This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Explorer is not starting

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I posted in the general hardware section originally as I didn't know the origin of the problem, please see synopsis below - My PC is currently having issues whilst loading. It takes longer to load then usual, and only loads an empty screen with the wallpaper visible but no desktop shortcuts and no taskbar at the bottom of the screen. CTRL Alt Delete will bring up the task manager and I can access folder and files through this but I cannot get the taskbar to reappear. I am using Windows XP. If I boot up in safe mode it reaches the same point and displays "safe mode" but again no luck with the desktop icons/taskbar. appleoddity replied stating it was a typical sign of a malware infection and asked me to re-post here. Any help appreciated (unable to download DDS given the nature of the problem) Simon
Hello Paxbrother,

Please download ComboFix from one of these locations:

NOTE: If you are guest watching this topic. ComboFix is a very powerful tool. The disclaimer clearly states that you should not use it without supervision. There is good reason for this as ComboFix can, and sometimes does, run into conflict on a computer and render it unusable.

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Hi, I won't be able to download ComboFix directly onto the affected PC because Explorer doesn't get as far as loading the internet connection, also no desktop icons and system tray appears so I won't be save it to desktop if I transfer ComboFix via USB. Thanks Simon
Hi Paxbrother,

See if you can do this:

This is a way to access your computer using a disk we will create.

Before starting you might like to print these instruction out so that you know what you are doing

  • Download OTLPE.iso and save it somewhere you can get it.
  • Insert a writable blank CD/DVD in your CD drive and click on the OTPLE.iso to burn a CD. NOTE:
  • Reboot your infected system using the boot CD you just created.
Note : If you do not know how to set your computer to boot from CD follow the steps here
  • The CD needs to detect your hardware and load the operating system…can take a bit of time, just be patient :)
  • Your system should now display a Reatogo desktop.
    Note : as you are running from CD it is not exactly speedy
  • Double-click on the OTLPE icon.
  • Select the Windows folder of the infected drive if it asks for a location
  • If asked "Do you wish to load the remote registry", select Yes
  • If asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start.
  • Press Run Scan to start the scan.
  • When finished, the file will be saved in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system.
  • Right click the file and select send to : select the USB drive.
  • Confirm that it has copied to the USB drive by selecting it
  • You can backup any files that you wish from this OS
  • Please post the contents of the C:\OTL.txt file in your reply.
Hi - I managed to get ComboFix onto the desktop and run it as descirbed in your first reply using Task Manager, see below for the log text (I am replying from the affected PC which loads correctly and can access online now)

—————


ComboFix 10-06-11.01 - Simon 12/06/2010 15:20:55.11.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.696 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Simon\Local Settings\Application Data\{ACAA8184-6337-4DB8-8073-84A381748ADA}
c:\documents and settings\Simon\Local Settings\Application Data\{ACAA8184-6337-4DB8-8073-84A381748ADA}\chrome.manifest
c:\documents and settings\Simon\Local Settings\Application Data\{ACAA8184-6337-4DB8-8073-84A381748ADA}\chrome\content\_cfg.js
c:\documents and settings\Simon\Local Settings\Application Data\{ACAA8184-6337-4DB8-8073-84A381748ADA}\chrome\content\overlay.xul
c:\documents and settings\Simon\Local Settings\Application Data\{ACAA8184-6337-4DB8-8073-84A381748ADA}\install.rdf
c:\windows\Nindbdi.dll
c:\windows\oxehegurixu.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\svchost.exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\Packet.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\STEC3.sys
c:\windows\system32\wpcap.dll
c:\windows\Temp\_ex-08.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Legacy_STEC3
——-\Service_NPF
——-\Service_STEC3


((((((((((((((((((((((((( Files Created from 2010-05-12 to 2010-06-12 )))))))))))))))))))))))))))))))
.

2010-05-25 21:55 . 2010-05-25 21:55 ——– d—–w- c:\documents and settings\Simon\Application Data\DivX
2010-05-25 21:55 . 2010-03-31 01:58 9200 ——w- c:\windows\system32\drivers\cdralw2k.sys
2010-05-25 21:55 . 2010-03-31 01:58 9072 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2010-05-25 21:55 . 2010-03-31 01:58 133616 ——w- c:\windows\system32\pxafs.dll
2010-05-25 21:49 . 2010-05-25 21:55 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-05-18 21:10 . 2010-05-18 21:10 ——– d—–w- c:\program files\Common Files\Java
2010-05-18 21:09 . 2010-04-12 16:29 411368 —-a-w- c:\windows\system32\deployJava1.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-12 14:33 . 2007-05-13 17:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Kontiki
2010-05-31 23:25 . 2007-08-27 19:07 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-05-31 02:52 . 2009-04-09 18:25 ——– d—–w- c:\documents and settings\Simon\Application Data\Spotify
2010-05-31 02:52 . 2010-02-25 00:38 0 —-a-w- c:\windows\Chucitubal.bin
2010-05-27 18:10 . 2010-02-25 00:38 120 —-a-w- c:\windows\Slenasoyuyebiy.dat
2010-05-25 21:53 . 2009-12-21 00:18 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-05-24 23:06 . 2007-05-13 17:20 ——– d—–w- c:\program files\Kontiki
2010-05-18 21:09 . 2004-05-19 13:22 ——– d—–w- c:\program files\Java
2010-04-29 01:14 . 2010-04-29 01:14 ——– d—–w- c:\program files\QuickTime
2010-04-24 07:33 . 2010-04-24 07:33 ——– d—–w- c:\documents and settings\All Users\Application Data\93890029
2010-04-19 21:54 . 2010-04-19 21:54 20747 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-04-19 21:54 . 2008-08-22 18:55 ——– d—–w- c:\program files\RALINK
2010-03-31 01:58 . 2005-11-26 11:27 125424 ——w- c:\windows\system32\pxinsi64.exe
2010-03-31 01:58 . 2005-11-26 11:27 123888 ——w- c:\windows\system32\pxcpyi64.exe
2010-03-31 01:58 . 2003-07-30 01:02 44944 ——w- c:\windows\system32\drivers\pxhelp20.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-06-01 196608]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-28 68856]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-26 204800]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"LVCOMSX"="c:\windows\System32\LVCOMSX.EXE" [2004-05-21 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-06-01 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-06-01 217088]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 81920]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2007-09-23 292152]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"4oD"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
7digital Locker.lnk - c:\program files\7digital Locker\7digitalLocker.exe [2007-5-1 2734100]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
AOL 8.0 Tray Icon.lnk - c:\program files\AOL 8.0\aoltray.exe [2004-5-19 36937]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2010-4-19 593920]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\My Games\\Supreme Commander\\Supreme Commander\\bin\\SupremeCommander.exe"=
"f:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\GPGNet\\GPG.Multiplayer.Client.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"f:\\program files\\itunes\\iTunes.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\burst\\core-new1.1.3\\btdownloadheadless.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\Program Files\\Star Wars Galactic Battleground\\Game\\Battlegrounds.exe"=
"c:\\WINDOWS\\SYSTEM32\\dplaysvr.exe"=

S3 lgmcbus;LGE Mobile driver (WDM);c:\windows\system32\DRIVERS\lgmcbus.sys –> c:\windows\system32\DRIVERS\lgmcbus.sys [?]
S3 lgmcmdfl;LGE Mobile USB WMC Modem Filter;c:\windows\system32\DRIVERS\lgmcmdfl.sys –> c:\windows\system32\DRIVERS\lgmcmdfl.sys [?]
S3 lgmcmdm;LGE Mobile USB WMC Modem Driver;c:\windows\system32\DRIVERS\lgmcmdm.sys –> c:\windows\system32\DRIVERS\lgmcmdm.sys [?]
S3 lgmcmgmt;LGE Mobile USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\lgmcmgmt.sys –> c:\windows\system32\DRIVERS\lgmcmgmt.sys [?]
S3 lgmcnd5;LGE Mobile USB WMC Ethernet ELDA (NDIS);c:\windows\system32\DRIVERS\lgmcnd5.sys –> c:\windows\system32\DRIVERS\lgmcnd5.sys [?]
S3 lgmcobex;LGE Mobile USB WMC OBEX Interface;c:\windows\system32\DRIVERS\lgmcobex.sys –> c:\windows\system32\DRIVERS\lgmcobex.sys [?]
S3 lgmcunic;LGE Mobile USB WMC Ethernet ELDA (WDM);c:\windows\system32\DRIVERS\lgmcunic.sys –> c:\windows\system32\DRIVERS\lgmcunic.sys [?]
S3 NaiFiltr;NaiFiltr;c:\windows\SYSTEM32\DRIVERS\NaiFiltr.sys [15/06/2004 19:36 23296]
.
Contents of the 'Scheduled Tasks' folder

2010-05-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://news.bbc.co.uk/
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local;
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: + &Download Express: download this file - c:\program files\Download Express\Add_Url.htm
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
Trusted Zone: belamionline.com\www
Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - f:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - f:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - f:\progra~1\DOWNLO~1\mdpph.dll
DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6}
DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - hxxps://moneymanager.egg.com/Pinsafe/accounttracking.cab
FF - ProfilePath - c:\documents and settings\Simon\Application Data\Mozilla\Firefox\Profiles\mjwfozk6.default\
FF - prefs.js: browser.startup.homepage - hxxp://news.bbc.co.uk/
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Simon\Application Data\Mozilla\Firefox\Profiles\mjwfozk6.default\extensions\{D249FD00-4DF9-11D9-9FDC-0080481ADA61}\components\mpint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin9.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

BHO-{0d3c8bef-d82d-4d63-aefe-a0e9cc1fe6af} - (no file)
HKCU-Run-Steam - (no file)
HKLM-Run-Ifiqixowet - c:\windows\oxehegurixu.dll
HKLM-Run-DivXUpdate - c:\program files\DivX\DivX Update\DivXUpdate.exe
AddRemove-Microsoft Interactive Training - c:\windows\orun32.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-12 15:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1648002289-3947860720-1545137810-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:21,9f,be,bd,63,0f,34,82,cd,84,4e,26,3c,0f,cd,83,fe,a7,67,d3,eb,52,5d,
3a,88,05,96,cd,99,25,30,ae,b5,9b,23,e6,a8,4e,7f,52,c8,c1,ff,63,31,09,ed,b8,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(216)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\progra~1\mcafee.com\vso\mcvsrte.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\wanmpsvc.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\SoftwareDistribution\Download\60cd82908dbb295dedb9fb0ac86f3dfb\update\update.exe
.
**************************************************************************
.
Completion time: 2010-06-12 15:44:39 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-12 14:44
ComboFix2.txt 2009-10-01 17:00

Pre-Run: 32,631,459,840 bytes free
Post-Run: 32,450,301,952 bytes free

Current=4 Default=4 Failed=2 LastKnownGood=1 Sets=1,2,3,4
- - End Of File - - 218F5EBD1C723B985C5067864DC17D9D
Hello Paxbrother,

You may have used Malwarebytes before. If you still have it on your machine please update and run. Post the scan report back here.

If you do not have Malwarebytes please download from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Next

Kaspersky on line scanner is very thorough. It can take a long time and for periods may seem not to be working. Just be patient and let it do its job.

Kaspersky works with Internet Explorer and Firefox 3.

Go to Kaspersky website and perform an online antivirus scan.

Note: you will need to turn off your security programs to allow Kaspersky to do its job.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start dowanloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Copy and paste that information in your next post.

So when you return please post
  • MBAM log
  • Kaspersky scan results
  • and tell me how your computer is performing now
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4192 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 12/06/2010 22:33:08 mbam-log-2010-06-12 (22-33-08).txt Scan type: Quick scan Objects scanned: 148961 Time elapsed: 9 minute(s), 4 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 9 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{4776c4dc-e894-7c06-2148-5d73cef5f905} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{4776c4dc-e894-7c06-2148-5d73cef5f905} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{50d5107a-d278-4871-8989-f4ceaaf59cfc} (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\All Users\Application Data\93890029 (Rogue.Multiple) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\All Users\Application Data\93890029\93890029.exe (Rogue.Multiple) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\msls50.dll (Trojan.Agent) -> Delete on reboot. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Tuesday, June 15, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, June 15, 2010 05:07:00 Records in database: 4278173 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 146367 Threats found: 9 Infected objects found: 12 Suspicious objects found: 0 Scan duration: 07:05:13 File name / Threat / Threats count C:\Documents and Settings\Simon\Application Data\Sun\Java\Deployment\cache\6.0\60\398d407c-23624804 Infected: Exploit.Java.CVE-2009-3867.gen 1 C:\Documents and Settings\Simon\Application Data\Sun\Java\Deployment\cache\6.0\60\398d407c-23624804 Infected: Trojan-Downloader.Java.Agent.cd 1 C:\Documents and Settings\Simon\Application Data\Sun\Java\Deployment\cache\6.0\60\398d407c-23624804 Infected: Trojan-Downloader.Java.OpenStream.al 1 C:\Program Files\World of Warcraft\WowError.exe Infected: Trojan-Downloader.Win32.Agent.dsta 1 C:\Qoobox\Quarantine\C\WINDOWS\Nindbdi.dll.vir Infected: Trojan-Downloader.Win32.Mufanom.nba 1 C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\svchost.exe.vir Infected: Trojan-Downloader.Win32.Small.apzo 1 C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_sdra64_.exe.zip Infected: Trojan-Spy.Win32.Zbot.aibn 1 C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP37\A0003471.exe Infected: Trojan-Banker.Win32.Bancos.ope 1 C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP60\A0009861.dll Infected: Trojan-Downloader.Win32.Mufanom.nba 1 C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP60\A0009864.exe Infected: Trojan-Downloader.Win32.Small.apzo 1 C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP61\A0010556.exe Infected: Packed.Win32.Krap.hc 1 C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP61\A0010560.dll Infected: Packed.Win32.Krap.hc 1 Selected area has been scanned. PC is running fine, no obvious problems
Hello Paxbrother,

Looking good, most of those are in the tools we have been using or in System Restore. We will remove them at next post all going well.

Just a couple to deal with now.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KillAll::

File::
C:\Documents and Settings\Simon\Application Data\Sun\Java\Deployment\cache\6.0\60\398d407c-23624804
C:\Program Files\World of Warcraft\WowError.exe

Reboot::

Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it will produce a log for you at C:\ComboFix.txt. Please post that here for further review.
ComboFix 10-06-20.06 - Simon 21/06/2010 19:53:34.13.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.602 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Simon\Desktop\CFScript.txt
* Created a new restore point

FILE ::
"c:\documents and settings\Simon\Application Data\Sun\Java\Deployment\cache\6.0\60\398d407c-23624804"
"c:\program files\World of Warcraft\WowError.exe"
.

((((((((((((((((((((((((( Files Created from 2010-05-21 to 2010-06-21 )))))))))))))))))))))))))))))))
.

2010-05-25 21:55 . 2010-06-15 23:31 ——– d—–w- c:\documents and settings\Simon\Application Data\DivX
2010-05-25 21:55 . 2010-03-31 01:58 9200 ——w- c:\windows\system32\drivers\cdralw2k.sys
2010-05-25 21:55 . 2010-03-31 01:58 9072 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2010-05-25 21:55 . 2010-03-31 01:58 133616 ——w- c:\windows\system32\pxafs.dll
2010-05-25 21:49 . 2010-05-25 21:55 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-21 19:05 . 2007-05-13 17:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Kontiki
2010-06-21 18:36 . 2007-08-27 19:07 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-17 16:14 . 2009-04-09 18:25 ——– d—–w- c:\documents and settings\Simon\Application Data\Spotify
2010-06-16 10:04 . 2008-01-02 19:39 ——– d—–w- c:\program files\World of Warcraft
2010-06-12 16:59 . 2009-02-01 16:26 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-31 02:52 . 2010-02-25 00:38 0 —-a-w- c:\windows\Chucitubal.bin
2010-05-27 18:10 . 2010-02-25 00:38 120 —-a-w- c:\windows\Slenasoyuyebiy.dat
2010-05-25 21:53 . 2009-12-21 00:18 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-05-24 23:06 . 2007-05-13 17:20 ——– d—–w- c:\program files\Kontiki
2010-05-18 21:10 . 2010-05-18 21:10 ——– d—–w- c:\program files\Common Files\Java
2010-05-18 21:09 . 2004-05-19 13:22 ——– d—–w- c:\program files\Java
2010-05-04 17:20 . 2004-02-06 17:05 832512 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2002-08-29 04:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-05-02 05:22 . 2008-09-28 15:48 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 14:39 . 2008-10-22 20:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2008-10-22 20:46 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-29 01:14 . 2010-04-29 01:14 ——– d—–w- c:\program files\QuickTime
2010-04-20 05:30 . 2002-08-29 04:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-19 21:54 . 2010-04-19 21:54 20747 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-04-12 16:29 . 2010-05-18 21:09 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-03-31 01:58 . 2005-11-26 11:27 125424 ——w- c:\windows\system32\pxinsi64.exe
2010-03-31 01:58 . 2005-11-26 11:27 123888 ——w- c:\windows\system32\pxcpyi64.exe
2010-03-31 01:58 . 2003-07-30 01:02 44944 ——w- c:\windows\system32\drivers\pxhelp20.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-06-01 196608]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-28 68856]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-26 204800]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"LVCOMSX"="c:\windows\System32\LVCOMSX.EXE" [2004-05-21 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-06-01 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-06-01 217088]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 81920]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2007-09-23 292152]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"4oD"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
7digital Locker.lnk - c:\program files\7digital Locker\7digitalLocker.exe [2007-5-1 2734100]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
AOL 8.0 Tray Icon.lnk - c:\program files\AOL 8.0\aoltray.exe [2004-5-19 36937]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2010-4-19 593920]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\My Games\\Supreme Commander\\Supreme Commander\\bin\\SupremeCommander.exe"=
"f:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\GPGNet\\GPG.Multiplayer.Client.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"f:\\program files\\itunes\\iTunes.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\burst\\core-new1.1.3\\btdownloadheadless.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\Program Files\\Star Wars Galactic Battleground\\Game\\Battlegrounds.exe"=
"c:\\WINDOWS\\SYSTEM32\\dplaysvr.exe"=

S3 lgmcbus;LGE Mobile driver (WDM);c:\windows\system32\DRIVERS\lgmcbus.sys –> c:\windows\system32\DRIVERS\lgmcbus.sys [?]
S3 lgmcmdfl;LGE Mobile USB WMC Modem Filter;c:\windows\system32\DRIVERS\lgmcmdfl.sys –> c:\windows\system32\DRIVERS\lgmcmdfl.sys [?]
S3 lgmcmdm;LGE Mobile USB WMC Modem Driver;c:\windows\system32\DRIVERS\lgmcmdm.sys –> c:\windows\system32\DRIVERS\lgmcmdm.sys [?]
S3 lgmcmgmt;LGE Mobile USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\lgmcmgmt.sys –> c:\windows\system32\DRIVERS\lgmcmgmt.sys [?]
S3 lgmcnd5;LGE Mobile USB WMC Ethernet ELDA (NDIS);c:\windows\system32\DRIVERS\lgmcnd5.sys –> c:\windows\system32\DRIVERS\lgmcnd5.sys [?]
S3 lgmcobex;LGE Mobile USB WMC OBEX Interface;c:\windows\system32\DRIVERS\lgmcobex.sys –> c:\windows\system32\DRIVERS\lgmcobex.sys [?]
S3 lgmcunic;LGE Mobile USB WMC Ethernet ELDA (WDM);c:\windows\system32\DRIVERS\lgmcunic.sys –> c:\windows\system32\DRIVERS\lgmcunic.sys [?]
S3 NaiFiltr;NaiFiltr;c:\windows\SYSTEM32\DRIVERS\NaiFiltr.sys [15/06/2004 19:36 23296]
.
Contents of the 'Scheduled Tasks' folder

2010-05-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://news.bbc.co.uk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local;
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: + &Download Express: download this file - c:\program files\Download Express\Add_Url.htm
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
Trusted Zone: belamionline.com\www
Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - f:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - f:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - f:\progra~1\DOWNLO~1\mdpph.dll
DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6}
DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - hxxps://moneymanager.egg.com/Pinsafe/accounttracking.cab
FF - ProfilePath - c:\documents and settings\Simon\Application Data\Mozilla\Firefox\Profiles\mjwfozk6.default\
FF - prefs.js: browser.startup.homepage - hxxp://news.bbc.co.uk/
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Simon\Application Data\Mozilla\Firefox\Profiles\mjwfozk6.default\extensions\{D249FD00-4DF9-11D9-9FDC-0080481ADA61}\components\mpint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin9.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

BHO-{0d3c8bef-d82d-4d63-aefe-a0e9cc1fe6af} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-21 20:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1648002289-3947860720-1545137810-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:21,9f,be,bd,63,0f,34,82,cd,84,4e,26,3c,0f,cd,83,fe,a7,67,d3,eb,52,5d,
3a,88,05,96,cd,99,25,30,ae,b5,9b,23,e6,a8,4e,7f,52,c8,c1,ff,63,31,09,ed,b8,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(864)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3064)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\progra~1\mcafee.com\vso\mcvsrte.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\wanmpsvc.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\SpywareGuard\sgmain.exe
c:\program files\SpywareGuard\sgbhp.exe
.
**************************************************************************
.
Completion time: 2010-06-21 20:13:50 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-21 19:13
ComboFix2.txt 2010-06-16 10:18
ComboFix3.txt 2010-06-12 14:44
ComboFix4.txt 2009-10-01 17:00

Pre-Run: 32,274,616,320 bytes free
Post-Run: 32,254,496,768 bytes free

Current=4 Default=4 Failed=2 LastKnownGood=1 Sets=1,2,3,4
- - End Of File - - 588AB039A081F9F17E48D5B8E57F554D
Hello Paxbrother,

I think your machine is clean.

We have a couple of last steps to perform and then you're all set.[image unavailable: Posted Image]

Follow these steps to uninstall Combofix and tools used in the removal of malware. This will also clean out and reset your Restore Points.
Step 2
  • Double-click OTL.exe to run it. (Vista users, please right click on OTL.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

MBAM can be uninstalled via control panel add/remove but it may be a useful tool to keep.

——————————————————————————————————————-

A reminder: Remember to turn back on any anti-malware programs you may have turned off during the cleaning process.

——————————————————————————————————————-

Now that your machine is clean here are some things that I think are worth having a look at if you don't already know about them:

———————————————————————————————————————

Regularly check that your Java is up to date. Older versions are vunerable to malicious attack.
  • Download from here Java Runtime Environment (JDK) Update
  • Scroll to where it says "Windows XP/Vista/2000/2003/2008 online" and download and follow the instructions to install.

    Reboot your computer.
    You also need to uininstall older versions of Java.

  • Click Start > Control Panel > Add or Remove Programs
  • Remove all Java updates except the latest one you have just installed.
——————————————————————————————————————–

Be sure and give the Temp folders a cleaning out now and then. This helps with security and your computer will run more efficiently. I clean mine once a week.

For ease of use, you might consider the following free program:
  • TFC.exe
——————————————————————————————————————–

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* Consider using an alternate browser.

Opera may be downloaded from here. It is one of the least targeted of all browers.

Avant may be downloaded from here. Another one that is less well known.

Firefox may be downloaded from Here. I use Firefox because I like it. Used to be one of the safest but now targeted probably as much as IE.

Adblock Plus is a good Add-on for Firefox that helps prevent those annoying pop ups.
———————————————————————————————————————–

Startuplite is a tool to help you stop some programs not needed when you start your computer from loading. They will begin automatically only when needed.

———————————————————————————————————————–

To help protect your computer in the future here are some free programs you can look at:

  • It is recommended that you do set Windows to check, download and install your updates automatically.

    * Click Start > Control Panel > Automatic Updates
    * Set the day and time for the update check. Set this to a time when your computer will normally be on and connected to the internet.
    * Click Apply then OK.

    And to keep your system clean consider choosing from these free for home use malware scanners and updating and running weekly.
  • Malwarebytes
  • SuperAntiSpyWare
Be aware of what emails you open and websites you visit.

Go here for some good advice about how to prevent infection.

Have a safe and happy computing day!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI