This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus/Malware Take-over

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

*****Please help as soon as possible….I promise to donate to this site and any person's site who helps me out!!******

I believe I have the Bankerfox.A Trojan Virus….

I just booted up my laptop and had an error message come up "error loading cvurttbm.dll", and then the dreaded popups for "AV Security Suite"….it's now taken over and am getting error messages galore. When I open a program, I get an error message "Spyware Alert - Application Infected….", and when I use Internet Explorer, I get "This site reported as unsafe" with 2 options "Go to Anti-Virus Home Page" and "Ignore Warning"….if I hit ignore warning, I can go to my desired web page.. I also can't access my "Windows Task Manager".

My AVG Anti-Virus isn't working, and I tried to install Microsft Essentials and that won't work as well….my Security Dialog Box pops up on occasion telling me the anti-virus program has is not activated, but won't let me activate it….

I'm under a major deadline of Thursday and am in dire straights. This is is my work computer…so this could be major. What can/should I do???

Below are my dds and hijackthis file logs…Thank you in advance for your timely help…

DDS Log

#
# A fatal error has been detected by the Java Runtime Environment:
#
# EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x02bc19ec, pid=8412, tid=9368
#
# JRE version: 6.0_14-b08
# Java VM: Java HotSpot™ Client VM (14.0-b16 mixed mode, sharing windows-x86 )
# Problematic frame:
# C 0x02bc19ec
#
# If you would like to submit a bug report, please visit:
# http://java.sun.com/webapps/bugreport/crash.jsp
# The crash happened outside the Java Virtual Machine in native code.
# See problematic frame for where to report the bug.
#

————— T H R E A D —————

Current thread (0x03203000): JavaThread "thread applet-Google-1" [_thread_in_native, id=9368, stack(0x035f0000,0x03640000)]

siginfo: ExceptionCode=0xc0000005, writing address 0x7c34218f

Registers:
EAX=0x00000000, EBX=0x26c35768, ECX=0x7c34218f, EDX=0x00000000
ESP=0x0363f930, EBP=0x255a255a, ESI=0x26c35768, EDI=0x03203000
EIP=0x02bc19ec, EFLAGS=0x00210216

Top of Stack: (sp=0x0363f930)
0x0363f930: 02bc1a04 02bc1a04 fffffffe 0363f93c
0x0363f940: 26c35768 0363f970 26c35f90 00000000
0x0363f950: 26c35768 00000000 0363f96c 0363f998
0x0363f960: 00992e83 00000000 00998269 231f9048
0x0363f970: 22bf0ff8 22bf0ff8 0363f978 26c356c7
0x0363f980: 0363f9a8 26c35f90 00000000 26c356e8
0x0363f990: 0363f96c 0363f9a4 0363f9cc 00992da1
0x0363f9a0: 22c3a4f8 231f9048 22bf0ff8 0363f9ac

Instructions: (pc=0x02bc19ec)
0x02bc19dc: f8 66 1a 2b f8 66 1a 2b 68 57 c3 26 00 8d 19 2b
0x02bc19ec: 88 09 19 2b 08 aa c3 22 30 eb 78 2b 58 ac 19 2b


Stack: [0x035f0000,0x03640000], sp=0x0363f930, free space=318k
Native frames: (J=compiled Java code, j=interpreted, Vv=VM code, C=native code)
C 0x02bc19ec

Java frames: (J=compiled Java code, j=interpreted, Vv=VM code)
j com.sun.media.sound.HeadspaceSoundbank.nOpenResource(Ljava/lang/String;)J+0
j com.sun.media.sound.HeadspaceSoundbank.initialize(Ljava/lang/String;)V+7
j com.sun.media.sound.HeadspaceSoundbank.(Ljava/net/URL;)V+89
j com.sun.media.sound.HsbParser.getSoundbank(Ljava/net/URL;)Ljavax/sound/midi/Soundbank;+5
j javax.sound.midi.MidiSystem.getSoundbank(Ljava/net/URL;)Ljavax/sound/midi/Soundbank;+36
j C.init(Ljava/net/URL;)V+19
j Google.init()V+734
j sun.plugin2.applet.Plugin2Manager$AppletExecutionRunnable.run()V+916
j java.lang.Thread.run()V+11
v ~StubRoutines::call_stub

————— P R O C E S S —————

Java Threads: ( => current thread )
0x03336c00 JavaThread "Java Sound Event Dispatcher" daemon [_thread_blocked, id=6784, stack(0x04640000,0x04690000)]
0x03252400 JavaThread "Image Fetcher 1" daemon [_thread_blocked, id=7132, stack(0x045a0000,0x045f0000)]
0x03253000 JavaThread "Image Fetcher 0" daemon [_thread_blocked, id=9272, stack(0x04460000,0x044b0000)]
0x03206c00 JavaThread "Keep-Alive-Timer" daemon [_thread_blocked, id=7888, stack(0x042e0000,0x04330000)]
0x03211800 JavaThread "D3D Screen Updater" daemon [_thread_blocked, id=8240, stack(0x044b0000,0x04500000)]
0x0320f000 JavaThread "thread applet-lorry.Debuggr.class-2" [_thread_blocked, id=10184, stack(0x04370000,0x043c0000)]
0x0320d800 JavaThread "AWT-EventQueue-3" [_thread_blocked, id=8232, stack(0x04410000,0x04460000)]
0x0320c800 JavaThread "Applet 4 LiveConnect Worker Thread" [_thread_blocked, id=9964, stack(0x043c0000,0x04410000)]
=>0x03203000 JavaThread "thread applet-Google-1" [_thread_in_native, id=9368, stack(0x035f0000,0x03640000)]
0x031dcc00 JavaThread "AWT-EventQueue-2" [_thread_blocked, id=10136, stack(0x04240000,0x04290000)]
0x031dbc00 JavaThread "Applet 3 LiveConnect Worker Thread" [_thread_blocked, id=10104, stack(0x041f0000,0x04240000)]
0x031d9000 JavaThread "Browser Side Object Cleanup Thread" [_thread_blocked, id=10128, stack(0x041a0000,0x041f0000)]
0x031d2800 JavaThread "Windows Tray Icon Thread" [_thread_in_native, id=10096, stack(0x03690000,0x036e0000)]
0x031be000 JavaThread "CacheCleanUpThread" daemon [_thread_blocked, id=10108, stack(0x030c0000,0x03110000)]
0x031e1c00 JavaThread "CacheMemoryCleanUpThread" daemon [_thread_blocked, id=10076, stack(0x03640000,0x03690000)]
0x031bc000 JavaThread "AWT-EventQueue-0" [_thread_blocked, id=7764, stack(0x035a0000,0x035f0000)]
0x031b9000 JavaThread "Java Plug-In Heartbeat Thread" [_thread_blocked, id=10100, stack(0x03550000,0x035a0000)]
0x031b6000 JavaThread "AWT-Windows" daemon [_thread_in_native, id=9596, stack(0x03450000,0x034a0000)]
0x031b4c00 JavaThread "AWT-Shutdown" [_thread_blocked, id=9104, stack(0x03400000,0x03450000)]
0x031b0800 JavaThread "Java2D Disposer" daemon [_thread_blocked, id=6936, stack(0x033b0000,0x03400000)]
0x02b5c400 JavaThread "Java Plug-In Pipe Worker Thread (Client-Side)" daemon [_thread_in_native, id=4832, stack(0x03110000,0x03160000)]
0x02b58c00 JavaThread "traceMsgQueueThread" daemon [_thread_blocked, id=10056, stack(0x03030000,0x03080000)]
0x02b55800 JavaThread "Timer-0" [_thread_blocked, id=7720, stack(0x02fe0000,0x03030000)]
0x02b39400 JavaThread "Low Memory Detector" daemon [_thread_blocked, id=10020, stack(0x02db0000,0x02e00000)]
0x02b32c00 JavaThread "CompilerThread0" daemon [_thread_blocked, id=8356, stack(0x02d60000,0x02db0000)]
0x02b31400 JavaThread "Attach Listener" daemon [_thread_blocked, id=10036, stack(0x02d10000,0x02d60000)]
0x02b30000 JavaThread "Signal Dispatcher" daemon [_thread_blocked, id=7420, stack(0x02cc0000,0x02d10000)]
0x02aee400 JavaThread "Finalizer" daemon [_thread_blocked, id=9132, stack(0x02c70000,0x02cc0000)]
0x02aecc00 JavaThread "Reference Handler" daemon [_thread_blocked, id=9700, stack(0x02c20000,0x02c70000)]
0x00886800 JavaThread "main" [_thread_blocked, id=10008, stack(0x00910000,0x00960000)]

Other Threads:
0x02aeb400 VMThread [stack: 0x02bd0000,0x02c20000] [id=10016]
0x02b43400 WatcherThread [stack: 0x02e00000,0x02e50000] [id=10044]

VM state:not at safepoint (normal execution)

VM Mutex/Monitor currently owned by a thread: None

Heap
def new generation total 4544K, used 2766K [0x22990000, 0x22e70000, 0x22e70000)
eden space 4096K, 66% used [0x22990000, 0x22c3b2d8, 0x22d90000)
from space 448K, 7% used [0x22d90000, 0x22d98770, 0x22e00000)
to space 448K, 0% used [0x22e00000, 0x22e00000, 0x22e70000)
tenured generation total 60544K, used 49932K [0x22e70000, 0x26990000, 0x26990000)
the space 60544K, 82% used [0x22e70000, 0x25f331b8, 0x25f33200, 0x26990000)
compacting perm gen total 12288K, used 2827K [0x26990000, 0x27590000, 0x2a990000)
the space 12288K, 23% used [0x26990000, 0x26c52d78, 0x26c52e00, 0x27590000)
ro space 8192K, 63% used [0x2a990000, 0x2aea96b0, 0x2aea9800, 0x2b190000)
rw space 12288K, 53% used [0x2b190000, 0x2b804b80, 0x2b804c00, 0x2bd90000)

Dynamic libraries:
0x00400000 - 0x00424000 C:\Program Files\Java\jre6\bin\java.exe
0x7c900000 - 0x7c9b2000 C:\WINDOWS\system32\ntdll.dll
0x7c800000 - 0x7c8f6000 C:\WINDOWS\system32\kernel32.dll
0x77dd0000 - 0x77e6b000 C:\WINDOWS\system32\ADVAPI32.dll
0x77e70000 - 0x77f02000 C:\WINDOWS\system32\RPCRT4.dll
0x77fe0000 - 0x77ff1000 C:\WINDOWS\system32\Secur32.dll
0x5cb70000 - 0x5cb96000 C:\WINDOWS\system32\ShimEng.dll
0x71590000 - 0x71609000 C:\WINDOWS\AppPatch\AcLayers.DLL
0x7e410000 - 0x7e4a1000 C:\WINDOWS\system32\USER32.dll
0x77f10000 - 0x77f59000 C:\WINDOWS\system32\GDI32.dll
0x7c9c0000 - 0x7d1d7000 C:\WINDOWS\system32\SHELL32.dll
0x77c10000 - 0x77c68000 C:\WINDOWS\system32\msvcrt.dll
0x77f60000 - 0x77fd6000 C:\WINDOWS\system32\SHLWAPI.dll
0x774e0000 - 0x7761d000 C:\WINDOWS\system32\ole32.dll
0x769c0000 - 0x76a74000 C:\WINDOWS\system32\USERENV.dll
0x73000000 - 0x73026000 C:\WINDOWS\system32\WINSPOOL.DRV
0x76390000 - 0x763ad000 C:\WINDOWS\system32\IMM32.DLL
0x773d0000 - 0x774d3000 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
0x7c340000 - 0x7c396000 C:\Program Files\Java\jre6\bin\msvcr71.dll
0x6d800000 - 0x6da8b000 C:\Program Files\Java\jre6\bin\client\jvm.dll
0x76b40000 - 0x76b6d000 C:\WINDOWS\system32\WINMM.dll
0x6d7b0000 - 0x6d7bc000 C:\Program Files\Java\jre6\bin\verify.dll
0x6d330000 - 0x6d34f000 C:\Program Files\Java\jre6\bin\java.dll
0x6d290000 - 0x6d298000 C:\Program Files\Java\jre6\bin\hpi.dll
0x76bf0000 - 0x76bfb000 C:\WINDOWS\system32\PSAPI.DLL
0x6d7f0000 - 0x6d7ff000 C:\Program Files\Java\jre6\bin\zip.dll
0x6d430000 - 0x6d436000 C:\Program Files\Java\jre6\bin\jp2native.dll
0x6d1d0000 - 0x6d1e3000 C:\Program Files\Java\jre6\bin\deploy.dll
0x77a80000 - 0x77b15000 C:\WINDOWS\system32\CRYPT32.dll
0x77b20000 - 0x77b32000 C:\WINDOWS\system32\MSASN1.dll
0x77120000 - 0x771ab000 C:\WINDOWS\system32\OLEAUT32.dll
0x3d930000 - 0x3da01000 C:\WINDOWS\system32\WININET.dll
0x02e50000 - 0x02e59000 C:\WINDOWS\system32\Normaliz.dll
0x3dfd0000 - 0x3e015000 C:\WINDOWS\system32\iertutil.dll
0x78130000 - 0x78258000 C:\WINDOWS\system32\urlmon.dll
0x6d6b0000 - 0x6d6f3000 C:\Program Files\Java\jre6\bin\regutils.dll
0x77c00000 - 0x77c08000 C:\WINDOWS\system32\VERSION.dll
0x7d1e0000 - 0x7d49c000 C:\WINDOWS\system32\msi.dll
0x6d610000 - 0x6d623000 C:\Program Files\Java\jre6\bin\net.dll
0x71ab0000 - 0x71ac7000 C:\WINDOWS\system32\WS2_32.dll
0x71aa0000 - 0x71aa8000 C:\WINDOWS\system32\WS2HELP.dll
0x6d630000 - 0x6d639000 C:\Program Files\Java\jre6\bin\nio.dll
0x6d000000 - 0x6d14a000 C:\Program Files\Java\jre6\bin\awt.dll
0x5ad70000 - 0x5ada8000 C:\WINDOWS\system32\uxtheme.dll
0x74720000 - 0x7476c000 C:\WINDOWS\system32\MSCTF.dll
0x77b40000 - 0x77b62000 C:\WINDOWS\system32\apphelp.dll
0x755c0000 - 0x755ee000 C:\WINDOWS\system32\msctfime.ime
0x6d230000 - 0x6d284000 C:\Program Files\Java\jre6\bin\fontmanager.dll
0x4fdd0000 - 0x4ff76000 C:\WINDOWS\system32\d3d9.dll
0x03500000 - 0x03506000 C:\WINDOWS\system32\d3d8thk.dll
0x71a50000 - 0x71a8f000 C:\WINDOWS\System32\mswsock.dll
0x76f20000 - 0x76f47000 C:\WINDOWS\system32\DNSAPI.dll
0x76fb0000 - 0x76fb8000 C:\WINDOWS\System32\winrnr.dll
0x76f60000 - 0x76f8c000 C:\WINDOWS\system32\WLDAP32.dll
0x76fc0000 - 0x76fc6000 C:\WINDOWS\system32\rasadhlp.dll
0x662b0000 - 0x66308000 C:\WINDOWS\system32\hnetcfg.dll
0x71a90000 - 0x71a98000 C:\WINDOWS\System32\wshtcpip.dll
0x68000000 - 0x68036000 C:\WINDOWS\system32\rsaenh.dll
0x5b860000 - 0x5b8b5000 C:\WINDOWS\system32\netapi32.dll
0x6d1a0000 - 0x6d1c3000 C:\Program Files\Java\jre6\bin\dcpr.dll
0x6d520000 - 0x6d544000 C:\Program Files\Java\jre6\bin\jsound.dll
0x6d550000 - 0x6d558000 C:\Program Files\Java\jre6\bin\jsoundds.dll
0x73f10000 - 0x73f6c000 C:\WINDOWS\system32\DSOUND.dll
0x76c30000 - 0x76c5e000 C:\WINDOWS\system32\WINTRUST.dll
0x76c90000 - 0x76cb8000 C:\WINDOWS\system32\IMAGEHLP.dll
0x72d20000 - 0x72d29000 C:\WINDOWS\system32\wdmaud.drv
0x72d10000 - 0x72d18000 C:\WINDOWS\system32\msacm32.drv
0x77be0000 - 0x77bf5000 C:\WINDOWS\system32\MSACM32.dll
0x77bd0000 - 0x77bd7000 C:\WINDOWS\system32\midimap.dll
0x76ee0000 - 0x76f1c000 C:\WINDOWS\system32\RASAPI32.dll
0x76e90000 - 0x76ea2000 C:\WINDOWS\system32\rasman.dll
0x76eb0000 - 0x76edf000 C:\WINDOWS\system32\TAPI32.dll
0x76e80000 - 0x76e8e000 C:\WINDOWS\system32\rtutils.dll
0x77c70000 - 0x77c95000 C:\WINDOWS\system32\msv1_0.dll
0x76790000 - 0x7679c000 C:\WINDOWS\system32\cryptdll.dll
0x76d60000 - 0x76d79000 C:\WINDOWS\system32\iphlpapi.dll
0x722b0000 - 0x722b5000 C:\WINDOWS\system32\sensapi.dll

VM Arguments:
jvm_args: -D__jvm_launched=43361725084 -Xbootclasspath/a:C:\PROGRA~1\Java\jre6\lib\deploy.jar;C:\PROGRA~1\Java\jre6\lib\javaws.jar;C:\PROGRA~1\Java\jre6\lib\plugin.jar
java_command: sun.plugin2.main.client.PluginMain write_pipe_name=jpi2_pid2872_pipe8,read_pipe_name=jpi2_pid2872_pipe7
Launcher Type: SUN_STANDARD

Environment Variables:
PATH=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\QuickTime\QTSystem\
USERNAME=Steve
OS=Windows_NT
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 11, GenuineIntel



————— S Y S T E M —————

OS: Windows XP Build 2600 Service Pack 3

CPU:total 2 (2 cores per cpu, 1 threads per core) family 6 model 15 stepping 11, cmov, cx8, fxsr, mmx, sse, sse2, sse3, ssse3

Memory: 4k page, physical 2095000k(109988k free), swap 4033140k(1952036k free)

vm_info: Java HotSpot™ Client VM (14.0-b16) for windows-x86 JRE (1.6.0_14-b08), built on May 21 2009 08:03:56 by "java_re" with MS VC++ 7.1

time: Fri May 28 11:18:42 2010
elapsed time: 5 seconds


HIJACKTHIS LOG

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:06:59 PM, on 6/16/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\hpzipm12.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Cmycua.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\documents and settings\steve\local settings\application data\pgaafa\gssohhc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\eFax Messenger 4.4\J2GTray.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Steve\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:1051
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O4 - HKLM\..\Run: [skb] rundll32 "cvurttbm.dll",,Run
O4 - HKLM\..\Run: [MChk] C:\WINDOWS\system32\ralgmoar.exe
O4 - HKLM\..\Run: [Uhuzemizufazemi] rundll32.exe "C:\WINDOWS\apozoquq.dll",Startup
O4 - HKLM\..\Run: [nmcosleincmcbj] c:\documents and settings\steve\local settings\application data\pgaafa\gssohhc.exe
O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
O4 - HKCU\..\Run: [M5T8QL3YW3] C:\DOCUME~1\Steve\LOCALS~1\Temp\Csh.exe
O4 - HKCU\..\Run: [Bqego] rundll32.exe "C:\WINDOWS\ndAPI1.dll",Startup
O4 - HKCU\..\Run: [nmcosleincmcbj] c:\documents and settings\steve\local settings\application data\pgaafa\gssohhc.exe
O4 - Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…indows-i586.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A0AB503-387F-4090-9F81-AF6B52A915DB}: NameServer = 93.188.163.7,93.188.166.242
O17 - HKLM\System\CCS\Services\Tcpip\..\{8EF758DE-BB28-4ED0-991E-C1A9856EDCEE}: NameServer = 93.188.163.7,93.188.166.242
O17 - HKLM\System\CCS\Services\Tcpip\..\{99F78BA8-992D-4188-9F0B-78B43DD98EA8}: NameServer = 93.188.163.7,93.188.166.242
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.163.7,93.188.166.242
O17 - HKLM\System\CS1\Services\Tcpip\..\{2A0AB503-387F-4090-9F81-AF6B52A915DB}: NameServer = 93.188.163.7,93.188.166.242
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.163.7,93.188.166.242
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\hpzipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 11818 bytes
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O4 - HKLM\..\Run: [skb] rundll32 "cvurttbm.dll",,Run
O4 - HKLM\..\Run: [MChk] C:\WINDOWS\system32\ralgmoar.exe
O4 - HKLM\..\Run: [Uhuzemizufazemi] rundll32.exe "C:\WINDOWS\apozoquq.dll",Startup
O4 - HKLM\..\Run: [nmcosleincmcbj] c:\documents and settings\steve\local settings\application data\pgaafa\gssohhc.exe
O4 - HKCU\..\Run: [M5T8QL3YW3] C:\DOCUME~1\Steve\LOCALS~1\Temp\Csh.exe
O4 - HKCU\..\Run: [Bqego] rundll32.exe "C:\WINDOWS\ndAPI1.dll",Startup
O4 - HKCU\..\Run: [nmcosleincmcbj] c:\documents and settings\steve\local settings\application data\pgaafa\gssohhc.exe

Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete these Files if listed:
C:\WINDOWS\system32\net.net
C:\WINDOWS\system32\ralgmoar.exe
C:\WINDOWS\apozoquq.dll
c:\documents and settings\steve\local settings\application data\pgaafa\gssohhc.exe
c:\documents and settings\steve\local settings\Temp\Csh.exe
C:\WINDOWS\ndAPI1.dll


Delete these Folders if listed:
c:\documents and settings\steve\local settings\application data\pgaafa


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Thank you for your prompt response! I did as you requested, but it would not allow me to delete the following files ("cannot delete due to write protected or currently in use")
C:\WINDOWS\apozoquq.dll
C:\WINDOWS\ndAPI1.dll

Also, I now cannot access the internet from my laptop. Hopefully this is not a major issue….however, I was able to transfer files to and from my desktop, so I was able to download the ATF Cleaner program and a new HJT run. The computer does not get the popups anymore, so that seems good. But again, I cannot access the internet for some reason….THANK YOU again for your help!

Here is the most recent HJT logfile:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:13:47 AM, on 6/17/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\hpzipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Documents and Settings\Steve\Application Data\39b.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\eFax Messenger 4.4\J2GTray.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Steve\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:1055
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Uhuzemizufazemi] rundll32.exe "C:\WINDOWS\apozoquq.dll",Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
O4 - HKCU\..\Run: [Bqego] rundll32.exe "C:\WINDOWS\ndAPI1.dll",Startup
O4 - Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…indows-i586.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A0AB503-387F-4090-9F81-AF6B52A915DB}: NameServer = 93.188.163.7,93.188.166.242
O17 - HKLM\System\CCS\Services\Tcpip\..\{8EF758DE-BB28-4ED0-991E-C1A9856EDCEE}: NameServer = 93.188.163.7,93.188.166.242
O17 - HKLM\System\CCS\Services\Tcpip\..\{99F78BA8-992D-4188-9F0B-78B43DD98EA8}: NameServer = 93.188.163.7,93.188.166.242
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.163.7,93.188.166.242
O17 - HKLM\System\CS1\Services\Tcpip\..\{2A0AB503-387F-4090-9F81-AF6B52A915DB}: NameServer = 93.188.163.7,93.188.166.242
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.163.7,93.188.166.242
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\hpzipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 10568 bytes
download the tools needed to a flash drive or other removable media, and run them from the USB device.

Download Combofix from any of the links below but rename it to ABCD.exe before saving it to your desktop.

Link 1
Link 2 If using this link, Right Click and select Save As.


Double click on the ABCD.exe ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

**Note: If Combofix (ABCD) won't run from the desktop, try running it from the USB device.


——————————————————————–

With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before doing any malware removal.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.


Go to Microsoft's website => http://support.microsoft.com/kb/310994

Scroll down to Step 1, and select the download that's appropriate for your Operating System. Download the file & save it as it's originally named.

Note: If you have SP3, use the SP2 package. Vista and Windows 7 users skip this part


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

[external image: Posted Image]


  • Drag the setup package onto ComboFix.exe and drop it.

  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.


    [external image: Posted Image]


  • At the next prompt, click 'Yes' to run the full ComboFix scan.

  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt in your next reply using Copy/Paste.


Notes:

Give it atleast 20-30 minutes to finish if needed.

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Also please describe how your computer behaves in your next reply.
Again…thank you so much. As you recommended, I put the files on a flash drive…first attempt running it on my laptop said that the ComboFix file had errors and to download again. I did and it ran the second time around. However, a message indicating it found "rootkit activity" popped up so it rebooted…it seemed to fun fine after that.

After ComboFix, I rebooted my laptop and it took FOREVER to shut down…I don't know if that is normal or not. In addition, my Microsft Security Essentials would not work after rebooting….so I uninstalled and reinstalled…it appears to be working now and is scanning my computer.

I used to have AVG 9.0….but this whole experience has soured me on them, so I switched to Microsft Security Essentials. Do you feel this is a good move, or do you have something else you could recommend?

My computer appears to working fine right now…so I'm crossing my fingers!

Thank you again….here's my ComboFix log:

ComboFix 10-06-17.01 - Steve 06/17/2010 15:57:48.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1702 [GMT -4:00]
Running from: g:\documents\Downloads\ABCD2.exe
Command switches used :: g:\documents\Downloads\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Outdated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Update\seupd.exe
c:\documents and settings\Steve\Application Data\39b.exe
c:\documents and settings\Steve\Local Settings\Application Data\{378F8537-7A04-47FE-A7F0-CAD367C10D57}
c:\documents and settings\Steve\Local Settings\Application Data\{378F8537-7A04-47FE-A7F0-CAD367C10D57}\chrome.manifest
c:\documents and settings\Steve\Local Settings\Application Data\{378F8537-7A04-47FE-A7F0-CAD367C10D57}\chrome\content\_cfg.js
c:\documents and settings\Steve\Local Settings\Application Data\{378F8537-7A04-47FE-A7F0-CAD367C10D57}\chrome\content\overlay.xul
c:\documents and settings\Steve\Local Settings\Application Data\{378F8537-7A04-47FE-A7F0-CAD367C10D57}\install.rdf
c:\program files\$NtUninstallWTF1012$
c:\program files\$NtUninstallWTF1012$\elUninstall.exe
c:\program files\Mozilla Firefox\searchplugins\google_search.xml
c:\windows\$NtUninstallMTF1011$
c:\windows\$NtUninstallMTF1011$\apUninstall.exe
c:\windows\apozoquq.dll
c:\windows\Cmycua.exe
c:\windows\ndAPI1.dll
c:\windows\system32\ernel32.dll
c:\windows\system32\win.com
c:\windows\xpsp1hfm.log

Infected copy of c:\windows\system32\drivers\intelppm.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-05-17 to 2010-06-17 )))))))))))))))))))))))))))))))
.

2010-06-17 19:56 . 2010-06-17 02:08 50176 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\SK5y5.dll
2010-06-17 19:38 . 2010-06-17 02:08 50176 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\QGMYW7.dll
2010-06-17 19:34 . 2010-06-17 19:34 ——– d-sh–w- c:\windows\ftpcache
2010-06-17 19:33 . 2006-10-04 18:21 3072000 —ha-w- c:\documents and settings\Steve\Application Data\U3\temp\Launchpad Removal.exe
2010-06-17 14:04 . 2010-06-17 14:14 ——– d—–w- C:\Transfer
2010-06-17 13:47 . 2010-06-17 02:08 50176 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\WS317u3.dll
2010-06-17 13:41 . 2010-06-17 02:08 50176 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\M7g31a.dll
2010-06-17 13:24 . 2010-06-17 02:08 50176 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\QG93a7.dll
2010-06-17 13:19 . 2010-06-17 02:08 50176 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\MYWSKUO.dll
2010-06-17 04:00 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-17 04:00 . 2010-06-17 04:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-17 04:00 . 2010-06-17 04:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-17 04:00 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-17 02:49 . 2010-06-17 02:50 ——– d—–w- c:\program files\Microsoft Security Essentials
2010-06-17 02:17 . 2010-06-17 02:08 50176 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\AAAA7kU.dll
2010-06-17 02:13 . 2010-06-17 13:25 0 —-a-w- c:\windows\Gmege.bin
2010-06-17 02:13 . 2010-06-17 02:13 120 —-a-w- c:\windows\Kwekocu.dat
2010-06-17 02:13 . 2010-06-17 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Update
2010-06-17 02:09 . 2010-06-17 02:09 50981 —-a-w- c:\windows\system32\eprkmryhdglezstlw.exe
2010-06-17 02:09 . 2010-06-17 02:09 ——– d—–w- C:\spoolerlogs
2010-06-17 02:09 . 2010-06-17 02:08 50176 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\IQ3w7u3.dll
2010-06-14 18:22 . 2010-06-14 18:22 ——– d—–w- c:\documents and settings\Steve\advfn
2010-05-27 20:51 . 2010-05-27 20:51 348160 —-a-w- c:\documents and settings\Steve\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-478953db-n\msvcr71.dll
2010-05-27 20:51 . 2010-05-27 20:51 503808 —-a-w- c:\documents and settings\Steve\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-478953db-n\msvcp71.dll
2010-05-27 20:51 . 2010-05-27 20:51 499712 —-a-w- c:\documents and settings\Steve\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-478953db-n\jmc.dll
2010-05-27 20:51 . 2010-05-27 20:51 ——– d—–w- c:\windows\Sun
2010-05-27 20:50 . 2010-05-27 20:50 410984 —-a-w- c:\windows\system32\deploytk.dll
2010-05-27 20:50 . 2010-05-27 20:50 ——– d—–w- c:\program files\Java
2010-05-27 20:50 . 2010-05-27 20:50 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-05-27 20:50 . 2010-05-27 20:50 152576 —-a-w- c:\documents and settings\Steve\Application Data\Sun\Java\jre1.6.0_14\lzma.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-17 19:33 . 2010-04-19 02:32 ——– d—–w- c:\documents and settings\Steve\Application Data\U3
2010-06-11 07:13 . 2010-04-10 19:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-07 13:01 . 2010-04-10 18:54 56275 —-a-w- c:\windows\system32\nvModes.dat
2010-06-06 22:56 . 2010-05-06 18:51 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-17 23:19 . 2010-04-10 21:30 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2010-05-12 15:29 . 2010-05-12 15:17 ——– d—–w- c:\documents and settings\Steve\Application Data\Apple Computer
2010-05-10 13:45 . 2010-05-10 13:45 ——– d—–w- c:\documents and settings\Steve\Application Data\DivX
2010-05-10 13:32 . 2010-05-10 13:32 ——– d—–w- c:\program files\Windows Media Connect 2
2010-05-07 13:40 . 2010-04-10 18:39 69624 —-a-w- c:\documents and settings\Steve\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-07 06:19 . 2010-04-10 19:56 ——– d—–w- c:\program files\Microsoft Works
2010-05-04 17:20 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-05-03 17:11 . 2010-05-03 16:58 ——– d—–w- c:\program files\QuickTime
2010-05-03 17:10 . 2010-05-03 17:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-05-03 17:02 . 2010-05-03 17:02 ——– d—–w- c:\program files\Common Files\Apple
2010-05-03 17:02 . 2010-05-03 17:02 ——– d—–w- c:\program files\Apple Software Update
2010-05-03 17:02 . 2010-05-03 17:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-05-02 05:22 . 2004-08-04 10:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-04 10:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-15 17:32 . 2010-04-15 17:32 7410688 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191319-191429.dll
2010-04-15 17:32 . 2010-04-15 17:32 7032320 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191222-191319.dll
2010-04-15 17:32 . 2010-04-15 17:32 2844160 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191714-19188.dll
2010-04-15 17:31 . 2010-04-15 17:31 6301696 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191127-191222.dll
2010-04-15 17:30 . 2010-04-15 17:30 5686272 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\19153-191714.dll
2010-04-15 17:29 . 2010-04-15 17:29 2776576 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191429-19153.dll
2010-04-15 17:28 . 2010-04-15 17:28 241512 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2010-04-15 17:28 . 2010-04-15 17:28 230752 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\patchw32.dll
2010-04-15 17:28 . 2010-04-15 17:28 956 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\rebase.cmd
2010-04-11 03:38 . 2010-04-11 03:38 4710 —-a-r- c:\documents and settings\Steve\Application Data\Microsoft\Installer\{DF6DA606-904D-4C18-823F-A4CFC3035E53}\ext.exe
2010-04-11 03:28 . 2010-04-11 03:28 1956656 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2010-04-10 19:10 . 2010-04-10 18:30 87263 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-04-10 18:52 . 2010-04-10 18:52 21425 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-04-10 18:52 . 2010-04-10 18:52 319488 —-a-w- c:\windows\system32\AegisI5Installer.exe
2010-04-10 18:42 . 2010-04-10 18:42 45056 —-a-r- c:\documents and settings\Steve\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe
2010-04-10 18:42 . 2010-04-10 18:42 10134 —-a-r- c:\documents and settings\Steve\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe
2010-04-10 18:28 . 2010-04-10 18:28 21640 —-a-w- c:\windows\system32\emptyregdb.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" [2008-10-07 95744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-01-25 159744]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-11 624248]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 303104]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"nwiz"="nwiz.exe" [2007-04-28 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]
"NVHotkey"="nvHotkey.dll" [2007-04-28 67584]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-05-27 148888]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]

c:\documents and settings\Steve\Start Menu\Programs\Startup\
eFax 4.4.lnk - c:\program files\eFax Messenger 4.4\J2GTray.exe [2008-10-7 656896]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-11 2150400]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2010-4-10 50688]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [11/2/2006 12:32 PM 97536]
R3 HPPLSBULK;HPPLSBULK;c:\windows\system32\drivers\hpplsbulk.sys [4/11/2010 12:31 AM 9344]
.
Contents of the 'Scheduled Tasks' folder

2010-06-17 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-04-11 02:18]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
uInternet Settings,ProxyServer = http=127.0.0.1:1055
uInternet Settings,ProxyOverride =
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Bqego - c:\windows\ndAPI1.dll
HKLM-Run-Uhuzemizufazemi - c:\windows\apozoquq.dll
AddRemove-$NtUninstallMTF1011$ - c:\windows\$NtUninstallMTF1011$\apUninstall.exe
AddRemove-$NtUninstallWTF1012$ - c:\program files\$NtUninstallWTF1012$\elUninstall.exe



**************************************************************************
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
Completion time: 2010-06-17 16:03:47
ComboFix-quarantined-files.txt 2010-06-17 20:03

Pre-Run: 72,740,175,872 bytes free
Post-Run: 72,734,801,920 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 739C0A0944463F34CBF05E472E81BDF1
I use MSE also.



Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/Virus_Malware_Take_over_t112670.html#entry660698
File::
c:\windows\Gmege.bin

Collect::
c:\windows\system32\Spool\prtprocs\w32x86\SK5y5.dll
c:\windows\system32\Spool\prtprocs\w32x86\QGMYW7.dll
c:\windows\system32\Spool\prtprocs\w32x86\WS317u3.dll
c:\windows\system32\Spool\prtprocs\w32x86\M7g31a.dll
c:\windows\system32\Spool\prtprocs\w32x86\QG93a7.dll
c:\windows\system32\Spool\prtprocs\w32x86\MYWSKUO.dll
c:\windows\system32\Spool\prtprocs\w32x86\AAAA7kU.dll
c:\windows\Kwekocu.dat
c:\windows\system32\eprkmryhdglezstlw.exe
c:\windows\system32\Spool\prtprocs\w32x86\IQ3w7u3.dll

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Well lucky me for having one of the newest infections….

Below is the most recent ComboFix logfile…computer appears to be running fine at the moment…

ComboFix 10-06-17.01 - Steve 06/17/2010 16:45:03.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1437 [GMT -4:00]
Running from: g:\documents\Downloads\ABCD2.exe
Command switches used :: g:\documents\Downloads\CFScript.txt
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

FILE ::
"c:\windows\Gmege.bin"

file zipped: c:\windows\Kwekocu.dat
file zipped: c:\windows\system32\eprkmryhdglezstlw.exe
file zipped: c:\windows\system32\Spool\prtprocs\w32x86\AAAA7kU.dll
file zipped: c:\windows\system32\Spool\prtprocs\w32x86\IQ3w7u3.dll
file zipped: c:\windows\system32\Spool\prtprocs\w32x86\M7g31a.dll
file zipped: c:\windows\system32\Spool\prtprocs\w32x86\MYWSKUO.dll
file zipped: c:\windows\system32\Spool\prtprocs\w32x86\QG93a7.dll
file zipped: c:\windows\system32\Spool\prtprocs\w32x86\QGMYW7.dll
file zipped: c:\windows\system32\Spool\prtprocs\w32x86\SK5y5.dll
file zipped: c:\windows\system32\Spool\prtprocs\w32x86\WS317u3.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Gmege.bin
c:\windows\Kwekocu.dat
c:\windows\system32\eprkmryhdglezstlw.exe
c:\windows\system32\Spool\prtprocs\w32x86\AAAA7kU.dll
c:\windows\system32\Spool\prtprocs\w32x86\IQ3w7u3.dll
c:\windows\system32\Spool\prtprocs\w32x86\M7g31a.dll
c:\windows\system32\Spool\prtprocs\w32x86\MYWSKUO.dll
c:\windows\system32\Spool\prtprocs\w32x86\QG93a7.dll
c:\windows\system32\Spool\prtprocs\w32x86\QGMYW7.dll
c:\windows\system32\Spool\prtprocs\w32x86\SK5y5.dll
c:\windows\system32\Spool\prtprocs\w32x86\WS317u3.dll

.
((((((((((((((((((((((((( Files Created from 2010-05-17 to 2010-06-17 )))))))))))))))))))))))))))))))
.

2010-06-17 20:18 . 2010-05-21 18:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-06-17 20:17 . 2010-06-17 20:17 ——– d—–w- c:\program files\Microsoft Security Essentials
2010-06-17 19:34 . 2010-06-17 19:34 ——– d-sh–w- c:\windows\ftpcache
2010-06-17 19:33 . 2006-10-04 18:21 3072000 —ha-w- c:\documents and settings\Steve\Application Data\U3\temp\Launchpad Removal.exe
2010-06-17 14:04 . 2010-06-17 14:14 ——– d—–w- C:\Transfer
2010-06-17 04:00 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-17 04:00 . 2010-06-17 04:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-17 04:00 . 2010-06-17 04:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-17 04:00 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-17 02:13 . 2010-06-17 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Update
2010-06-17 02:09 . 2010-06-17 02:09 ——– d—–w- C:\spoolerlogs
2010-06-14 18:22 . 2010-06-14 18:22 ——– d—–w- c:\documents and settings\Steve\advfn
2010-05-27 20:51 . 2010-05-27 20:51 348160 —-a-w- c:\documents and settings\Steve\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-478953db-n\msvcr71.dll
2010-05-27 20:51 . 2010-05-27 20:51 503808 —-a-w- c:\documents and settings\Steve\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-478953db-n\msvcp71.dll
2010-05-27 20:51 . 2010-05-27 20:51 499712 —-a-w- c:\documents and settings\Steve\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-478953db-n\jmc.dll
2010-05-27 20:51 . 2010-05-27 20:51 ——– d—–w- c:\windows\Sun
2010-05-27 20:50 . 2010-05-27 20:50 410984 —-a-w- c:\windows\system32\deploytk.dll
2010-05-27 20:50 . 2010-05-27 20:50 ——– d—–w- c:\program files\Java
2010-05-27 20:50 . 2010-05-27 20:50 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-05-27 20:50 . 2010-05-27 20:50 152576 —-a-w- c:\documents and settings\Steve\Application Data\Sun\Java\jre1.6.0_14\lzma.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-17 19:33 . 2010-04-19 02:32 ——– d—–w- c:\documents and settings\Steve\Application Data\U3
2010-06-11 07:13 . 2010-04-10 19:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-07 13:01 . 2010-04-10 18:54 56275 —-a-w- c:\windows\system32\nvModes.dat
2010-06-06 22:56 . 2010-05-06 18:51 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-17 23:19 . 2010-04-10 21:30 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2010-05-12 15:29 . 2010-05-12 15:17 ——– d—–w- c:\documents and settings\Steve\Application Data\Apple Computer
2010-05-10 13:45 . 2010-05-10 13:45 ——– d—–w- c:\documents and settings\Steve\Application Data\DivX
2010-05-10 13:32 . 2010-05-10 13:32 ——– d—–w- c:\program files\Windows Media Connect 2
2010-05-07 13:40 . 2010-04-10 18:39 69624 —-a-w- c:\documents and settings\Steve\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-07 06:19 . 2010-04-10 19:56 ——– d—–w- c:\program files\Microsoft Works
2010-05-04 17:20 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-05-03 17:11 . 2010-05-03 16:58 ——– d—–w- c:\program files\QuickTime
2010-05-03 17:10 . 2010-05-03 17:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-05-03 17:02 . 2010-05-03 17:02 ——– d—–w- c:\program files\Common Files\Apple
2010-05-03 17:02 . 2010-05-03 17:02 ——– d—–w- c:\program files\Apple Software Update
2010-05-03 17:02 . 2010-05-03 17:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-05-02 05:22 . 2004-08-04 10:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-04 10:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-15 17:32 . 2010-04-15 17:32 7410688 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191319-191429.dll
2010-04-15 17:32 . 2010-04-15 17:32 7032320 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191222-191319.dll
2010-04-15 17:32 . 2010-04-15 17:32 2844160 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191714-19188.dll
2010-04-15 17:31 . 2010-04-15 17:31 6301696 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191127-191222.dll
2010-04-15 17:30 . 2010-04-15 17:30 5686272 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\19153-191714.dll
2010-04-15 17:29 . 2010-04-15 17:29 2776576 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191429-19153.dll
2010-04-15 17:28 . 2010-04-15 17:28 241512 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2010-04-15 17:28 . 2010-04-15 17:28 230752 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\patchw32.dll
2010-04-15 17:28 . 2010-04-15 17:28 956 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\rebase.cmd
2010-04-11 03:38 . 2010-04-11 03:38 4710 —-a-r- c:\documents and settings\Steve\Application Data\Microsoft\Installer\{DF6DA606-904D-4C18-823F-A4CFC3035E53}\ext.exe
2010-04-11 03:28 . 2010-04-11 03:28 1956656 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2010-04-10 19:10 . 2010-04-10 18:30 87263 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-04-10 18:52 . 2010-04-10 18:52 21425 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-04-10 18:52 . 2010-04-10 18:52 319488 —-a-w- c:\windows\system32\AegisI5Installer.exe
2010-04-10 18:42 . 2010-04-10 18:42 45056 —-a-r- c:\documents and settings\Steve\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe
2010-04-10 18:42 . 2010-04-10 18:42 10134 —-a-r- c:\documents and settings\Steve\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe
2010-04-10 18:28 . 2010-04-10 18:28 21640 —-a-w- c:\windows\system32\emptyregdb.dat
.

((((((((((((((((((((((((((((( SnapShot@2010-06-17_20.03.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-17 20:09 . 2010-06-17 20:09 16384 c:\windows\Temp\Perflib_Perfdata_2bc.dat
+ 2010-06-17 20:17 . 2010-06-17 20:17 272384 c:\windows\Installer\6773a.msi
+ 2010-06-17 20:17 . 2010-06-17 20:17 254976 c:\windows\Installer\67734.msi
+ 2010-06-17 20:17 . 2010-06-17 20:17 301056 c:\windows\Installer\6772e.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" [2008-10-07 95744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-01-25 159744]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-11 624248]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 303104]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"nwiz"="nwiz.exe" [2007-04-28 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]
"NVHotkey"="nvHotkey.dll" [2007-04-28 67584]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-05-27 148888]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]

c:\documents and settings\Steve\Start Menu\Programs\Startup\
eFax 4.4.lnk - c:\program files\eFax Messenger 4.4\J2GTray.exe [2008-10-7 656896]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-11 2150400]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2010-4-10 50688]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [11/2/2006 12:32 PM 97536]
R3 HPPLSBULK;HPPLSBULK;c:\windows\system32\drivers\hpplsbulk.sys [4/11/2010 12:31 AM 9344]

— Other Services/Drivers In Memory —

*NewlyCreated* - MPFILTER
*NewlyCreated* - MSMPSVC
.
Contents of the 'Scheduled Tasks' folder

2010-06-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 22:02]

2010-06-17 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-04-11 02:18]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
uInternet Settings,ProxyServer = http=127.0.0.1:1055
uInternet Settings,ProxyOverride =
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

AddRemove-eprkmryhdglezstlw - c:\windows\system32\eprkmryhdglezstlw.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-17 16:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-06-17 16:50:19
ComboFix-quarantined-files.txt 2010-06-17 20:50
ComboFix2.txt 2010-06-17 20:03

Pre-Run: 72,512,765,952 bytes free
Post-Run: 72,504,725,504 bytes free

- - End Of File - - CF720B40F4076A261A4931D7D9B92023
Upload was successful
That's looking better :thumbup:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
I think it was installed okay….but when installing I got 2 error messages: 1. VbAccelerator SGrid II Control - Run-time error '0' 2. Malwarebytes' Anti-Malware - Run-time error '440' - Automation error I clicked "ok" on both occasions and it appeared to load up just fine. After running the program, 4 infections were found…I removed them and below is the logfile…everything appears to be still running fine at the moment… Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4210 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 6/17/2010 5:11:25 PM mbam-log-2010-06-17 (17-11-25).txt Scan type: Quick scan Objects scanned: 121090 Time elapsed: 4 minute(s), 23 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

remove these leftover files and folders if listed:
These might all be on your G:
g:\documents\Downloads\ABCD2.exe
ComboFix
QooBox
combofix.txt
combofix-quarantine-files.txt

To be on the safe side, I would also change all my passwords.



Here's my usual all clean post

Log looks good :D


This infection appears to have been cleaned, but as the malware could be configured to run any program a remote attacker requires, it's impossible to be 100% sure that any machine is clean.


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.

  • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • WOT Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop
WOT has an addon available for both Firefox, IE and chrome.

Only run one Anti-Virus and Firewall program.


I would suggest you read How to Prevent Malware:
THANK YOU sooooo much! Now just tell me how to donate! This is an awesome site and I have recommended it to numerous people. You guys are top notch! Thanks again…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI