This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Solved] Any problems with this log?

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I ran a virus check with Avira and if I read the report right, it found four issues but only did anything about one of them. However, I can't find anything wrong using other software such as MBAM. Here's an HJT log; can you find anything wrong here?

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:13:18 PM, on 2010-06-07
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\TOSHIBA\gigabeat room 3.0\TosGBWatcher.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Rocketfish 2.4GHz Ergo Laser Mouse Driver\ICO.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Software install files\eekebove.exe
C:\Windows\System32\notepad.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [TosGbWatcher] "C:\Program Files\TOSHIBA\gigabeat room 3.0\TosGbWatcher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] C:\Program Files\Rocketfish 2.4GHz Ergo Laser Mouse Driver\ICO.EXE
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jweffles\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O18 - Protocol: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files\Cozi Express\CoziProtocolHandler.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\Windows\runservice.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)

–
End of file - 8797 bytes



Also, because the Avira log said something about rootkits, I looked around for an anti-rootkit tool. Free ones that actually work on Vista seem to be very hard to find (if y'all have any recommendations, I'm all ears). Anyway, here's a report from a tool called GMER. It's supposed to be easy for nontechnical users to use but I don't understand it at all. It seems to detect lots of stuff but not give me the option of doing anything about it (all the right-click options to do so are greyed out).



GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-07 18:22:20
Windows 6.0.6002 Service Pack 2
Running: eekebove.exe; Driver: C:\Users\Jweffles\AppData\Local\Temp\pwryrkob.sys


—- Kernel code sections - GMER 1.0.15 —-

.text C:\Windows\system32\drivers\spssys.sys section is writeable [0x8A3552C0, 0x24932, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[6488] ntdll.dll!LdrLoadDll 77529390 5 Bytes JMP 000413F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74567817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [745BA86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7456BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7455F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [745675E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7455E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74598395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7456DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7455FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7455FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [745571CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [745ECAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [7458C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7455D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74556853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7455687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3112] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74562AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Hi,

What symptoms are you experiencing that lead you to believe you may be infected?

Please do the following:

  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    C:\Software install files\eekebove.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


NEXT


What files are being found by your AV? In what location?

Please do an on-line scan with Kaspersky:



**Vista users - right click on the IE icon and run as administrator

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan.
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
eekebove.exe is the executable for the rootkit scanner I mentioned. Only one of the programs on that site found anything suspicious about it, as you can see:

VirSCAN.org Scanned Report :
Scanned time : 2010/06/10 23:09:04 (CDT)
Scanner results: 3% Scanner(s) (1/36) found malware!
File Name : eekebove.exe
File Size : 293376 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : f80f6e09e7f4bafe478ca0da6137e1e2
SHA1 : 719082766cf4f60c8bdaa2b2c9f6967ecbcf8722
Online report : http://virscan.org/report/57d54240f2c71202…06e17c62f8.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.0.0.11 20100611053112 2010-06-11 5.22 -
AhnLab V3 2010.06.11.01 2010.06.11 2010-06-11 1.33 -
AntiVir 8.2.2.6 7.10.8.57 2010-06-10 0.29 -
Antiy 2.0.18 20100611.4745797 2010-06-11 0.12 -
Arcavir 2009 201006101825 2010-06-10 0.25 -
Authentium 5.1.1 201006102208 2010-06-10 3.07 -
AVAST! 4.7.4 100610-1 2010-06-10 0.08 -
AVG 8.5.793 271.1.1/2930 2010-06-11 1.70 -
BitDefender 7.90123.6170365 7.32143 2010-06-11 4.16 -
ClamAV 0.96.1 11177 2010-06-11 0.30 -
Comodo 3.13.579 5057 2010-06-11 0.85 -
CP Secure 1.3.0.5 2010.06.11 2010-06-11 0.19 -
Dr.Web 5.0.2.3300 2010.06.11 2010-06-11 9.26 -
F-Prot 4.4.4.56 20100610 2010-06-10 3.32 -
F-Secure 7.02.73807 2010.06.10.07 2010-06-10 0.62 -
Fortinet 4.1.133 12.38 2010-06-10 0.24 -
GData 21.328/21.110 20100610 2010-06-10 6.47 -
ViRobot 20100610 2010.06.10 2010-06-10 0.36 -
Ikarus T3.1.01.84 2010.06.11.76043 2010-06-11 6.65 -
JiangMin 13.0.900 2010.06.10 2010-06-10 1.32 -
Kaspersky 5.5.10 2010.06.10 2010-06-10 0.38 -
KingSoft 2009.2.5.15 2010.6.9.18 2010-06-09 0.72 -
McAfee 5400.1158 6009 2010-06-10 17.39 -
Microsoft 1.5802 2010.06.10 2010-06-10 7.22 -
Norman 6.04.12 6.04.00 2010-06-10 4.01 -
Panda 9.05.01 2010.06.10 2010-06-10 2.10 -
Trend Micro 9.120-1004 7.232.01 2010-06-10 0.11 -
Quick Heal 10.00 2010.06.11 2010-06-11 1.67 -
Rising 20.0 22.51.04.01 2010-06-11 1.85 -
Sophos 3.07.1 4.54 2010-06-11 3.53 -
Sunbelt 3.9.2424.2 6432 2010-06-10 18.32 -
Symantec 1.3.0.24 20100610.003 2010-06-10 0.14 -
nProtect 20100609.02 8604465 2010-06-09 17.84 -
The Hacker 6.5.2.0 v00297 2010-06-10 0.52 -
VBA32 3.12.12.5 20100610.0802 2010-06-10 4.12 Win32 Shadow Driver Install (suspicious)
VirusBuster 4.5.11.10 10.126.76/2041616 2010-06-11 4.22 -

Here are Avira Antivir's relevant log entries:

The file 'C:\Users\Jweffles\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\445d036-489a77cb'
contained a virus or unwanted program 'EXP/Java.Agent.F.6' [exploit]
Action(s) taken:
The file was moved to the quarantine directory under the name '48ec9c27.qua'.

Scan ended [The scan has been done completely.].
Number of files: 421677
Number of folders: 24914
Number of malware: 2
Number of errors: 0

Note that the end of scan report says there were two instances of malware found, but there was only one actual "Detection" entry. That's what worried me. As mentioned previously, the original, longer report also appeared to say something about finding two rootkits. But now I can't find that anywhere; I probably should have copied it and dumped it into a text file.

To get back to your first question - there were no particular symptoms that prompted me to worry, I simply decided it had been a while (a few months) since I most recently did a full virus scan and it was about time I did another.

The Kapersky page gives me an error message saying I have to launch the browser as an administrator (I am already logged in as one, and in any case, I've been told that running a browser as administrator is a very bad idea). It also screws up my mouse. Nevertheless, I'll close this window after sending this message and try running it again.
Okay, I got the online virus scan to run. Here is the report: KASPERSKY ONLINE SCANNER 7.0: scan report Friday, June 11, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, June 11, 2010 01:30:41 Records in database: 4254216 Scan settings scan using the following database extended Scan archives yes Scan e-mail databases yes Scan area My Computer C:\ E:\ F:\ Scan statistics Objects scanned 206762 Threats found 1 Infected objects found 1 Suspicious objects found 0 Scan duration 02:54:56 File name Threat Threats count C:\Downloads\White_Darkness_-_Messe_Noir_Uncensored-5312296.exe Infected: Hoax.Win32.ArchSMS.e 1 Selected area has been scanned. I have shredded the above-noted file.
OK,

the file found is just in Java cache which just needs to be emptied,

use this utility as well

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.



NEXT


Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your reply.
Avira popped up and said it found something else: The file 'C:\Users\Jweffles\AppData\Local\Mozilla\Firefox\Profiles\o7q9wgla.default\Cache\26EBF7A7d01' contained a virus or unwanted program 'HTML/Rce.Gen' [virus] Action(s) taken: The file was moved to the quarantine directory under the name '4ff65d5f.qua'. I cleared out Avira's quarantine. How does one clear the Java cache? I'll do the rest of what you suggested the next time I turn my computer on.
I was looking to see if you had the latest Java installed as well, so I could give you those instuctions at the same time,

but clear the cache this way:

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
Okay. I cleared the Java cache, then ran TFC. It seemed to be claiming to be removing gigabytes of stuff, though a check of my available free disk space doesn't corroborate that; then it crashed, so I restored Explorer from Task Manager and re-ran TFC making sure to choose Run as Administrator and it worked smoothly this time.

Here is the list from HJT. Note that this would, at various times, have also included some unrecommended file-sharing programs like Limewire; not malware themselves, but certainly potential sources of it for the unwary.

32 Bit HP CIO Components Installer
7-Zip 4.65
ABC (remove only)
Acrobat.com
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.2
Apple Software Update
ArgMap
Armageddon
Avira AntiVir Personal - Free Antivirus
Baldur's Gate
Bullzip PDF Printer 6.0.0.865
CDisplay 1.8
Choice Guard
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Combined Community Codec Pack 2009-09-09
Compatibility Pack for the 2007 Office system
Consumer In-Home Service Agreement
Cozi
D-Box 2.2
DC++ 0.750
Dell Dock
Dell Getting Started Guide
Dell Support Center (Support Software)
Dell Touchpad
Dell Wireless WLAN Card Utility
DELL0604
D-Fend Reloaded 0.9.3 (deinstall)
Eastside UK pre-game Editor v2007.1.6
EDocs
ffdshow [rev 2844] [2009-03-30]
FHLSim
FHLSim.com Fantasy Hockey League Simulator
FreeMind
GMHockey2009Eng
GoToAssist 8.0.0.514
GPL Ghostscript Lite 8.64
Gravity 2.9
Hearts of Iron 2 Doomsday Armageddon
HiJackThis
HOI2 Doomsday Armageddon 1.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Imaging Device Functions 8.0
HP OCR Software 8.0
HP Officejet Pro All-In-One Series
HP Solution Center 8.0
HP Update
Intel® Matrix Storage Manager
Java™ 6 Update 17
Java™ 6 Update 7
Junk Mail filter update
Malwarebytes' Anti-Malware
Media Player Classic - Home Cinema v. 1.3.1249.0
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Office Live Add-in 1.5
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office XP Professional with FrontPage
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Might and Magic® VI
Might and Magic® VII
Mozilla Firefox (3.6.3)
Mozilla Thunderbird (2.0.0.24)
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NHL Eastside Hockey Manager 2007
OGA Notifier 2.0.0048.0
Power Tab Editor 1.7
PowerDVD
Quest Hockey Sim - Version 2009.07.30
QuickSet
QuickTime
Rocketfish 2.4GHz Ergo Laser Mouse
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator DE
Roxio Creator Tools
Roxio Express Labeler 3
Roxio Update Manager
SecureW2 EAP Suite 1.0.6 for Windows
SimonT Hockey Simulator Support Files
StuffIt Expander 2010
Sword of the Stars
TOSHIBA gigabeat applications 3.0
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
UseNeXT
WildTangent Games
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Player Firefox Plugin
Zip Motion Block Video codec (Remove Only)

The only other sort-of suspicious thing my machine is currently doing is undergoing random bursts of high disk activity for no obvious reason. This is probably just the indexing (dis)service built into Vista, but it makes me nervous in light of these recent malware discoveries on my system. (And even if that's all it is, I wish I could turn it off; the indexing doesn't seem to do anything useful on versions of Windows prior to Windows 7, it just slows you down periodically to no good purpose.)
Okay, something weird just happened; the taskbar moved to the top of the screen when I tried to click the Start button. I can't move it back down even though "Lock the taskbar" is not checked. Will reboot momentarily and see if that helps.

EDIT: After rebooting, eventually, it allowed me to move it back down, though it took several tries.
Hi,

Please do the following:

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 20 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 20 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u20 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u20-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT
Okay, I yoinked my old Java (along with a bunch of those hockey programs and Office Live, which I've been meaning to do anyway - I see some of this activity is reflected in the attach.txt) and installed the new one, then did DDS. Here's the DDS.txt: DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 23:02:10.94 on 2010-06-11 Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_20 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.3034.1636 [GMT -5:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\STacSV.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Windows\runservice.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Avira\AntiVir Desktop\avshadow.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\RUNDLL32.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Windows\System32\WLTRAY.EXE C:\Windows\system32\igfxsrvc.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\system32\taskeng.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\TOSHIBA\gigabeat room 3.0\TosGBWatcher.exe C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\Rocketfish 2.4GHz Ergo Laser Mouse Driver\ICO.EXE C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k HPService C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Program Files\Microsoft Office\Office10\MSACCESS.EXE C:\Windows\System32\notepad.exe C:\Program Files\Rocketfish 2.4GHz Ergo Laser Mouse Driver\Pelmiced.exe C:\Windows\system32\msiexec.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Jweffles\Desktop\dds.com C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uWindow Title = Internet Explorer provided by Dell BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [Google Update] "c:\users\jweffles\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [QuickSet] c:\program files\dell\quickset\QuickSet.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe" mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [TosGbWatcher] "c:\program files\toshiba\gigabeat room 3.0\TosGbWatcher.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Mouse Suite 98 Daemon] c:\program files\rocketfish 2.4ghz ergo laser mouse driver\ICO.EXE mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\users\jweffles\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\program files\cozi express\CoziProtocolHandler.dll Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: igfxcui - igfxdev.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\jweffles\appdata\roaming\mozilla\firefox\profiles\o7q9wgla.default\ FF - prefs.js: network.proxy.type - 2 FF - component: c:\program files\microsoft\search enhancement pack\search helper\firefoxextension\searchhelperextension\components\SEPsearchhelperff.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\jweffles\appdata\local\google\update\1.2.183.27\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 Spssys;Toshiba SPS Service;c:\windows\system32\drivers\spssys.sys [2009-5-20 164256] R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-11-1 11608] R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\VCdRom.sys [2009-8-2 8576] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_ae0b52e0\AEstSrv.exe [2009-3-4 81920] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-11-1 135336] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-11-1 267432] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-11-1 60936] R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-23 155648] R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2010-5-22 2560] R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc –> RUNDLL32.EXE ykx32coinst,serviceStartProc [?] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] S3 rkhdrv40;Rootkit Unhooker Driver;c:\windows\system32\drivers\rkhdrv40.sys [2010-6-7 24448] =============== Created Last 30 ================ 2010-06-12 04:00:39 0 d—–w- c:\programdata\Sun 2010-06-12 03:59:53 411368 —-a-w- c:\windows\system32\deployJava1.dll 2010-06-11 04:42:01 0 d—–w- c:\users\jweffles\appdata\roaming\WildTangent 2010-06-09 02:57:05 108144 —-a-w- c:\windows\system32\CmdLineExt.dll 2010-06-09 02:26:19 0 d—–w- c:\program files\Lighthouse Interactive 2010-06-07 23:06:21 0 d—–w- c:\program files\Trend Micro 2010-06-07 22:56:10 24448 —-a-w- c:\windows\system32\drivers\rkhdrv40.sys 2010-06-07 22:47:49 102800 —-a-w- c:\windows\system32\drivers\tmcomm.sys 2010-06-07 20:08:32 0 d—–w- c:\users\jweffles\Pavark 2010-06-07 09:09:51 0 d—–w- c:\users\jweffles\appdata\roaming\Avira 2010-06-06 04:32:36 0 d—–w- c:\users\jweffles\appdata\roaming\Malwarebytes 2010-06-06 04:32:29 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-06 04:32:27 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-06-06 04:32:27 0 d—–w- c:\programdata\Malwarebytes 2010-06-06 04:32:27 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-06-05 08:01:16 0 d—–w- c:\programdata\eMule 2010-06-05 08:00:39 0 d—–w- c:\program files\eMule 2010-06-03 09:00:42 0 d—–w- c:\program files\Smith Micro 2010-06-03 04:07:30 0 d—–w- c:\users\jweffles\appdata\roaming\Gravity 2010-06-03 04:07:30 0 d—–w- c:\program files\Microplanet 2010-06-03 02:29:13 19456 —-a-w- c:\windows\system32\drivers\PELUSBlf.SYS 2010-06-03 02:29:13 18944 —-a-w- c:\windows\system32\drivers\PELMOUSE.SYS 2010-06-03 02:29:13 167936 —-a-r- c:\windows\system32\XMOUSE.CPL 2010-06-03 02:29:13 12288 —-a-w- c:\windows\system32\drivers\HIDUSB.0 2010-06-03 02:29:13 0 d—–w- c:\program files\Rocketfish 2.4GHz Ergo Laser Mouse Driver 2010-06-03 02:29:10 86772 —-a-r- c:\windows\TPMX_INI.cab 2010-06-03 02:29:10 7902 —-a-r- c:\windows\x32.cat 2010-06-03 02:29:10 12088 —-a-r- c:\windows\PHIDMOU.INF 2010-06-03 02:29:09 21413 —-a-r- c:\windows\ms98.cab 2010-06-03 02:29:01 0 d—–w- c:\windows\X32 2010-06-03 02:29:00 0 d—–w- c:\windows\Metadata 2010-06-02 06:09:43 2048 —-a-w- c:\windows\system32\tzres.dll 2010-06-02 05:40:35 0 d—–w- c:\users\jweffles\New Folder (1) 2010-05-28 07:33:59 9728 —-a-w- c:\windows\system32\ftlx041e.dll 2010-05-28 07:33:59 9216 —-a-w- c:\windows\system32\ftlx0411.dll 2010-05-28 07:33:59 296960 —-a-w- c:\windows\winhlp32.exe 2010-05-28 07:33:59 194560 —-a-w- c:\windows\system32\ftsrch.dll 2010-05-28 06:30:23 0 d–h–w- c:\windows\PIF 2010-05-28 06:10:52 0 d—–w- c:\users\jweffles\D-Fend Reloaded 2010-05-28 05:10:04 0 d—–w- c:\users\jweffles\appdata\roaming\.dbox 2010-05-28 05:00:00 0 d—–w- C:\DOSgames 2010-05-26 07:01:58 74544 —-a-w- c:\users\jweffles\appdata\roaming\GDIPFONTCACHEV1.DAT 2010-05-25 05:44:33 48128 —-a-w- C:\plchat.doc 2010-05-24 07:53:36 0 —ha-w- c:\windows\SwSys2.bmp 2010-05-24 07:53:36 0 —ha-w- c:\windows\SwSys1.bmp 2010-05-24 07:52:45 0 d—–w- C:\GMHockey2009Eng 2010-05-24 06:40:25 0 d—–w- C:\Dossier Rich 2010-05-24 05:09:47 303 —-a-w- c:\windows\ST6UNST.000 2010-05-23 19:49:53 0 d—–w- c:\program files\Eastside UK 2010-05-23 02:27:44 0 d—–w- c:\users\jweffles\appdata\roaming\Sports Interactive 2010-05-22 22:00:01 126976 —-a-w- c:\windows\lcmmfu.cpl 2010-05-22 22:00:00 825 –sha-w- c:\windows\system32\mmf.sys 2010-05-22 21:59:58 48640 —-a-w- c:\windows\mmfs.dll 2010-05-22 21:59:58 2560 —-a-w- c:\windows\Runservice.exe 2010-05-22 21:57:10 0 d—–w- c:\program files\Sports Interactive 2010-05-22 21:56:31 0 d—–w- c:\windows\Downloaded Installations 2010-05-22 20:59:45 0 d—–w- c:\program files\Fantasy Hockey League 2010-05-14 22:39:09 0 d—–w- c:\users\jweffles\.freemind 2010-05-14 22:39:00 0 d—–w- c:\program files\FreeMind 2010-05-14 22:33:26 0 d—–w- c:\program files\ArgMap 2010-05-14 22:33:20 73216 —-a-w- c:\windows\ST6UNST.EXE 2010-05-14 22:33:20 249856 ——w- c:\windows\Setup1.exe 2010-05-14 18:32:32 0 d—–w- C:\suspect 2010-05-13 15:27:41 738816 —-a-w- c:\windows\system32\inetcomm.dll ==================== Find3M ==================== 2010-06-03 02:29:32 51200 —-a-w- c:\windows\inf\infpub.dat 2010-06-03 02:29:32 143360 —-a-w- c:\windows\inf\infstrng.dat 2010-06-03 02:29:29 143360 —-a-w- c:\windows\inf\infstor.dat 2010-05-26 17:06:41 34304 —-a-w- c:\windows\system32\atmlib.dll 2010-05-26 14:47:41 289792 —-a-w- c:\windows\system32\atmfd.dll 2010-05-12 16:21:16 221568 ——w- c:\windows\system32\MpSigStub.exe 2010-05-04 19:15:20 834048 —-a-w- c:\windows\system32\wininet.dll 2010-05-04 18:37:45 78336 —-a-w- c:\windows\system32\ieencode.dll 2010-05-01 14:13:48 2037248 —-a-w- c:\windows\system32\win32k.sys 2010-04-05 17:01:01 67072 —-a-w- c:\windows\system32\asycfilt.dll 2009-11-02 00:08:27 665600 —-a-w- c:\windows\inf\drvindex.dat 2008-01-21 02:43:21 174 –sha-w- c:\program files\desktop.ini 2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-03-04 17:14:08 8192 –sha-w- c:\windows\users\default\NTUSER.DAT ============= FINISH: 23:03:33.12 =============== And here is attach.txt: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume3 Install Date: 2009-03-04 3:44:07 AM System Uptime: 2010-06-11 8:41:48 PM (3 hours ago) Motherboard: Dell Inc. | | 0G848F Processor: Intel® Pentium® Dual CPU T3400 @ 2.16GHz | Microprocessor | 2167/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 134 GiB total, 19.652 GiB free. E: is FIXED (NTFS) - 15 GiB total, 8.507 GiB free. F: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Microsoft 6to4 Adapter Device ID: ROOT\*6TO4MP\0002 Manufacturer: Microsoft Name: Microsoft 6to4 Adapter #2 PNP Device ID: ROOT\*6TO4MP\0002 Service: tunnel Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Microsoft 6to4 Adapter Device ID: ROOT\*6TO4MP\0004 Manufacturer: Microsoft Name: Microsoft 6to4 Adapter #3 PNP Device ID: ROOT\*6TO4MP\0004 Service: tunnel ==== System Restore Points =================== RP291: 2010-06-10 8:27:47 PM - Scheduled Checkpoint RP292: 2010-06-11 2:23:26 AM - Windows Update RP293: 2010-06-11 4:44:12 PM - Scheduled Checkpoint RP294: 2010-06-11 10:55:36 PM - Removed FHLSim.com Fantasy Hockey League Simulator RP295: 2010-06-11 10:56:41 PM - Removed Java™ 6 Update 7 RP296: 2010-06-11 10:57:33 PM - Removed Java™ 6 Update 17 RP297: 2010-06-11 10:58:14 PM - Removed Microsoft Office Live Add-in 1.5 RP298: 2010-06-11 10:59:25 PM - Installed Java™ 6 Update 20 ==== Installed Programs ====================== 32 Bit HP CIO Components Installer 7-Zip 4.65 ABC (remove only) Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3.2 Apple Software Update ArgMap Armageddon Avira AntiVir Personal - Free Antivirus Baldur's Gate BPD_HPSU BPD_Scan BPDSoftware BPDSoftware_Ini BufferChm Bullzip PDF Printer 6.0.0.865 CDisplay 1.8 Choice Guard Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Combined Community Codec Pack 2009-09-09 Compatibility Pack for the 2007 Office system Consumer In-Home Service Agreement Cozi D-Box 2.2 D-Fend Reloaded 0.9.3 (deinstall) DC++ 0.750 Dell Dock Dell Getting Started Guide Dell Support Center (Support Software) Dell Touchpad Dell Wireless WLAN Card Utility DELL0604 Destinations DeviceManagementQFolder DocProc DocProcQFolder Eastside UK pre-game Editor v2007.1.6 EDocs eSupportQFolder Fax ffdshow [rev 2844] [2009-03-30] FreeMind Google Chrome GoToAssist 8.0.0.514 GPL Ghostscript Lite 8.64 Gravity 2.9 Hearts of Iron 2 Doomsday Armageddon HiJackThis HOI2 Doomsday Armageddon 1.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Imaging Device Functions 8.0 HP OCR Software 8.0 HP Officejet Pro All-In-One Series HP Solution Center 8.0 HP Update HPProductAssistant Intel® Matrix Storage Manager Java Auto Updater Java™ 6 Update 20 Junk Mail filter update Malwarebytes' Anti-Malware Media Player Classic - Home Cinema v. 1.3.1249.0 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office XP Professional with FrontPage Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Works Might and Magic® VI Might and Magic® VII Mozilla Firefox (3.6.3) Mozilla Thunderbird (2.0.0.24) MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) NetDeviceManager NHL Eastside Hockey Manager 2007 OGA Notifier 2.0.0048.0 Power Tab Editor 1.7 PowerDVD QuickSet QuickTime Rocketfish 2.4GHz Ergo Laser Mouse Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager Scan SecureW2 EAP Suite 1.0.6 for Windows SimonT Hockey Simulator Support Files SolutionCenter Status StuffIt Expander 2010 Sword of the Stars Toolbox TOSHIBA gigabeat applications 3.0 TrayApp UnloadSupport Update for Microsoft .NET Framework 3.5 SP1 (KB963707) UseNeXT WebReg WildTangent Games Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sync Windows Live Toolbar Windows Live Upload Tool Windows Live Writer Windows Media Player Firefox Plugin Zip Motion Block Video codec (Remove Only) ==== Event Viewer Messages From Past Week ======== 2010-06-11 3:55:06 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.10.102 for the Network Card with network address 00225F706C40 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). 2010-06-11 3:02:16 AM, Error: Service Control Manager [7031] - The Windows Defender service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 2010-06-11 1:47:42 PM, Error: Service Control Manager [7000] - The Intel® PRO/1000 PCI Express Network Connection Driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 2010-06-11 1:47:42 PM, Error: Service Control Manager [7000] - The Intel® PRO/1000 NDIS 6 Adapter Driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 2010-06-11 1:14:27 PM, Error: Service Control Manager [7034] - The Dock Login Service service terminated unexpectedly. It has done this 1 time(s). 2010-06-11 1:10:30 PM, Error: Service Control Manager [7034] - The Audio Service service terminated unexpectedly. It has done this 1 time(s). 2010-06-07 6:43:04 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the Plug and Play service, but this action failed with the following error: A system shutdown has already been scheduled. 2010-06-07 6:43:04 PM, Error: Service Control Manager [7031] - The Plug and Play service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine. 2010-06-07 6:43:04 PM, Error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine. 2010-06-06 1:06:04 AM, Error: EventLog [6008] - The previous system shutdown at 1:03:53 AM on 06/06/2010 was unexpected. 2010-06-04 3:54:00 AM, Error: cdrom [11] - The driver detected a controller error on \Device\CdRom0. ==== End Of File =========================== (Just out of curiosity, if you saw a program such as EMule or Limewire in there, what would you recommend? I uninstalled both shortly before the initial virus scan.)
Hi

The logs are clean,

Just some housekeeping to do now.

You can delete the DDS and GMER programs and logs from your desktop:

try a defrag with this utility:

Download and run Auslogics Disc Defragmenter


NEXT


Set a new restore point:

  • press the Win key on the keyboard, type Restore then press enter to get to the System Restore section.
  • Click "Create a restore point" Click on the "Create" button to create a new restore point. You may be prompted for permission to continue - ALLOW it to continue. You'll be prompted for a name, and you might want to give it a useful name that you'll be able to easily identify later.
  • Click the Create button, and then the system will create the restore point.
  • When it's all finished, you'll get a message saying it's completed successfully.
  • You will now have a new restore point

Then remove all previous Restore Points
  • Click Win key on the keyboard, type cleanmgr to access the disk cleanup
  • choose all files on the computer, then choose the C: drive, press OK Disk cleanup calculates the files, this takes a few minutes > another menu will pop up.
  • At the top, click on the More Options tab, under System Restore and Shadow Copies group,
  • Click the Clean up button,
  • Vista will ask you if you’re sure, click on the Delete button, click OK > Delete Files

Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Okay, I'll start in on the cleanup steps you recommended. A defrag is another thing I've been meaning to do for a while anyway. I'll put the taskbar thing down to a one-time bug (possibly in the software for my new mouse), and I'm guessing from the lack of response that the file-sharing programs aren't that evil.

(One of the things I was getting at with those questions was - are those a vector for infections other than via user error? I.E. is there a known means other than inadvertently downloading and running a trojan or something by which the presence of those programs can lead to malware infection?)

Anyway, thanks for the assistance and you have my permission to regard this case as closed.
I don't condone the use of peer2peer programs you are obviously aware of the pitfalls of using them they are a conduit for malware and in all likely hood was the cause of your current issues. You seemed to be quite well aware of that hence no lecture from me. You would be doing yourself a favour by removing them. Generally it's user error that causes the problems, but often just visiting the wrong web site can cause an infection, that's why I like using Web of Trust, it at least gives some warning.
I think this was actually a "visiting the wrong web site" case (a fake tube site where none of the videos actually work and it claims you need to download a special codec; like an idiot I refused to do this by clicking "no" rather than by Alt-F4ing the hell out of there, but of course the site designer could have set that "no" button up to do anything). At least that's the only obvious flub I can recall in the last week or so before the initial scan. Like I said earlier, my computer was showing no obvious symptoms of trouble, I just decided to do a virus scan because I hadn't in a while (only later remembering the above incident).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI