This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] 'You system is infected'

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I need ur help… Last night I was just browsing Twitter and Facebook (not like I was downloading any porn or anything lol) and then suddenly my comp just crashed on me. And the background on my comp just went Green with a box stating ' Your system is infected' blah blah. My comp has slowed right down, it seems to have locked my whole desktop too. I can't seem to get rid of it, have no idea how I even got it in the first place =/ Please help! Any advice would be much appreciated. Thanks in advance :)
Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 3 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.


http://download.bleepingcomputer.com/grinler/rkill.exe
http://download.bleepingcomputer.com/grinler/rkill.com
http://download.bleepingcomputer.com/grinler/rkill.scr



Note:

You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message. Run rkill repeatedly until it's able to do it's job. This may take a few tries. You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.

At this point, you should now be able to run analysis tools.

Once the tool has run, do NOT reboot the machine, and then try to run DDS and GMER.

If for some reason the machine reboots, repeat the process. Again, try not to restart the machine.


NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT




Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thnx for the reply. Erm this may seem like a stupid question but how do I run analysis tools?? Sorry I feel so stupid!
so sorry, I should have explained the DDS and GMER programs are the analysis tools If you are unable to download with the infected computer, then download rkill to a USB stick on another computer and transfer to the infected one.
No, all rkill does is free up the computer to allow other programs to run once rkill does it's job, you should be able to download and run DDS and GMER, DDS and GMER will have logs for you to post
Orite okay, sorry no good at this kind of thing lol As requested: DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 14:42:35.87 on 22/05/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.510.172 [GMT 1:00] AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\PSIService.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\BT Yahoo\BT Yahoo Help\bin\mad.exe C:\Program Files\BT Yahoo\BT Yahoo Help\bin\mpbtn.exe C:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\explorer.exe C:\Documents and Settings\LYNDA.LOUIS\My Documents\Downloads\dds(2).com ============== Pseudo HJT Report =============== uSearch Page = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/ uWindow Title = Microsoft Internet Explorer provided by BT Yahoo! Broadband uSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html uStart Page = www.rihannadaily.com mDefault_Search_URL = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/ mSearch Page = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/ mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html uInternet Settings,ProxyOverride = local uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/ mURLSearchHooks: H - No File mWinlogon: Userinit=c:\windows\system32\userinit.exe BHO: Yahoo! Companion BHO: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\ycomp5_3_17_0.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {2afc0e7a-bdc7-933c-c3be-97fc5afebd9c} - c:\windows\system32\rxoq.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: MSNToolBandBHO: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\01.02.3000.1001\en-us\msntb.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL TB: BT Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\ycomp5_3_17_0.dll TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File TB: {A057A204-BACC-4D26-B2F2-48F8CCAB3ED4} - No File TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [SpeedTouch USB Diagnostics] "c:\program files\thomson\speedtouch usb\Dragdiag.exe" /icon mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" dRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\btyaho~1.lnk - c:\program files\bt yahoo\bt yahoo help\bin\matcli.exe mPolicies-system: EnableLUA = 0 (0x0) IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - {88B2EE0B-4EE5-46C0-A377-31D5C329B3EA} - c:\program files\yahoo!\browser\ysidebarIE.dll LSP: c:\windows\system32\helpers32.dll Trusted Zone: digital-supply.com Trusted Zone: get-key-se10.com DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw_promo.cab DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} - c:\program files\yahoo!\common\yucconfig.dll DPF: {2D337EB0-3BFB-42A3-B314-A24BBA8C085B} - hxxp://download.yahoo.com/dl/mail/yautoiol1.cab DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - c:\program files\yahoo!\common\yinsthelper.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1146240302656 DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://download.yahoo.com/dl/installs/yab_af.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: {BADDA763-E7F6-494C-B27D-B1EFFB91B68F} = 194.74.65.68 62.6.40.178 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxsrvc.dll Notify: kbupdate - kbupdate.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\lynda~1.lou\applic~1\mozilla\firefox\profiles\k2mrq08p.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2151295&SearchSource=3&q= FF - prefs.js: browser.search.selectedEngine - Rihanna Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2151295&SearchSource=13 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2151295&SearchSource=2&q= FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-5-11 12552] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-11 325896] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-5-11 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-11 108552] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480] R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-4-10 1247600] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408] S0 esff;esff;c:\windows\system32\drivers\esff.sys –> c:\windows\system32\drivers\esff.sys [?] S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe –> c:\progra~1\avg\avg8\avgemc.exe [?] S2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe –> c:\progra~1\avg\avg8\avgwdsvc.exe [?] S2 gupdate1ca2bb85a67c670;Google Update Service (gupdate1ca2bb85a67c670);c:\program files\google\update\GoogleUpdate.exe [2009-9-2 133104] S2 SVKP;SVKP; [x] S3 EraserUtilDrv10614;EraserUtilDrv10614;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv10614.sys –> c:\program files\common files\symantec shared\eengine\EraserUtilDrv10614.sys [?] S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2009-5-29 580096] =============== Created Last 30 ================ 2010-05-22 08:33:58 0 d—–w- c:\docume~1\alluse~1\applic~1\PC Tools 2010-05-22 07:47:15 0 —-a-w- c:\windows\system32\6334.exe 2010-05-21 21:16:31 0 —-a-w- c:\windows\system32\18467.exe 2010-05-21 20:56:30 0 —-a-w- c:\windows\system32\41.exe 2010-05-21 20:53:46 0 —-a-w- c:\windows\system32\ES15.exe 2010-05-21 20:53:31 0 —-a-w- c:\windows\system32\helpers32.dll 2010-05-21 20:52:36 4278 —-a-w- c:\windows\system32\warnings.html ==================== Find3M ==================== 2010-03-10 06:15:52 420352 —-a-w- c:\windows\system32\vbscript.dll 2010-03-10 06:15:52 420352 —-a-w- c:\windows\system32\dllcache\vbscript.dll 2010-02-25 10:54:36 11070976 ——w- c:\windows\system32\dllcache\ieframe.dll 2010-02-24 13:11:07 455680 ——w- c:\windows\system32\dllcache\mrxsmb.sys 2010-02-24 09:54:25 173056 ——w- c:\windows\system32\dllcache\ie4uinit.exe 2005-05-13 16:12:00 217073 –sha-r- c:\windows\meta4.exe 2005-10-24 10:13:58 66560 –sha-r- c:\windows\MOTA113.exe 2005-10-13 20:27:00 422400 –sha-r- c:\windows\x2.64.exe 2005-10-07 18:14:52 308224 –sha-r- c:\windows\system32\avisynth.dll 2005-07-14 11:31:20 27648 –sha-r- c:\windows\system32\AVSredirect.dll 2005-06-26 14:32:28 616448 –sha-r- c:\windows\system32\cygwin1.dll 2005-06-21 21:37:42 45568 –sha-r- c:\windows\system32\cygz.dll 2009-09-04 11:24:51 88 –sh–r- c:\windows\system32\FC37759F07.sys 2004-01-24 23:00:00 70656 –sha-r- c:\windows\system32\i420vfw.dll 2009-09-04 11:25:30 2516 –sha-w- c:\windows\system32\KGyGaAvL.sys 2006-04-27 09:24:24 2945024 –sha-r- c:\windows\system32\Smab.dll 2005-02-28 12:16:22 240128 –sha-r- c:\windows\system32\x.264.exe 2004-01-24 23:00:00 70656 –sha-r- c:\windows\system32\yv12vfw.dll 2009-05-17 11:08:39 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009051720090518\index.dat ============= FINISH: 14:45:11.03 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 17/10/2003 17:29:11 System Uptime: 22/05/2010 10:42:03 (4 hours ago) Motherboard: Dell Computer Corp. | | 0G1548 Processor: Intel® Pentium® 4 CPU 2.40GHz | Microprocessor | 2392/533mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 74 GiB total, 9.108 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1661: 21/02/2010 15:07:21 - System Checkpoint RP1662: 22/02/2010 17:56:32 - System Checkpoint RP1663: 23/02/2010 19:50:55 - System Checkpoint RP1664: 24/02/2010 12:00:23 - Software Distribution Service 3.0 RP1665: 25/02/2010 13:13:08 - System Checkpoint RP1666: 27/02/2010 10:09:15 - System Checkpoint RP1667: 28/02/2010 12:52:51 - System Checkpoint RP1668: 01/03/2010 16:48:08 - System Checkpoint RP1669: 02/03/2010 17:59:37 - System Checkpoint RP1670: 03/03/2010 16:47:40 - Removed FinePixViewer Resource RP1671: 03/03/2010 17:02:19 - Removed FinePixViewer RP1672: 03/03/2010 17:03:46 - Removed FinePix Studio RP1673: 04/03/2010 12:00:27 - Software Distribution Service 3.0 RP1674: 05/03/2010 15:18:47 - Installed Fowl Words RP1675: 06/03/2010 17:22:51 - System Checkpoint RP1676: 07/03/2010 21:21:40 - System Checkpoint RP1677: 10/03/2010 06:53:58 - System Checkpoint RP1678: 10/03/2010 12:03:40 - Software Distribution Service 3.0 RP1679: 11/03/2010 18:17:41 - System Checkpoint RP1680: 13/03/2010 11:14:27 - System Checkpoint RP1681: 14/03/2010 20:39:29 - System Checkpoint RP1682: 15/03/2010 21:44:25 - System Checkpoint RP1683: 17/03/2010 10:08:45 - System Checkpoint RP1684: 18/03/2010 10:21:58 - System Checkpoint RP1685: 19/03/2010 10:45:28 - System Checkpoint RP1686: 20/03/2010 11:15:18 - System Checkpoint RP1687: 21/03/2010 11:56:54 - System Checkpoint RP1688: 22/03/2010 15:30:10 - System Checkpoint RP1689: 23/03/2010 16:25:29 - System Checkpoint RP1690: 24/03/2010 20:10:18 - System Checkpoint RP1691: 25/03/2010 22:02:03 - System Checkpoint RP1692: 27/03/2010 17:07:23 - System Checkpoint RP1693: 28/03/2010 22:01:46 - System Checkpoint RP1694: 29/03/2010 22:38:15 - System Checkpoint RP1695: 30/03/2010 22:38:28 - System Checkpoint RP1696: 31/03/2010 12:00:29 - Software Distribution Service 3.0 RP1697: 01/04/2010 14:20:26 - System Checkpoint RP1698: 02/04/2010 14:35:53 - System Checkpoint RP1699: 03/04/2010 19:41:49 - System Checkpoint RP1700: 05/04/2010 10:45:37 - System Checkpoint RP1701: 05/04/2010 12:41:04 - Installed Adobe Reader 9.3. RP1702: 06/04/2010 16:33:01 - System Checkpoint RP1703: 07/04/2010 20:18:02 - System Checkpoint RP1704: 09/04/2010 11:39:23 - System Checkpoint RP1705: 10/04/2010 12:36:26 - System Checkpoint RP1706: 11/04/2010 18:13:40 - System Checkpoint RP1707: 12/04/2010 19:16:03 - System Checkpoint RP1708: 13/04/2010 19:19:58 - System Checkpoint RP1709: 14/04/2010 12:01:14 - Software Distribution Service 3.0 RP1710: 15/04/2010 12:00:26 - Software Distribution Service 3.0 RP1711: 16/04/2010 13:03:20 - System Checkpoint RP1712: 17/04/2010 18:30:55 - System Checkpoint RP1713: 19/04/2010 12:09:38 - Installed Championship Manager 2010 Challenge Demo RP1714: 20/04/2010 21:54:11 - System Checkpoint RP1715: 22/04/2010 16:26:16 - System Checkpoint RP1716: 23/04/2010 21:16:08 - System Checkpoint RP1717: 25/04/2010 13:34:13 - System Checkpoint RP1718: 26/04/2010 22:10:02 - System Checkpoint RP1719: 27/04/2010 22:16:42 - System Checkpoint RP1720: 29/04/2010 17:13:32 - System Checkpoint RP1721: 30/04/2010 18:42:56 - System Checkpoint RP1722: 01/05/2010 18:46:11 - System Checkpoint RP1723: 03/05/2010 12:09:37 - System Checkpoint RP1724: 04/05/2010 14:45:15 - System Checkpoint RP1725: 05/05/2010 17:30:42 - System Checkpoint RP1726: 06/05/2010 18:16:32 - System Checkpoint RP1727: 07/05/2010 12:43:28 - Installed Safari RP1728: 08/05/2010 13:59:58 - System Checkpoint RP1729: 09/05/2010 20:58:24 - System Checkpoint RP1730: 11/05/2010 09:00:48 - System Checkpoint RP1731: 12/05/2010 10:56:13 - System Checkpoint RP1732: 12/05/2010 12:00:24 - Software Distribution Service 3.0 RP1733: 13/05/2010 13:04:15 - System Checkpoint RP1734: 14/05/2010 17:37:42 - System Checkpoint RP1735: 15/05/2010 20:12:08 - System Checkpoint RP1736: 17/05/2010 15:40:35 - System Checkpoint RP1737: 18/05/2010 19:01:17 - System Checkpoint RP1738: 19/05/2010 21:30:27 - System Checkpoint RP1739: 20/05/2010 21:44:15 - System Checkpoint RP1740: 21/05/2010 23:32:24 - System Checkpoint RP1741: 22/05/2010 10:14:24 - avast! Free Antivirus Setup RP1742: 22/05/2010 10:21:52 - Removed Championship Manager 2010 Challenge Demo RP1743: 22/05/2010 10:35:59 - Removed Fowl Words ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3 AOL UK Apple Application Support Apple Mobile Device Support Apple Software Update Bonjour Broadcom Management Programs BT Yahoo! Applications BT Yahoo! Broadband Internet Connection Manager 4.2 BT Yahoo! Help BufferChm Conexant SmartHSFi V92 56K DF PCI Modem D1400 D1400_Help Dell ResourceCD DeviceManagementQFolder Digital Line Detect dj_sf_ProductContext dj_sf_software dj_sf_software_req Dungeon Keeper 2 getPlus®_ocx Google Update Helper Help and Support Customization Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB932716-v2) Hotfix for Windows XP (KB945060-v3) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB954708) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) HP Deskjet 8.0 Software HP Imaging Device Functions 8.0 Intel® Extreme Graphics Driver iO Streaming Web Plugin iTunes Java Auto Updater Java™ 6 Update 18 Jesterware DVD Rip to PSP Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Search Enhancement Pack Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Works 7.0 Mozilla Firefox (3.5.9) MSN Toolbar MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) NetWaiting OpenMG Limited Patch 4.4-06-13-19-01 OpenMG Secure Module 4.4.00 QuickTime Rhapsody Player Engine Security Update for CAPICOM (KB931906) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 Series (KB969878) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980232) Sony USB Driver SpeedTouch USB Software Status SUPERAntiSpyware Free Edition Symantec KB-DocID:2003093015493306 Toolbox TrayApp UnloadSupport Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB971930) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VC80CRTRedist - 8.0.50727.762 WebFldrs XP WebReg Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WinRAR archiver ==== Event Viewer Messages From Past Week ======== 22/05/2010 10:01:42, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory. 22/05/2010 10:01:42, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver. 22/05/2010 09:52:03, error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s). 22/05/2010 08:50:08, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'smss32.exe' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 19/05/2010 09:28:13, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: esff 19/05/2010 09:28:11, error: Service Control Manager [7001] - The AVG8 E-mail Scanner service depends on the AVG8 WatchDog service which failed to start because of the following error: The system cannot find the file specified. 19/05/2010 09:28:11, error: Service Control Manager [7000] - The SVKP service failed to start due to the following error: The system cannot find the file specified. 19/05/2010 09:28:11, error: Service Control Manager [7000] - The AVG8 WatchDog service failed to start due to the following error: The system cannot find the file specified. ==== End Of File ===========================
You are doing just fine :D If there is anything you don't understand, just ask. The GMER program may give you a few problems. If you have trouble running it, just check the boxes beside "sections" and the "c:\" drive, leave everything else blank, or try running it in safe mode. Make sure your security programs are totally disabled, or they will interfere.
Thnx for being so understanding and helpful :)


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-22 14:59:08
Windows 5.1.2600 Service Pack 3
Running: 2vl0p11d.exe; Driver: C:\DOCUME~1\LYNDA~1.LOU\LOCALS~1\Temp\pxtdypog.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xEFEE20B0]

—- Kernel code sections - GMER 1.0.15 —-

.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF87777AC]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\svchost.exe[1064] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0096000A
.text C:\WINDOWS\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0097000A
.text C:\WINDOWS\System32\svchost.exe[1064] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 006A000C
.text C:\WINDOWS\System32\svchost.exe[1064] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 0181000A
.text C:\WINDOWS\System32\svchost.exe[1064] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00E6000A

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\00001412 -> \Driver\atapi \Device\Harddisk0\DR0 83B6450C

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI@NoChange 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS@Installed 1

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Sorry for the late reply…




ComboFix 10-05-21.06 - LYNDA 22/05/2010 17:13:40.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.510.232 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\a.zip
c:\docume~1\LYNDA~1.LOU\LOCALS~1\Temp\install_flash_player.exe
c:\documents and settings\LYNDA.LOUIS\Local Settings\Application Data\icqgsym.exe
c:\program files\webmediaplayer\resources\languages_v2.xml
c:\program files\webmediaplayer\resources\webmedias
c:\program files\webmediaplayer\skins\classic.skn
c:\program files\webmediaplayer\sqlite3.dll
c:\windows\system32\18467.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\bszip.dll
c:\windows\system32\crt.dat
c:\windows\system32\ES15.exe
c:\windows\system32\helpers32.dll
c:\windows\system32\kboem32.dat
c:\windows\system32\warnings.html
c:\windows\Temp\tmp3.tmp

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2010-04-22 to 2010-05-22 )))))))))))))))))))))))))))))))
.

2010-05-22 16:10 . 2008-04-13 18:40 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-05-22 08:33 . 2010-05-22 08:33 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\PC Tools
2010-05-22 08:33 . 2010-05-22 08:33 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-05-14 10:41 . 2010-05-21 12:26 ——– d—–w- c:\documents and settings\Amy.FAMILY\Local Settings\Application Data\WMTools Downloaded Files
2010-05-04 14:12 . 2010-05-04 14:12 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\Template
2010-05-01 13:04 . 2010-05-01 13:04 ——– d-sh–w- c:\documents and settings\Amy.FAMILY\IECompatCache
2010-04-24 15:14 . 2010-04-24 15:14 ——– d-sh–w- c:\documents and settings\Amy.FAMILY\PrivacIE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-22 09:36 . 2003-10-08 11:05 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-05-22 09:16 . 2007-12-03 18:57 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-22 09:15 . 2010-02-15 14:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-21 20:51 . 2010-05-21 20:51 20 —-a-w- c:\documents and settings\Amy.FAMILY\Application Data\qvjsge.dat
2010-05-12 10:19 . 2004-10-11 13:21 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-03 08:17 . 2010-02-19 19:32 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\Apple Computer
2010-05-02 19:03 . 2010-03-06 11:04 ——– d—–w- c:\documents and settings\LYNDA.LOUIS\Application Data\KewlBoxPrefs
2010-04-21 17:08 . 2010-04-21 17:06 ——– d—–w- c:\program files\iTunes
2010-04-21 17:08 . 2010-04-21 17:06 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-21 17:06 . 2010-04-21 17:06 ——– d—–w- c:\program files\iPod
2010-04-21 17:06 . 2010-02-17 18:47 ——– d—–w- c:\program files\Common Files\Apple
2010-04-21 16:59 . 2010-02-17 18:52 ——– d—–w- c:\program files\QuickTime
2010-04-21 16:53 . 2010-04-21 16:53 ——– d—–w- c:\program files\Bonjour
2010-04-16 11:14 . 2005-11-23 17:39 ——– d—–w- c:\program files\MSN Messenger
2010-04-09 07:46 . 2010-01-25 19:17 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-03-31 09:01 . 2010-03-16 18:35 ——– d—–w- c:\documents and settings\LYNDA.LOUIS\Application Data\vlc
2010-03-26 10:15 . 2010-03-05 15:22 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\KewlBoxPrefs
2010-03-24 14:16 . 2009-07-11 10:33 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-10 06:15 . 2002-08-29 04:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24 . 2004-02-06 17:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2002-08-29 04:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2005-05-13 16:12 . 2005-05-13 16:12 217073 –sha-r- c:\windows\meta4.exe
2005-10-24 10:13 . 2005-10-24 10:13 66560 –sha-r- c:\windows\MOTA113.exe
2005-10-13 20:27 . 2005-10-13 20:27 422400 –sha-r- c:\windows\x2.64.exe
2005-10-07 18:14 . 2005-10-07 18:14 308224 –sha-r- c:\windows\SYSTEM32\avisynth.dll
2005-07-14 11:31 . 2005-07-14 11:31 27648 –sha-r- c:\windows\SYSTEM32\AVSredirect.dll
2005-06-26 14:32 . 2005-06-26 14:32 616448 –sha-r- c:\windows\SYSTEM32\cygwin1.dll
2005-06-21 21:37 . 2005-06-21 21:37 45568 –sha-r- c:\windows\SYSTEM32\cygz.dll
2009-09-04 11:24 . 2009-05-07 17:37 88 –sh–r- c:\windows\SYSTEM32\FC37759F07.sys
2004-01-24 23:00 . 2004-01-24 23:00 70656 –sha-r- c:\windows\SYSTEM32\i420vfw.dll
2009-09-04 11:25 . 2009-05-07 17:14 2516 –sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
2006-04-27 09:24 . 2006-04-27 09:24 2945024 –sha-r- c:\windows\SYSTEM32\Smab.dll
2005-02-28 12:16 . 2005-02-28 12:16 240128 –sha-r- c:\windows\SYSTEM32\x.264.exe
2004-01-24 23:00 . 2004-01-24 23:00 70656 –sha-r- c:\windows\SYSTEM32\yv12vfw.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BT Yahoo! Help.lnk - c:\program files\BT Yahoo\BT Yahoo Help\bin\matcli.exe [2010-2-15 217088]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-12 17:37 11952 —-a-w- c:\windows\SYSTEM32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys [11/05/2009 19:32 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [11/05/2009 19:32 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [11/05/2009 19:32 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/01/2010 08:56 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 08:56 74480]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 08:56 7408]
S0 esff;esff;c:\windows\system32\drivers\esff.sys –> c:\windows\system32\drivers\esff.sys [?]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe –> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe –> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S2 gupdate1ca2bb85a67c670;Google Update Service (gupdate1ca2bb85a67c670);c:\program files\Google\Update\GoogleUpdate.exe [02/09/2009 11:30 133104]
S2 SVKP;SVKP; [x]
S3 EraserUtilDrv10614;EraserUtilDrv10614;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10614.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10614.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-05-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2010-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-02 10:30]

2010-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-02 10:30]

2010-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1981325244-2770366524-784814343-1015Core.job
- c:\documents and settings\Amy.FAMILY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-10 21:00]

2010-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1981325244-2770366524-784814343-1015UA.job
- c:\documents and settings\Amy.FAMILY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-10 21:00]

2009-12-23 c:\windows\Tasks\NSSstub.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2009-12-17 20:29]

2010-05-22 c:\windows\Tasks\User_Feed_Synchronization-{0E0F1A53-A5B0-4B2F-AA2C-FCF35A3FAFC1}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.rihannadaily.com
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
Trusted Zone: digital-supply.com
Trusted Zone: get-key-se10.com
FF - ProfilePath - c:\documents and settings\LYNDA.LOUIS\Application Data\Mozilla\Firefox\Profiles\k2mrq08p.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2151295&SearchSource;=3&q;=
FF - prefs.js: browser.search.selectedEngine - Rihanna Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2151295&SearchSource;=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2151295&SearchSource;=2&q;=
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

BHO-{2AFC0E7A-BDC7-933C-C3BE-97FC5AFEBD9C} - c:\windows\system32\rxoq.dll
WebBrowser-{A057A204-BACC-4D26-B2F2-48F8CCAB3ED4} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-22 17:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Toolbar\QuickComplete]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
@=""
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
@=""
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
@=""
"Installed"="1"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(692)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3180)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PSIService.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\wanmpsvc.exe
c:\program files\BT Yahoo\BT Yahoo Help\bin\mad.exe
c:\program files\BT Yahoo\BT Yahoo Help\bin\mpbtn.exe
c:\progra~1\Motive\ASSTCO~1\MOTIVE~1.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-05-22 17:44:21 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-22 16:43

Pre-Run: 16,693,723,136 bytes free
Post-Run: 16,631,918,592 bytes free

- - End Of File - - 901BC3EBB01850C9A25D3EA2AD7CB89D
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/You_system_infected_t112195.html&view=findpost&p=654743#entry654743

Collect::
c:\documents and settings\Amy.FAMILY\Application Data\qvjsge.dat
c:\windows\system32\drivers\esff.sys

Driver::
esff
SVKP

RegLock::
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Toolbar\QuickComplete]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

DDS::
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
Trusted Zone: digital-supply.com
Trusted Zone: get-key-se10.com

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT




Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
ComboFix 10-05-21.06 - LYNDA 22/05/2010 18:36:42.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.510.144 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\LYNDA.LOUIS\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

file zipped: c:\documents and settings\Amy.FAMILY\Application Data\qvjsge.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Amy.FAMILY\Application Data\qvjsge.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ESFF
——-\Legacy_SVKP
——-\Service_esff
——-\Service_SVKP


((((((((((((((((((((((((( Files Created from 2010-04-22 to 2010-05-22 )))))))))))))))))))))))))))))))
.

2010-05-22 16:10 . 2008-04-13 18:40 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-05-22 16:10 . 2008-04-13 18:40 96512 —-a-w- c:\windows\system32\dllcache\atapi.sys
2010-05-22 08:33 . 2010-05-22 08:33 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\PC Tools
2010-05-22 08:33 . 2010-05-22 08:33 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-05-14 10:41 . 2010-05-21 12:26 ——– d—–w- c:\documents and settings\Amy.FAMILY\Local Settings\Application Data\WMTools Downloaded Files
2010-05-04 14:12 . 2010-05-04 14:12 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\Template
2010-05-01 13:04 . 2010-05-01 13:04 ——– d-sh–w- c:\documents and settings\Amy.FAMILY\IECompatCache
2010-04-24 15:14 . 2010-04-24 15:14 ——– d-sh–w- c:\documents and settings\Amy.FAMILY\PrivacIE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-22 11:23 . 2010-05-22 11:23 61440 —-a-w- c:\documents and settings\LYNDA.LOUIS\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-774e9d4f-n\decora-sse.dll
2010-05-22 11:23 . 2010-05-22 11:23 348160 —-a-w- c:\documents and settings\LYNDA.LOUIS\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3f6fe5d7-n\msvcr71.dll
2010-05-22 11:23 . 2010-05-22 11:23 12800 —-a-w- c:\documents and settings\LYNDA.LOUIS\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-774e9d4f-n\decora-d3d.dll
2010-05-22 11:23 . 2010-05-22 11:23 503808 —-a-w- c:\documents and settings\LYNDA.LOUIS\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3f6fe5d7-n\msvcp71.dll
2010-05-22 11:23 . 2010-05-22 11:23 499712 —-a-w- c:\documents and settings\LYNDA.LOUIS\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3f6fe5d7-n\jmc.dll
2010-05-22 09:36 . 2003-10-08 11:05 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-05-22 09:16 . 2007-12-03 18:57 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-22 09:15 . 2010-02-15 14:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-12 10:19 . 2004-10-11 13:21 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-03 08:17 . 2010-02-19 19:32 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\Apple Computer
2010-05-02 19:03 . 2010-03-06 11:04 ——– d—–w- c:\documents and settings\LYNDA.LOUIS\Application Data\KewlBoxPrefs
2010-04-27 13:41 . 2010-04-27 13:41 1956808 —-a-w- c:\documents and settings\Amy.FAMILY\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2010-04-21 17:08 . 2010-04-21 17:06 ——– d—–w- c:\program files\iTunes
2010-04-21 17:08 . 2010-04-21 17:06 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-21 17:06 . 2010-04-21 17:06 ——– d—–w- c:\program files\iPod
2010-04-21 17:06 . 2010-02-17 18:47 ——– d—–w- c:\program files\Common Files\Apple
2010-04-21 16:59 . 2010-02-17 18:52 ——– d—–w- c:\program files\QuickTime
2010-04-21 16:53 . 2010-04-21 16:53 ——– d—–w- c:\program files\Bonjour
2010-04-21 16:46 . 2010-04-21 16:46 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-04-16 11:14 . 2005-11-23 17:39 ——– d—–w- c:\program files\MSN Messenger
2010-04-09 07:46 . 2010-01-25 19:17 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-03-31 09:01 . 2010-03-16 18:35 ——– d—–w- c:\documents and settings\LYNDA.LOUIS\Application Data\vlc
2010-03-26 10:15 . 2010-03-05 15:22 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\KewlBoxPrefs
2010-03-24 14:16 . 2009-07-11 10:33 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-10 06:15 . 2002-08-29 04:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24 . 2004-02-06 17:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2002-08-29 04:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2005-05-13 16:12 . 2005-05-13 16:12 217073 –sha-r- c:\windows\meta4.exe
2005-10-24 10:13 . 2005-10-24 10:13 66560 –sha-r- c:\windows\MOTA113.exe
2005-10-13 20:27 . 2005-10-13 20:27 422400 –sha-r- c:\windows\x2.64.exe
2005-10-07 18:14 . 2005-10-07 18:14 308224 –sha-r- c:\windows\SYSTEM32\avisynth.dll
2005-07-14 11:31 . 2005-07-14 11:31 27648 –sha-r- c:\windows\SYSTEM32\AVSredirect.dll
2005-06-26 14:32 . 2005-06-26 14:32 616448 –sha-r- c:\windows\SYSTEM32\cygwin1.dll
2005-06-21 21:37 . 2005-06-21 21:37 45568 –sha-r- c:\windows\SYSTEM32\cygz.dll
2009-09-04 11:24 . 2009-05-07 17:37 88 –sh–r- c:\windows\SYSTEM32\FC37759F07.sys
2004-01-24 23:00 . 2004-01-24 23:00 70656 –sha-r- c:\windows\SYSTEM32\i420vfw.dll
2009-09-04 11:25 . 2009-05-07 17:14 2516 –sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
2006-04-27 09:24 . 2006-04-27 09:24 2945024 –sha-r- c:\windows\SYSTEM32\Smab.dll
2005-02-28 12:16 . 2005-02-28 12:16 240128 –sha-r- c:\windows\SYSTEM32\x.264.exe
2004-01-24 23:00 . 2004-01-24 23:00 70656 –sha-r- c:\windows\SYSTEM32\yv12vfw.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BT Yahoo! Help.lnk - c:\program files\BT Yahoo\BT Yahoo Help\bin\matcli.exe [2010-2-15 217088]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-12 17:37 11952 —-a-w- c:\windows\SYSTEM32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys [11/05/2009 19:32 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [11/05/2009 19:32 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [11/05/2009 19:32 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/01/2010 08:56 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 08:56 74480]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 08:56 7408]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe –> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe –> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S2 gupdate1ca2bb85a67c670;Google Update Service (gupdate1ca2bb85a67c670);c:\program files\Google\Update\GoogleUpdate.exe [02/09/2009 11:30 133104]
S3 EraserUtilDrv10614;EraserUtilDrv10614;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10614.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10614.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-05-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2010-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-02 10:30]

2010-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-02 10:30]

2010-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1981325244-2770366524-784814343-1015Core.job
- c:\documents and settings\Amy.FAMILY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-10 21:00]

2010-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1981325244-2770366524-784814343-1015UA.job
- c:\documents and settings\Amy.FAMILY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-10 21:00]

2010-05-22 c:\windows\Tasks\User_Feed_Synchronization-{0E0F1A53-A5B0-4B2F-AA2C-FCF35A3FAFC1}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.rihannadaily.com
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
TCP: {BADDA763-E7F6-494C-B27D-B1EFFB91B68F} = 194.74.65.69 194.72.9.38
FF - ProfilePath - c:\documents and settings\LYNDA.LOUIS\Application Data\Mozilla\Firefox\Profiles\k2mrq08p.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2151295&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Rihanna Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2151295&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2151295&SearchSource=2&q=
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-22 18:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(692)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(2896)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PSIService.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\wanmpsvc.exe
c:\program files\BT Yahoo\BT Yahoo Help\bin\mad.exe
c:\program files\BT Yahoo\BT Yahoo Help\bin\mpbtn.exe
c:\progra~1\Motive\ASSTCO~1\MOTIVE~1.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-05-22 19:01:22 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-22 18:01
ComboFix2.txt 2010-05-22 16:44

Pre-Run: 16,633,839,616 bytes free
Post-Run: 16,568,672,256 bytes free

- - End Of File - - 721603F04E8A8E72B47A41FE98892153
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4131 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 22/05/2010 19:30:43 mbam-log-2010-05-22 (19-30-43).txt Scan type: Quick scan Objects scanned: 168060 Time elapsed: 16 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 27 Files Infected: 40 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/anti-leech plugin,version=1.0.1.8 (Trojan.AntiLeechPlugin) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\Guest\Application Data\Starware353 (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\BrowserSearch (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Configurator (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ErrorSearch (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Games (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Games\images (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Games\images\active (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Games\images\default (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Layouts (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Manager (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Movies (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Movies\images (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Movies\images\active (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Movies\images\default (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\RecipeSearch_Foreign (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Recipes_Foreign (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Reference (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\RelatedSearch (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ScreensaversMarketingSitePager (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ScreensaversMarketingSitePager\images (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ScreensaversMarketingSitePager\images\active (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ScreensaversMarketingSitePager\images\default (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Toolbar (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ToolbarLogo (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ToolbarSearch (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\TravelSearch (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Weather (Adware.Starware) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\ntor325.dll (Trojan.Hiloti) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\BrowserSearch\BrowserSearch.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\BrowserSearch\BrowserSearch.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Configurator\Configurator.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Configurator\Configurator.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ErrorSearch\ErrorSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ErrorSearch\ErrorSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Games\GamesOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Games\GamesOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Games\images\active\Games0.bmp (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Layouts\ToolbarLayout.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Layouts\ToolbarLayout.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Manager\ManagerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Manager\ManagerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Movies\MoviesOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Movies\MoviesOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Movies\images\active\Movies0.bmp (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\RecipeSearch_Foreign\RecipeSearch_ForeignOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\RecipeSearch_Foreign\RecipeSearch_ForeignOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Recipes_Foreign\Recipes_ForeignOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Recipes_Foreign\Recipes_ForeignOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Reference\ReferenceOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Reference\ReferenceOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\RelatedSearch\RelatedSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\RelatedSearch\RelatedSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Toolbar\TBProductsOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Toolbar\TBProductsOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ToolbarLogo\ToolbarLogoOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ToolbarLogo\ToolbarLogoOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ToolbarSearch\ToolbarSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\ToolbarSearch\ToolbarSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\TravelSearch\TravelSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\TravelSearch\TravelSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Weather\AlertArchive.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Weather\WeatherOptions.xml (Adware.Starware) -> Quarantined and deleted successfully. C:\Documents and Settings\Guest\Application Data\Starware353\Weather\WeatherOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\ClickToFindandFixErrors.ico (Malware.Trace) -> Quarantined and deleted successfully.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI