This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] computer attacked by internet virus

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 8/4/2009 9:40:51 PM
System Uptime: 4/22/2010 6:25:10 PM (0 hours ago)

Motherboard: Dell Inc. | | 0YD479
Processor: Intel® Core™2 CPU T7200 @ 2.00GHz | Microprocessor | 1995/166mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 57.375 GiB free.
D: is CDROM (UDF)
E: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Photosmart C7200 series
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer: HP
Name: Photosmart C7200 series
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:

Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: HP LaserJet P2015 Series
Device ID: ROOT\MULTIFUNCTION\0001
Manufacturer: Hewlett-Packard
Name: HP LaserJet P2015 Series
PNP Device ID: ROOT\MULTIFUNCTION\0001
Service:

==== System Restore Points ===================


==== Installed Programs ======================

32 Bit HP CIO Components Installer
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.2
AIO_Scan
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
AVG Free 9.0
Bonjour
BufferChm
C7200
C7200_Help
Cards_Calendar_OrderGift_DoMorePlugout
Command & Conquer 3
Command & Conquer™ 3: Kane's Wrath
Command & Conquer™ 4 Tiberian Twilight
Command & Conquer™ Red Alert™ 3
Copy
CustomerResearchQFolder
CutePDF Writer 2.8
Dell Resource CD
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DocProc
DocProcQFolder
EA Download Manager
EA Download Manager UI
ERUNT 1.1j
eSupportQFolder
Fax
Google Toolbar for Internet Explorer
GPBaseService
GPBaseService2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Customer Participation Program 10.0
HP Imaging Device Functions 10.0
HP Photosmart All-In-One Driver Software 10.0 Rel .2
HP Photosmart Essential 2.5
HP Smart Web Printing 4.60
HP Solution Center 13.0
HP Update
HP_Network_UserGuide
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookWebPack1
HPProductAssistant
HPSSupply
iTunes
Java™ 6 Update 17
LimeWire 5.3.6
LogMeIn
Malwarebytes' Anti-Malware
MarketResearch
McAfee Security Scan
Microsoft .NET Framework 3.5 SP1
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mozilla Firefox (3.5.3)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Network
NVIDIA Drivers
OCR Software by I.R.I.S. 10.0
PanoStandAlone
pdfsam
PS_AIO_02_ProductContext
PS_AIO_02_Software
PS_AIO_02_Software_Min
PSSWCORE
QuickTime
Rightdown Software - Toolbar
Scan
Shop for HP Supplies
SigmaTel Audio
SmartWebPrinting
SolutionCenter
Status
Synaptics Pointing Device Driver
Tank wars 1.1
The Battle for Middle-earth ™ II
The Lord of the Rings, The Rise of the Witch-king
Toolbox
TrayApp
TrojanHunter 5.0
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VideoToolkit01
War Chess
WebReg
World in Conflict: Soviet Assault

==== End Of File ===========================



GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-22 19:25:00
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Dan\AppData\Local\Temp\pwlorkow.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
my husband says his computer was getting "taken over" so he shut it down and I ran these scans under safe mode. the restorePoint file I tried to run failed and as far as I know the other steps were followed ok.

The error messages I keep getting say that files are infected and do I want to activate my antivirus software at the same time that my avg is reporting several infected files etc etc. I'm not sure what it's doing.

The internet comes up with a page that is redirecting to http://antispyware-soft.microsoft.com/bloc…76.0&pgid=1 it was supposed to be opening up ksl.com and hotmail. which should not be unsafe or compromised sites. etc. etc. that's the gist of the problem. Hope that explains the situation sufficiently.
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 5 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Hello stressa.

Peer-to-Peer Programs Warning
Your log shows that you are using so called peer-to-peer or file-sharing programs. These programs allow to share files between users as the name(s) suggest. In today's world cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is also important to note that sharing entertainment files and proprietary software infringes the copyright laws in many countries over the world and you are putting yourself at risk of being indicted through organizations watching over the rights of the authors of such files (i.e. the RIAA for music files, or the MPAA for movie files in the USA) or the authors of the files themselves.

It is your decision whether or not you wish to keep your program(s). However, please refrain from using them until your computer has been declared clean

Please do the following.

Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.


Please post the logs from exehelper and Combofix in your next reply.Thanks
i wasn't aware we were using p2p software. which programs are you referring to so that I can talk to my husband about it. (it's his laptop) I'll work on the next steps hopefully this evening when I get home.
yes. I apologize. I need a few more days to get the next part in. Big family function going on this weekend and I'm afraid I won't be able to get to it until next week. Sorry. I appreciate your help and patience.
Hi,i am unable to open the attached combofix.txt.Please copy/paste the log into a reply and also please do this with any future logs Yes the p2p i referred to was limewire.
ComboFix 10-05-03.03 - Dan 05/03/2010 18:17:35.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1170 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\Desktop Shortcuts\theresavirusfixstuff\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\windows\asam.exe

.
((((((((((((((((((((((((( Files Created from 2010-04-04 to 2010-05-04 )))))))))))))))))))))))))))))))
.

2010-05-04 00:26 . 2010-05-04 00:27 ——– d—–w- c:\users\Dan\AppData\Local\temp
2010-05-04 00:26 . 2010-05-04 00:26 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-04-22 16:08 . 2010-05-04 00:08 17408 —-a-w- c:\windows\system32\rpcnetp.dll
2010-04-22 16:08 . 2010-04-24 00:02 17408 —-a-w- c:\windows\system32\rpcnetp.exe
2010-04-22 14:29 . 2010-05-04 00:07 ——– d—–w- c:\users\Dan\AppData\Local\xivjooifb
2010-04-22 14:27 . 2010-04-22 14:27 242696 —-a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2010-04-22 14:25 . 2010-04-22 14:25 1689952 —-a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-04-16 23:39 . 2010-04-16 23:39 ——– d—–w- c:\users\Dan\AppData\Local\CutePDF Writer
2010-04-16 23:38 . 2010-04-16 23:38 ——– d—–w- c:\program files\GPLGS
2010-04-16 23:37 . 2009-11-05 14:39 87552 —-a-w- c:\windows\system32\cpwmon2k.dll
2010-04-16 23:37 . 2010-04-16 23:37 ——– d—–w- c:\program files\Acro Software
2010-04-16 23:37 . 2010-04-16 23:37 ——– d—–w- c:\program files\Ask.com
2010-04-15 09:01 . 2010-04-15 09:02 ——– d—–w- C:\d215d5d990a2519c8dcc4e
2010-04-15 03:49 . 2010-04-15 03:50 ——– d—–w- c:\program files\Common Files\Adobe
2010-04-14 23:05 . 2010-02-23 11:10 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 23:05 . 2010-02-23 11:10 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 23:05 . 2010-02-23 11:10 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 23:05 . 2010-02-18 14:07 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 23:05 . 2010-02-18 14:07 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 23:05 . 2010-03-05 14:01 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 23:05 . 2010-02-18 14:07 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 23:05 . 2010-02-18 13:30 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 23:05 . 2010-02-18 11:28 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-13 18:21 . 2009-12-23 11:33 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-13 18:21 . 2010-01-13 17:34 98304 —-a-w- c:\windows\system32\cabview.dll
2010-04-08 14:43 . 2010-04-08 14:43 4255072 —-a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-04-07 23:54 . 2010-04-07 23:54 303104 —-a-w- c:\windows\sttray_AVG_RESTORED_1.exe
2010-04-07 23:54 . 2010-04-07 23:54 303104 —-a-w- c:\windows\sttray_AVG_RESTORED.exe
2010-04-06 19:54 . 2010-04-06 19:54 ——– d—–w- c:\program files\iPod
2010-04-06 19:53 . 2010-04-06 19:54 ——– d—–w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-06 19:53 . 2010-04-06 19:54 ——– d—–w- c:\program files\iTunes
2010-04-06 19:51 . 2010-04-06 19:51 ——– d—–w- c:\program files\QuickTime
2010-04-06 19:47 . 2010-04-06 19:47 ——– d—–w- c:\program files\Bonjour
2010-04-06 19:45 . 2010-04-06 19:45 73000 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-04 00:08 . 2009-11-14 06:35 ——– d—–w- c:\programdata\avg9
2010-05-04 00:08 . 2009-08-05 10:14 57752 —-a-w- c:\windows\system32\rpcnet.dll
2010-04-22 14:26 . 2009-08-05 04:16 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-16 03:29 . 2009-08-05 03:59 40626 —-a-w- c:\users\Dan\AppData\Roaming\nvModes.dat
2010-04-15 09:18 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-04-14 09:02 . 2009-08-05 10:14 57752 ——w- c:\windows\system32\rpcnet.exe
2010-04-08 04:19 . 2009-12-15 08:17 ——– d—–w- c:\programdata\Electronic Arts
2010-04-06 19:54 . 2009-08-09 03:00 ——– d—–w- c:\program files\Common Files\Apple
2010-04-06 19:53 . 2009-08-09 03:02 ——– d—–w- c:\programdata\Apple Computer
2010-04-03 04:06 . 2010-04-03 03:33 ——– d—–w- c:\users\Dan\AppData\Roaming\Command and Conquer 4
2010-04-03 00:03 . 2009-12-15 07:51 ——– d—–w- c:\program files\Electronic Arts
2010-03-24 18:17 . 2010-03-24 08:04 952768 —-a-w- c:\programdata\Adobe\Reader\9.2\ARM\1655\AdobeARM.exe
2010-03-24 18:17 . 2010-03-24 08:04 70584 —-a-w- c:\programdata\Adobe\Reader\9.2\ARM\1655\AdobeExtractFiles.dll
2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\programdata\Adobe\Reader\9.2\ARM\1655\ReaderUpdater.exe
2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\programdata\Adobe\Reader\9.2\ARM\1655\AcrobatUpdater.exe
2010-03-12 15:44 . 2010-03-12 15:44 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-12 15:44 . 2009-08-05 04:16 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-12 15:44 . 2009-08-05 04:16 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-24 14:34 . 2009-08-05 04:07 59848 —-a-w- c:\users\Dan\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-23 06:39 . 2010-03-31 04:20 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 04:20 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33 . 2010-03-31 04:20 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55 . 2010-03-31 04:20 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06 . 2010-03-11 10:00 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-11 10:00 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-11 10:00 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-12 17:46 . 2010-02-12 17:46 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 17:46 . 2010-02-12 17:46 107808 —-a-w- c:\windows\system32\dns-sd.exe
2006-11-22 14:57 . 2006-11-22 14:57 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 22:50 1197448 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-12 39408]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-16 815104]
"THGuard"="c:\program files\TrojanHunter 5.0\THGuard.exe" [2008-10-24 1056928]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-10-05 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-05 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-05 81920]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2007-10-05 86016]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

c:\users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):a7,78,a8,aa,b7,4b,ca,01

S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-12 216200]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-04-22 242896]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-03-12 916760]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-03-12 308064]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [2008-08-11 12856]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-05-04 c:\windows\Tasks\User_Feed_Synchronization-{EA6EE15C-DA15-4380-9CCE-32343F6C988F}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ksl.com/
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:5555
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: mykmart.com\uskihsvpowa
Trusted Zone: mykmart.com\www
FF - ProfilePath - c:\users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\w5o762xc.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SigmatelSysTrayApp - sttray.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-03 18:27
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\users\Dan\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2846841112-1908449010-1053283845-1000\Software\SecuROM\License information*]
"datasecu"=hex:23,01,28,e9,bf,13,ac,2b,01,5f,6a,6d,50,7b,a9,b3,f3,32,2a,43,63,
fc,88,16,f1,24,14,b1,64,bb,93,b0,f1,54,17,ea,37,bb,f5,5a,9b,f6,c3,a2,ec,f4,\
"rkeysecu"=hex:76,28,bf,e4,e8,ef,57,9b,87,08,6a,80,b9,11,b6,ae

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-05-03 18:31:19
ComboFix-quarantined-files.txt 2010-05-04 00:31

Pre-Run: 59,329,822,720 bytes free
Post-Run: 60,011,585,536 bytes free

- - End Of File - - 47150339910C8FAD3B74E59E86E78A65
and here is the exehelper log. exeHelper by Raktor Build 20100414 Run at 18:00:28 on 05/03/10 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished–
and,… we don't use limewire anymore. We just never uninstalled it. i wasn't sure if it would delete the music my husband previously downloaded with it. We are now buying music off itunes.
Hello stressa.Please do the following.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    uRun: [onywygoj] c:\users\dan\appdata\local\xivjooifb\coffskjtssd.exe 
    Trusted Zone: mykmart.com\uskihsvpowa
    Trusted Zone: mykmart.com\www
    
    Folder::
    c:\users\Dan\AppData\Local\xivjooifb
    
    DirLook::
    C:\d215d5d990a2519c8dcc4e
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


You have Malwarebytes installed,please update and run a quick scan.Post the log.

In your next reply please post the following
  • Combofix log
  • MBAM log
  • How your computer is running now

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI