[Resolved] Virus updates blocked
31 min read
- Go to Start > Run and type: cmd.exe
- press Ok.
- At the command prompt type: c:\mbr.exe -t >>"C:\mbr.log"
- press Enter.
- A "DOS" box will open and quickly disappear. That is normal.
- A log file named mbr.log will be created and saved to the root of the system drive (usually C:\).
- Copy and paste the results of the mbr.log in your next reply.
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !
dir /d "C:\Documents and Settings" > look2.txt start notepad look2.txt
Save this as look.bat Choose to "Save type as - All Files"
It should look like this: [external image: Posted Image]
Double click on look.bat & allow it to run. A notepad file will open. Copy that information into your next reply, please.
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
- They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')
KillAll:: Registry:: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "65533:TCP"=- "52344:TCP"=- "2479:TCP"=- "9438:TCP"=- "3389:TCP"=-
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you.
- Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
NEXT:
Malwarebytes' Anti-Malware
I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:
- Open Malwarebytes' Anti-Malware
- Select the Update tab
- Click Check for Updates
- After the update have been completed, Select the Scanner tab.
- Select Perform quick scan, then click on Scan
- Leave the default options as it is and click on Start Scan
- When done, you will be prompted. Click OK, then click on Show Results
- Checked (ticked) all items and click on Remove Selected
- After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
NEXT:
Please make sure you include the following items in your next post:
1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that was produced after running the ComboFix script.
3. The log that was produced after running the MalwareBytes' Anti-Malware scan.
4. An update on how your computer is currently running.
ComboFix 10-03-07.02 - Lancesandra 03/08/2010 15:17:53.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.566 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Lancesandra\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2010-02-08 to 2010-03-08 )))))))))))))))))))))))))))))))
.
2010-03-08 00:32 . 2010-03-08 00:32 77312 —-a-w- C:\mbr.exe
2010-03-08 00:13 . 2010-03-08 00:17 ——– d—–w- C:\_OTL
2010-03-07 17:25 . 2010-03-07 17:25 ——– d—–w- c:\program files\ERUNT
2010-03-07 16:58 . 2010-03-07 16:58 ——– d—–w- c:\program files\Trend Micro
2010-03-07 16:28 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-07 16:28 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-07 16:28 . 2010-03-07 16:28 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-07 15:41 . 2010-02-23 20:04 1664256 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-03-06 23:38 . 2010-03-06 23:38 ——– d—–w- C:\$AVG
2010-03-06 23:12 . 2010-03-06 23:12 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-06 23:12 . 2010-03-06 23:12 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-06 23:12 . 2010-03-06 23:12 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-06 23:12 . 2010-03-06 23:12 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-06 23:12 . 2010-03-08 17:29 ——– d—–w- c:\windows\system32\drivers\Avg
2010-03-06 23:12 . 2010-03-07 15:50 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-03-06 23:11 . 2010-03-06 23:11 ——– d—–w- c:\program files\AVG
2010-03-06 23:11 . 2010-03-06 23:11 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-03-06 13:28 . 2009-07-28 21:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-03-03 23:53 . 2010-03-03 23:53 ——– d—–w- c:\documents and settings\Lancesandra\Application Data\Windows Search
2010-03-01 02:37 . 2010-03-03 23:59 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-03-01 02:37 . 2010-03-01 02:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-01 02:05 . 2010-03-01 02:05 ——– d—–w- c:\documents and settings\Lancesandra\Application Data\Malwarebytes
2010-03-01 02:05 . 2010-03-01 02:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-26 13:01 . 2010-02-26 13:02 ——– d—–w- c:\program files\CCleaner
2010-02-26 02:27 . 2010-02-26 02:27 0 —-a-w- c:\windows\nsreg.dat
2010-02-26 02:26 . 2010-02-26 02:26 ——– d—–w- c:\documents and settings\Lancesandra\Local Settings\Application Data\Mozilla
2010-02-22 05:27 . 2010-02-22 05:27 197760 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-21 22:17 . 2007-10-23 15:27 110592 —-a-w- c:\documents and settings\Lancesandra\Application Data\U3\temp\cleanup.exe
2010-02-21 22:10 . 2007-10-23 15:22 3350528 —ha-w- c:\documents and settings\Lancesandra\Application Data\U3\temp\Launchpad Removal.exe
2010-02-21 22:09 . 2010-02-21 22:17 ——– d—–w- c:\documents and settings\Lancesandra\Application Data\U3
2010-02-21 21:43 . 2010-02-21 21:43 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\IsolatedStorage
2010-02-21 21:43 . 2010-02-21 21:43 ——– d—–w- c:\documents and settings\Lancesandra\Local Settings\Application Data\Intuit
2010-02-21 21:37 . 2010-02-21 21:37 ——– d—–w- c:\documents and settings\Lancesandra\Application Data\Intuit
2010-02-21 21:37 . 2010-02-21 21:37 ——– d—–w- c:\program files\Common Files\AnswerWorks 5.0
2010-02-21 21:31 . 2010-02-21 21:31 ——– d—–w- c:\documents and settings\Lancesandra\Local Settings\Application Data\IsolatedStorage
2010-02-21 21:31 . 2010-02-21 21:36 ——– d—–w- c:\program files\Common Files\Intuit
2010-02-21 21:30 . 2010-02-21 21:30 ——– d—–w- c:\program files\TurboTax
2010-02-21 21:29 . 2010-02-21 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Intuit
2010-02-11 01:25 . 2010-02-11 01:25 ——– d—–w- c:\program files\Common Files\Remote Control USB Driver
2010-02-09 00:09 . 2010-02-09 00:09 ——– d—–w- c:\documents and settings\Lancesandra\Local Settings\Application Data\assembly
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-06 13:25 . 2009-10-31 00:08 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-02-26 21:46 . 2010-02-26 21:46 ——– d—–w- c:\documents and settings\Administrator\Application Data\Windows Search
2010-02-21 21:43 . 2009-10-31 04:58 94888 —-a-w- c:\documents and settings\Lancesandra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-11 01:25 . 2009-05-05 16:00 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-10 09:02 . 2009-05-05 16:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-02-05 22:41 . 2010-02-05 22:41 ——– d—–w- c:\program files\Common Files\Research In Motion
2010-02-05 22:41 . 2010-02-05 22:41 ——– d—–w- c:\program files\AT&T
2010-02-05 22:33 . 2009-11-18 17:34 ——– d—–w- c:\program files\Sierra Wireless Inc
2010-02-03 23:52 . 2010-02-03 23:52 ——– d—–w- c:\documents and settings\All Users\Application Data\AT&T
2010-01-02 23:37 . 2010-01-02 23:37 0 —-a-w- c:\documents and settings\Lancesandra\Application Data\wklnhst.dat
2009-12-31 16:50 . 2009-04-28 04:51 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2009-04-28 04:51 916480 ——w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2009-04-28 05:01 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2009-04-28 04:51 33280 —-a-w- c:\windows\system32\csrsrv.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-03-07_22.21.08 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-04-28 04:51 . 2009-10-28 15:07 46080 c:\windows\system32\tzchange.exe
+ 2009-04-28 04:51 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe
+ 2009-07-12 06:02 . 2009-07-12 06:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2009-04-28 04:51 . 2009-12-09 05:53 726528 c:\windows\system32\jscript.dll
- 2009-04-28 04:51 . 2009-06-22 06:44 726528 c:\windows\system32\jscript.dll
- 2009-04-28 04:51 . 2009-06-22 06:44 726528 c:\windows\system32\dllcache\jscript.dll
+ 2009-04-28 04:51 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll
+ 2010-03-08 02:50 . 2010-03-08 02:50 195584 c:\windows\Installer\57ddfa.msi
+ 2010-03-08 02:50 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976662-IE8\spuninst\updspapi.dll
+ 2010-03-08 02:50 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976662-IE8\spuninst\spuninst.exe
+ 2010-03-08 02:50 . 2009-06-22 06:44 726528 c:\windows\ie8updates\KB976662-IE8\jscript.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 20:04 1664256 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DA3D342F-FF20-4E31-9E82-22334155730C}]
2009-06-02 14:51 2695168 —-a-w- c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6CD56C02-CB4D-41B5-A0FE-B479061CCB41}"= "c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll" [2009-06-02 2695168]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{6cd56c02-cb4d-41b5-a0fe-b479061ccb41}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{6CD56C02-CB4D-41B5-A0FE-B479061CCB41}"= "c:\program files\Antbar\Ant.com Toolbar\tbcore3.dll" [2009-06-02 2695168]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{6cd56c02-cb4d-41b5-a0fe-b479061ccb41}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB00982.TBSB00982]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-16 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-16 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-06 1434920]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-03-06 79144]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-5-5 376832]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-06 23:12 12464 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 07:04 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AT&T Communication Manager]
2009-10-09 23:58 883272 —-a-w- c:\program files\AT&T\Communication Manager\ATTCM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-06 22:51 3885408 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2008-04-14 12:00 59392 —-a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-04-27 21:08 17881088 —-a-w- c:\windows\RTHDCPL.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\AT&T\\Communication Manager\\SwiApiMux.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4118:TCP"= 4118:TCP:Services
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/6/2010 5:12 PM 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/6/2010 5:12 PM 242696]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/6/2010 5:11 PM 308064]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [5/5/2009 10:39 AM 55152]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [4/27/2009 7:59 PM 38912]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [5/5/2009 10:00 AM 1684736]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [10/9/2009 5:59 PM 121416]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [3/6/2010 5:12 PM 369920]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 4:08 PM 533360]
S3 SRS_PremiumSound_Service;SRS Labs Premium Sound;c:\windows\system32\drivers\SRS_PremiumSound_i386.sys [5/5/2009 11:16 AM 232872]
S3 SWNC8UA3;Sierra Wireless MUX NDIS Driver (UMTSA3);c:\windows\system32\drivers\swnc8ua3.sys [3/31/2009 2:45 PM 190080]
S3 SWUMXA3;Sierra Wireless USB MUX Driver (UMTSA3);c:\windows\system32\drivers\swumxa3.sys [5/4/2009 3:57 PM 148096]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [3/16/2009 3:27 PM 39040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: bmnet.dll
Trusted Zone: intuit.com\ttlc
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Lancesandra\Application Data\Mozilla\Firefox\Profiles\we7cl42s.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-08 15:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(784)
c:\windows\system32\bmnet.dll
- - - - - - - > 'explorer.exe'(1048)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
.
**************************************************************************
.
Completion time: 2010-03-08 15:27:39 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-08 21:27
ComboFix2.txt 2010-03-07 22:23
Pre-Run: 61,571,989,504 bytes free
Post-Run: 61,542,473,728 bytes free
- - End Of File - - 29E98EFB5F47EE77FB9D7E7400E01A12
Malwarebytes' Anti-Malware 1.44
Database version: 3838
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
3/8/2010 3:49:37 PM
mbam-log-2010-03-08 (15-49-37).txt
Scan type: Quick Scan
Objects scanned: 126819
Time elapsed: 5 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
I would also like to see a list of installed programs, so please do this:
Click Start > Run then copy/paste the following single-line command into the Run box and click OK:
C:\Qoobox\Add-Remove Programs.txt
A text file should open. Post the contents of that file in your next reply.
@echo off if exist %systemroot%\system32\termsrv32.dll del /q %systemroot%\system32\termsrv32.dll >nul 2>&1 reg add HKLM\SYSTEM\CurrentControlSet\Services\TermService\Parameters /v ServiceDll /t REG_EXPAND_SZ /d ^%systemroot^%\System32\termsrv.dll /f
Save this as runme.bat Choose to "Save type as - All Files"
It should look like this: [external image: Posted Image]
Double click on runme.bat & allow it to run. A black window/box will appear and then disappear very quickly. Please do not be alarmed. This is normal.
NEXT:
ComboFix Script
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
- They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')
KillAll:: Registry:: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "4118:TCP"=-
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you.
- Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
NEXT:
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
- Close any open programs
- Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
- Once the update is complete, click on Settings.
- Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
- Spyware, adware, dialers, and other riskware
- Archives
- E-mail databases
- Click on My Computer under the green Scan bar to the left to start the scan.
- Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
- Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
- Click View report… at the bottom.
- Click the Save report… button.
[external image: Posted Image]
- Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please make sure you include the following items in your next post:
1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that was produced after running the ComboFix script.
3. The log that was produced after running the Kaspersky Online Scanner.
4. =====> An update on how your computer is currently running. <=====
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI