This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] ComboFix Log according to previous instruction

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Just now able to get back to computer repair (think taxes and kids!). I have followed all the instructions and have copied the ComboFix log below. The computer seems to be running fine now. :yeah:
Questions: What was the problem? Are all infections cleaned from this machine now? Can I be sure that there is no root kit, packet sniffer or keylogger on this computer now?
Thank you so much!
Jennifer
ps-love the name of the website!

Here is the prior thread link that was closed a couple of days ago: http://forums.whatthetech.com/Possible_Tro…on_t111550.html


ComboFix 10-04-21.01 - Parents 04/21/2010 14:06:35.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.907 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\temp\brr
c:\windows\desktop
c:\windows\system32\Data
c:\windows\system32\service
c:\windows\system32\service\12082009_TIS17_SfFniAU.log
c:\windows\system32\service\27062009_TIS17_SfFniAU.log
F:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2010-03-21 to 2010-04-21 )))))))))))))))))))))))))))))))
.

2010-04-10 23:08 . 2010-04-10 23:08 ——– d—–w- c:\program files\ERUNT
2010-04-10 22:51 . 2008-03-06 16:51 3840 —-a-w- c:\windows\system32\drivers\BANTExt.sys
2010-04-10 22:28 . 2010-04-10 22:33 ——– d—–w- c:\documents and settings\Administrator\Application Data\HPAppData
2010-04-10 21:02 . 2010-04-10 21:05 23112 —-a-w- c:\windows\hpqins15.dat
2010-04-10 20:59 . 2010-04-21 19:01 ——– d—–w- c:\documents and settings\Parents\Application Data\HpUpdate
2010-04-10 20:59 . 2010-04-10 20:59 ——– d—–w- c:\windows\Hewlett-Packard
2010-04-07 21:17 . 2010-04-07 21:17 ——– d—–w- c:\documents and settings\Andrew\Application Data\HPAppData
2010-04-07 20:50 . 2010-04-13 19:03 ——– d—–w- c:\documents and settings\Parents\Application Data\HPAppData
2010-04-07 20:44 . 2010-04-07 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\WEBREG
2010-04-07 20:43 . 2010-04-07 20:46 ——– d—–w- c:\documents and settings\Parents\Application Data\HP
2010-04-07 20:42 . 2008-10-28 10:31 16496 —-a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-04-07 20:42 . 2008-10-28 10:31 49920 —-a-r- c:\windows\system32\drivers\HPZid412.sys
2010-04-07 20:41 . 2008-10-06 20:38 121344 —-a-w- c:\windows\system32\hpf3l083.dll
2010-04-07 20:41 . 2008-10-06 20:37 315392 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp083.dll
2010-04-07 20:41 . 2008-10-29 18:56 271704 —-a-r- c:\windows\system32\hpzids01.dll
2010-04-07 20:41 . 2008-10-28 10:31 21568 —-a-r- c:\windows\system32\drivers\HPZius12.sys
2010-04-07 20:41 . 2008-10-29 18:57 974848 —-a-r- c:\windows\system32\hpost_p02b.dll
2010-04-07 20:41 . 2008-10-29 18:57 307200 —-a-r- c:\windows\system32\hposc_p02a.dll
2010-04-07 20:41 . 2008-10-28 10:31 372736 —-a-r- c:\windows\system32\hppldcoi.dll
2010-04-07 20:41 . 2008-10-28 10:31 309760 —-a-r- c:\windows\system32\difxapi.dll
2010-04-07 20:41 . 2008-10-29 18:57 737280 —-a-r- c:\windows\system32\hposwia_p02b.dll
2010-04-07 18:28 . 2010-04-07 18:28 ——– d—–w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-04-07 18:06 . 2010-04-07 18:06 ——– d—–w- c:\program files\Common Files\HP
2010-04-07 18:05 . 2010-04-07 20:43 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2010-04-07 18:05 . 2010-04-07 18:05 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2010-04-07 18:04 . 2010-04-10 21:00 ——– d—–w- c:\program files\HP
2010-04-07 18:04 . 2008-04-13 17:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-04-07 18:04 . 2008-04-13 17:45 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2010-04-07 17:57 . 2010-04-07 20:44 161787 —-a-w- c:\windows\hpoins36.dat
2010-04-07 17:57 . 2009-06-24 09:40 652 ——w- c:\windows\hpomdl36.dat
2010-04-07 14:42 . 2010-04-07 14:42 ——– d—–w- c:\documents and settings\Parents\Application Data\Sunbelt
2010-04-07 14:42 . 2010-04-07 14:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Sunbelt
2010-04-07 14:42 . 2010-04-07 14:42 ——– d—–w- c:\program files\Sunbelt Software
2010-04-07 12:21 . 2010-02-24 15:16 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-04-07 04:40 . 2010-04-07 04:40 ——– d—–w- c:\documents and settings\Parents\Application Data\Malwarebytes
2010-04-07 04:40 . 2010-03-30 05:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-07 04:40 . 2010-04-07 04:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-07 04:40 . 2010-04-07 04:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-07 04:40 . 2010-03-30 05:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-07 04:12 . 2010-04-07 04:12 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-04-07 04:12 . 2010-04-07 04:12 ——– d—–w- c:\program files\IObit
2010-04-07 03:54 . 2010-04-07 03:54 ——– d—–w- c:\program files\CCleaner
2010-04-06 22:18 . 2010-04-06 22:18 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2010-04-06 22:18 . 2010-04-06 22:18 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2010-04-06 15:54 . 2010-04-06 15:54 503808 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7a4ea8ed-n\msvcp71.dll
2010-04-06 15:54 . 2010-04-06 15:54 499712 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7a4ea8ed-n\jmc.dll
2010-04-06 15:54 . 2010-04-06 15:54 348160 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7a4ea8ed-n\msvcr71.dll
2010-04-06 15:54 . 2010-04-06 15:54 61440 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-572568a5-n\decora-sse.dll
2010-04-06 15:54 . 2010-04-06 15:54 12800 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-572568a5-n\decora-d3d.dll
2010-04-06 15:06 . 2010-04-06 15:06 ——– d—–w- c:\documents and settings\Parents\Local Settings\Application Data\Temp
2010-04-06 14:50 . 2009-10-23 15:28 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-03-24 08:04 . 2010-03-24 18:17 952768 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\AdobeARM.exe
2010-03-24 08:04 . 2010-03-24 18:17 70584 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\AdobeExtractFiles.dll
2010-03-24 08:04 . 2010-03-24 18:17 326056 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\ReaderUpdater.exe
2010-03-24 08:04 . 2010-03-24 18:17 326056 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\AcrobatUpdater.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-10 21:11 . 2004-02-28 23:49 ——– d—–w- c:\program files\Common Files\Adobe
2010-04-07 22:12 . 2007-11-03 01:09 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-07 21:15 . 2009-07-24 18:21 41960 -c–a-w- c:\documents and settings\Andrew\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-07 20:43 . 2004-01-23 01:11 41960 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-07 16:35 . 2004-01-23 00:58 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-07 16:34 . 2007-05-17 14:41 ——– d—–w- c:\program files\FinePixViewer
2010-04-07 16:33 . 2007-05-17 14:42 ——– d—–w- c:\documents and settings\Parents\Application Data\FUJIFILM
2010-04-07 16:10 . 2007-07-22 16:39 ——– d—–w- c:\program files\Common Files\Apple
2010-04-07 16:04 . 2009-09-14 17:23 ——– d—–w- c:\program files\QuickTime
2010-04-07 15:21 . 2009-02-22 20:31 ——– d—–w- c:\program files\Windows Live
2010-04-06 23:29 . 2004-02-29 03:02 ——– d—–w- c:\program files\Google
2010-04-06 22:01 . 2004-01-27 20:43 41576 —-a-w- c:\documents and settings\Kids\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-06 15:53 . 2004-01-23 00:31 ——– d—–w- c:\program files\Java
2010-04-06 15:19 . 2008-02-03 01:23 ——– d—–w- c:\documents and settings\Parents\Application Data\StarOffice8
2010-03-10 06:15 . 2002-08-29 11:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-09 09:28 . 2009-02-22 19:30 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-25 06:24 . 2004-02-06 23:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2002-08-29 11:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 1980-01-01 06:00 2146304 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 1980-01-01 06:00 2024448 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2003-07-10 18:19 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2003-06-30 22:30 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2004-08-04 07:56 . 2005-02-17 17:35 73728 -csha-w- c:\windows\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2004-05-28 323584]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-11-03 4800512]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-01-26 1020248]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 17:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher 2.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk
backup=c:\windows\pss\Exif Launcher 2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Parents^Start Menu^Programs^Startup^Folding@Home 5.03.lnk]
path=c:\documents and settings\Parents\Start Menu\Programs\Startup\Folding@Home 5.03.lnk
backup=c:\windows\pss\Folding@Home 5.03.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
2002-04-03 07:01 135264 —-a-w- c:\program files\Creative\SBLive\Diagnostics\diagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2003-08-13 16:27 28672 —-a-w- c:\windows\SYSTEM32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 07:00 90112 -c—-w- c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 —-a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=

R2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [9/14/2009 1:19 PM 10384]
R2 tmpreflt;tmpreflt;c:\windows\SYSTEM32\DRIVERS\tmpreflt.sys [9/14/2009 1:52 PM 36368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R2 WMP300NSvc;WMP300NSvc;c:\program files\Linksys\WMP300N\WLService.exe [11/14/2008 12:23 AM 53307]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\SYSTEM32\DRIVERS\TM_CFW.sys [9/14/2009 1:52 PM 339984]
R3 tmevtmgr;tmevtmgr;c:\windows\SYSTEM32\DRIVERS\tmevtmgr.sys [9/14/2009 1:55 PM 50704]
R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [9/14/2009 1:56 PM 497008]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [9/14/2009 1:56 PM 689416]
R3 WMP300Nv1;Linksys Wireless-N PCI Adapter WMP300N Driver;c:\windows\SYSTEM32\DRIVERS\WMP300Nv1.sys [11/14/2008 12:18 AM 822400]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys –> c:\windows\system32\drivers\SBREdrv.sys [?]
S3 P1130VID;Creative WebCam NX Pro;c:\windows\SYSTEM32\DRIVERS\P1130Vid.sys [10/19/2006 10:05 PM 90229]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-01 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\SYSTEM32\cleanmgr.exe [2002-08-29 00:12]

2010-04-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]

2010-04-21 c:\windows\Tasks\User_Feed_Synchronization-{87256BA6-AB36-408B-A11D-9D8824DECCB8}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?hl=en
uDefault_Search_URL = hxxp://www.google.com/ie
mSearch Bar =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Parents\Application Data\Mozilla\Firefox\Profiles\6jph20mi.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://webmail.central.cox.net/
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-PCMService - c:\program files\Dell\Media Experience\PCMService.exe
MSConfigStartUp-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
MSConfigStartUp-RoxioAudioCentral - c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
MSConfigStartUp-SBAMTray - c:\program files\Sunbelt Software\CounterSpy\SBAMTray.exe
MSConfigStartUp-SDTray - c:\program files\Spyware Doctor\SDTrayApp.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
AddRemove-101 Dalmatians StoryBook - c:\disney\101_ASB\101_DEL95.EXE
AddRemove-Adobe Flash Player ActiveX - c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
AddRemove-Adobe Flash Player Plugin - c:\windows\system32\Macromed\Flash\uninstall_plugin.exe



**************************************************************************

disk not found C:\

please note that you need administrator rights to perform deep scan
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(960)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2010-04-21 14:13:39
ComboFix-quarantined-files.txt 2010-04-21 19:13

Pre-Run: 53,213,671,424 bytes free
Post-Run: 53,182,865,408 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 9006F47018615680F4B4F6FA4ED6BBAB
There's never a 100% guarantee that a computer is free of all infections.
Where the infection came from? I have no idea.

Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

If you used DeFogger
You must remember to re-enable your Emulation drivers once we are finished, double click DeFogger to run the tool.

  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.


To be on the safe side, I would also change all my passwords.



Here's my usual all clean post

Log looks good :D


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
    5. Change the Download signed ActiveX controls to Prompt
    6. Change the Download unsigned ActiveX controls to Disable
    7. Change the Initialize and script ActiveX controls not marked as safe to Disable
    8. Change the Installation of desktop items to Prompt
    9. Change the Launching programs and files in an IFRAME to Prompt
    10. Change the Navigate sub-frames across different domains to Prompt
    11. When all these settings have been made, click on the OK button.
    12. If it prompts you as to whether or not you want to save the settings, press the Yes button.

  • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.


I would suggest you read How to Prevent Malware:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI