 2009-11-27 16:37 28,672 a——- c:\windows\system32\msvidc32.dll 2009-11-27 16:37 28,672 a——- c:\windows\system32\dllcache\msvidc32.dll 2009-11-27 16:37 11,264 a——- c:\windows\system32\msrle32.dll 2009-11-27 16:37 8,704 a——- c:\windows\system32\tsbyuv.dll 2009-11-27 16:37 84,992 ——– c:\windows\system32\dllcache\avifil32.dll 2009-11-27 16:37 48,128 ——– c:\windows\system32\dllcache\iyuv_32.dll 2009-11-27 16:37 11,264 ——– c:\windows\system32\dllcache\msrle32.dll 2009-11-27 16:37 8,704 ——– c:\windows\system32\dllcache\tsbyuv.dll 2009-11-21 16:36 470,528 a——- c:\windows\apppatch\AcLayers.dll 2009-11-21 16:36 470,528 ——– c:\windows\system32\dllcache\aclayers.dll 2007-02-25 11:58 132 a——- c:\program files\2.ini 2006-07-06 19:15 365 a——- c:\program files\Shortcut to iTunes.lnk 2005-04-01 13:11 266 —sh— c:\program files\desktop.ini 2005-04-01 13:11 11,079 —-h— c:\program files\folder.htt 2004-09-03 10:32 3,488 a——- c:\windows\inf\other\cmiainfo.sys 2006-08-25 16:05 10,856 a–sh— c:\windows\system32\KGyGaAvL.sys ============= FINISH: 9:45:56.96 ===============
Hi pjd100,

Some of the detections are in your Outlook Express Deleted Items folder. Please open Outlook Express and empty the Deleted Items folder in all accounts.


There may have been a false positive by Kaspersky, let's see if others share it's opinion.

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time if more than file is listed, into the "Suspicious files to scan" box on the top of the page:

    C:\Program Files\Adobe\Photoshop 7.0\Samples\Droplets\Photoshop Droplets\Aged Photo.exe

  • Click on the Upload button
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


We'll use this next tool to remove the rest. This tool will also clear the Java cache.

Download OTL to your desktop.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}]

:Files
C:\Documents and Settings\kate\Desktop\songz for bart\usher uturn.mp3 

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.


Please post back with the VirScan results and the OTL fix log

Thanks
Ran VirScan but lost the log when OTL rebooted :blush: here is OTL log All processes killed ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found. ========== FILES ========== C:\Documents and Settings\kate\Desktop\songz for bart\usher uturn.mp3 moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Default User User: All Users User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: All Users.WINDOWS User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 65716 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: pete ->Temp folder emptied: 108681396 bytes ->Temporary Internet Files folder emptied: 5094890 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 102308961 bytes User: kate ->Temp folder emptied: 17241 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 34453781 bytes ->FireFox cache emptied: 122356167 bytes User: lucy ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Java cache emptied: 15953313 bytes ->FireFox cache emptied: 86335531 bytes User: gillian ->Temp folder emptied: 1035908 bytes ->Temporary Internet Files folder emptied: 123916 bytes ->Java cache emptied: 16168038 bytes ->FireFox cache emptied: 105791074 bytes User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->FireFox cache emptied: 13942720 bytes %systemdrive% .tmp files removed: 12864 bytes %systemroot% .tmp files removed: 2219108 bytes %systemroot%\System32 .tmp files removed: 3474432 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 32768 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 2973382 bytes Total Files Cleaned = 592.00 mb OTL by OldTimer - Version 3.1.28.0 log created on 02172010_220653 Files\Folders moved on Reboot… File\Folder C:\WINDOWS\temp\_avast5_\Webshlock.txt not found! Registry entries deleted on Reboot…
VirScan Log -




VirSCAN.org Scanned Report :
Scanned time : 2010/02/15 18:10:06 (GMT)
Scanner results: 6% Scanner(s) (2/36) found malware!
File Name : Aged Photo.exe
File Size : 129003 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 5af6dc6e8afde532aa9518dc70117f0e
SHA1 : f6bd91b98e328dabd00c874b666237b682e40d9c
Online report : http://virscan.org/report/0e68387b287144bc…dcc18a98d5.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20100216010711 2010-02-16 4.48 -
AhnLab V3 2010.02.16.00 2010.02.16 2010-02-16 1.75 -
AntiVir 8.2.1.170 7.10.4.70 2010-02-15 0.27 -
Antiy 2.0.18 20100213.3845580 2010-02-13 0.02 -
Arcavir 2009 201002101845 2010-02-10 0.04 -
Authentium 5.1.1 201002151315 2010-02-15 1.41 -
AVAST! 4.7.4 100215-0 2010-02-15 0.01 -
AVG 8.5.720 271.1.1/2660 2010-02-01 5.17 -
BitDefender 7.81008.5077080 7.30397 2010-02-16 5.16 -
ClamAV 0.95.3 10392 2010-02-15 0.04 -
Comodo 3.13.579 3409 2010-02-15 0.91 -
CP Secure 1.3.0.5 2010.02.16 2010-02-16 0.07 -
Dr.Web 5.0.1.12222 2010.02.16 2010-02-16 5.40 -
F-Prot 4.4.4.56 20100215 2010-02-15 1.35 -
F-Secure 7.02.73807 2010.02.15.13 2010-02-15 9.78 -
Fortinet 11.499- 11.499 2010-02-15 0.30 -
GData 19.10523/19.755 20100215 2010-02-15 6.33 Trojan-Downloader.Win32.Agent.dcnp [Engine:A]
ViRobot 20100213 2010.02.13 2010-02-13 0.63 -
Ikarus T3.1.01.80 2010.02.15.75198 2010-02-15 4.52 -
JiangMin 13.0.900 2010.02.08 2010-02-08 8.54 -
Kaspersky 5.5.10 2010.02.15 2010-02-15 0.06 Trojan-Downloader.Win32.Agent.dcnp
KingSoft 2009.2.5.15 2010.2.15.7 2010-02-15 0.70 -
McAfee 5.3.00 5893 2010-02-15 3.57 -
Microsoft 1.5406 2010.02.15 2010-02-15 7.49 -
Norman 6.01.09 6.01.00 2010-02-10 2.01 -
Panda 9.05.01 2010.02.14 2010-02-14 1.93 -
Trend Micro 9.120-1004 6.850.07 2010-02-15 0.03 -
Quick Heal 10.00 2010.02.15 2010-02-15 1.43 -
Rising 20.0 22.34.01.03 2010-02-09 1.14 -
Sophos 3.04.1 4.50 2010-02-16 3.27 -
Sunbelt 3.9.2400.2 5678 2010-02-14 3.63 -
Symantec 1.3.0.24 20100211.002 2010-02-11 0.00 -
nProtect 20100215.01 7253254 2010-02-15 8.30 -
The Hacker [removed] v00194 2010-02-15 0.57 -
VBA32 3.12.12.2 20100214.2301 2010-02-14 2.79 -
VirusBuster 4.5.11.10 10.119.57/2018042 2010-02-15 2.39 -
Hi pjd100,

It looks like it's a false positive, so it's ok. I'm pretty sure GData uses the Kaspersky engine.

If no other problems, we can clean up our tools.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • 7xy0cvkl.exe (GMER random named file you downloaded)

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall



Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM, keep it updated and use it regularly.


Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7.1.0 first. Be sure to move any PDF documents to another folder first though.



Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have those already.



You have SpywareBlaster installed, use it

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0

-More tips and programs can be found HERE

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Above suggestions and actions taken have been noted or taken………………… Thanks for all your time and effort Pete Stockport Cheshire UK
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI