This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HJT Posts and Registry Help

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

AVG succesfully removed. ComboFix ran succesfully, here is log: ComboFix 10-03-06.08 - Ortiz Family 03/07/2010 10:19:37.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1614 [GMT -7:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\COUPON~1.DLL c:\windows\COUPON~1.OCX c:\windows\CouponPrinter.ocx c:\windows\Downloaded Program Files\popcaploader.inf . ((((((((((((((((((((((((( Files Created from 2010-02-07 to 2010-03-07 ))))))))))))))))))))))))))))))) . 2010-04-03 16:09 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-03 16:09 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-04-03 08:02 . 2010-04-03 08:02 ——– d—–w- c:\program files\Common Files\Apple 2010-04-03 08:01 . 2010-04-03 08:01 ——– d—–w- c:\documents and settings\Ortiz Family\Local Settings\Application Data\Apple 2010-04-03 08:01 . 2010-04-03 08:01 ——– d—–w- c:\program files\Apple Software Update 2010-04-03 08:01 . 2010-04-03 08:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple 2010-04-03 08:01 . 2010-04-03 08:01 ——– d—–w- c:\documents and settings\Ortiz Family\Local Settings\Application Data\Apple Computer 2010-04-03 08:00 . 2010-02-16 22:36 ——– d—–w- c:\program files\Quicktime 2010-04-03 05:49 . 2010-04-03 05:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Adobe Systems 2010-03-06 22:56 . 2010-03-06 22:56 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe 2010-03-06 22:16 . 2010-03-06 22:23 152576 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2010-03-06 22:16 . 2010-03-06 22:23 79488 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-03-06 22:11 . 2010-03-06 22:15 664 —-a-w- c:\windows\system32\d3d9caps.dat 2010-03-06 18:18 . 2010-03-06 23:02 ——– d—–w- c:\documents and settings\Ortiz Family\Local Settings\Application Data\NOS 2010-03-06 18:15 . 2010-03-06 18:15 38784 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-03-06 18:15 . 2010-03-06 18:15 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee 2010-03-06 18:15 . 2010-03-06 18:15 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee Security Scan 2010-03-06 18:14 . 2010-03-06 18:14 ——– d—–w- c:\program files\McAfee Security Scan 2010-03-05 23:45 . 2010-03-05 23:45 ——– d—–w- c:\program files\ESET 2010-03-04 20:53 . 2010-03-04 20:53 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache 2010-03-04 20:52 . 2010-03-07 06:18 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft 2010-03-04 20:51 . 2010-03-04 20:53 ——– d—–w- c:\documents and settings\Administrator 2010-03-04 18:37 . 2010-03-04 18:37 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google 2010-03-03 23:32 . 2007-11-27 10:24 14640 ——w- c:\windows\system32\spmsgXP_2k3.dll 2010-03-03 23:24 . 2010-03-03 23:24 ——– d—–w- c:\documents and settings\Ortiz Family\Local Settings\Application Data\HTC 2010-03-03 23:24 . 2010-03-03 23:33 ——– d—–w- c:\documents and settings\Ortiz Family\Application Data\Teleca 2010-03-03 23:23 . 2010-03-03 23:23 ——– d—–w- c:\documents and settings\All Users\Application Data\HTC 2010-03-03 23:23 . 2010-03-03 23:23 ——– d—–w- c:\program files\Common Files\Teleca Shared 2010-03-03 23:23 . 2010-03-03 23:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Teleca 2010-03-03 23:22 . 2009-07-02 21:42 25728 —-a-w- c:\windows\system32\drivers\ANDROIDUSB.sys 2010-03-03 23:22 . 2009-07-02 21:42 1122664 —-a-w- c:\windows\system32\WdfCoInstaller01007.dll 2010-03-03 23:21 . 2010-03-03 23:23 ——– d—–w- c:\program files\HTC 2010-03-03 23:18 . 2010-03-03 23:18 ——– d—–w- c:\windows\Downloaded Installations 2010-03-03 22:50 . 2008-04-13 19:45 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys 2010-03-03 22:50 . 2008-04-13 19:45 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2010-03-02 18:00 . 2010-03-02 18:00 ——– d—–w- c:\documents and settings\Ortiz Family\Application Data\Uniblue 2010-03-02 18:00 . 2010-03-02 18:00 ——– d—–w- c:\program files\Uniblue 2010-02-19 23:47 . 2010-02-19 23:47 3604480 —-a-w- c:\windows\system32\GPhotos.scr . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-04-03 08:05 . 2009-07-02 14:13 22392 —-a-w- c:\documents and settings\Ortiz Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-04-03 06:25 . 2009-12-15 23:07 ——– d—–w- c:\documents and settings\Ortiz Family\Application Data\uTorrent 2010-03-07 15:13 . 2009-11-26 16:30 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9 2010-03-06 23:17 . 2009-07-17 13:04 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS 2010-03-06 18:15 . 2009-07-17 13:05 ——– d—–w- c:\program files\Common Files\Adobe AIR 2010-03-06 18:15 . 2009-07-17 13:06 38784 —-a-w- c:\documents and settings\Ortiz Family\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-03-03 23:33 . 2010-03-03 23:33 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf 2010-03-03 23:33 . 2010-03-03 23:33 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf 2010-02-17 15:45 . 2009-11-06 15:52 ——– d—–w- c:\program files\Coupons 2010-02-16 03:41 . 2009-07-05 09:52 ——– d—–w- c:\program files\Common Files\Adobe 2010-02-02 23:21 . 2010-02-02 23:19 ——– d—–w- c:\program files\Trend Micro 2010-02-02 00:52 . 2009-07-17 13:04 ——– d—–w- c:\program files\Google 2010-02-02 00:51 . 2010-02-02 00:51 ——– d—–w- c:\program files\Picasa 2010-01-26 17:58 . 2009-10-20 14:26 ——– d—–w- c:\program files\File Scanner Library (Spybot - Search & Destroy) 2010-01-22 10:17 . 2009-12-16 09:22 ——– d—–w- c:\program files\Microsoft Silverlight 2010-01-14 19:55 . 2009-07-03 03:44 5058 —-a-w- c:\windows\Help\hhcolreg.dat 2010-01-14 19:51 . 2010-01-14 19:51 ——– d—–w- c:\documents and settings\Ortiz Family\Application Data\Microsoft Web Folders 2009-12-31 16:50 . 2003-03-31 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys 2009-12-21 19:14 . 2003-03-31 12:00 916480 —-a-w- c:\windows\system32\wininet.dll 2009-12-16 18:43 . 2009-07-02 05:38 343040 —-a-w- c:\windows\system32\mspaint.exe 2009-12-14 07:08 . 2003-03-31 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll 2009-12-08 19:27 . 2003-03-31 12:00 2189184 —-a-w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43 . 2002-08-29 01:04 2066048 —-a-w- c:\windows\system32\ntkrnlpa.exe 2009-10-19 06:41 . 2009-10-19 06:41 472064 —-a-w- c:\program files\RootRepeal.exe 2009-10-19 06:39 . 2009-10-19 06:39 50688 —-a-w- c:\program files\ATF_Cleaner.exe 2009-10-19 06:33 . 2009-10-19 06:32 4045528 —-a-w- c:\program files\mbam-setup.exe 2009-10-19 04:04 . 2009-10-19 04:02 4165792 —-a-w- c:\program files\AROTrial_mt.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
Oops! sorry, here it is:

ComboFix 10-03-06.08 - Ortiz Family 03/07/2010 10:19:37.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1614 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\COUPON~1.DLL
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\Downloaded Program Files\popcaploader.inf

.
((((((((((((((((((((((((( Files Created from 2010-02-07 to 2010-03-07 )))))))))))))))))))))))))))))))
.

2010-04-03 16:09 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-03 16:09 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-03 08:02 . 2010-04-03 08:02 ——– d—–w- c:\program files\Common Files\Apple
2010-04-03 08:01 . 2010-04-03 08:01 ——– d—–w- c:\documents and settings\Ortiz Family\Local Settings\Application Data\Apple
2010-04-03 08:01 . 2010-04-03 08:01 ——– d—–w- c:\program files\Apple Software Update
2010-04-03 08:01 . 2010-04-03 08:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-04-03 08:01 . 2010-04-03 08:01 ——– d—–w- c:\documents and settings\Ortiz Family\Local Settings\Application Data\Apple Computer
2010-04-03 08:00 . 2010-02-16 22:36 ——– d—–w- c:\program files\Quicktime
2010-04-03 05:49 . 2010-04-03 05:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Adobe Systems
2010-03-06 22:56 . 2010-03-06 22:56 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-03-06 22:16 . 2010-03-06 22:23 152576 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-03-06 22:16 . 2010-03-06 22:23 79488 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-06 22:11 . 2010-03-06 22:15 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-06 18:18 . 2010-03-06 23:02 ——– d—–w- c:\documents and settings\Ortiz Family\Local Settings\Application Data\NOS
2010-03-06 18:15 . 2010-03-06 18:15 38784 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-03-06 18:15 . 2010-03-06 18:15 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-03-06 18:15 . 2010-03-06 18:15 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2010-03-06 18:14 . 2010-03-06 18:14 ——– d—–w- c:\program files\McAfee Security Scan
2010-03-05 23:45 . 2010-03-05 23:45 ——– d—–w- c:\program files\ESET
2010-03-04 20:53 . 2010-03-04 20:53 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-03-04 20:52 . 2010-03-07 06:18 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
2010-03-04 20:51 . 2010-03-04 20:53 ——– d—–w- c:\documents and settings\Administrator
2010-03-04 18:37 . 2010-03-04 18:37 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-03-03 23:32 . 2007-11-27 10:24 14640 ——w- c:\windows\system32\spmsgXP_2k3.dll
2010-03-03 23:24 . 2010-03-03 23:24 ——– d—–w- c:\documents and settings\Ortiz Family\Local Settings\Application Data\HTC
2010-03-03 23:24 . 2010-03-03 23:33 ——– d—–w- c:\documents and settings\Ortiz Family\Application Data\Teleca
2010-03-03 23:23 . 2010-03-03 23:23 ——– d—–w- c:\documents and settings\All Users\Application Data\HTC
2010-03-03 23:23 . 2010-03-03 23:23 ——– d—–w- c:\program files\Common Files\Teleca Shared
2010-03-03 23:23 . 2010-03-03 23:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Teleca
2010-03-03 23:22 . 2009-07-02 21:42 25728 —-a-w- c:\windows\system32\drivers\ANDROIDUSB.sys
2010-03-03 23:22 . 2009-07-02 21:42 1122664 —-a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-03-03 23:21 . 2010-03-03 23:23 ——– d—–w- c:\program files\HTC
2010-03-03 23:18 . 2010-03-03 23:18 ——– d—–w- c:\windows\Downloaded Installations
2010-03-03 22:50 . 2008-04-13 19:45 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-03-03 22:50 . 2008-04-13 19:45 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2010-03-02 18:00 . 2010-03-02 18:00 ——– d—–w- c:\documents and settings\Ortiz Family\Application Data\Uniblue
2010-03-02 18:00 . 2010-03-02 18:00 ——– d—–w- c:\program files\Uniblue
2010-02-19 23:47 . 2010-02-19 23:47 3604480 —-a-w- c:\windows\system32\GPhotos.scr

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-03 08:05 . 2009-07-02 14:13 22392 —-a-w- c:\documents and settings\Ortiz Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-03 06:25 . 2009-12-15 23:07 ——– d—–w- c:\documents and settings\Ortiz Family\Application Data\uTorrent
2010-03-07 15:13 . 2009-11-26 16:30 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-03-06 23:17 . 2009-07-17 13:04 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-03-06 18:15 . 2009-07-17 13:05 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-03-06 18:15 . 2009-07-17 13:06 38784 —-a-w- c:\documents and settings\Ortiz Family\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-03-03 23:33 . 2010-03-03 23:33 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
2010-03-03 23:33 . 2010-03-03 23:33 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-02-17 15:45 . 2009-11-06 15:52 ——– d—–w- c:\program files\Coupons
2010-02-16 03:41 . 2009-07-05 09:52 ——– d—–w- c:\program files\Common Files\Adobe
2010-02-02 23:21 . 2010-02-02 23:19 ——– d—–w- c:\program files\Trend Micro
2010-02-02 00:52 . 2009-07-17 13:04 ——– d—–w- c:\program files\Google
2010-02-02 00:51 . 2010-02-02 00:51 ——– d—–w- c:\program files\Picasa
2010-01-26 17:58 . 2009-10-20 14:26 ——– d—–w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2010-01-22 10:17 . 2009-12-16 09:22 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-14 19:55 . 2009-07-03 03:44 5058 —-a-w- c:\windows\Help\hhcolreg.dat
2010-01-14 19:51 . 2010-01-14 19:51 ——– d—–w- c:\documents and settings\Ortiz Family\Application Data\Microsoft Web Folders
2009-12-31 16:50 . 2003-03-31 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2003-03-31 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2009-07-02 05:38 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2003-03-31 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:27 . 2003-03-31 12:00 2189184 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2002-08-29 01:04 2066048 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-19 06:41 . 2009-10-19 06:41 472064 —-a-w- c:\program files\RootRepeal.exe
2009-10-19 06:39 . 2009-10-19 06:39 50688 —-a-w- c:\program files\ATF_Cleaner.exe
2009-10-19 06:33 . 2009-10-19 06:32 4045528 —-a-w- c:\program files\mbam-setup.exe
2009-10-19 04:04 . 2009-10-19 04:02 4165792 —-a-w- c:\program files\AROTrial_mt.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-09-02 21:56 1175944 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-17 39408]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Ortiz Family^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Ortiz Family\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Ortiz Family^Start Menu^Programs^Startup^DING!.lnk]
path=c:\documents and settings\Ortiz Family\Start Menu\Programs\Startup\DING!.lnk
backup=c:\windows\pss\DING!.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Ortiz Family^Start Menu^Programs^Startup^MEMonitor.lnk]
path=c:\documents and settings\Ortiz Family\Start Menu\Programs\Startup\MEMonitor.lnk
backup=c:\windows\pss\MEMonitor.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Ortiz Family^Start Menu^Programs^Startup^MemTurbo.lnk]
path=c:\documents and settings\Ortiz Family\Start Menu\Programs\Startup\MemTurbo.lnk
backup=c:\windows\pss\MemTurbo.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 22:57 948672 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 08:57 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-06-05 19:35 335872 —-a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDBitSet]
2002-12-06 22:19 200704 ——w- c:\program files\HP CD-DVD\Umbrella\DVDBitSet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDTray]
2002-12-18 22:50 53248 ——w- c:\program files\HP CD-DVD\Umbrella\DVDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hp 1000 firmware]
2001-12-15 18:10 36864 ——w- c:\program files\hp LaserJet 1000\fwdl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2003-09-10 09:06 1208380 ——w- c:\program files\ahead\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mobile Connectivity Suite]
2009-05-27 22:46 598016 —-a-r- c:\program files\HTC\HTC Sync\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2003-09-10 09:07 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-07 00:27 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-07-17 13:05 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R3 US122;US122 Driver;c:\windows\system32\drivers\US122.sys [7/1/2009 10:57 PM 213196]
R3 Us122WdmService;US122 Wdm Audio;c:\windows\system32\drivers\US122Wdm.sys [7/1/2009 10:57 PM 86648]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [3/3/2010 4:22 PM 25728]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 5:49 AM 227232]
S3 US122DL;US122 Firmware Downloader;c:\windows\system32\drivers\US122DL.sys [7/1/2009 10:57 PM 17277]
.
Contents of the 'Scheduled Tasks' folder

2010-04-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2010-03-07 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-09-02 21:56]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
Notify-avgrsstarter - avgrsstx.dll
MSConfigStartUp-AROReminder - c:\program files\Advanced Registry Optimizer\aro.exe
MSConfigStartUp-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
AddRemove-Waves Diamond Bundle v5.0 - c:\progra~1\coolpro2\Waves\UNINST~1\UNWISE.EXE
AddRemove-Waves L3 Multimaximizer v1.0 - c:\progra~1\coolpro2\Waves\MULTIM~1\UNWISE.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-07 10:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-03-07 10:28:27
ComboFix-quarantined-files.txt 2010-03-07 17:28

Pre-Run: 66,793,156,608 bytes free
Post-Run: 66,827,055,104 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - B1C264211BC2BBE0C63C1A40CED80BE5
Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT



Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
Malwarebytes' Anti-Malware 1.44 Database version: 3833 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 3/7/2010 11:32:58 AM mbam-log-2010-03-07 (11-32-58).txt Scan type: Quick Scan Objects scanned: 121551 Time elapsed: 4 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Try this scanner instead:

Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Sorry had to leave unexpectedly out of town, I left the eset scan running, when I returned today the nothing was running so I went to program files>eset>log and got this, I think it is the right one. ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=aae685f3d2c8f64483d39d13e62dcc51 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-03-06 07:31:48 # local_time=2010-03-06 12:31:48 (-0700, Mountain Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 2597199 2597199 0 0 # compatibility_mode=1024 16777175 100 0 7661866 7661866 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=150876 # found=10 # cleaned=0 # scan_time=27812 G:\!–GAMES\kids - Fisher Price Pet Shop - gizmo14.iso Win32/Adware.DSSAgent application 00000000000000000000000000000000 I G:\C drive Backup\My Documents\Julio\Adobe hax\midacskg.rar probably a variant of Win32/TrojanDownloader.Agent trojan 00000000000000000000000000000000 I G:\C drive Backup\Shared\2_Adobe Photoshop 8 CS Crack+Keygenerator.zip probably a variant of Win32/TrojanDownloader.Agent trojan 00000000000000000000000000000000 I G:\ISO'S\!PROGRAMS\Adobe Photoshop CS4\Adobe.Photoshop.CS4.Extended.Incl.[Retail].Patch-NoPE\Adobe.Photoshop.CS4.Extended.Incl.[Retail].Patch-NoPE.rar multiple threats 00000000000000000000000000000000 I G:\ISO'S\!PROGRAMS\PORTABLES 2009 MEGA PACK\Portables 2009.iso multiple threats 00000000000000000000000000000000 I G:\ISO'S\WINDOWS\02-02-2009-Vortex-3G\02-02-2009-Vortex-3G.iso multiple threats 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1150.ZIP probably a variant of Win32/TrojanDownloader.Agent trojan 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1336.ZIP probably a variant of Win32/TrojanDownloader.Agent trojan 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1366.ZIP multiple threats 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1367.ZIP VBS/Disabler.NAB trojan 00000000000000000000000000000000 I # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=aae685f3d2c8f64483d39d13e62dcc51 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-03-08 01:16:51 # local_time=2010-03-07 06:16:51 (-0700, Mountain Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 2754092 2754092 0 0 # compatibility_mode=8192 67108863 100 0 74285 74285 0 0 # scanned=147073 # found=4 # cleaned=0 # scan_time=21221 G:\Windows OneCare Backup\JULIO\2009\Files\Part 1150.ZIP probably a variant of Win32/TrojanDownloader.Agent trojan 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1336.ZIP probably a variant of Win32/TrojanDownloader.Agent trojan 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1366.ZIP multiple threats 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1367.ZIP VBS/Disabler.NAB trojan 00000000000000000000000000000000 I
Hi.

Please do the following:


  • Go to Start->Run and type in notepad and hit OK.
  • Then copy and paste the content of the following codebox into Notepad:

    @echo off 
    if exist "%temp%\log.txt" del "%temp%\log.txt"
    
    for %%g in ( 
    "G:\!–GAMES\kids - Fisher Price Pet Shop - gizmo14.iso"
    "G:\C drive Backup\My Documents\Julio\Adobe hax\midacskg.rar"
    "G:\C drive Backup\Shared\2_Adobe Photoshop 8 CS Crack+Keygenerator.zip"
    "G:\ISO'S\!PROGRAMS\Adobe Photoshop CS4\Adobe.Photoshop.CS4.Extended.Incl.[Retail].Patch-NoPE\Adobe.Photoshop.CS4.Extended.Incl.[Retail].Patch-NoPE.rar"
    "G:\ISO'S\!PROGRAMS\PORTABLES 2009 MEGA PACK\Portables 2009.iso" 
    "G:\ISO'S\WINDOWS\02-02-2009-Vortex-3G\02-02-2009-Vortex-3G.iso" 
    "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1150.ZIP"
    "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1336.ZIP" 
    "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1366.ZIP" 
    "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1367.ZIP" 
    "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1150.ZIP" 
    "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1336.ZIP" 
    "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1366.ZIP" 
    "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1367.ZIP" 
    ) do (
    del /a/f/q %%g >nul 2>&1
    if exist %%g echo.%%g>>"%temp%\log.txt"
    )
    if exist "%temp%\log.txt" ( start notepad "%temp%\log.txt"
    ) else echo.Deleted Successfully !!
    pause
    del %0
  • Save the file to your DESKTOP as "find.bat". Make sure to save it with the quotes.
  • Once saved, the icon to click should look like this on your desktop:

    [external image: Posted Image]
  • Double click find.bat. to run it. A small black box should open and close - this is normal.
  • Let me know if it deletes successfully.


NEXT

Visit ADOBEand download the latest version of Acrobat Reader (version 9.3)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 17 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


NEXT


Please advise how your computer is running and if there are any outstanding issues
I never received a "successful deletion" message, "find.bat" saved fine, when I went to run it, the black screen came up, then the following message notepad popped up too: "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1150.ZIP" "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1336.ZIP" "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1366.ZIP" "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1367.ZIP" "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1150.ZIP" "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1336.ZIP" "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1366.ZIP" "G:\Windows OneCare Backup\JULIO\2009\Files\Part 1367.ZIP" after that, the find.bat icon on my desktop dissappeared. Did not bother to run the adobe updater & Java without succesful deletion, whould I still attempt to?
Unstant replay…unfortunately. The Adobe installer, first time I tried said cannot download either Adobe or McAfee, on 2nd try it allowed a run then quit upon set-up with same error code 1316 about -eng.us- files again Ditto with Java, I go to control panel, switch to classic view, click on Java and wystem instantly shuts down…u think it may be a hardware issue? Once again, the offer stands if you or someone there would prefer to Remotely control my rig. A while back we had to dump & reformat the PC. I presume we reloaded all the core components….I was so proud of myself too!!!! :wall: :smack:
no, I can't do the remote PC unfortunately

I don't believe this is malware related at all,

there doses not appear to be any active malware files left, so it may very well be a hardware issue.

Let's clean up the tools we used.

I'll leave you with my usual closing recommendations, then start a new topic in the Hardware forum

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.
well, I guess its a good thing we didnt find anything eh? A few quick things, you said you would suggest another antivirus program, being that we deleted AVG to try to trun those scans and the fact that I couldnt turn it off without uninstalling it, and also, would you consider the current condition of my registry to be in good enough shape to run ERUNT now?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI