This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can't get to internet through my user setting

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Help please! I'm not very tech savvy… My user setting is the Admin of our home desktop computer. I am running on Windows XP. I am logging in to my computer from work through Log Me In and found a series of "threat warnings" on my desktop wanting me to purchase an "upgrade" to a virus protection software. There were MANY windows of this I was trying to close out and I ended up restarting the computer to get them to clear. Once the system restarted, they were gone but trying to open internet explorer came up with the error message that it could not find the internet connection. When I tried to "diagnose" it said there were problems with a few of the firewall settings. I tried to restore those and did not work. I tried system restore to several different dates but the system said it could not restore and to try another date. I went back several weeks. When I switched to my husband's user setting on the computer, the internet worked. I use AVG Free and Malbytes on my computer. AVG said there were no infections detected. Please help? I will be eternally Grateful!
Hi,

Please do the following


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thank you for responding! I saved it to my desktop and am running it but nothing is happening yet. How do I make sure that the script blocking protection is not enabled?
Thanks! Okay, here is one report: DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 10:38:31.92 on Mon 03/01/2010 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.377 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\Explorer.EXE C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe C:\WINDOWS\system32\hphmon06.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DellSupport\DSAgnt.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe C:\Program Files\AWS\WeatherBug\Weather.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\Documents and Settings\Gary\My Documents\RCA Detective\RCADetective.exe C:\Program Files\internet explorer\iexplore.exe C:\Documents and Settings\Gary\Desktop\dds.com ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mStart Page = hxxp://home.sweetim.com uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = uURLSearchHooks: H - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File TB: {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll EB: Search panel: {932f10bd-e7d7-df34-7e9e-121e94d5b766} - c:\windows\system32\bjpddtbqglhnpcy.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [DellTransferAgent] "c:\documents and settings\all users\application data\dell\transferagent\TransferAgent.exe" uRun: [Cognac] c:\docume~1\gary\locals~1\temp\A.tmp.exe uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1 uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10d.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb11.exe mRun: [HPHUPD06] c:\program files\hp\{aac4fc36-8f89-4587-8dd3-ebc57c83374d}\hphupd06.exe mRun: [HPHmon06] c:\windows\system32\hphmon06.exe mRun: [Hpppta] c:\program files\hewlett-packard\hp precisionscan\precisionscan\hpppta.exe /ICON mRun: [SansaDispatch] c:\program files\sandisk\sansa updater\SansaDispatch.exe mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" mRun: [sgakfhsn] c:\documents and settings\chris\local settings\application data\vpvsuh\cbhysftav.exe StartupFolder: c:\docume~1\gary\startm~1\programs\startup\downlo~1.lnk - c:\program files\snocap\download manager\NodeStarter.exe StartupFolder: c:\docume~1\gary\startm~1\programs\startup\rcadet~1.lnk - c:\documents and settings\gary\my documents\rca detective\RCADetective.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe uPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) uPolicies-explorer: NoWindowsUpdate = 1 (0x1) uPolicies-system: Wallpaper = uPolicies-system: DisableRegistryTools = 1 (0x1) mPolicies-explorer: NoActiveDesktop = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - hxxp://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.4.4.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/46.19/uploader2.cab DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145929355125 DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100 Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll Notify: LMIinit - LMIinit.dll AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, append.dll IFEO: ehshell.exe - "c:\program files\logmein\x86\LogMeInSystray.exe" -MceShellRedirect Hosts: 192.168.200.3 ad.doubleclick.net Hosts: 192.168.200.3 ad.fastclick.net Hosts: 192.168.200.3 ads.fastclick.net Hosts: 192.168.200.3 atdmt.com Hosts: 192.168.200.3 awaps.net Note: multiple HOSTS entries found. Please refer to Attach.txt ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\gary\applic~1\mozilla\firefox\profiles\brlukivz.default\ FF - HiddenExtension: XUL Cache: {B442BE21-9ABB-4EBE-B0E0-787F16EE2F53} - c:\documents and settings\chris\local settings\application data\{B442BE21-9ABB-4EBE-B0E0-787F16EE2F53} FF - HiddenExtension: XUL Cache: {48B449A6-81F5-462D-A659-92DB488F8A23} - c:\documents and settings\gary\local settings\application data\{48B449A6-81F5-462D-A659-92DB488F8A23} FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [2006-7-27 4064] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-21 335240] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-5-21 27784] R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\adobe\photoshop elements 7.0\PhotoshopElementsFileAgent.exe [2008-9-16 169312] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-2-7 297752] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-7-24 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2009-7-29 47640] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-5 135664] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-6-20 30192] S3 JL2004A;JL2004A Photo Viewer;c:\windows\system32\drivers\pv_wdm.sys [2006-4-26 87144] S4 LMIRfsClientNP;LMIRfsClientNP; [x] =============== Created Last 30 ================ 2010-02-13 22:12:05 0 d—–w- c:\program files\PDF995 2010-02-13 22:12:05 0 d—–w- c:\program files\HRBlock2009 2010-02-13 22:11:07 0 d—–w- c:\docume~1\alluse~1\applic~1\TaxCut 2010-02-13 21:28:47 1048 —-a-w- C:\net_save.dna 2010-02-13 21:28:36 0 d—–w- c:\program files\support.com 2010-02-13 21:28:26 0 d—–w- c:\program files\common files\SupportSoft ==================== Find3M ==================== 2009-12-31 16:50:03 353792 —-a-w- c:\windows\system32\drivers\srv.sys 2009-12-31 16:50:03 353792 ——w- c:\windows\system32\dllcache\srv.sys 2009-12-31 15:33:06 70656 ——w- c:\windows\system32\dllcache\ie4uinit.exe 2009-12-31 15:33:06 13824 ——w- c:\windows\system32\dllcache\ieudinit.exe 2009-12-18 13:05:43 634648 ——w- c:\windows\system32\dllcache\iexplore.exe 2009-12-18 13:04:09 161792 ——w- c:\windows\system32\dllcache\ieakui.dll 2009-12-16 18:43:27 343040 —-a-w- c:\windows\system32\mspaint.exe 2009-12-16 18:43:27 343040 ——w- c:\windows\system32\dllcache\mspaint.exe 2009-12-14 07:08:23 33280 —-a-w- c:\windows\system32\csrsrv.dll 2009-12-14 07:08:23 33280 ——w- c:\windows\system32\dllcache\csrsrv.dll 2009-12-09 02:34:18 411368 —-a-w- c:\windows\system32\deploytk.dll 2009-12-08 19:27:51 2189184 ——w- c:\windows\system32\dllcache\ntoskrnl.exe 2009-12-08 19:26:15 2145280 —-a-w- c:\windows\system32\ntoskrnl.exe 2009-12-08 19:26:15 2145280 ——w- c:\windows\system32\dllcache\ntkrnlmp.exe 2009-12-08 18:43:51 2023936 —-a-w- c:\windows\system32\ntkrnlpa.exe 2009-12-08 18:43:51 2023936 ——w- c:\windows\system32\dllcache\ntkrpamp.exe 2009-12-08 18:43:50 2066048 ——w- c:\windows\system32\dllcache\ntkrnlpa.exe 2009-12-08 09:23:28 474112 ——w- c:\windows\system32\dllcache\shlwapi.dll 2009-12-04 18:22:22 455424 ——w- c:\windows\system32\dllcache\mrxsmb.sys 2008-07-21 01:28:02 6580 –sha-w- c:\windows\system32\KGyGaAvL.sys 2008-09-26 07:07:54 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092620080927\index.dat 2009-07-21 16:13:35 16384 –sha-w- c:\windows\temp\cookies\index.dat 2009-07-21 16:13:35 16384 –sha-w- c:\windows\temp\history\history.ie5\index.dat 2009-07-21 16:13:35 49152 –sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat ============= FINISH: 10:55:02.59 =============== Here is the other report: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 4/6/2006 6:43:15 PM System Uptime: 3/1/2010 9:40:15 AM (1 hours ago) Motherboard: Dell Inc. | | 0JC474 Processor: Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2793/800mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 51 GiB total, 4.172 GiB free. D: is FIXED (NTFS) - 18 GiB total, 1.666 GiB free. E: is CDROM () F: is Removable G: is FIXED (FAT32) - 931 GiB total, 918.351 GiB free. ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP661: 1/14/2010 1:12:42 AM - System Checkpoint RP662: 1/14/2010 3:00:23 AM - Software Distribution Service 3.0 RP663: 1/15/2010 3:27:07 AM - System Checkpoint RP664: 1/16/2010 4:26:54 AM - System Checkpoint RP665: 1/17/2010 5:26:33 AM - System Checkpoint RP666: 1/18/2010 5:53:51 AM - System Checkpoint RP667: 1/19/2010 6:53:50 AM - System Checkpoint RP668: 1/20/2010 3:02:16 AM - Software Distribution Service 3.0 RP669: 1/21/2010 9:38:44 AM - System Checkpoint RP670: 1/22/2010 3:00:23 AM - Software Distribution Service 3.0 RP671: 1/23/2010 10:46:57 AM - System Checkpoint RP672: 1/24/2010 11:17:29 AM - System Checkpoint RP673: 1/25/2010 11:20:42 AM - System Checkpoint RP674: 1/26/2010 11:24:24 AM - System Checkpoint RP675: 1/27/2010 12:12:25 PM - System Checkpoint RP676: 1/28/2010 12:40:40 PM - System Checkpoint RP677: 1/29/2010 1:39:58 PM - System Checkpoint RP678: 1/30/2010 2:00:05 PM - System Checkpoint RP679: 1/31/2010 3:00:39 PM - System Checkpoint RP680: 2/1/2010 3:12:23 PM - System Checkpoint RP681: 2/2/2010 5:12:36 PM - System Checkpoint RP682: 2/3/2010 8:15:07 AM - Avg8 Update RP683: 2/4/2010 10:39:19 AM - System Checkpoint RP684: 2/5/2010 1:23:33 PM - System Checkpoint RP685: 2/6/2010 7:58:17 PM - System Checkpoint RP686: 2/7/2010 8:56:26 PM - System Checkpoint RP687: 2/8/2010 9:27:13 PM - System Checkpoint RP688: 2/9/2010 10:27:41 PM - System Checkpoint RP689: 2/10/2010 3:00:39 AM - Software Distribution Service 3.0 RP690: 2/11/2010 10:01:28 AM - System Checkpoint RP691: 2/12/2010 10:29:23 AM - System Checkpoint RP692: 2/13/2010 12:08:22 PM - System Checkpoint RP693: 2/13/2010 4:52:35 PM - Removed Google Toolbar for Firefox RP694: 2/13/2010 4:54:39 PM - Removed Microsoft Money Shared Libraries RP695: 2/13/2010 5:11:59 PM - Installed H&R Block Deluxe + Efile + State 2009. RP696: 2/14/2010 11:06:38 AM - Installed H&R Block Georgia 2009. RP697: 2/15/2010 11:36:30 AM - System Checkpoint RP698: 2/16/2010 12:37:15 PM - System Checkpoint RP699: 2/17/2010 12:39:58 PM - System Checkpoint RP700: 2/18/2010 1:37:02 PM - System Checkpoint RP701: 2/19/2010 1:42:14 PM - System Checkpoint RP702: 2/20/2010 5:27:27 PM - System Checkpoint RP703: 2/21/2010 9:24:43 PM - System Checkpoint RP704: 2/22/2010 11:58:32 PM - System Checkpoint RP705: 2/24/2010 3:00:28 AM - Software Distribution Service 3.0 RP706: 2/25/2010 10:04:03 AM - System Checkpoint RP707: 2/26/2010 11:27:39 AM - System Checkpoint RP708: 2/27/2010 11:48:54 AM - System Checkpoint RP709: 2/28/2010 5:08:11 PM - System Checkpoint RP710: 3/1/2010 9:36:40 AM - Restore Operation RP711: 3/1/2010 9:47:40 AM - Restore Operation ==== Hosts File Hijack ====================== Hosts: 192.168.200.3 ad.doubleclick.net Hosts: 192.168.200.3 ad.fastclick.net Hosts: 192.168.200.3 ads.fastclick.net Hosts: 192.168.200.3 atdmt.com Hosts: 192.168.200.3 awaps.net Hosts: 192.168.200.3 banner.fastclick.net Hosts: 192.168.200.3 banners.fastclick.net Hosts: 192.168.200.3 click.atdmt.com Hosts: 192.168.200.3 clicks.atdmt.com Hosts: 192.168.200.3 engine.awaps.net Hosts: 192.168.200.3 fastclick.net Hosts: 192.168.200.3 ftp.avp.ch Hosts: 192.168.200.3 ftp.kasperskylab.ru Hosts: 192.168.200.3 updates5.kaspersky-labs.com Hosts: 192.168.200.3 www.awaps.net Hosts: 192.168.200.3 www.viruslist.ru ==== Installed Programs ====================== Adobe AIR Adobe Flash Player 10 ActiveX Adobe Photoshop Elements 7.0 Adobe Photoshop.com Inspiration Browser Adobe Reader 8.1.3 Adobe Type Manager 4.0 Advanced Registry Optimizer Amazon MP3 Downloader 1.0.3 AOLIcon Apple Software Update AVG Free 8.5 BufferChm Comcast High-Speed Internet Install Wizard Compatibility Pack for the 2007 Office system Conexant D850 56K V.9x DFVc Modem Coupon Printer for Windows CreativeProjects CreativeProjectsTemplates Critical Update for Windows Media Player 11 (KB959772) CueTour Data Access Objects (DAO) 3.5 Data Lifeguard Diagnostic for Windows Dell CinePlayer Dell Digital Jukebox Driver Dell Driver Reset Tool Dell Game Console Dell System Restore DellSupport Destinations Digital Content Portal Digital Line Detect Director EarthLink setup files Efficient Networks SpeedStream DSL ELIcon Google Desktop Google Toolbar for Internet Explorer Google Update Helper H&R Block Deluxe + Efile + State 2009 H&R Block Georgia 2009 Hemera Photo-Objects Gallery for HP High Definition Audio Driver Package - KB835221 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) HP Diagnostic Assistant HP Image Zone 4.0 HP PrecisionScan HP Software Update HPSystemDiagnostics ImageMixer3 InstantShare Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections Drivers Intel® PROSet for Wired Connections Java™ 6 Update 17 Java™ 6 Update 5 Learn2 Player (Uninstall Only) LiveUpdate 2.6 (Symantec Corporation) Lizardtech DjVu Control (autoinstall) LogMeIn Macromedia Shockwave Player Malwarebytes' Anti-Malware Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Encarta Encyclopedia Standard 2006 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Works Microsoft Works Suite 2006 Setup Launcher Microsoft Works Suite Add-in for Microsoft Word Modem Helper Mozilla Firefox (2.0.0.4) MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Musicmatch for Windows Media Player Nero 7 Ultra Edition NetWaiting Otto Overland Personal Ancestral File 5 Photo Viewer Photo Viewer V2.08 PhotoGallery PhotoshopdotcomInspirationBrowser Photosmart 320,370,7400,8100,8400 Series PlayStation®Network Downloader PlayStation®Store PrintScreen PS8100 PSPrinters06 QFolder QuickProjects QuickTime RCA Detective™ [removed] RCA easyRip [removed] RealPlayer RegCure [removed] Roxio DLA Roxio MyDVD LE Roxio RecordNow Audio Roxio RecordNow Copy Roxio RecordNow Data Scrapbook Factory Deluxe Search Assist Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978706) SkinsHP1 Sonic Activation Module Sonic Encoders Sony Media Manager for PSP 3.0 Spybot - Search & Destroy 1.4 TrayApp Uninstall Photo Viewer Unload Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Media Player 10 (KB910393) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 URL Assistant Viewpoint Media Player WeatherBug WebCyberCoach 3.2 Dell WebFldrs XP WebReg Windows Driver Package - (mr7910) Image (08/08/2006 1.4.0.0) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 10 Hotfix - KB895316 Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] Windows Media Player 11 Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB925766 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 Works Upgrade YouData ==== End Of File =========================== Should I wait until you advise differently or should I do the next step of your original instructions?
Sorry this is taking so long. I'm trying but my computer at home is frozen up during this scan. Will post as soon as I can. Thank you again!
It is still locked up and my husband isn't home to manually turn it off and on. I'm going to let it keep running to see if it frees up; otherwise I hope to get a hold of him to manually restart the computer. This is so aggrevating! It will be a while before my next post then, after lunch. Thank you for trying to help me. Once I get it restarted and re-run that GMER scan I will post ASAP. Thank you again…
I'm back… Got the computer restarted (several times - it keeps locking up on me when I run the GMER scan). I am going to let it run now - I am assuming that it will produce a report similar to the other two scans when I select "scan." Thank you again for being patient with me!
Okay, apparently running the GMER scan just made it mad. I stepped away for a moment and came back to a solid blue screen stating that a problem was detected and windows was shut down… Technical Information: *** STOP: 0x0000008E (0xc0000005, 0xf72B2DF6, 0xF761DAF0, 0x00000000) *** Ntfs.sys - Address F72B2DF6 base at F72A2000, Date Stamp 48025be5 Dump of physical memory complete. I rebooted into safe mode but the computer wouldn't let me access the internet from any user setting - including the one I'm using now. I'm gonna try the scan again but it may not work again… any ideas?
Hi, try running it in safe mode with all your security programs disabled and all other programs closed. make note of anything that says Rootkit Hidden Suspicious modification max++ if you cannot save a report if you still can't get anything out of it, we'll move on, but try and note anything you can
I was able to finally run a scan but it literally ran all night. I started it at around 8:00 pm and at 7:00 this morning it was still running. It looked like it just looped through the same files because I recognized many from last night. I stopped it, it froze up, re-started the computer again and it ran a quick scan. I went to save the document and it froze up again. I restarted the computer again but am afraid the computer will lock up again (as I am remoting into the computer from my office and no one is home to restart it). I will try it again after lunch and try to post the findings. I'm sorry my computer is being so difficult! But thank you for your continued help!
I'm back - it finally worked! whew, what an ordeal!

Here is what came up…

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-02 20:06:08
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Gary\LOCALS~1\Temp\kgtcypog.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 ATMhelpr.SYS (Windows NT Font Driver Helper/Adobe Systems Incorporated)

Device \FileSystem\Fastfat \Fat A8F06D20
Device \FileSystem\Fastfat \Fat A8EFF60A

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\CLSID\{E4379E50-68C5-D33E-7FBA-56058C6AAC72}\InprocServer32@ C:\WINDOWS\system32\KODAKO~1.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E4379E50-68C5-D33E-7FBA-56058C6AAC72}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E4379E50-68C5-D33E-7FBA-56058C6AAC72}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{E4379E50-68C5-D33E-7FBA-56058C6AAC72}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{E4379E50-68C5-D33E-7FBA-56058C6AAC72}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{E4379E50-68C5-D33E-7FBA-56058C6AAC72}\ProgID@ KodakOneTouch.OneTouchPrinting.1
Reg HKLM\SOFTWARE\Classes\CLSID\{E4379E50-68C5-D33E-7FBA-56058C6AAC72}\ToolboxBitmap32@ C:\WINDOWS\system32\KODAKO~1.DLL, 101
Reg HKLM\SOFTWARE\Classes\CLSID\{E4379E50-68C5-D33E-7FBA-56058C6AAC72}\TypeLib@ {81EBC6E0-D805-11D3-8920-00104B9876B8}
Reg HKLM\SOFTWARE\Classes\CLSID\{E4379E50-68C5-D33E-7FBA-56058C6AAC72}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{E4379E50-68C5-D33E-7FBA-56058C6AAC72}\VersionIndependentProgID@ KodakOneTouch.OneTouchPrinting

—- EOF - GMER 1.0.15 —-

Thanks again!
Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI