This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infection

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 20:50:24.75 on Wed 02/24/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.387 [GMT -6:00] AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\system32\dllhost.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\stsystra.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Skype\Phone\Skype.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\AVG\AVG8\avgui.exe C:\Documents and Settings\Shaughnessy\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://m.www.yahoo.com/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" StartupFolder: c:\docume~1\shaugh~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\shaugh~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll Notify: avgrsstarter - avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\shaugh~1\applic~1\mozilla\firefox\profiles\a1h6040u.default\ FF - plugin: c:\documents and settings\shaughnessy\local settings\application data\yahoo!\browserplus\2.4.21\plugins\npybrowserplus_2.4.21.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-7-12 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-7-12 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-7-12 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-12 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-12 297752] R3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);c:\windows\system32\drivers\SMCWGU.sys [2009-7-12 408064] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-9-20 133104] =============== Created Last 30 ================ 2010-02-22 21:14 261,632 a——- c:\windows\PEV.exe 2010-02-22 21:14 161,792 a——- c:\windows\SWREG.exe 2010-02-22 21:14 98,816 a——- c:\windows\sed.exe 2010-02-22 21:14 77,312 a——- c:\windows\MBR.exe 2010-01-31 18:23 8,704 ac—— c:\windows\system32\dllcache\kbdjpn.dll 2010-01-31 18:23 8,192 ac—— c:\windows\system32\dllcache\kbdkor.dll 2010-01-31 18:23 6,144 ac—— c:\windows\system32\dllcache\kbd101c.dll 2010-01-31 18:23 5,632 ac—— c:\windows\system32\dllcache\kbd103.dll 2010-01-31 18:23 8,704 a——- c:\windows\system32\kbdjpn.dll 2010-01-31 18:23 8,192 a——- c:\windows\system32\kbdkor.dll 2010-01-31 18:23 6,144 a——- c:\windows\system32\kbd101c.dll 2010-01-31 18:23 5,632 a——- c:\windows\system32\kbd103.dll 2010-01-31 18:23 6,144 ac—— c:\windows\system32\dllcache\kbd101b.dll 2010-01-31 18:23 6,144 a——- c:\windows\system32\kbd101b.dll 2010-01-31 18:23 6,144 ac—— c:\windows\system32\dllcache\kbd106.dll 2010-01-31 18:23 6,144 a——- c:\windows\system32\kbd106.dll ==================== Find3M ==================== 2010-01-07 16:07 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 16:07 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-01-06 18:15 97,970 a——- c:\windows\Publix Preschool Pals Uninstaller.exe 2009-12-31 10:50 353,792 a——- c:\windows\system32\drivers\srv.sys 2009-12-21 13:14 916,480 ——– c:\windows\system32\wininet.dll 2009-12-17 17:14 411,368 a——- c:\windows\system32\deploytk.dll 2009-12-16 12:43 343,040 a——- c:\windows\system32\mspaint.exe 2009-12-14 01:08 33,280 a——- c:\windows\system32\csrsrv.dll 2009-12-08 13:26 2,145,280 ——– c:\windows\system32\ntoskrnl.exe 2009-12-08 12:43 2,023,936 ——– c:\windows\system32\ntkrnlpa.exe 2009-11-27 11:11 1,291,776 a——- c:\windows\system32\quartz.dll 2009-11-27 11:11 17,920 a——- c:\windows\system32\msyuv.dll 2009-11-27 10:07 28,672 a——- c:\windows\system32\msvidc32.dll 2009-11-27 10:07 8,704 a——- c:\windows\system32\tsbyuv.dll 2009-11-27 10:07 84,992 a——- c:\windows\system32\avifil32.dll 2009-11-27 10:07 48,128 a——- c:\windows\system32\iyuv_32.dll 2009-11-27 10:07 11,264 a——- c:\windows\system32\msrle32.dll 2009-08-23 17:57 245,760 a–sh— c:\windows\system32\config\systemprofile\ietldcache\index.dat 2009-08-23 17:57 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009082320090824\index.dat ============= FINISH: 20:50:53.66 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 7/12/2009 3:52:03 PM System Uptime: 2/24/2010 3:17:10 AM (17 hours ago) Motherboard: Dell Inc. | | 0FJ030 Processor: Intel® Pentium® D CPU 2.80GHz | Microprocessor | 2794/800mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 228 GiB total, 211.132 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: TI Technologies Inc. Description: RADEON X300 SE 128MB HyperMemory Secondary Device ID: PCI\VEN_1002&DEV_5B70&SUBSYS_06031002&REV_00\4&1A646D2D&0&0108 Manufacturer: ATI Technologies Inc. Name: RADEON X300 SE 128MB HyperMemory Secondary PNP Device ID: PCI\VEN_1002&DEV_5B70&SUBSYS_06031002&REV_00\4&1A646D2D&0&0108 Service: ati2mtag Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Ethernet Controller Device ID: PCI\VEN_8086&DEV_109A&SUBSYS_01D11028&REV_01\4&22443A69&0&00E5 Manufacturer: Name: Ethernet Controller PNP Device ID: PCI\VEN_8086&DEV_109A&SUBSYS_01D11028&REV_01\4&22443A69&0&00E5 Service: Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: PCI Simple Communications Controller Device ID: PCI\VEN_14F1&DEV_2F20&SUBSYS_200F14F1&REV_00\4&5855BE9&0&28F0 Manufacturer: Name: PCI Simple Communications Controller PNP Device ID: PCI\VEN_14F1&DEV_2F20&SUBSYS_200F14F1&REV_00\4&5855BE9&0&28F0 Service: ==== System Restore Points =================== RP179: 11/27/2009 3:29:44 PM - System Checkpoint RP180: 11/28/2009 4:37:24 PM - System Checkpoint RP181: 11/29/2009 5:25:24 PM - System Checkpoint RP182: 11/30/2009 6:49:01 PM - System Checkpoint RP183: 12/1/2009 7:27:39 PM - System Checkpoint RP184: 12/2/2009 8:00:27 PM - System Checkpoint RP185: 12/3/2009 8:19:20 PM - System Checkpoint RP186: 12/4/2009 11:49:56 PM - System Checkpoint RP187: 12/5/2009 12:30:20 PM - Installed Java™ 6 Update 17 RP188: 12/6/2009 12:59:57 PM - System Checkpoint RP189: 12/7/2009 1:37:03 PM - System Checkpoint RP190: 12/8/2009 7:53:06 PM - System Checkpoint RP191: 12/9/2009 9:13:39 AM - Avg8 Update RP192: 12/10/2009 7:43:27 AM - Software Distribution Service 3.0 RP193: 12/11/2009 8:02:52 AM - System Checkpoint RP194: 12/12/2009 10:51:32 AM - System Checkpoint RP195: 12/13/2009 9:55:15 AM - Avg8 Update RP196: 12/13/2009 9:56:10 AM - Avg8 Update RP197: 12/14/2009 10:19:06 AM - System Checkpoint RP198: 12/15/2009 11:25:09 AM - System Checkpoint RP199: 12/16/2009 2:57:50 PM - Installed OpenOffice.org 3.1 RP200: 12/17/2009 3:15:46 PM - System Checkpoint RP201: 12/18/2009 4:22:34 PM - System Checkpoint RP202: 12/19/2009 5:36:42 PM - System Checkpoint RP203: 12/20/2009 3:00:19 AM - Software Distribution Service 3.0 RP204: 12/21/2009 5:04:24 AM - System Checkpoint RP205: 12/21/2009 9:50:49 AM - Avg8 Update RP206: 12/22/2009 10:41:42 AM - System Checkpoint RP207: 12/23/2009 6:05:42 PM - System Checkpoint RP208: 12/24/2009 6:52:24 PM - System Checkpoint RP209: 12/25/2009 8:52:24 PM - System Checkpoint RP210: 12/26/2009 6:22:11 PM - Removed AVG Free 8.5 RP211: 12/26/2009 6:45:20 PM - Removed AVG Free 8.5 RP212: 12/27/2009 3:02:43 PM - OTL Restore Point RP213: 12/27/2009 8:17:02 PM - Installed WOT for Internet Explorer RP214: 12/28/2009 8:07:33 AM - Avg8 Update RP215: 12/29/2009 12:02:18 PM - System Checkpoint RP216: 12/30/2009 12:41:52 PM - System Checkpoint RP217: 12/31/2009 1:02:46 PM - System Checkpoint RP218: 1/2/2010 10:38:57 AM - System Checkpoint RP219: 1/3/2010 12:41:00 PM - System Checkpoint RP220: 1/4/2010 8:41:53 AM - Avg8 Update RP221: 1/5/2010 12:26:07 PM - System Checkpoint RP222: 1/6/2010 2:33:49 PM - System Checkpoint RP223: 1/7/2010 2:34:51 PM - System Checkpoint RP224: 1/8/2010 3:01:22 PM - System Checkpoint RP225: 1/9/2010 3:46:34 PM - System Checkpoint RP226: 1/11/2010 5:51:35 AM - System Checkpoint RP227: 1/12/2010 8:19:06 AM - System Checkpoint RP228: 1/13/2010 3:00:14 AM - Software Distribution Service 3.0 RP229: 1/14/2010 1:56:30 PM - System Checkpoint RP230: 1/15/2010 3:17:28 PM - System Checkpoint RP231: 1/17/2010 8:52:42 AM - System Checkpoint RP232: 1/18/2010 9:19:34 AM - System Checkpoint RP233: 1/19/2010 10:42:06 AM - System Checkpoint RP234: 1/20/2010 3:00:14 AM - Software Distribution Service 3.0 RP235: 1/21/2010 3:01:57 AM - System Checkpoint RP236: 1/22/2010 3:00:16 AM - Software Distribution Service 3.0 RP237: 1/23/2010 3:21:39 AM - System Checkpoint RP238: 1/24/2010 3:45:42 AM - System Checkpoint RP239: 1/25/2010 4:33:42 AM - System Checkpoint RP240: 1/26/2010 5:45:43 AM - System Checkpoint RP241: 1/27/2010 6:33:43 AM - System Checkpoint RP242: 1/28/2010 11:36:08 AM - System Checkpoint RP243: 1/29/2010 1:12:43 PM - System Checkpoint RP244: 1/30/2010 1:15:53 PM - System Checkpoint RP245: 2/2/2010 9:33:52 AM - Avg8 Update RP246: 2/3/2010 10:49:53 AM - System Checkpoint RP247: 2/4/2010 12:23:21 PM - System Checkpoint RP248: 2/5/2010 2:26:17 PM - System Checkpoint RP249: 2/6/2010 2:35:44 PM - System Checkpoint RP250: 2/7/2010 4:02:49 PM - System Checkpoint RP251: 2/8/2010 4:51:22 PM - System Checkpoint RP252: 2/9/2010 5:03:20 PM - System Checkpoint RP253: 2/10/2010 3:00:15 AM - Software Distribution Service 3.0 RP254: 2/11/2010 3:24:46 AM - System Checkpoint RP255: 2/12/2010 3:48:47 AM - System Checkpoint RP256: 2/13/2010 6:26:31 AM - System Checkpoint RP257: 2/14/2010 7:36:48 AM - System Checkpoint RP258: 2/15/2010 8:24:50 AM - System Checkpoint RP259: 2/16/2010 10:52:51 AM - System Checkpoint RP260: 2/17/2010 8:14:57 PM - System Checkpoint RP261: 2/18/2010 8:24:18 PM - System Checkpoint RP262: 2/19/2010 9:24:17 PM - System Checkpoint RP263: 2/20/2010 9:25:35 PM - System Checkpoint RP264: 2/21/2010 10:35:34 PM - System Checkpoint RP265: 2/22/2010 11:00:19 PM - System Checkpoint RP266: 2/23/2010 11:59:36 PM - System Checkpoint RP267: 2/24/2010 3:00:18 AM - Software Distribution Service 3.0 RP268: 2/24/2010 8:43:20 PM - Installed Java™ 6 Update 18 ==== Installed Programs ====================== Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3 Apple Application Support Apple Mobile Device Support Apple Software Update ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver AVG Free 8.5 AVS Update Manager 1.0 AVS Video Converter 6 AVS4YOU Software Navigator 1.3 Bonjour Citrix Presentation Server Client Compatibility Pack for the 2007 Office system EPSON Printer Software ERUNT 1.1j Google Chrome Google Earth Google Toolbar for Internet Explorer Google Update Helper High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) iTunes Java Auto Updater Java™ 6 Update 18 KeePass Password Safe 1.17 Malwarebytes' Anti-Malware Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft Office Excel Viewer 2003 Microsoft Office Word Viewer 2003 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable MobileMe Control Panel Mozilla Firefox (3.5.2) OpenOffice.org 3.1 Publix Preschool Pals QuickTime Safari Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978706) SigmaTel Audio Skype web features Skype™ 4.1 Update for Windows Internet Explorer 8 (KB972636) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) WebFldrs XP Windows Internet Explorer 8 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 WOT for Internet Explorer Yahoo! BrowserPlus ==== Event Viewer Messages From Past Week ======== 2/23/2010 7:38:33 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 2/23/2010 7:10:04 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the AVG Free8 WatchDog service to connect. 2/23/2010 7:10:04 PM, error: Service Control Manager [7001] - The AVG Free8 E-mail Scanner service depends on the AVG Free8 WatchDog service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion. 2/23/2010 7:10:04 PM, error: Service Control Manager [7000] - The AVG Free8 WatchDog service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. ==== End Of File ===========================
Hi,

Logs look clean

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI