This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Audio Virus Plays Random Advertisements

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Please do the following:

(this command assumes you extracted the Bootkit Remover to your desktop - let me know if you extracted it somewhere else.)

Click Start > Run and copy and paste the below into the Run box and click OK.

"%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0

Now reboot your PC

and run the ComboFix script from my previous post.
Here is the log from the combo fix ComboFix 10-06-27.06 - Optimus 06/28/2010 13:47:33.4.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2663 [GMT -7:00] Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe Command switches used :: c:\documents and settings\Optimus\Desktop\CFScript.txt file zipped: c:\system volume information\Microsoft\services.exe file zipped: c:\system volume information\Microsoft\smss.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\system volume information\Microsoft\services.exe c:\system volume information\Microsoft\smss.exe . ((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-28 ))))))))))))))))))))))))))))))) . 2010-06-28 17:14 . 2010-06-28 17:17 ——– d—–w- c:\documents and settings\Optimus\Application Data\PeaZip 2010-06-28 17:13 . 2010-06-28 17:13 ——– d—–w- c:\program files\PeaZip 2010-06-27 18:25 . 2010-06-27 18:25 ——– d—–w- C:\_OTL 2010-06-27 02:00 . 2010-06-27 02:00 ——– d—–w- c:\program files\Common Files\Java 2010-06-27 01:59 . 2010-06-27 01:59 ——– d—–w- c:\program files\Sun 2010-06-27 01:59 . 2010-06-27 01:59 411368 —-a-w- c:\windows\system32\deployJava1.dll 2010-06-23 22:37 . 2010-06-23 22:37 ——– d—–w- c:\program files\Windows Installer Clean Up 2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\documents and settings\Optimus\Application Data\Malwarebytes 2010-06-23 08:23 . 2010-04-29 22:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-06-23 08:23 . 2010-06-23 08:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-06-23 08:23 . 2010-04-29 22:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-06-22 23:58 . 2008-10-10 11:52 452440 —-a-w- c:\windows\system32\d3dx10_40.dll 2010-06-22 23:58 . 2008-10-10 11:52 2036576 —-a-w- c:\windows\system32\D3DCompiler_40.dll 2010-06-22 23:58 . 2008-10-10 11:52 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll 2010-06-22 23:58 . 2010-06-22 23:58 ——– d—–w- c:\windows\Logs 2010-06-22 23:58 . 2010-06-22 23:59 ——– d—–w- c:\program files\Heroes of Newerth . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-06-28 20:54 . 2006-07-27 20:12 ——– d—–w- c:\program files\Steam 2010-06-27 18:16 . 2010-06-27 18:16 503808 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2af84d0c-n\msvcp71.dll 2010-06-27 18:16 . 2010-06-27 18:16 499712 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2af84d0c-n\jmc.dll 2010-06-27 18:16 . 2010-06-27 18:16 348160 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2af84d0c-n\msvcr71.dll 2010-06-27 18:16 . 2010-06-27 18:16 61440 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-709cfa19-n\decora-sse.dll 2010-06-27 18:16 . 2010-06-27 18:16 12800 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-709cfa19-n\decora-d3d.dll 2010-06-27 01:59 . 2006-06-26 23:54 ——– d—–w- c:\program files\Java 2010-06-27 01:35 . 2006-09-06 03:28 ——– d—–w- c:\program files\Common Files\Adobe 2010-06-27 01:06 . 2006-06-24 21:44 ——– d—–w- c:\program files\Warcraft III 2010-06-25 00:22 . 2007-10-26 22:00 ——– d—–w- c:\program files\Common Files\Symantec Shared 2010-06-23 22:37 . 2010-06-23 22:37 3584 —-a-r- c:\documents and settings\Optimus\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe 2010-06-23 22:36 . 2009-12-16 22:48 ——– d—–w- c:\program files\MSECACHE 2010-06-23 22:23 . 2007-06-20 04:34 ——– d—–w- c:\program files\Google 2010-06-23 21:56 . 2006-06-24 21:13 ——– d—–w- c:\program files\Common Files\InstallShield 2010-06-23 21:56 . 2006-06-24 21:21 ——– d–h–w- c:\program files\InstallShield Installation Information 2010-06-23 08:16 . 2009-08-26 04:53 ——– d—–w- c:\program files\LimeWire 2010-06-23 08:12 . 2006-11-08 05:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2010-06-23 08:00 . 2009-05-15 00:12 ——– d—–w- c:\program files\CCleaner 2010-06-23 01:57 . 2006-06-25 21:38 ——– d—–w- c:\program files\WC3Banlist 2010-06-23 01:55 . 2006-11-18 22:57 ——– d—–w- c:\program files\Electronic Arts 2010-06-17 06:57 . 2006-06-25 16:34 ——– d—–w- c:\program files\World of Warcraft 2010-06-09 08:15 . 2007-09-10 06:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-05-08 03:49 . 2010-05-08 03:49 ——– d—–w- c:\documents and settings\Optimus\Application Data\SPORE 2010-05-08 03:49 . 2006-08-14 21:19 107888 —-a-w- c:\windows\system32\CmdLineExt.dll 2010-05-02 05:22 . 2004-08-04 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys 2010-04-20 05:30 . 2004-08-04 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll 2010-04-16 16:09 . 2004-08-04 12:00 667136 —-a-w- c:\windows\system32\wininet.dll 2010-04-16 16:09 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll 2010-04-14 15:57 . 2009-11-09 19:46 79488 —-a-w- c:\documents and settings\Optimus\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll . ((((((((((((((((((((((((((((( SnapShot@2010-06-26_18.22.44 ))))))))))))))))))))))))))))))))))))))))) . + 2010-06-28 20:54 . 2010-06-28 20:54 16384 c:\windows\temp\Perflib_Perfdata_6cc.dat + 2010-06-28 01:36 . 2010-06-28 01:36 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012010062720100628\index.dat + 2006-06-24 21:09 . 2010-06-28 20:36 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat - 2006-06-24 21:09 . 2010-06-26 18:17 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2010-06-27 01:59 . 2010-06-27 01:59 153376 c:\windows\system32\javaws.exe + 2010-06-27 01:59 . 2010-06-27 01:59 145184 c:\windows\system32\javaw.exe + 2010-06-27 01:59 . 2010-06-27 01:59 145184 c:\windows\system32\java.exe + 2006-06-24 21:09 . 2010-06-28 20:36 163840 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2010-06-27 02:00 . 2010-06-27 02:00 180224 c:\windows\Installer\f191.msi + 2010-06-27 01:59 . 2010-06-27 01:59 386048 c:\windows\Installer\f18c.msi + 2010-06-27 01:59 . 2010-06-27 01:59 576000 c:\windows\Installer\f187.msi + 2010-06-27 01:58 . 2010-06-27 01:58 438784 c:\windows\Installer\f183.msi + 2010-06-27 01:36 . 2010-06-27 01:36 3940352 c:\windows\Installer\dd2f.msi + 2006-06-29 03:07 . 2010-05-28 19:37 32472008 c:\windows\system32\MRT.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files\Steam\Steam.exe" [2010-05-08 1238352] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2009-05-15 1103216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2009-01-13 18084864] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "HostManager"="c:\program files\Common Files\AOL\1151188401\ee\AOLSoftware.exe" [2006-05-10 50760] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-9-24 282624] HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] [BU] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Common Files\\AOL\\1151188401\\ee\\aolsoftware.exe"= "c:\\Program Files\\Common Files\\AOL\\1151188401\\ee\\aim6.exe"= "c:\\Program Files\\World of Warcraft\\WoW-1.11.0-enUS-downloader.exe"= "c:\\Program Files\\Steam\\SteamApps\\[removed]\\team fortress classic\\hl.exe"= "c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.2.6108-to-2.0.2.6144-enUS-downloader.exe"= "c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"= "c:\\Program Files\\Warcraft III\\war3.exe"= "c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.2.6144-to-2.0.2.6178-enUS-downloader.exe"= "c:\\Program Files\\Burning Crusade Closed Beta\\WoW-2.0.3.6282-to-2.0.3.6299-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.6.6337-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"= "c:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"= "c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"= "c:\\Program Files\\Steam\\SteamApps\\psycho_rage\\counter-strike source\\hl2.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Steam\\Steam.exe"= "c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"= "c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Steam\\SteamApps\\psycho_rage\\team fortress 2\\hl2.exe"= "c:\\Program Files\\Total War\\Medieval - Total War\\Medieval_TW.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Steam\\SteamApps\\common\\left 4 dead demo\\left4dead.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\World of Warcraft\\Launcher.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"= "c:\\Program Files\\Burning Crusade Closed Beta\\BackgroundDownloader.exe"= "c:\\Program Files\\Steam\\SteamApps\\common\\america's army 3\\Binaries\\AA3Game.exe"= "c:\\Program Files\\Heroes of Newerth\\hon.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 "6112:TCP"= 6112:TCP:Blizzard Downloader "6881:TCP"= 6881:TCP:Blizzard Downloader R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/8/2009 8:12 PM 24652] . Contents of the 'Scheduled Tasks' folder 2010-05-29 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:34] 2010-06-25 c:\windows\Tasks\Norton Security Scan for Optimus.job - c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.7.0.52\Nss.exe [2009-12-12 14:23] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://lioncam1.lmu.edu/activex/AMC.cab FF - ProfilePath - c:\documents and settings\Optimus\Application Data\Mozilla\Firefox\Profiles\5oxadeo9.default\ FF - prefs.js: browser.search.selectedEngine - AIM Search FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir;=2706&query;= FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); . - - - - ORPHANS REMOVED - - - - BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file) ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync] "Name"="ActiveSync" "DisplayName"="Microsoft ActiveSync" "Param1"="ActiveSync" "Type"="wellknown" "Order"=dword:00000000 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings] "Name"="IESettings" "Type"="IESettings" "Order"=dword:00000003 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles] "Name"="MediaFiles" "Type"="MediaFiles" "Order"=dword:00000002 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW] "Name"="NPW" "Param1"="NPW" "Type"="wellknown" "Order"=dword:00000001 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:26,fc,c1,ca,41,a1,9b,41,7b,e3,87,70,66,de,ee,2c,f2,f2,7c,49,5c,5f,54, 16,04,c6,27,74,f4,bc,e6,df,83,9d,a4,79,f6,2a,21,f3,9a,8a,b7,a0,b4,8a,78,32,\ "??"=hex:f0,21,15,d4,32,f9,f5,39,34,a4,1c,86,43,ce,d9,df [HKEY_USERS\S-1-5-21-299502267-2139871995-839522115-1004\Software\SecuROM\License information*] "datasecu"=hex:8b,f7,b7,24,e0,f4,3b,7c,50,28,8c,77,aa,e3,23,9b,fd,4c,23,5b,36, 7a,c4,21,4a,55,8a,2e,37,93,88,0f,f5,e6,71,fd,7d,79,fb,ac,2d,c6,7f,81,1d,00,\ "rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44 . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(764) c:\windows\system32\COMRes.dll . ———————— Other Running Processes ———————— . c:\windows\system32\nvsvc32.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\HPZipm12.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\PnkBstrB.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\wscntfy.exe c:\windows\RTHDCPL.EXE c:\windows\system32\RUNDLL32.EXE c:\windows\system32\msiexec.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2010-06-28 13:59:23 - machine was rebooted ComboFix-quarantined-files.txt 2010-06-28 20:59 ComboFix2.txt 2010-06-28 02:29 ComboFix3.txt 2010-06-26 18:23 ComboFix4.txt 2010-06-25 01:38 Pre-Run: 28,094,726,144 bytes free Post-Run: 28,136,382,464 bytes free - - End Of File - - D317376D9D22F091DD97FA8D9F86610A
Hi,

That looks like it worked, but the files didn't upload automatically, so we need to do it manually.

Please do the following;

Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/Audio_Virus_Plays_Random_Advertisements_t112790.html

Click the Browse button and navigate to C:\Qoobox\Quarantine

There should be a zip file there called [4]-Submit_****-**-**_**.**.**.zip ( the * denotes Date and Time stamp - yours will be close to this - 06/28/2010 13:47:33 )
Select this file and click Open
In the Largest box please put
File Requested By CatByteFailed Collect::

Finally click SendFile

Please return here and let me know when that file has been uploaded.



NEXT


Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c "mbr -t" >Log.txt&Log.txt&del Log.txt

A Notepad file will open. Post the contents of Log.txt in your next reply.



NEXT


Re-run Bootkit remover to get a new status log.

Double click Remover.exe to run it.

It will show a Black screen with some data on it

Right click on the screen and select > Select All

Press Control+C

Now open a notepad and press Control+V

Post the resultant log here please


NEXT


Please run a fresh OTL log and post it here, also describe how your computer is running now and if there are any outstanding issues.
Hi,

I have not seen any of the symptoms the computer was experiencing earlier, it seems to have worked!!! Thank you very much. I sent that file you asked for. Here are the three logs you requested. Thank you for all your help, I really appreciate it along with all your patience. Any specific advice on how to avoid this from happening again?


Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK


Bootkit Remover version 1.0.0.1
© 2009 eSage Lab
www.esagelab.com

\\.\C: -> \\.\PhysicalDrive0
MD5: 6def5ffcbcdbdb4082f1015625e597bd

Size Device Name MBR Status
——————————————–
153 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)


Press any key to quit…


OTL logfile created on: 6/28/2010 3:53:05 PM - Run 4
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Optimus\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 84.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 153.38 Gb Total Space | 26.24 Gb Free Space | 17.11% Space Free | Partition Type: NTFS
Drive D: | 3.86 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MARIO
Current User Name: Optimus
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Optimus\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\AOL\1151188401\ee\aolsoftware.exe (America Online, Inc.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Optimus\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (getPlus® Helper) getPlus® – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (catchme) – File not found
DRV - (PnkBstrK) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nvata) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (prohlp02) – C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) – C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (sfhlp01) – C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "AIM Search"
FF - prefs.js..browser.startup.homepage: "http://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir;=2706&query;="

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/24 00:48:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/26 18:59:41 | 000,000,000 | —D | M]

[2009/11/15 19:40:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Mozilla\Extensions
[2009/08/12 00:04:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Mozilla\Extensions\[removed]
[2006/09/09 10:28:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Mozilla\Firefox\Profiles\5oxadeo9.default\extensions
[2010/06/28 15:05:03 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/26 18:59:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/06/26 18:59:30 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/06/28 13:54:33 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151188401\ee\aolsoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\PROGRA~1\MI3AA1~1\wcescomm.exe File not found
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe File not found
O4 - Startup: C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://lioncam1.lmu.edu/activex/AMC.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/06/24 14:06:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/08/05 10:02:19 | 000,398,600 | R— | M] (Electronic Arts Inc.) - D:\Autorun.exe – [ UDF ]
O32 - AutoRun File - [2008/08/05 09:23:19 | 000,000,043 | R— | M] () - D:\Autorun.inf – [ UDF ]
O32 - AutoRun File - [2008/08/05 09:52:02 | 000,000,000 | R–D | M] - D:\autorun – [ UDF ]
O33 - MountPoints2\{5d913196-5aa5-11de-853c-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{5d913196-5aa5-11de-853c-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{5d913196-5aa5-11de-853c-806d6172696f}\Shell\AutoRun\command - "" = D:\Autorun.exe – [2008/08/05 10:02:19 | 000,398,600 | R— | M] (Electronic Arts Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/06/28 15:50:59 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Optimus\Desktop\.ptmp901596
[2010/06/28 13:52:42 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/06/28 13:45:37 | 000,000,000 | —D | C] – C:\ComboFix
[2010/06/28 10:14:31 | 000,499,712 | —- | C] (eSage Lab) – C:\Documents and Settings\Optimus\Desktop\remover.exe
[2010/06/28 10:14:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\Application Data\PeaZip
[2010/06/28 10:13:47 | 000,000,000 | —D | C] – C:\Program Files\PeaZip
[2010/06/27 11:25:36 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/26 19:00:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/06/26 18:59:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/06/26 18:59:46 | 000,000,000 | —D | C] – C:\Program Files\Sun
[2010/06/24 18:18:15 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/06/24 18:16:54 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/06/24 18:16:54 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/06/24 18:16:54 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/06/24 18:16:54 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/06/24 18:09:15 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/06/24 18:08:13 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/23 15:37:01 | 000,000,000 | —D | C] – C:\Program Files\Windows Installer Clean Up
[2010/06/23 15:06:28 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Optimus\Recent
[2010/06/23 01:23:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\Application Data\Malwarebytes
[2010/06/23 01:23:38 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/23 01:23:37 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/23 01:23:37 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/23 01:23:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/22 16:59:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\My Documents\Heroes of Newerth
[2010/06/22 16:58:35 | 000,000,000 | —D | C] – C:\WINDOWS\Logs
[2010/06/22 16:58:21 | 000,000,000 | —D | C] – C:\Program Files\Heroes of Newerth
[2010/05/08 18:34:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\WINDOWS
[2010/05/08 18:34:37 | 000,000,000 | —D | C] – C:\MAXIS
[2010/05/07 20:49:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\My Documents\My Spore Creations
[2010/05/07 20:49:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Optimus\Application Data\SPORE

========== Files - Modified Within 90 Days ==========

[2010/06/28 13:54:50 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/06/28 13:54:41 | 000,194,449 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/06/28 13:54:38 | 000,012,540 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/28 13:54:33 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/06/28 13:54:11 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/28 13:54:10 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/28 13:53:11 | 009,175,040 | -H– | M] () – C:\Documents and Settings\Optimus\NTUSER.DAT
[2010/06/28 13:53:11 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Optimus\ntuser.ini
[2010/06/28 13:34:08 | 000,478,504 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\bootkit_remover.rar
[2010/06/28 10:13:49 | 000,000,606 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\PeaZip.lnk
[2010/06/27 19:07:35 | 000,000,925 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Shortcut to ComboFix.exe.lnk
[2010/06/27 01:02:26 | 000,013,044 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\windows-volume-control.png
[2010/06/27 00:59:27 | 000,001,594 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\ddd
[2010/06/27 00:57:42 | 000,132,096 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\RootRepeal(2).exe
[2010/06/26 18:41:33 | 080,398,104 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\jdk-6u20-windows-i586.exe
[2010/06/26 18:35:51 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/06/24 18:18:21 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/06/24 18:14:45 | 000,000,666 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Shortcut to ComboFix.lnk
[2010/06/24 18:10:00 | 003,719,852 | R— | M] () – C:\Documents and Settings\Optimus\Desktop\ComboFix.exe
[2010/06/24 18:03:52 | 000,000,562 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Optimus.job
[2010/06/24 11:05:45 | 000,001,464 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Roorepealscan
[2010/06/23 15:46:17 | 000,012,540 | —- | M] () – C:\WINDOWS\System32\wpa.bak
[2010/06/23 15:29:34 | 000,000,477 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/23 15:29:34 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/06/22 16:59:07 | 000,001,606 | —- | M] () – C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Quick Launch\Heroes of Newerth.lnk
[2010/06/22 16:59:07 | 000,001,588 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Heroes of Newerth.lnk
[2010/06/19 15:43:26 | 000,000,751 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2010/06/09 11:07:34 | 000,169,896 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/28 22:52:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/07 20:49:28 | 000,107,888 | —- | M] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2010/05/06 09:25:22 | 000,002,515 | —- | M] () – C:\Documents and Settings\Optimus\Desktop\Microsoft Office Word 2007.lnk
[2010/05/05 22:08:29 | 000,013,688 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Sociology 100 Study Guide.docx
[2010/05/03 22:11:12 | 000,015,417 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Philosophy Study Guide.docx
[2010/05/03 11:03:34 | 000,013,080 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou58.docx
[2010/05/02 19:06:06 | 000,382,347 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\I speak directly to the people.docx
[2010/04/29 21:20:00 | 000,061,569 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.2FINAL.docx
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/29 14:17:50 | 000,946,286 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Drive for Muscularity, Body Image, Gym.pptx
[2010/04/28 23:03:04 | 000,012,728 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou57.docx
[2010/04/26 22:05:01 | 000,026,333 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\SOCFINALPAPER.docx
[2010/04/26 15:58:12 | 000,256,512 | —- | M] () – C:\WINDOWS\PEV.exe
[2010/04/25 22:06:46 | 000,025,682 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\In 1954 the U.docx
[2010/04/22 23:56:35 | 000,014,965 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Sociology Notes.docx
[2010/04/21 20:13:10 | 000,025,151 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.1.docx
[2010/04/21 19:39:41 | 000,013,766 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou56.docx
[2010/04/20 15:38:26 | 000,024,428 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Introduction.docx
[2010/04/19 23:07:18 | 000,017,722 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Walking through the grocery store.docx
[2010/04/18 19:21:41 | 000,014,609 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\This week we had to read about post modernism and Jean Baudrillard.docx
[2010/04/14 19:23:39 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Optimus\My Documents\~$lking through the grocery store.docx
[2010/04/13 08:33:11 | 000,014,705 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey (1).docx
[2010/04/12 21:45:45 | 000,014,645 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey.docx
[2010/04/12 21:39:40 | 002,120,876 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\SINGH#1.pdf
[2010/04/12 19:30:58 | 000,013,639 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Coverletter (1).docx
[2010/04/12 19:23:04 | 000,039,936 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Resume (1).doc
[2010/04/08 23:05:54 | 000,877,247 | —- | M] () – C:\Documents and Settings\Optimus\My Documents\DMSCALE.pdf

========== Files Created - No Company Name ==========

[2010/06/28 13:34:07 | 000,478,504 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\bootkit_remover.rar
[2010/06/28 10:13:49 | 000,000,606 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\PeaZip.lnk
[2010/06/27 19:07:35 | 000,000,925 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\Shortcut to ComboFix.exe.lnk
[2010/06/27 17:51:21 | 000,000,272 | —- | C] () – C:\Documents and Settings\Optimus\mbr.log
[2010/06/27 17:51:21 | 000,000,272 | —- | C] () – C:\Documents and Settings\Optimus\Log.txt
[2010/06/27 01:02:25 | 000,013,044 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\windows-volume-control.png
[2010/06/27 00:59:27 | 000,001,594 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\ddd
[2010/06/27 00:57:41 | 000,132,096 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\RootRepeal(2).exe
[2010/06/26 18:37:47 | 080,398,104 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\jdk-6u20-windows-i586.exe
[2010/06/26 18:35:51 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/06/24 18:18:21 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/06/24 18:18:17 | 000,260,272 | —- | C] () – C:\cmldr
[2010/06/24 18:16:54 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/06/24 18:16:54 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/06/24 18:16:54 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/06/24 18:16:54 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/06/24 18:16:54 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/06/24 18:14:45 | 000,000,666 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\Shortcut to ComboFix.lnk
[2010/06/24 18:10:00 | 003,719,852 | R— | C] () – C:\Documents and Settings\Optimus\Desktop\ComboFix.exe
[2010/06/24 11:05:45 | 000,001,464 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\Roorepealscan
[2010/06/23 15:30:08 | 000,256,000 | —- | C] () – C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\PowerReg Scheduler.exe
[2010/06/23 15:30:08 | 000,000,876 | —- | C] () – C:\Documents and Settings\Optimus\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk
[2010/06/22 16:59:07 | 000,001,606 | —- | C] () – C:\Documents and Settings\Optimus\Application Data\Microsoft\Internet Explorer\Quick Launch\Heroes of Newerth.lnk
[2010/06/22 16:59:06 | 000,001,588 | —- | C] () – C:\Documents and Settings\Optimus\Desktop\Heroes of Newerth.lnk
[2010/05/08 18:34:37 | 000,136,448 | —- | C] () – C:\WINDOWS\RMTOOLS.DLL
[2010/05/03 11:37:49 | 000,015,417 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Philosophy Study Guide.docx
[2010/05/02 19:36:54 | 000,013,080 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou58.docx
[2010/05/01 22:41:29 | 000,013,688 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Sociology 100 Study Guide.docx
[2010/04/29 12:24:01 | 000,946,286 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Drive for Muscularity, Body Image, Gym.pptx
[2010/04/28 22:09:34 | 000,382,347 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\I speak directly to the people.docx
[2010/04/26 21:59:41 | 000,012,728 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou57.docx
[2010/04/25 22:39:26 | 000,026,333 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\SOCFINALPAPER.docx
[2010/04/22 23:56:35 | 000,014,965 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Sociology Notes.docx
[2010/04/21 22:42:25 | 000,061,569 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.2FINAL.docx
[2010/04/21 20:13:10 | 000,025,151 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Introduction1.1.docx
[2010/04/21 16:36:03 | 000,013,766 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Sou56.docx
[2010/04/20 12:19:27 | 000,025,682 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\In 1954 the U.docx
[2010/04/18 19:21:40 | 000,014,609 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\This week we had to read about post modernism and Jean Baudrillard.docx
[2010/04/14 19:23:39 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Optimus\My Documents\~$lking through the grocery store.docx
[2010/04/13 08:33:11 | 000,014,705 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey (1).docx
[2010/04/12 22:11:51 | 000,017,722 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Walking through the grocery store.docx
[2010/04/12 21:39:40 | 002,120,876 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\SINGH#1.pdf
[2010/04/12 19:24:07 | 000,013,639 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Coverletter (1).docx
[2010/04/12 19:23:04 | 000,039,936 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Mario Souza Resume (1).doc
[2010/04/09 21:19:03 | 000,014,645 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\Performance Enhancing Drugs Survey.docx
[2010/04/08 23:05:54 | 000,877,247 | —- | C] () – C:\Documents and Settings\Optimus\My Documents\DMSCALE.pdf
[2009/06/10 08:29:34 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009/06/10 08:29:34 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/06/10 08:29:34 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2009/06/10 08:29:32 | 001,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/11/18 13:44:40 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/12/18 19:17:38 | 000,137,544 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/05/27 21:49:01 | 000,000,047 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/03/31 16:46:15 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2006/09/13 14:21:44 | 000,000,173 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/08/31 16:52:19 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/08/14 14:20:26 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/06/24 15:31:19 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2006/06/24 14:27:14 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2006/06/24 14:13:17 | 000,000,269 | R— | C] () – C:\WINDOWS\System32\raidmgmt.ini
[2006/06/24 14:12:58 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/06/24 14:12:55 | 000,005,309 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/06/24 14:12:53 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006/06/01 17:22:00 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/06/01 17:22:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2009/09/08 20:12:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/05/12 09:40:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/17 19:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2006/06/24 15:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\acccore
[2009/09/08 17:35:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Aim
[2007/09/15 09:35:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\BitTorrent
[2007/04/07 18:32:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\GetRightToGo
[2007/09/12 21:27:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Leadertech
[2006/11/19 10:12:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\My Battle for Middle-earth™ II Files
[2010/06/28 10:17:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\PeaZip
[2009/12/24 18:49:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\runic games
[2006/10/11 21:50:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Simple Star
[2006/10/11 22:08:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Snapfish
[2010/05/07 20:49:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\SPORE
[2007/04/07 19:05:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Turbine
[2007/01/27 02:08:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Optimus\Application Data\Viewpoint

========== Purity Check ==========


< End of report >
Hi

yes, that seems to have fixed it, just some strays to tidy up now, after that we can clean up our tools

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
    O33 - MountPoints2\{5d913196-5aa5-11de-853c-806d6172696f}\Shell - "" = AutoRun
    O33 - MountPoints2\{5d913196-5aa5-11de-853c-806d6172696f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{5d913196-5aa5-11de-853c-806d6172696f}\Shell\AutoRun\command - "" = D:\Autorun.exe – [2008/08/05 10:02:19 | 000,398,600 | R— | M] (Electronic Arts Inc.)
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log
All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5d913196-5aa5-11de-853c-806d6172696f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5d913196-5aa5-11de-853c-806d6172696f}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5d913196-5aa5-11de-853c-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5d913196-5aa5-11de-853c-806d6172696f}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5d913196-5aa5-11de-853c-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5d913196-5aa5-11de-853c-806d6172696f}\ not found. File move failed. D:\Autorun.exe scheduled to be moved on reboot. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYFLASH] User: All Users User: Default User User: LocalService User: NetworkService User: Optimus ->Flash cache emptied: 7190 bytes Total Flash Files Cleaned = 0.00 mb
Hi


Just the cleanup to do now.

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.



    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Thank you for all your help! My computer is running faster than even before I got the virus. I appreciate all your patience when it came to my computer. Take care!
Good, I'm glad we were able to resolve it in the end.Sorry I missed it to begin with. This new infection is cropping up more and more now, do you have any idea where it came from?
I couldn't tell you exactly, as it started when I turned on my computer in the morning. I feel it may have infected my computer when I was searching how to find out what kind of motherboard I have and what video cards are compatible with it, some of the websites seemed sketchy but I can't recall which ones I went to. Maybe online websites that offer free movies? I visit those from time to time, and visited one close to the time from when I got infected. I will keep trying to remember and will be sure to post it or e-mail you if i remember exactly where I went leading up to the infection. Thanks again for all your help
You are welcome stay safe :wave: ~CB (I'll mark this thread as resolved - send me a PM if you recall the source of this infection - would like to get my hands on the dropper so it can be examined)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI