This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer reinfected- can't access internet

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Mowman,
Thank you for your latest directions. I had run kaspersky, awaiting your reply and it came back clean. I am posting the Combofix report. I still could not post to Whatthetech using Foxfire, even though I reloaded the page several times.
-Jcatsmom

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, September 19, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, September 19, 2010 09:22:57
Records in database: 4223502
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Objects scanned: 57635
Threats found: 0
Infected objects found: 0
Suspicious objects found: 0
Scan duration: 01:22:40

No threats found. Scanned area is clean.

Selected area has been scanned.

ComboFix 10-09-17.04 - Dee 09/19/2010 12:59:13.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1616 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dee\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((( Files Created from 2010-08-19 to 2010-09-19 )))))))))))))))))))))))))))))))
.

2010-09-18 01:50 . 2010-09-18 01:50 ——– d—–w- c:\program files\ESET
2010-09-15 18:55 . 2010-09-15 18:55 ——– d—–w- C:\_OTL
2010-09-12 21:17 . 2010-09-12 21:17 444 —-a-w- c:\windows\system32\d3d8caps.dat
2010-09-04 04:42 . 2010-09-04 04:42 ——– d—–w- c:\program files\Common Files\Java
2010-09-04 04:40 . 2010-09-04 04:40 79488 —-a-w- c:\documents and settings\Dee\Application Data\Sun\Java\jre1.6.0_21\gtapi.dll
2010-09-04 04:40 . 2010-09-04 04:40 152576 —-a-w- c:\documents and settings\Dee\Application Data\Sun\Java\jre1.6.0_21\lzma.dll
2010-09-03 18:51 . 2010-09-03 18:51 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2010-09-03 02:14 . 2010-09-03 02:14 ——– d—–w- c:\windows\system32\scripting
2010-09-03 02:14 . 2010-09-03 02:14 ——– d—–w- c:\windows\system32\en
2010-09-03 02:14 . 2010-09-03 02:14 ——– d—–w- c:\windows\system32\bits
2010-09-03 02:14 . 2010-09-03 02:14 ——– d—–w- c:\windows\l2schemas
2010-09-03 02:06 . 2010-09-03 02:06 ——– d—–w- c:\windows\EHome
2010-09-03 01:51 . 2010-09-03 23:24 ——– d—–w- c:\windows\ie8updates
2010-09-02 23:23 . 2010-09-02 23:23 503808 —-a-w- c:\documents and settings\Dee\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e937b63-n\msvcp71.dll
2010-09-02 23:23 . 2010-09-02 23:23 499712 —-a-w- c:\documents and settings\Dee\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e937b63-n\jmc.dll
2010-09-02 23:23 . 2010-09-02 23:23 348160 —-a-w- c:\documents and settings\Dee\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e937b63-n\msvcr71.dll
2010-09-02 23:23 . 2010-09-02 23:23 61440 —-a-w- c:\documents and settings\Dee\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5eec6c57-n\decora-sse.dll
2010-09-02 23:23 . 2010-09-02 23:23 12800 —-a-w- c:\documents and settings\Dee\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5eec6c57-n\decora-d3d.dll
2010-09-02 23:22 . 2010-09-04 04:41 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-31 03:11 . 2010-08-31 03:11 388096 —-a-r- c:\documents and settings\Dee\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-30 13:05 . 2010-08-30 13:05 ——– d—–w- c:\program files\Trend Micro
2010-08-30 12:24 . 2010-08-30 12:24 ——– d—–w- c:\program files\HD Tune
2010-08-30 12:21 . 2010-06-24 12:22 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2010-08-30 12:21 . 2010-06-24 12:21 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-30 12:21 . 2010-06-24 12:21 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2010-08-30 04:12 . 2010-08-30 04:12 ——– d—–w- C:\found.001
2010-08-30 02:22 . 2010-08-30 02:22 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-08-30 02:21 . 2010-08-30 02:21 ——– d-sh–w- c:\documents and settings\Dee\PrivacIE
2010-08-29 15:48 . 2010-08-29 15:48 ——– d-sh–w- c:\documents and settings\Guest\IECompatCache
2010-08-29 15:47 . 2010-08-29 15:47 ——– d-sh–w- c:\documents and settings\Guest\PrivacIE
2010-08-29 03:02 . 2010-08-29 03:02 ——– d-sh–w- c:\documents and settings\Dee\IECompatCache
2010-08-29 02:54 . 2010-08-29 02:54 ——– d-sh–w- c:\documents and settings\Dee\IETldCache
2010-08-29 02:48 . 2010-08-29 02:48 ——– d-sh–w- c:\documents and settings\Guest\IETldCache
2010-08-29 02:33 . 2010-08-29 02:35 ——– dc-h–w- c:\windows\ie8
2010-08-28 17:41 . 2010-08-28 17:41 ——– d—–w- c:\documents and settings\Dee\Application Data\Malwarebytes
2010-08-28 17:41 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-28 17:41 . 2010-08-28 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-28 17:41 . 2010-08-28 17:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-28 17:41 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-19 13:34 . 2010-01-08 14:46 ——– d—–w- c:\program files\McAfee
2010-09-16 01:35 . 2010-07-28 23:16 452104 —-a-w- c:\documents and settings\Dee\Application Data\Real\Update\setup3.12\setup.exe
2010-09-06 21:57 . 2005-05-08 18:17 58080 -c–a-w- c:\documents and settings\Dee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-03 16:15 . 2009-11-24 00:21 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2010-09-03 02:16 . 2004-08-10 18:13 77423 —-a-w- c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
2010-09-03 01:55 . 2009-03-20 15:12 ——– d—–w- c:\program files\Microsoft Silverlight
2010-08-17 13:17 . 2004-08-04 10:00 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-05 16:24 . 2010-07-25 19:58 ——– d—–w- c:\program files\Advanced Registry Optimizer
2010-08-04 17:01 . 2010-08-04 17:01 ——– d—–w- c:\documents and settings\Guest\Application Data\Sammsoft
2010-08-03 18:26 . 2010-08-03 18:26 ——– d—–w- c:\documents and settings\Dee\Application Data\Sammsoft
2010-07-24 15:53 . 2008-04-22 13:48 ——– d—–w- c:\program files\Creative
2010-07-24 15:53 . 2005-04-14 04:55 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-24 15:49 . 2005-04-27 22:23 ——– d—–w- c:\program files\V5385 Digital Camera
2010-07-24 15:46 . 2009-03-06 18:44 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-24 15:46 . 2009-03-06 18:44 ——– d—–w- c:\program files\NOS
2010-07-24 15:46 . 2008-12-28 20:16 ——– d—–w- c:\program files\Coupons
2010-07-24 15:44 . 2005-04-14 04:55 ——– d—–w- c:\program files\Common Files\InstallShield
2010-07-24 15:42 . 2005-06-05 01:07 ——– d—–w- c:\documents and settings\Dee\Application Data\Ulead Systems
2010-07-24 15:40 . 2005-04-14 05:04 ——– d—–w- c:\program files\Common Files\Intuit
2010-07-24 15:35 . 2005-04-14 04:53 ——– d—–w- c:\program files\Java
2010-07-24 15:15 . 2006-04-12 23:59 ——– d—–w- c:\program files\Dell
2010-07-24 15:08 . 2008-04-22 14:01 ——– d—–w- c:\program files\Audible
2010-07-22 15:49 . 2004-08-04 10:00 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-17 14:56 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2010-07-15 20:18 . 2010-01-08 14:49 120136 —-a-w- c:\windows\system32\drivers\Mpfp.sys
2010-07-02 14:03 . 2010-03-15 02:55 439816 —-a-w- c:\documents and settings\Dee\Application Data\Real\Update\setup3.10\setup.exe
2010-06-30 12:31 . 2004-08-04 10:00 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2004-08-04 10:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2004-08-04 10:00 1851904 —-a-w- c:\windows\system32\win32k.sys
2008-07-24 19:21 . 2008-07-24 19:20 10420936 -c–a-w- c:\program files\xlviewer.exe
2008-01-10 19:50 . 2005-04-27 21:44 848 –sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-09-17_16.13.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-09-19 14:31 . 2010-09-19 14:31 16384 c:\windows\Temp\Perflib_Perfdata_630.dat
- 2010-09-17 03:03 . 2010-09-17 16:03 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-09-17 03:03 . 2010-09-19 13:34 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-04-18 21:02 . 2010-09-19 13:34 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-04-18 21:02 . 2010-09-17 16:03 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-09-18 01:19 . 2010-09-19 13:34 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
- 2010-09-02 22:39 . 2010-09-17 16:03 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-23 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-30 417792]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-11 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
backup=c:\windows\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-12 04:16 39792 -c–a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\SYSTEM32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HelpCenter4.1]
2007-04-13 01:59 198184 -c–a-w- c:\program files\FastAccessDSL\HelpCenter43\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 21:24 54840 —-a-w- c:\program files\HP1610\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hplampc]
2002-01-17 15:40 40448 —-a-w- c:\windows\SYSTEM32\hplampc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-20 15:32 77824 —-a-w- c:\windows\SYSTEM32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-20 15:36 114688 —-a-w- c:\windows\SYSTEM32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-09-20 15:35 94208 —-a-w- c:\windows\SYSTEM32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-30 14:16 417792 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 19:42 1404928 -c–a-w- c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-08-23 17:23 185896 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
2003-11-18 22:20 45056 -c—-w- c:\program files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 —-a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [5/11/2010 3:04 PM 203280]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 hp4200c;%usbscan.SvcDesc%;c:\windows\SYSTEM32\DRIVERS\hp4200c.sys [8/23/2005 10:43 AM 9312]
S3 SAUSBHW;%SAUSBHW.SvcDesc%;c:\windows\system32\Drivers\sausb.sys –> c:\windows\system32\Drivers\sausb.sys [?]
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;c:\windows\SYSTEM32\DRIVERS\rt2500usb.sys [8/3/2005 11:01 AM 79616]
.
Contents of the 'Scheduled Tasks' folder

2005-04-18 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-04 00:12]

2010-07-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-05-11 17:22]

2010-05-11 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-05-11 17:22]

2010-09-19 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/mywaybiz
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: kaspersky.com\www
FF - ProfilePath - c:\documents and settings\Dee\Application Data\Mozilla\Firefox\Profiles\psq040np.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true);user_pref(general.useragent.extra.zencast, c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-19 13:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1120)
c:\windows\system32\WININET.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-09-19 13:06:57
ComboFix-quarantined-files.txt 2010-09-19 18:06
ComboFix2.txt 2010-09-17 16:16

Pre-Run: 62,352,224,256 bytes free
Post-Run: 62,446,211,072 bytes free

- - End Of File - - 0A7580BBBA52C9A446C76B71EC80256D
Try the following to resolve the Firefox issue

1.Close Firefox
2.Click start>run and type in firefox -safe-mode
3.In the open window (upon launching safe mode), select "Reset preferences to default Firefox"
4.Click on "Make the changes and restart "

Let us know if this resolves the issue.
Mowman, I am able to post in Foxfire now. I update the Quicktime add-on. I don't know it that made the difference. Could be that I just don't get an insertion point in the textbox and didn't know what was going on. Computer is running well. Thanks! :notworthy: Jcatsmom I can add additional text, but I can't edit the about text to correct my grammar error or indicate that I update Quicktime after resetting to default all use settings using foxfire safe-mode. Would it make any difference to be unplugged from the internet when trying it?
Mowman, I checked a similar text box on the customer service page of a commercial website and I have the insertion point on it. I can only backspace/delete in this box. I can not use the up or down arrows or the home or end keys. Very strange. I used ATF cleaner to clear out the caches.-JCatsmom
Hi, Mowman. I followed those logical directions of uninstalling and reinstalling Mozilla. No change. Tried again without saving bookmarks. Same result. Finally decided to test posting from my Mozilla on my personal computer. Whaddya know??!!! I can't manipulate text and don't have an insertion point in it either. I'm not worried that the symptom points towards remaining infection in the computer. -Jcatsmom
The Firefox problems are not malware related,you can try asking in our browser forum if you wish. http://forums.whatthetech.com/index.php?showforum=123


You now appear clean of infections,please do the following.


ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)






Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.




Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.




Here are some recommendations to help you stay clean.

Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
Thank you for all your help, Mowman! B) I successfully installed Spyware Blaster to help protect the computer. I attemped to install Cloudmark Desktop One to improve spam filtering, but couldn't get the e-mail account assigned properly. AT&T said their version of Internet Security through McAfee should be adequate. Went around and around with McAfee. Turns out the program needs to be reinstalled so that I can better configure the Spam filtering. I hope my friend is able to keep this computer clean for a lonnnngg time.-Jcatsmom

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI