This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HijackThis Log and post Security-Tool virus problems

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The other day I got the "Security Tool" virus. I was able to remove it from my computer, however, now it's running much slower, websites don't remember my information or keep me logged in, and some java apps aren't working correctly.

I used Hijackthis after the virus was removed, creating this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:34:09 AM, on 2/20/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Drew\Start Menu\Programs\Startup\monnid32.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [LXCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [CTFMON] C:\WINDOWS\Temp\_ex-08.exe
O4 - HKLM\..\Run: [Inuhokofat] rundll32.exe "C:\WINDOWS\ofogefix.dll",Startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: monnid32.exe
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: NkvMon.exe.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe



I'm including all of the log because, honestly, I'm not sure what information is relevant and what isn't. I'm hoping that cleaning up any other problems with hijackthis will help my computer run more smoothly.

Can anyone suggest which files I should "fix" with hijackthis and which ones I shouldn't?

Thank you,
Andrew Reed
Hi,


Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi,

First off, thank you very much for the help, I really appreciate it.

Here is the content of DDS.txt:



DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 14:13:55.59 on Tue 02/23/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1519.1015 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Drew\Start Menu\Programs\Startup\monnid32.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Documents and Settings\Drew\Desktop\dds.com
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: {dbc80044-a445-435b-bc74-9c25c1c588a9} - Java™ Plug-In 2 SSV Helper
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\program files\yahoo!\messenger\yhexbmes0521.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [AlcxMonitor] ALCXMNTR.EXE
mRun: [LXCCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXCCtime.dll,_RunDLLEntry@16
mRun: [Inuhokofat] rundll32.exe "c:\windows\ehalotefacosa.dll",Startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\documents and settings\drew\start menu\programs\startup\monnid32.exe
StartupFolder: c:\docume~1\drew\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Adobe Reader Speed Launch.lnk.disabled
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\NkvMon.exe.lnk.disabled
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - {4C171D40-8277-11D5-AD55-00010333D0AD} - c:\program files\yahoo!\messenger\yhexbmes0521.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
LSA: Notification Packages = scecli menopcr.dll
Hosts: 127.0.0.1 www.spywareinfo.com

============= SERVICES / DRIVERS ===============

R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]

=============== Created Last 30 ================

2010-02-23 13:02:03 0 d—–w- c:\program files\MSECACHE
2010-02-23 06:52:01 0 d—–w- c:\program files\WinPcap
2010-02-23 06:50:48 0 d—–w- c:\program files\JRE
2010-02-23 06:28:25 0 d—–w- c:\program files\Eusing Free Registry Cleaner
2010-02-20 04:13:36 1024 —-a-w- c:\windows\wininit.ini
2010-02-20 00:32:05 792064 —-a-w- c:\windows\system32\drivers\jahitdws.sys
2010-02-20 00:31:57 35328 —ha-w- c:\windows\dfrgtver.dll
2010-02-19 22:16:02 120 —-a-w- c:\windows\Vqeyuz.dat
2010-02-19 22:16:02 0 —-a-w- c:\windows\Rgexahemilekih.bin
2010-02-19 22:12:01 148 —-a-w- c:\windows\system32\fjhdyfhsn.bat
2010-02-19 22:12:00 35328 —ha-w- c:\windows\system32\dfrgtver.dll
2010-02-19 22:11:52 4 —-a-w- c:\docume~1\drew\applic~1\avdrn.dat
2010-02-15 07:04:57 0 d—–w- c:\program files\NetDraft
2010-02-14 22:09:55 0 d—–w- c:\docume~1\drew\applic~1\OpenOffice.org
2010-02-14 22:02:40 0 d—–w- c:\program files\OpenOffice.org 3
2010-02-14 22:02:08 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-08 19:41:11 0 d—–w- c:\program files\Magic Workstation2
2010-02-08 19:34:32 0 d—–w- c:\program files\Trend Micro
2010-02-05 18:55:03 0 d—–w- c:\docume~1\alluse~1\applic~1\acccore
2010-02-05 18:54:26 0 d—–w- c:\program files\common files\AOL
2010-02-05 18:54:12 0 d—–w- c:\program files\AIM6
2010-01-27 11:08:22 0 d—–w- c:\windows\system32\XPSViewer
2010-01-27 11:07:21 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-27 11:07:21 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-27 11:07:21 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-27 11:07:21 575488 ——w- c:\windows\system32\xpsshhdr.dll
2010-01-27 11:07:21 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2010-01-27 11:07:21 1676288 ——w- c:\windows\system32\xpssvcs.dll
2010-01-27 11:07:21 117760 ——w- c:\windows\system32\prntvpt.dll
2010-01-27 11:07:20 0 d—–w- C:\b4cf18e6eadd3026163d883f70
2010-01-27 11:02:49 0 d—–w- c:\program files\MSXML 6.0
2010-01-27 08:03:58 0 d—–w- c:\windows\ServicePackFiles

==================== Find3M ====================

2010-01-05 10:00:29 832512 —-a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00:21 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00:20 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:14:12 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 12:58:04 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35:35 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:55:25 2180352 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19:32 2057728 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-11-27 17:33:35 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 17:33:35 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 16:37:27 8704 —-a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:37:27 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:37:27 48128 —-a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:37:27 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:37:27 11264 —-a-w- c:\windows\system32\msrle32.dll

============= FINISH: 14:23:51.09 ===============


I have attached "Attach.txt" to this message, I'm not sure how to zip the file or if that is strictly necessary, if it is I apologize and will attempt to zip it and attach that to my next post.


In GMER, I unchecked "Sections", "IAT/EAT", and "C:\" (under "Files"). "Show All" was unchecked at the beginning and I left it unchecked.

Here is the result of the GMER scan:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-23 14:34:24
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Drew\LOCALS~1\Temp\kfdiiaod.sys


—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 89784BB8

—- Services - GMER 1.0.15 —-

Service (*** hidden *** ) [BOOT] jahitdws <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\jahitdws@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\jahitdws@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\jahitdws@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\jahitdws@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet002\Services\jahitdws@Type 1
Reg HKLM\SYSTEM\ControlSet002\Services\jahitdws@Start 0
Reg HKLM\SYSTEM\ControlSet002\Services\jahitdws@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\jahitdws@Group Boot Bus Extender
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@TracesProcessed 649
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@TracesSuccessful 71

—- EOF - GMER 1.0.15 —-



Thank you again for all the help.

Attachments:

Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Thankyouthankyouthankyouthankyou,

I followed your instructions and my computer seems to be running as fast as it did before. Here is the content of C:\ComboFix.txt:


ComboFix 10-02-23.03 - Drew 02/23/2010 18:22:09.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1519.1101 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
The following files were disabled during the run:
c:\windows\dfrgtver.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Drew\Application Data\avdrn.dat
c:\documents and settings\Drew\Local Settings\Application Data\{A7340874-1CF5-4237-97DF-0BC1735F136C}
c:\documents and settings\Drew\Local Settings\Application Data\{A7340874-1CF5-4237-97DF-0BC1735F136C}\chrome.manifest
c:\documents and settings\Drew\Local Settings\Application Data\{A7340874-1CF5-4237-97DF-0BC1735F136C}\chrome\content\_cfg.js
c:\documents and settings\Drew\Local Settings\Application Data\{A7340874-1CF5-4237-97DF-0BC1735F136C}\chrome\content\overlay.xul
c:\documents and settings\Drew\Local Settings\Application Data\{A7340874-1CF5-4237-97DF-0BC1735F136C}\install.rdf
c:\documents and settings\Drew\Start Menu\Programs\Startup\monnid32.exe
c:\program files\Internet Explorer\SET35E.tmp
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\windows\ehalotefacosa.dll
c:\windows\system32\drivers\jahitdws.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
D:\Autorun.inf

c:\windows\system32\Drivers\atapi.sys . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_npf
——-\Legacy_jahitdws
——-\Service_jahitdws


((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.

2010-02-23 13:02 . 2010-02-23 13:02 ——– d—–w- c:\program files\MSECACHE
2010-02-23 06:50 . 2010-02-23 06:50 ——– d—–w- c:\program files\JRE
2010-02-23 06:28 . 2010-02-23 06:46 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2010-02-22 20:24 . 2010-02-23 06:52 ——– d—–w- c:\program files\Common Files\Java
2010-02-20 00:37 . 2010-02-20 00:37 61440 —-a-w- c:\documents and settings\Drew\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-570a53d1-n\decora-sse.dll
2010-02-20 00:37 . 2010-02-20 00:37 503808 —-a-w- c:\documents and settings\Drew\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-78b91192-n\msvcp71.dll
2010-02-20 00:37 . 2010-02-20 00:37 499712 —-a-w- c:\documents and settings\Drew\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-78b91192-n\jmc.dll
2010-02-20 00:37 . 2010-02-20 00:37 348160 —-a-w- c:\documents and settings\Drew\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-78b91192-n\msvcr71.dll
2010-02-20 00:37 . 2010-02-20 00:37 12800 —-a-w- c:\documents and settings\Drew\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-570a53d1-n\decora-d3d.dll
2010-02-20 00:31 . 2010-02-20 00:31 35328 —-a-w- c:\windows\dfrgtver.dll
2010-02-19 22:16 . 2010-02-23 22:18 120 —-a-w- c:\windows\Vqeyuz.dat
2010-02-19 22:16 . 2010-02-23 06:57 0 —-a-w- c:\windows\Rgexahemilekih.bin
2010-02-19 22:12 . 2010-02-20 00:32 148 —-a-w- c:\windows\system32\fjhdyfhsn.bat
2010-02-19 22:12 . 2010-02-19 22:12 35328 —ha-w- c:\windows\system32\dfrgtver.dll
2010-02-15 07:04 . 2010-02-23 06:47 ——– d—–w- c:\program files\NetDraft
2010-02-14 22:09 . 2010-02-23 17:04 1 —-a-w- c:\documents and settings\Drew\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-02-14 22:09 . 2010-02-14 22:09 ——– d—–w- c:\documents and settings\Drew\Application Data\OpenOffice.org
2010-02-14 22:02 . 2010-02-14 22:02 ——– d—–w- c:\program files\OpenOffice.org 3
2010-02-14 22:02 . 2010-02-14 22:01 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-08 19:41 . 2010-02-23 06:49 ——– d—–w- c:\program files\Magic Workstation2
2010-02-08 19:34 . 2010-02-08 19:34 ——– d—–w- c:\program files\Trend Micro
2010-02-05 18:57 . 2010-02-05 18:57 ——– d—–w- c:\documents and settings\Drew\Application Data\acccore
2010-02-05 18:56 . 2010-02-05 18:56 ——– d—–w- c:\documents and settings\Drew\Local Settings\Application Data\AOL
2010-02-05 18:55 . 2010-02-05 18:55 ——– d—–w- c:\documents and settings\Drew\Local Settings\Application Data\AOL OCP
2010-02-05 18:55 . 2010-02-05 18:55 ——– d—–w- c:\documents and settings\All Users\Application Data\acccore
2010-02-05 18:54 . 2010-02-05 18:57 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL OCP
2010-02-05 18:54 . 2010-02-05 18:54 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2010-02-05 18:54 . 2010-02-05 18:54 ——– d—–w- c:\program files\Common Files\AOL
2010-02-05 18:54 . 2010-02-05 18:56 ——– d—–w- c:\program files\AIM6
2010-01-28 22:11 . 2010-01-28 22:11 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-01-28 22:06 . 2010-01-28 22:06 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-01-27 11:08 . 2010-01-27 11:08 ——– d—–w- c:\windows\system32\XPSViewer
2010-01-27 11:08 . 2010-01-27 11:08 ——– d—–w- c:\program files\MSBuild
2010-01-27 11:07 . 2010-01-27 11:07 ——– d—–w- c:\program files\Reference Assemblies
2010-01-27 11:07 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-01-27 11:07 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-27 11:07 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-27 11:07 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2010-01-27 11:07 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2010-01-27 11:07 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2010-01-27 11:07 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2010-01-27 11:07 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-27 11:07 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-01-27 11:07 . 2010-01-27 11:07 ——– d—–w- C:\b4cf18e6eadd3026163d883f70
2010-01-27 11:02 . 2010-01-27 11:02 ——– d—–w- c:\program files\MSXML 6.0
2010-01-27 08:03 . 2010-01-27 08:03 ——– d—–w- c:\windows\ServicePackFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 06:52 . 2008-06-23 01:23 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-23 06:51 . 2006-11-09 23:12 ——– d—–w- c:\program files\Magic Workstation
2010-02-23 06:51 . 2005-07-13 21:52 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-23 06:47 . 2008-06-23 01:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-20 00:31 . 2010-02-20 00:31 24 —-a-w- c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
2010-02-19 22:11 . 2010-02-19 22:11 24 —-a-w- c:\documents and settings\NetworkService\Application Data\cqfyto.dat
2010-02-15 09:04 . 2005-07-16 22:30 22032 -c–a-w- c:\documents and settings\Drew\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-05 18:55 . 2005-07-11 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-02-05 18:53 . 2005-07-11 00:55 ——– d—–w- c:\program files\AIM
2010-01-28 22:06 . 2007-09-27 22:41 ——– d—–w- c:\program files\Google
2010-01-26 23:32 . 2005-09-16 19:54 ——– d—–w- c:\program files\Lx_cats
2010-01-05 10:00 . 2004-08-04 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-04 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-04 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:14 . 2004-08-04 12:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 12:58 . 2005-07-10 20:11 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2004-08-04 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:55 . 2004-08-04 12:00 2180352 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19 . 2004-08-03 22:59 2057728 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41 . 2004-08-04 12:00 453760 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:33 . 2004-08-04 12:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 17:33 . 2004-08-04 00:56 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:37 . 2004-08-04 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:37 . 2004-08-04 12:00 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:37 . 2004-08-04 12:00 11264 —-a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:37 . 2004-08-04 00:56 48128 —-a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:37 . 2001-08-17 22:36 8704 —-a-w- c:\windows\system32\tsbyuv.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-27 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-01-10 69632]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\documents and settings\Drew\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk.disabled [2005-7-16 1757]
NkvMon.exe.lnk.disabled [2005-8-30 1567]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli menopcr.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" /s
"LXCCCATS"=rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Apprentice\\Appr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Magic Workstation\\MWSPlay.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\NetDraft\\NETDRAFT.EXE"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 2:15 PM 24652]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/28/2010 5:06 PM 135664]
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:06]

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Inuhokofat - c:\windows\ehalotefacosa.dll
Notify-WgaLogon - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-23 22:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(680)
c:\windows\menopcr.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3120)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\dfrgtver.dll
c:\windows\menopcr.dll
.
———————— Other Running Processes ————————
.
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\ALCXMNTR.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
.
**************************************************************************
.
Completion time: 2010-02-23 22:27:23 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-24 03:27

Pre-Run: 23,258,107,904 bytes free
Post-Run: 23,409,377,280 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - D29E112FC9ECC99A1414FDEA6C86FD8D




Two points of interest, I don't know if they're significant: when Combofix first started running, a screen popped up saying a program was trying to attach to it, the program was C:\windows\dfrgtver.dll.

Also, after restarting the computer and getting the Combofix log, I started Internet Explorer and an error message saying "CTF Loader has encountered a problem and needs to close." I don't know what CTF Loader is or if this is significant.




THANK YOU again, so much.
Drew
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/HijackThis_Log_post_Security_Tool_virus_problems_t110425.html&view=findpost&p=635673#entry635673

Collect::
c:\windows\Vqeyuz.dat
c:\windows\system32\fjhdyfhsn.bat
c:\windows\dfrgtver.dll
c:\windows\system32\dfrgtver.dll
c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
c:\documents and settings\NetworkService\Application Data\cqfyto.dat
c:\windows\menopcr.dll

File::
c:\windows\Rgexahemilekih.bin

Registry::
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"=hex(7):73,63,65,63,6c,69,00,00

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT



Extract the file and run it.

Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)

please post the content of that log TDSSKiller
New Combofix Log:

ComboFix 10-02-24.01 - Drew 02/24/2010 16:59:39.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1519.1110 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Drew\Desktop\CFScript.txt

FILE ::
"c:\windows\Rgexahemilekih.bin"

file zipped: c:\documents and settings\NetworkService\Application Data\cqfyto.dat
file zipped: c:\windows\menopcr.dll
file zipped: c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
file zipped: c:\windows\system32\dfrgtver.dll
file zipped: c:\windows\system32\fjhdyfhsn.bat
file zipped: c:\windows\Vqeyuz.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\NetworkService\Application Data\cqfyto.dat
c:\windows\menopcr.dll
c:\windows\Rgexahemilekih.bin
c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
c:\windows\system32\dfrgtver.dll
c:\windows\system32\fjhdyfhsn.bat
c:\windows\Vqeyuz.dat

.
((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.

2010-02-24 03:52 . 2010-02-24 04:47 ——– d—–w- c:\documents and settings\Drew\Application Data\mIRC
2010-02-24 03:52 . 2010-02-24 04:42 ——– d—–w- c:\program files\mIRC
2010-02-23 13:02 . 2010-02-23 13:02 ——– d—–w- c:\program files\MSECACHE
2010-02-23 06:50 . 2010-02-23 06:50 ——– d—–w- c:\program files\JRE
2010-02-23 06:28 . 2010-02-23 06:46 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2010-02-22 20:24 . 2010-02-23 06:52 ——– d—–w- c:\program files\Common Files\Java
2010-02-20 00:31 . 2010-02-20 00:31 35328 —-a-w- c:\windows\dfrgtver.dll
2010-02-15 07:04 . 2010-02-23 06:47 ——– d—–w- c:\program files\NetDraft
2010-02-14 22:09 . 2010-02-14 22:09 ——– d—–w- c:\documents and settings\Drew\Application Data\OpenOffice.org
2010-02-14 22:02 . 2010-02-14 22:02 ——– d—–w- c:\program files\OpenOffice.org 3
2010-02-14 22:02 . 2010-02-14 22:01 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-08 19:41 . 2010-02-23 06:49 ——– d—–w- c:\program files\Magic Workstation2
2010-02-08 19:34 . 2010-02-08 19:34 ——– d—–w- c:\program files\Trend Micro
2010-02-05 18:57 . 2010-02-05 18:57 ——– d—–w- c:\documents and settings\Drew\Application Data\acccore
2010-02-05 18:56 . 2010-02-05 18:56 ——– d—–w- c:\documents and settings\Drew\Local Settings\Application Data\AOL
2010-02-05 18:55 . 2010-02-05 18:55 ——– d—–w- c:\documents and settings\Drew\Local Settings\Application Data\AOL OCP
2010-02-05 18:55 . 2010-02-05 18:55 ——– d—–w- c:\documents and settings\All Users\Application Data\acccore
2010-02-05 18:54 . 2010-02-05 18:57 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL OCP
2010-02-05 18:54 . 2010-02-05 18:54 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2010-02-05 18:54 . 2010-02-05 18:54 ——– d—–w- c:\program files\Common Files\AOL
2010-02-05 18:54 . 2010-02-05 18:56 ——– d—–w- c:\program files\AIM6
2010-01-28 22:11 . 2010-01-28 22:11 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-01-28 22:06 . 2010-01-28 22:06 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-01-27 11:08 . 2010-01-27 11:08 ——– d—–w- c:\windows\system32\XPSViewer
2010-01-27 11:08 . 2010-01-27 11:08 ——– d—–w- c:\program files\MSBuild
2010-01-27 11:07 . 2010-01-27 11:07 ——– d—–w- c:\program files\Reference Assemblies
2010-01-27 11:07 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-01-27 11:07 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-27 11:07 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-27 11:07 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2010-01-27 11:07 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2010-01-27 11:07 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2010-01-27 11:07 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2010-01-27 11:07 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-27 11:07 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-01-27 11:07 . 2010-01-27 11:07 ——– d—–w- C:\b4cf18e6eadd3026163d883f70
2010-01-27 11:02 . 2010-01-27 11:02 ——– d—–w- c:\program files\MSXML 6.0
2010-01-27 08:03 . 2010-01-27 08:03 ——– d—–w- c:\windows\ServicePackFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 17:04 . 2010-02-14 22:09 1 —-a-w- c:\documents and settings\Drew\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-02-23 06:52 . 2008-06-23 01:23 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-23 06:51 . 2006-11-09 23:12 ——– d—–w- c:\program files\Magic Workstation
2010-02-23 06:51 . 2005-07-13 21:52 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-23 06:47 . 2008-06-23 01:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-20 00:37 . 2010-02-20 00:37 61440 —-a-w- c:\documents and settings\Drew\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-570a53d1-n\decora-sse.dll
2010-02-20 00:37 . 2010-02-20 00:37 503808 —-a-w- c:\documents and settings\Drew\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-78b91192-n\msvcp71.dll
2010-02-20 00:37 . 2010-02-20 00:37 499712 —-a-w- c:\documents and settings\Drew\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-78b91192-n\jmc.dll
2010-02-20 00:37 . 2010-02-20 00:37 348160 —-a-w- c:\documents and settings\Drew\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-78b91192-n\msvcr71.dll
2010-02-20 00:37 . 2010-02-20 00:37 12800 —-a-w- c:\documents and settings\Drew\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-570a53d1-n\decora-d3d.dll
2010-02-15 09:04 . 2005-07-16 22:30 22032 -c–a-w- c:\documents and settings\Drew\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-05 18:55 . 2005-07-11 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-02-05 18:53 . 2005-07-11 00:55 ——– d—–w- c:\program files\AIM
2010-01-28 22:06 . 2007-09-27 22:41 ——– d—–w- c:\program files\Google
2010-01-26 23:32 . 2005-09-16 19:54 ——– d—–w- c:\program files\Lx_cats
2010-01-05 10:00 . 2004-08-04 12:00 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-04 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-04 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:14 . 2004-08-04 12:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 12:58 . 2005-07-10 20:11 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2004-08-04 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:55 . 2004-08-04 12:00 2180352 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19 . 2004-08-03 22:59 2057728 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41 . 2004-08-04 12:00 453760 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:33 . 2004-08-04 12:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 17:33 . 2004-08-04 00:56 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:37 . 2004-08-04 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:37 . 2004-08-04 12:00 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:37 . 2004-08-04 12:00 11264 —-a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:37 . 2004-08-04 00:56 48128 —-a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:37 . 2001-08-17 22:36 8704 —-a-w- c:\windows\system32\tsbyuv.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-27 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-01-10 69632]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\documents and settings\Drew\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk.disabled [2005-7-16 1757]
NkvMon.exe.lnk.disabled [2005-8-30 1567]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" /s
"LXCCCATS"=rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Apprentice\\Appr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Magic Workstation\\MWSPlay.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\NetDraft\\NETDRAFT.EXE"=
"c:\\Program Files\\mIRC\\mirc.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 2:15 PM 24652]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/28/2010 5:06 PM 135664]
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:06]

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-24 17:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3780)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\dfrgtver.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\wscntfy.exe
c:\windows\ALCXMNTR.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2010-02-24 17:12:54 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-24 22:12
ComboFix2.txt 2010-02-24 03:27

Pre-Run: 23,524,499,456 bytes free
Post-Run: 23,500,808,192 bytes free

- - End Of File - - BF4EBCA9725901C8459A951BE134C39B




Content of TDSSkiller Log:


TDSS rootkit removing tool, Kaspersky Lab, 2010
version 2.2.6 Feb 21 2010 21:24:13

Scanning Services …

Scanning Kernel memory …

Completed

Results:
Memory objects infected / cured / cured on reboot: 0 / 0 / 0
Registry objects infected / cured / cured on reboot: 0 / 0 / 0
File objects infected / cured / cured on reboot: 0 / 0 / 0

Press any key to continue . . .






Thank you again,
Andrew Reed
Hi,

The files I wanted to upload didn't go automatically, so we need to upload them manually,

Please do the following:


Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/HijackThis_Log_post_Security_Tool_virus_problems_t110425.html

Click the Browse button and navigate to C:\Qoobox\Quarantine

There should be a zip file there called [4]-Submit_****-**-**_**.**.**.zip ( the * denotes Date and Time stamp - yours will be close to this 02/24/2010 16:59:39 )
Select this file and click Open
In the Largest box please put
File Requested By CatByte
Failed Submit::

Finally click SendFile

Please return here and let me know when that file has been uploaded.

NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT



Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
Here are the contents of my mbam-log (retrieved after restarting): Malwarebytes' Anti-Malware 1.44 Database version: 3792 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 2/25/2010 3:15:29 PM mbam-log-2010-02-25 (15-15-29).txt Scan type: Quick Scan Objects scanned: 116044 Time elapsed: 5 minute(s), 26 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\dfrgtver.dll (Spyware.Passwords) -> Delete on reboot. Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\dfrgtver.dll (Spyware.Passwords) -> Delete on reboot. I can't use the other program you suggest because I don't have java on my computer and whenever I try to download java, the installation starts and suddenly stops. I'm going to try downloading an older version of java and see if that works.
Try the manual installation from here:

http://www.java.com/en/download/manual.jsp

If you still can't install Java - try this scanner instead:


Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
I still cant install Java. Results of ESET scan: C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\20\1b0842d4-4799540c probably a variant of Win32/Agent trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-33c9664f probably a variant of Win32/Agent trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\22\74018dd6-2475861b Java/TrojanDownloader.OpenStream.NAB trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\24\3e021ed8-638779fe multiple threats C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\47\bd7ce2f-1744c322 probably a variant of Win32/Agent trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\49\49820371-13087b89 probably a variant of Win32/Agent trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\59\4d13647b-5171183c Java/TrojanDownloader.OpenStream.NAC trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-7e718e96-1fc38e6b.class Java/TrojanDownloader.OpenStream.NAC trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-44f46a27-6d69470b.zip multiple threats C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-1378d0f5.zip probably a variant of Win32/Agent trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-4a5d57d0-1231904b.zip probably a variant of Win32/Agent trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-350f6755.zip probably a variant of Win32/Agent trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-2dc6c1cd.zip probably a variant of Win32/Agent trojan C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-52b9c4dc-7c5817b2.zip Java/TrojanDownloader.OpenStream.NAB trojan C:\Qoobox\Quarantine\[4]-Submit_2010-02-24_16.59.22.zip multiple threats C:\Qoobox\Quarantine\C\Documents and Settings\Drew\Start Menu\Programs\Startup\_monnid32_.exe.zip a variant of Win32/Kryptik.CPN trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\fjhdyfhsn.bat.vir BAT/KillFiles.NCB trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\jahitdws.sys.vir a variant of Win32/Rootkit.Kryptik.AF trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_jahitdws_.sys.zip a variant of Win32/Rootkit.Kryptik.AF trojan C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1304\A0091688.bat BAT/KillFiles.NCB trojan C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1305\A0092772.exe a variant of Win32/Kryptik.CNA trojan C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1305\A0092774.exe Win32/Adware.MalwareRemoval application C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1306\A0092784.exe multiple threats C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1307\A0092902.exe a variant of Win32/Kryptik.CNA trojan C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1310\A0094061.exe multiple threats C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1310\A0094080.bat BAT/KillFiles.NCB trojan C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1310\A0094086.exe a variant of Win32/Kryptik.CNA trojan C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1310\A0094087.dll a variant of Win32/PSW.Papras.AW trojan C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1310\A0095256.dll a variant of Win32/PSW.Papras.AW trojan C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1310\A0095289.sys a variant of Win32/Rootkit.Kryptik.AF trojan C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1311\A0095446.dll a variant of Win32/PSW.Papras.AW trojan C:\System Volume Information\_restore{965B8C3B-3B05-456B-B423-82BC73FD53FC}\RP1311\A0095617.bat BAT/KillFiles.NCB trojan I notice a few of those have to do with Java, maybe its a related problem. Computer is running mostly normal except I still get the "CFT Loader" error messages, and websites still keep me signed in. Thanks again for all the help, Drew
Hi,

Let's get rid of all the Java then try again with the install:



Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Files
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\20\1b0842d4-4799540c 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-33c9664f 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\22\74018dd6-2475861b 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\24\3e021ed8-638779fe 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\47\bd7ce2f-1744c322 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\49\49820371-13087b89 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\59\4d13647b-5171183c 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-7e718e96-1fc38e6b.class 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-44f46a27-6d69470b.zip 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-1378d0f5.zip 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-4a5d57d0-1231904b.zip 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-350f6755.zip 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-2dc6c1cd.zip 
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-52b9c4dc-7c5817b2.zip 

:Commands
[purity]
[emptytemp]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




NEXT


  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.


Now Navigate to the following folder c:\Documents and Settings\Drew\Application Data\Sun\Java

and delete the Java folder

Now try and install Java again

Also advise how your computer is running and if there are any outstanding issues.
Ran OTM, rebooted. OTM Log: All processes killed ========== FILES ========== C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\20\1b0842d4-4799540c moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-33c9664f moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\22\74018dd6-2475861b moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\24\3e021ed8-638779fe moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\47\bd7ce2f-1744c322 moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\49\49820371-13087b89 moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\6.0\59\4d13647b-5171183c moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-7e718e96-1fc38e6b.class moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-44f46a27-6d69470b.zip moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-1378d0f5.zip moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-4a5d57d0-1231904b.zip moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-350f6755.zip moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-2dc6c1cd.zip moved successfully. C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\OP.jar-52b9c4dc-7c5817b2.zip moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Drew ->Temp folder emptied: 101624 bytes ->Temporary Internet Files folder emptied: 69376251 bytes ->Java cache emptied: 14174770 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 78991 bytes Deleted Java folder, went back to java.com and tried to install Java again, same thing happened: download started, clicked "Install", the installer just never came up. Otherwise computer is running fine again, and websites are keeping me logged in. Thank you, Drew

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI