This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] BackDooor.Generic12.AAVT

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Nothing found!! was echoed to the screen! :thumbup:

Does that mean we're in the clear?

On another note, my wireless is now hanging on "Acquiring network address" (I'm still using internet on another computer)
probably because we stopped that service in RC

Open a command prompt. Start > Run > cmd > press Enter.
copy the following command, and paste it into the command prompt
sc config netbt start= auto
Press Enter. You should see this:
[SC] ChangeServiceConfig SUCCESS
Let me know.

Reboot and see if it will now connect
OK

DDS.txt:


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 18:16:24.09 on 26/02/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.453 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe -k bthsvcs
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG9\avgnsx.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Creative\Software Update 3\SoftAuto.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Documents and Settings\Donal\Application Data\Dropbox\bin\Dropbox.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Donal\My Documents\Downloads\dds.com
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.mhhe.com/simproject
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=2057
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup
uRun: [SoftAuto.exe] "c:\program files\creative\software update 3\SoftAuto.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [ShowLOMControl] 1 (0x1)
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [tsnpstd3] c:\windows\tsnpstd3.exe
mRun: [snpstd3] c:\windows\vsnpstd3.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [MP10_EnsureFileVer] c:\windows\inf\unregmp2.exe /EnsureFileVersions
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\donal\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\donal\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\donal\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 2.3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - c:\program files\common files\autodesk shared\acstart17.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1223424891709
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\donal\applic~1\mozilla\firefox\profiles\tamgyp9z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://en-gb.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - prefs.js: network.proxy.type - 2
FF - component: c:\documents and settings\donal\application data\mozilla\firefox\profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-7-25 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-11-5 28424]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-7-25 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-8 285392]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]
S3 PTSimBus;PenTablet Bus Enumerator;c:\windows\system32\drivers\ptsimbus.sys –> c:\windows\system32\drivers\PTSimBus.sys [?]
S3 PTSimHid;PenTablet Simulated HID MiniDriver;c:\windows\system32\drivers\ptsimhid.sys –> c:\windows\system32\drivers\PTSimHid.sys [?]
S3 VSPerfDrv;Performance Tools Driver;c:\program files\microsoft visual studio 8\team tools\performance tools\VSPerfDrv.sys [2005-9-23 54464]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe [2005-9-23 2799808]

=============== Created Last 30 ================

2010-02-26 15:30:05 0 d—–w- C:\ComboFix
2010-02-26 13:57:53 0 d—–w- c:\windows\maxdriver
2010-02-26 10:47:48 417136 —-a-w- c:\windows\handle.exe
2010-02-25 22:42:46 0 d-sha-r- C:\cmdcons
2010-02-25 18:35:13 98816 —-a-w- c:\windows\sed.exe
2010-02-25 18:35:13 77312 —-a-w- c:\windows\MBR.exe
2010-02-25 18:35:13 261632 —-a-w- c:\windows\PEV.exe
2010-02-25 18:35:13 161792 —-a-w- c:\windows\SWREG.exe
2010-02-24 18:06:39 339 —-a-w- c:\documents and settings\donal\.spmanagerprefs
2010-02-24 17:58:47 0 d—–w- c:\documents and settings\donal\.artofillusion
2010-02-24 17:35:30 0 d—–w- c:\program files\JMF2.1.1e
2010-02-24 17:33:39 0 d—–w- c:\documents and settings\donal\.SunDownloadManager
2010-02-24 17:24:38 0 d—–w- c:\program files\ArtOfIllusion
2010-02-24 16:47:32 473600 —-a-w- c:\windows\SYCLicense80Ux64_090901.dll
2010-02-24 16:47:32 4296704 —-a-w- c:\windows\DXLib80Ux64.dll
2010-02-24 16:47:32 425984 —-a-w- c:\windows\SYCLicenseU_090901.dll
2010-02-24 16:47:32 2805760 —-a-w- c:\windows\DXLib80U.dll
2010-02-24 16:47:32 278528 —-a-w- c:\windows\SYCLicense_090901.dll
2010-02-24 16:47:31 824320 —-a-w- c:\windows\SYCGUI80Ux64.dll
2010-02-24 16:47:31 696320 —-a-w- c:\windows\SYCGUI80U.dll
2010-02-24 16:47:31 532480 —-a-w- c:\windows\SYCGUI71.dll
2010-02-24 16:47:31 3055616 —-a-w- c:\windows\DXLib60.dll
2010-02-24 16:47:31 2826240 —-a-w- c:\windows\DXLib71.dll
2010-02-24 16:47:30 532480 —-a-w- c:\windows\SYCGUI.dll
2010-02-24 16:47:28 0 d—–w- c:\program files\SYCODE
2010-02-23 07:48:20 0 d—–w- c:\docume~1\donal\applic~1\Malwarebytes
2010-02-23 07:48:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 07:48:12 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-23 07:48:11 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-23 07:48:11 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-18 20:56:59 102400 —-a-w- c:\windows\mmvem.exe
2010-02-11 17:07:04 0 d—–w- c:\program files\Mendeley Desktop
2010-02-03 12:51:29 0 d—–w- c:\docume~1\donal\applic~1\Clickteam
2010-02-03 12:51:26 111 —-a-w- c:\windows\easkdiry.ini

==================== Find3M ====================

2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23791.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23790.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378F.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378E.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378D.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378C.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378B.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS2378A.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23789.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23788.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23787.DLL
2010-01-25 19:44:48 10752 —-a-w- c:\windows\system32\PSS23786.DLL
2009-12-31 16:50:03 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-31 16:50:03 353792 ——w- c:\windows\system32\dllcache\srv.sys
2009-12-31 15:33:06 70656 ——w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ——w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ——w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ——w- c:\windows\system32\dllcache\ieakui.dll
2009-12-17 17:14:00 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43:27 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-16 18:43:27 343040 ——w- c:\windows\system32\dllcache\mspaint.exe
2009-12-14 07:08:23 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-14 07:08:23 33280 ——w- c:\windows\system32\dllcache\csrsrv.dll
2009-12-10 14:54:13 201728 —-a-w- c:\windows\system32\Analogy.scr
2009-12-08 19:27:51 2189184 ——w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-12-08 19:26:15 2145280 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 19:26:15 2145280 ——w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-08 18:43:51 2023936 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 18:43:51 2023936 ——w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-08 18:43:50 2066048 ——w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-08 09:23:28 474112 ——w- c:\windows\system32\dllcache\shlwapi.dll
2009-12-04 18:22:22 455424 ——w- c:\windows\system32\dllcache\mrxsmb.sys

============= FINISH: 18:17:06.17 ===============


Attach.txt:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 01/11/2007 12:32:31
System Uptime: 26/02/2010 18:10:38 (0 hours ago)

Motherboard: Dell Inc. | |
Processor: Genuine Intel® CPU T2400 @ 1.83GHz | Microprocessor | 1830/166mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 69 GiB total, 41.016 GiB free.
D: is CDROM ()
X: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP4: 25/02/2010 12:19:31 - Installed Java™ 6 Update 18
RP5: 25/02/2010 18:59:47 - System Checkpoint
RP6: 26/02/2010 01:13:24 - OTL Restore Point

==== Installed Programs ======================

µTorrent
Ableton Live v7.0.1
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Reader 9.3
Alarm Clock v1.0
Analogy Screen Saver
AutoCAD 2007 - English
Autodesk DWF Viewer
AVG Free 9.0
Broadcom Management Programs
Canon Utilities Digital Photo Professional 3.7
Canon Utilities EOS Utility
CinepPlayer 30 Update
Conexant HDA D110 MDC V.92 Modem
Creative Centrale
Creative Removable Disk Manager
Creative Software Update
CutePDF Writer 2.7
Dell Media Experience
Dell Support 5.0.0 (630)
Dell System Restore
Digital Line Detect
Dropbox
ERUNT 1.1j
GIMP 2.4.5
GlassFish V2 UR2
Google Talk Plugin
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Inkscape 0.46
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software
Internal Network Card Power Management
Internet Explorer Default Page
Java 2 Runtime Environment, SE v1.4.2_03
Java Auto Updater
Java DB 10.3.1.4
Java Media Framework 2.1.1e
Java™ 6 Update 18
Java™ 6 Update 2
Java™ 6 Update 7
Java™ SE Development Kit 6 Update 7
Macromedia Flash Player 8
Malwarebytes' Anti-Malware
MATLAB 7.1
mCore
MCU
mDrWiFi
MediaMonkey 3.0
Mendeley Desktop 0.9.5.2
mHlpDell
Microsoft .NET Compact Framework 1.0 SP3 Developer
Microsoft .NET Compact Framework 2.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Device Emulator version 1.0 - ENU
Microsoft Document Explorer 2005
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
Microsoft SQL Server 2005 Tools Express Edition
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual J# 2.0 Redistributable Package
Microsoft Visual Studio 2005 Team Suite - ENU
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft Works 7.0
mIWA
mLogView
mMHouse
Mobile note taker 3.0
Modem Helper
Mozilla Firefox (3.5.8)
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser
mWlsSafe
mWMI
mXML
mZConfig
NetBeans IDE 6.1
NetWaiting
OpenOffice.org 2.3
Pd-0.39.3-extended
PDF Manual NW-E010 Series
Pharos
Picasa 3
PowerDVD 5.7
PowerISO
Pro/ENGINEER Schools Edition Release Wildfire 4.0 Datecode M030
Protege 3.3.1
QuickSet
QuickTime
RealPlayer
Scribus [removed]
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978706)
Sonic Activation Module
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spelling Dictionaries Support For Adobe Reader 9
STL Import for Pro ENGINEER
Synaptics Pointing Device Driver
SyncBack
TrueCrypt
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
USB PC Camera Plus
VideoLAN VLC media player 0.8.6d
Viewpoint Media Player
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows XP Service Pack 3
WinRAR archiver

==== Event Viewer Messages From Past Week ========

26/02/2010 17:45:54, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the NetBios over Tcpip service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
26/02/2010 17:45:54, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
25/02/2010 23:06:35, information: Windows File Protection [64002] - File replacement was attempted on the protected system file nls302en.lex. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
25/02/2010 16:43:22, error: Dhcp [1002] - The IP address lease 192.168.1.33 for the Network Card with network address 00130212666E has been denied by the DHCP server 10.3.64.4 (The DHCP Server sent a DHCPNACK message).
25/02/2010 12:17:23, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. .
25/02/2010 12:17:23, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\system32\TAPI32.dll. Reference error message: The operation completed successfully. .
25/02/2010 12:17:22, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000009A' while processing the file 'ntuser.ini' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
24/02/2010 23:59:23, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD APPDRV AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SCDEmu Tcpip truecrypt
24/02/2010 23:59:23, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
24/02/2010 23:59:23, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
24/02/2010 23:59:23, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
24/02/2010 23:59:23, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
24/02/2010 23:59:14, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
24/02/2010 23:58:55, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
24/02/2010 23:58:51, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
24/02/2010 17:29:25, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
24/02/2010 02:00:21, error: Dhcp [1002] - The IP address lease 10.3.4.245 for the Network Card with network address 0015C54BB53B has been denied by the DHCP server 10.3.0.2 (The DHCP Server sent a DHCPNACK message).
24/02/2010 01:54:49, error: Service Control Manager [7034] - The WebClient service terminated unexpectedly. It has done this 1 time(s).
23/02/2010 08:07:35, error: Service Control Manager [7034] - The MATLAB Server service terminated unexpectedly. It has done this 1 time(s).
23/02/2010 06:01:44, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
23/02/2010 00:10:21, error: Service Control Manager [7000] - The adfs service failed to start due to the following error: The system cannot find the file specified.
22/02/2010 21:43:37, error: Dhcp [1002] - The IP address lease 10.6.1.116 for the Network Card with network address 00130212666E has been denied by the DHCP server 10.3.64.4 (The DHCP Server sent a DHCPNACK message).
19/02/2010 12:03:47, error: Dhcp [1002] - The IP address lease 10.5.18.196 for the Network Card with network address 0015C54BB53B has been denied by the DHCP server 10.3.0.4 (The DHCP Server sent a DHCPNACK message).

==== End Of File ===========================
Hi,

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/BackDooor_Generic12_AAVT_t110492.html

Collect::
c:\windows\system32\PSS23791.DLL	
c:\windows\system32\PSS23790.DLL	
c:\windows\system32\PSS2378F.DLL	
c:\windows\system32\PSS2378E.DLL	
c:\windows\system32\PSS2378D.DLL
c:\windows\system32\PSS2378C.DLL	
c:\windows\system32\PSS2378B.DLL	
c:\windows\system32\PSS2378A.DLL	
c:\windows\system32\PSS23789.DLL	
c:\windows\system32\PSS23788.DLL	
c:\windows\system32\PSS23787.DLL	
c:\windows\system32\PSS23786.DLL

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.



NEXT


  • Hold down the Windows key and press R to open a run box
  • type the following text into the run box

    appwiz.cpl

  • This will open your Programs And Features(Vista) or Add or Remove Programs (XP)
  • A list of installed programs will populate
  • Remove the following programs:

Java 2 Runtime Environment, SE v1.4.2_03
Java DB 10.3.1.4
Java Media Framework 2.1.1e
Java™ 6 Update 2
Java™ 6 Update 7
Java™ SE Development Kit 6 Update 7

leave the Java autoupdater and Java™ 6 Update18 in place as they are the recent versions
ComboFix ran (and for the first time a warning didn't pop up about rootkit activity) but no message box opened with the log, so I don't know if any of the files were submitted. I found the zipped files and have attached them to this post. The log is below. I removed the specified Java programs.

ComboFix 10-02-25.02 - Donal 26/02/2010 18:44:56.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.339 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Donal\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\windows\system32\PSS23786.DLL
file zipped: c:\windows\system32\PSS23787.DLL
file zipped: c:\windows\system32\PSS23788.DLL
file zipped: c:\windows\system32\PSS23789.DLL
file zipped: c:\windows\system32\PSS2378A.DLL
file zipped: c:\windows\system32\PSS2378B.DLL
file zipped: c:\windows\system32\PSS2378C.DLL
file zipped: c:\windows\system32\PSS2378D.DLL
file zipped: c:\windows\system32\PSS2378E.DLL
file zipped: c:\windows\system32\PSS2378F.DLL
file zipped: c:\windows\system32\PSS23790.DLL
file zipped: c:\windows\system32\PSS23791.DLL
.
The following files were disabled during the run:
c:\progra~1\PHAROS~1\Core\PRNTRACK.DLL


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\PSS23786.DLL
c:\windows\system32\PSS23787.DLL
c:\windows\system32\PSS23788.DLL
c:\windows\system32\PSS23789.DLL
c:\windows\system32\PSS2378A.DLL
c:\windows\system32\PSS2378B.DLL
c:\windows\system32\PSS2378C.DLL
c:\windows\system32\PSS2378D.DLL
c:\windows\system32\PSS2378E.DLL
c:\windows\system32\PSS2378F.DLL
c:\windows\system32\PSS23790.DLL
c:\windows\system32\PSS23791.DLL

.
((((((((((((((((((((((((( Files Created from 2010-01-26 to 2010-02-26 )))))))))))))))))))))))))))))))
.

2010-02-26 13:57 . 2010-02-26 14:08 ——– d—–w- c:\windows\maxdriver
2010-02-26 10:47 . 2008-11-18 13:15 417136 —-a-w- c:\windows\handle.exe
2010-02-24 17:58 . 2010-02-24 18:18 ——– d—–w- c:\documents and settings\Donal\.artofillusion
2010-02-24 17:33 . 2010-02-24 17:34 ——– d—–w- c:\documents and settings\Donal\.SunDownloadManager
2010-02-24 17:24 . 2010-02-24 18:18 ——– d—–w- c:\program files\ArtOfIllusion
2010-02-24 16:47 . 2009-11-12 17:04 4296704 —-a-w- c:\windows\DXLib80Ux64.dll
2010-02-24 16:47 . 2009-11-12 16:53 2805760 —-a-w- c:\windows\DXLib80U.dll
2010-02-24 16:47 . 2009-09-01 17:03 473600 —-a-w- c:\windows\SYCLicense80Ux64_090901.dll
2010-02-24 16:47 . 2009-09-01 17:01 425984 —-a-w- c:\windows\SYCLicenseU_090901.dll
2010-02-24 16:47 . 2009-09-01 17:01 278528 —-a-w- c:\windows\SYCLicense_090901.dll
2010-02-24 16:47 . 2009-12-02 21:02 532480 —-a-w- c:\windows\SYCGUI71.dll
2010-02-24 16:47 . 2009-12-02 19:48 696320 —-a-w- c:\windows\SYCGUI80U.dll
2010-02-24 16:47 . 2009-12-02 19:47 824320 —-a-w- c:\windows\SYCGUI80Ux64.dll
2010-02-24 16:47 . 2009-11-12 16:41 2826240 —-a-w- c:\windows\DXLib71.dll
2010-02-24 16:47 . 2009-11-12 16:00 3055616 —-a-w- c:\windows\DXLib60.dll
2010-02-24 16:47 . 2009-12-02 19:24 532480 —-a-w- c:\windows\SYCGUI.dll
2010-02-24 16:47 . 2010-02-24 16:47 ——– d—–w- c:\program files\SYCODE
2010-02-24 01:23 . 2010-02-24 01:23 ——– d—–w- c:\program files\ERUNT
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\documents and settings\Donal\Application Data\Malwarebytes
2010-02-23 07:48 . 2010-01-07 16:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-23 07:48 . 2010-02-23 07:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 07:48 . 2010-01-07 16:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-18 20:56 . 2010-02-18 20:56 102400 —-a-w- c:\windows\mmvem.exe
2010-02-11 17:08 . 2010-02-11 17:08 ——– d—–w- c:\documents and settings\Donal\Local Settings\Application Data\Mendeley Ltd
2010-02-11 17:07 . 2010-02-11 17:07 ——– d—–w- c:\program files\Mendeley Desktop
2010-02-03 12:51 . 2010-02-03 12:51 ——– d—–w- c:\documents and settings\Donal\Application Data\Clickteam

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-26 18:58 . 2010-01-09 15:20 ——– d—–w- c:\documents and settings\Donal\Application Data\Dropbox
2010-02-26 18:58 . 2007-11-05 20:40 ——– d—–w- c:\documents and settings\Donal\Application Data\OpenOffice.org2
2010-02-26 12:31 . 2010-01-09 15:21 91696 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\Uninstall.exe
2010-02-26 12:31 . 2010-02-26 12:31 13264416 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\cache\Dropbox-update-0.7.110.exe
2010-02-26 05:10 . 2010-02-26 05:10 21979992 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\Dropbox.exe
2010-02-24 17:35 . 2010-02-24 17:35 ——– d—–w- c:\program files\JMF2.1.1e
2010-02-24 17:31 . 2006-04-20 11:16 ——– d—–w- c:\program files\Common Files\Java
2010-02-24 17:30 . 2006-04-20 11:16 ——– d—–w- c:\program files\Java
2010-02-24 00:00 . 2010-01-05 19:11 ——– d—–w- c:\program files\SyncBack
2010-02-22 21:33 . 2008-11-11 23:30 ——– d—–w- c:\program files\MATLAB71
2010-02-11 17:09 . 2007-11-05 20:41 1 —-a-w- c:\documents and settings\Donal\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-01-25 19:45 . 2010-01-25 19:44 ——– d—–w- c:\program files\Pharos
2010-01-25 19:44 . 2010-01-25 19:44 ——– d—–w- c:\program files\PharosSystems
2010-01-25 17:28 . 2008-04-24 22:28 ——– d—–w- c:\documents and settings\Donal\Application Data\gtk-2.0
2010-01-21 01:53 . 2007-11-05 20:43 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-05 10:00 . 2004-08-10 11:51 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-10 11:51 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-10 11:50 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2006-04-20 10:56 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-26 03:53 . 2009-12-26 03:53 223440 —-a-w- c:\windows\system32\drivers\truecrypt.sys
2009-12-17 17:14 . 2009-01-27 13:38 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2004-08-10 12:01 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-16 14:42 . 2009-12-24 11:03 872960 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 14:42 . 2009-12-24 11:03 43008 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 14:42 . 2009-12-24 11:03 340480 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 14:41 . 2009-12-24 11:03 346624 —-a-w- c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-14 07:08 . 2004-08-10 11:50 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-10 14:54 . 2009-12-10 14:54 201728 —-a-w- c:\windows\system32\Analogy.scr
2009-12-09 01:19 . 2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll
2009-12-08 19:26 . 2004-08-10 11:51 2145280 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-03 21:59 2023936 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2006-04-20 10:56 455424 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-05-28 401408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="1 (0x1)" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 397312]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-12-15 839680]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-20 98304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 1117184]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-11-29 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-28 185872]
"MP10_EnsureFileVer"="c:\windows\inf\unregmp2.exe" [2008-04-14 208896]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Donal\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Donal\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2009-4-18 11000]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-20 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-08 02:04 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_07\\jre\\bin\\java.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\nms\\nmsd.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\obj\\pro_comm_msg.exe"=
"c:\\Program Files\\ProENGINEER Schools Edition\\i486_nt\\obj\\xtop.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\MD 86149 Notetaker\\Easy note taker.exe"=
"c:\\Documents and Settings\\Donal\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\PharosSystems\\Core\\CTskMstr.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [25/07/2008 20:49 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [25/07/2008 20:49 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [08/11/2009 02:03 285392]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 11:42 64000]
S3 PTSimBus;PenTablet Bus Enumerator;c:\windows\system32\DRIVERS\PTSimBus.sys –> c:\windows\system32\DRIVERS\PTSimBus.sys [?]
S3 PTSimHid;PenTablet Simulated HID MiniDriver;c:\windows\system32\DRIVERS\PTSimHid.sys –> c:\windows\system32\DRIVERS\PTSimHid.sys [?]
S3 VSPerfDrv;Performance Tools Driver;c:\program files\Microsoft Visual Studio 8\Team Tools\Performance Tools\VSPerfDrv.sys [23/09/2005 02:42 54464]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23/09/2005 07:01 2799808]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2888152682-1930892750-3906037613-1012Core.job
- c:\documents and settings\lisa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-17 13:19]

2010-02-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2888152682-1930892750-3906037613-1012UA.job
- c:\documents and settings\lisa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-17 13:19]

2010-02-24 c:\windows\Tasks\SyncBack Daily Iomega College 4 Sync.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]

2010-02-24 c:\windows\Tasks\SyncBack DropBox.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]

2010-02-21 c:\windows\Tasks\SyncBack Weekly HD sync.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]

2010-02-21 c:\windows\Tasks\SyncBack Weekly Images Backup Iomega.job
- c:\program files\SyncBack\SyncBack.exe [2010-01-05 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.mhhe.com/simproject
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=2057
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://en-gb.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - prefs.js: network.proxy.type - 2
FF - component: c:\documents and settings\Donal\Application Data\Mozilla\Firefox\Profiles\tamgyp9z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-26 18:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc21.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\@*& Æ]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Application Data\\Intel\\Wireless\\"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(620)
c:\windows\system32\WININET.dll
c:\progra~1\PHAROS~1\Core\PRNTRACK.DLL
c:\documents and settings\Donal\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKeeper.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
c:\progra~1\PHAROS~1\Core\CTskMstr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\rundll32.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\OpenOffice.org 2.3\program\soffice.exe
c:\program files\OpenOffice.org 2.3\program\soffice.BIN
.
**************************************************************************
.
Completion time: 2010-02-26 19:05:45 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-26 19:05
ComboFix2.txt 2010-02-26 15:50
ComboFix3.txt 2010-02-26 14:49
ComboFix4.txt 2010-02-25 23:20
ComboFix5.txt 2010-02-26 18:43

Pre-Run: 44,020,289,536 bytes free
Post-Run: 43,986,063,360 bytes free

- - End Of File - - B34FBDC90FD9AC222B1569475FE1B1F7
OK,

The files didn't upload, I need you to upload them for me:

Please do this


Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/Infections_Removal_f27.html

Click the Browse button and navigate to C:\Qoobox\Quarantine
Locate your zip file there [4]-Submit_2010-02-26_18.44.36.zip
Select this file and click Open
In the Largest box please put
File Requested By CatByte
Failed Submit::

Finally click SendFile

Please return here and let me know when that file has been uploaded.


NEXT



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
The MBAM log is below.

I'm having trouble with Kaspersky. The "Program download and update" goes fine, but the Database update sits on 1%, until a message box pops up saying:

0 [ERROR: Connection to updates source cannot be established]

I can't select My Computer under the Scan banner, presumably because that download failed.

Malwarebytes' Anti-Malware 1.44
Database version: 3795
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

26/02/2010 20:29:39
mbam-log-2010-02-26 (20-29-39).txt

Scan type: Quick Scan
Objects scanned: 140575
Time elapsed: 6 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi,

Yes, that happens with Kaspersky sometimes:

Please try the following scan:



Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Hi sorry for the delay.

The scan took hours because I left my external HD plugged in. The log is below:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=7.00.6000.16981 (vista_gdr.091215-2244)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=74cba0f40e7dfe4ba8939895ac206b39
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-02-27 08:24:12
# local_time=2010-02-27 08:24:12 (+0000, GMT Standard Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1024 16777191 100 0 9648853 9648853 0 0
# compatibility_mode=8192 67108863 100 0 3769 3769 0 0
# scanned=334114
# found=2
# cleaned=0
# scan_time=11185
C:\i386\GTDownDE_87.ocx probably a variant of Win32/Adware.Agent application 00000000000000000000000000000000 I
E:\Installation Files\office2k3\Office2003.iso probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
Hi,

Please do the following:

P2P - I see you have P2P software µTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Add or Remove Programs.



NEXT


Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c del /f/a/q "C:\i386\GTDownDE_87.ocx" "E:\Installation Files\office2k3\Office2003.iso"



NEXT



Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.


  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI