This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Lots of Viruses, Exploits, Trojans, and Worms!

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been having problems with my browser (redirection, random page opens, weird stuff!) , but i used combofix and got rid of the symptoms, but i used Kaspersky Online Scanner 7 and saw many, many more things. :wacko:

So here is the hijackthis log:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:49:08 PM, on 9/26/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ANIWConnService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\lxducoms.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\AVG\AVG9\avgemc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\D-Link\DWA-130\AirNCFG.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8.hpwis.com/
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: MSN Toolbar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: MSN Toolbar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [D-Link D-Link Wireless N DWA-130] C:\Program Files\D-Link\DWA-130\AirNCFG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1258433462562
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1258433356218
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ANIWConn Service (ANIWConnService) - Unknown owner - C:\WINDOWS\system32\ANIWConnService.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToMyPC - Unknown owner - C:\Program Files\Citrix\GoToMyPC\g2svc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxdu_device - - C:\WINDOWS\System32\lxducoms.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Presentation Foundation Font Cache 4.0.0.0 (WPFFontCache_v0400) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (file missing)

–
End of file - 10333 bytes


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
And Here is the Kaspersky log:
~~~~~~~~~~~~~~~~~~~~~~~~~~~

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, September 26, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, September 26, 2010 11:11:47
Records in database: 4242833
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Objects scanned: 178673
Threats found: 35
Infected objects found: 57
Suspicious objects found: 0
Scan duration: 08:44:33


File name / Threat / Threats count
C:\Documents and Settings\aimee\aimee's Documents\WebfettiSetup2.3.50.45.ZKman000.exe Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.a.ax 1
C:\Documents and Settings\LocalService\Application Data\Sun\Java\Deployment\cache\6.0\12\20c3828c-7dc155c2 Infected: Exploit.Java.Agent.cw 1
C:\Documents and Settings\LocalService\Application Data\Sun\Java\Deployment\cache\6.0\12\20c3828c-7dc155c2 Infected: Exploit.Java.Agent.cu 1
C:\Documents and Settings\LocalService\Application Data\Sun\Java\Deployment\cache\6.0\12\20c3828c-7dc155c2 Infected: Exploit.Java.Agent.cv 1
C:\Documents and Settings\LocalService\Application Data\Sun\Java\Deployment\cache\6.0\53\2eb68b5-45a027e7 Infected: Exploit.Java.CVE-2009-3867.j 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\10\653a8b4a-62813b50 Infected: Exploit.Java.Agent.bu 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\16\7de60ad0-55eccd24 Infected: Exploit.Java.Agent.n 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\21\210921d5-2f533d26 Infected: Trojan-Downloader.Java.Agent.cf 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\24\1ba84018-2d3a1828 Infected: Trojan.Java.Agent.ab 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\24\1ba84018-2d3a1828 Infected: Trojan.Java.Agent.aa 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\24\1ba84018-2d3a1828 Infected: Trojan.Java.Agent.ac 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\3\4e84bf83-3044ec3c Infected: Trojan-Downloader.Java.Agent.fx 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\3\4e84bf83-3044ec3c Infected: Exploit.Java.Agent.f 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\3\4e84bf83-3044ec3c Infected: Trojan-Downloader.Java.Agent.fy 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\33\6ca560a1-6f0249db Infected: Trojan-Downloader.Java.Agent.cf 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\35\41e8aee3-7e2e29f4 Infected: Exploit.Java.Agent.bu 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\43\35fae22b-3968fb1b Infected: Trojan-Downloader.Java.Agent.fx 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\43\35fae22b-3968fb1b Infected: Exploit.Java.Agent.f 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\43\35fae22b-3968fb1b Infected: Trojan-Downloader.Java.Agent.fy 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\34db286c-7ae3c5c9 Infected: Trojan.Java.Agent.ab 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\34db286c-7ae3c5c9 Infected: Trojan.Java.Agent.aa 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\34db286c-7ae3c5c9 Infected: Trojan.Java.Agent.ac 1
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\48\4084a7b0-37a477ea Infected: Exploit.Java.Agent.bu 2
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\21\6b29b615-2b11cdcd Infected: Exploit.Java.Agent.s 3
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\6cce12f-709da560 Infected: Trojan-Downloader.Java.Agent.ft 1
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\6cce12f-709da560 Infected: Trojan-Downloader.Java.Agent.fu 1
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\6cce12f-709da560 Infected: Trojan-Downloader.Java.Agent.fv 1
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\49\1e6e4631-26db5f15 Infected: Trojan-Downloader.Java.Agent.eo 1
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\49\1e6e4631-26db5f15 Infected: Exploit.Java.Agent.t 1
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\49\1e6e4631-26db5f15 Infected: Trojan-Downloader.Java.Agent.ep 1
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\49\30d59331-19524a5f Infected: Trojan.Java.Agent.l 1
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\49\30d59331-19524a5f Infected: Trojan-Downloader.Java.Agent.do 1
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\49\30d59331-19524a5f Infected: Trojan-Downloader.Java.Agent.dn 1
C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Email-Worm.Win32.Bagle.b 1
C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Email-Worm.Win32.NetSky.c 3
C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Email-Worm.Win32.Bagle.n 1
C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Email-Worm.Win32.Bagle.ai 1
C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Trojan-Spy.HTML.Citifraud.ai 2
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\archive.pst Infected: Trojan-Spy.HTML.Bankfraud.w 2
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\archive.pst Infected: Trojan-Spy.HTML.Smitfraud.a 2
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\archive.pst Infected: Trojan-Spy.HTML.Smitfraud.c 2
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Trojan-Spy.HTML.Bayfraud.hn 4
C:\hp\region\EN_US-ie.reg Infected: Trojan.WinREG.StartPage 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\serial.sys.vir Infected: Virus.Win32.TDSS.b 1
C:\RECYCLER\S-1-5-21-4070528092-1652519551-2728482840-1003\Dc3.exe Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.a.ax 1

Selected area has been scanned.



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Any help will be greatly appreciated, Thanks!
Hi Ben B., welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Combofix is a very powerful tool and should not be used without supervision.

Most of the delections are exploits in some old java. We can take of these.

The detections in your OutLook Express are in the Deleted Items folder. Please empty the Deleted Item folder in all accounts on that computer.

The detections in OutLook will need to be dealt with in a similar way. Delete any unsolicited email. The detections are usually in ones that have attachments. Then compact the folders.

Instructions Here

I need to see the combofix log. Do not run combofix again.

Open windows explorer (right click the start button and click explore)
  • Navigate to this folder,C:\ and click on it.
  • In the right hand panel locate this file combofix.txt
  • Please post it's contents in your next reply.
Next
  • In the left hand panel navigate to this folder C:\Qoobox
  • Click on it.
  • In the right panel locate this file Add-Remove Programs.txt
  • Please post it's contents in your next reply.
Please post back with
  • combofix.txt
  • Add-Remove Programs.txt

Please describe all symptoms you are experiencing.

Thanks
Ok
so am i supposed to delete the java exploits? and how do i access the deletions folder?

here is the combofix log:



ComboFix 10-09-25.03 - Owner 09/25/2010 16:23:10.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1016.589 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix2.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
ADS - svchost.exe: deleted 88 bytes in 2 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Application Data\020000001b3d667c942C.manifest
c:\documents and settings\Owner\Application Data\020000001b3d667c942O.manifest
c:\documents and settings\Owner\Application Data\020000001b3d667c942P.manifest
c:\documents and settings\Owner\Application Data\020000001b3d667c942S.manifest
c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ljbhrpug.default\extensions\{0d2243d4-211b-4d0f-8b94-3170d4c5b590}
c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ljbhrpug.default\extensions\{0d2243d4-211b-4d0f-8b94-3170d4c5b590}\chrome.manifest
c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ljbhrpug.default\extensions\{0d2243d4-211b-4d0f-8b94-3170d4c5b590}\chrome\xulcache.jar
c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ljbhrpug.default\extensions\{0d2243d4-211b-4d0f-8b94-3170d4c5b590}\defaults\preferences\xulcache.js
c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ljbhrpug.default\extensions\{0d2243d4-211b-4d0f-8b94-3170d4c5b590}\install.rdf
c:\documents and settings\Owner\GoToAssistDownloadHelper.exe
c:\documents and settings\Owner\mp3info.exe
C:\Install.exe
c:\program files\Common Files\Uninstall
c:\windows\Downloaded Program Files\MiniBugTransporter.dll
c:\windows\system32\_003719_.tmp.dll
c:\windows\system32\576633510
c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
c:\windows\system32\unrar.exe
D:\Autorun.inf

Infected copy of c:\windows\system32\drivers\serial.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-08-25 to 2010-09-25 )))))))))))))))))))))))))))))))
.

2010-09-25 21:30 . 2010-09-25 21:30 ——– d—–w- c:\program files\Trend Micro
2010-09-23 21:11 . 2010-09-23 21:11 4093792 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-09-23 21:11 . 2010-09-23 21:11 3586912 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-09-23 21:11 . 2010-09-23 21:11 620896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgnsx.exe
2010-09-23 21:11 . 2010-09-23 21:11 1619296 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssie.dll
2010-09-23 21:11 . 2010-09-23 21:11 942432 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-09-23 21:11 . 2010-09-23 21:11 598368 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgsrmx.dll
2010-09-23 21:11 . 2010-09-23 21:11 4371296 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-09-23 21:11 . 2010-09-23 21:11 300896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchclx.dll
2010-09-23 21:09 . 2010-09-23 21:09 1690952 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-09-18 03:06 . 2010-04-19 16:25 2117704 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-09-13 03:09 . 2010-09-13 03:09 ——– d—–w- c:\documents and settings\Owner\Application Data\Mp3tag
2010-09-13 03:09 . 2010-09-13 03:09 ——– d—–w- c:\program files\Mp3tag
2010-09-13 02:56 . 2010-09-13 02:49 67584 —-a-w- c:\windows\mp3info.exe
2010-09-12 19:51 . 2010-09-12 19:51 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Conduit
2010-09-09 22:17 . 2010-09-09 22:17 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\World_of_AI
2010-09-06 20:13 . 2010-09-06 20:13 ——– d—–w- c:\program files\iPod
2010-09-06 20:13 . 2010-09-06 20:15 ——– d—–w- c:\program files\iTunes
2010-09-06 19:53 . 2010-09-06 19:53 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe
2010-09-04 20:29 . 2004-01-28 21:03 21456 —-a-w- c:\windows\system32\drivers\SilvrLnk.sys
2010-09-04 20:29 . 2004-02-04 16:27 49536 —-a-w- c:\windows\system32\drivers\tiehdusb.sys
2010-09-04 20:28 . 2010-09-04 20:28 ——– d—–w- c:\program files\Common Files\TI Shared
2010-09-04 20:28 . 2010-09-04 20:29 ——– d—–w- c:\program files\TI Education
2010-09-04 20:24 . 2010-09-04 20:24 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-09-03 23:36 . 2010-09-03 23:36 ——– d—–w- c:\program files\IMSIDesign
2010-09-03 23:34 . 2010-09-03 23:34 ——– d—–w- c:\documents and settings\Owner\Application Data\IMSIDesign
2010-09-03 23:28 . 2010-09-03 23:32 ——– d—–w- c:\program files\TurboCAD Professional v17.1
2010-09-02 03:32 . 2010-09-02 03:32 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\MyBabylon-English
2010-08-29 05:15 . 2010-08-29 05:15 ——– d—–w- c:\documents and settings\Owner\Application Data\ImgBurn
2010-08-29 01:21 . 2010-08-29 01:22 ——– d—–w- c:\program files\ImgBurn

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-12 02:16 . 2010-02-14 00:11 ——– d—–w- c:\documents and settings\Owner\Application Data\FrostWire
2010-09-11 21:01 . 2010-02-14 00:07 ——– d—–w- c:\program files\FrostWire
2010-09-04 22:40 . 2003-07-24 15:36 128760 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-04 01:13 . 2008-07-21 18:06 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-27 23:24 . 2009-02-15 01:08 ——– d—–w- c:\program files\QuickTime
2010-08-23 23:51 . 2010-08-23 23:51 ——– d—–w- c:\documents and settings\All Users\Application Data\boost_interprocess
2010-08-23 23:00 . 2010-08-23 23:00 ——– d—–w- c:\program files\MyBabylon-English
2010-08-23 23:00 . 2010-08-23 23:00 ——– d—–w- c:\program files\Conduit
2010-08-23 23:00 . 2010-08-23 23:00 ——– d—–w- c:\program files\Babylon
2010-08-23 22:46 . 2009-02-17 00:15 ——– d—–w- c:\program files\Common Files\Java
2010-08-23 22:44 . 2009-02-17 00:15 ——– d—–w- c:\program files\Java
2010-08-16 23:16 . 2010-08-16 23:16 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-08-12 05:42 . 2010-08-12 05:42 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-08-12 05:42 . 2010-06-28 05:12 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-08-12 00:22 . 2010-08-12 00:22 162488 —-a-w- c:\windows\StoneAir Stingray Uninstaller.exe
2010-08-10 23:13 . 2010-08-10 23:13 ——– d—–w- c:\program files\Microsoft Games
2010-08-10 19:01 . 2009-11-18 01:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-10 18:57 . 2003-04-10 10:28 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-10 18:56 . 2010-08-07 05:13 ——– d—–w- c:\program files\video4fuze
2010-08-10 18:55 . 2010-01-02 04:48 ——– d—–w- c:\documents and settings\Owner\Application Data\SanDisk
2010-08-07 05:16 . 2010-08-07 05:16 ——– d—–w- c:\documents and settings\Owner\Application Data\ssorgatem productions
2010-08-06 15:51 . 2010-08-06 15:51 ——– d—–w- c:\documents and settings\Owner\Application Data\AnvSoft
2010-08-05 06:39 . 2010-08-05 06:39 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-6dd841e1-n\decora-sse.dll
2010-08-05 06:39 . 2010-08-05 06:39 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-78188cb4-n\msvcp71.dll
2010-08-05 06:39 . 2010-08-05 06:39 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-78188cb4-n\jmc.dll
2010-08-05 06:39 . 2010-08-05 06:39 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-78188cb4-n\msvcr71.dll
2010-08-05 06:39 . 2010-08-05 06:39 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-6dd841e1-n\decora-d3d.dll
2010-08-03 05:59 . 2007-01-22 15:09 ——– d—–w- c:\program files\Windows Media Connect 2
2010-07-17 11:00 . 2010-06-27 20:12 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-15 15:40 . 2009-11-17 07:27 243024 -c–a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-15 15:40 . 2010-07-15 15:40 12536 —-a-w- c:\windows\system32\avgrsstx.dll
2010-07-15 15:38 . 2009-11-17 07:27 216400 -c–a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-07 20:47 . 2010-07-07 20:47 1063320 —-a-w- c:\documents and settings\Owner\gotomypc_538.exe
2010-07-05 16:28 . 2010-07-05 16:28 257257 —-a-w- c:\documents and settings\Owner\Application Data\OpenCandy\DLMGR3.exe
2010-07-01 22:49 . 2010-07-01 22:49 7046096 —-a-w- c:\documents and settings\Owner\gosetup.exe
2010-06-29 17:58 . 2003-04-25 15:45 14336 —-a-w- c:\windows\system32\svchost.exe
2009-03-09 15:14 . 2009-03-09 15:14 61 -csh–w- c:\windows\cnerolf.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
"{75942cb8-8cc1-417a-81bf-f12acf75006f}"= "c:\program files\MyBabylon-English\tbMyBa.dll" [2010-06-14 2734688]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_CLASSES_ROOT\clsid\{75942cb8-8cc1-417a-81bf-f12acf75006f}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{75942cb8-8cc1-417a-81bf-f12acf75006f}]
2010-06-14 01:10 2734688 —-a-w- c:\program files\MyBabylon-English\tbMyBa.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 16:25 2117704 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
"{75942cb8-8cc1-417a-81bf-f12acf75006f}"= "c:\program files\MyBabylon-English\tbMyBa.dll" [2010-06-14 2734688]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{75942cb8-8cc1-417a-81bf-f12acf75006f}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{75942CB8-8CC1-417A-81BF-F12ACF75006F}"= "c:\program files\MyBabylon-English\tbMyBa.dll" [2010-06-14 2734688]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{75942cb8-8cc1-417a-81bf-f12acf75006f}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2002-07-18 200767]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-02 126976]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"PS2"="c:\windows\system32\ps2.exe" [2002-08-01 81920]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-11-02 155648]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-15 2065760]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"D-Link D-Link Wireless N DWA-130"="c:\program files\D-Link\DWA-130\AirNCFG.exe" [2008-10-01 1679360]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]

c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\
mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2009-7-10 189952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-15 15:40 12536 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
"2763:TCP"= 2763:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/17/2009 1:27 AM 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/17/2009 1:27 AM 243024]
R3 RTL8192u;Realtek RTL8192U Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192u.sys [1/1/2010 6:06 PM 443776]
S3 WLIU2KG125S;BUFFALO WLI-U2-KG125S Wireless LAN Adapter Driver;c:\windows\system32\drivers\usb8023.sys [4/25/2003 9:46 AM 12800]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/9/2009 2:24 PM 685816]
.
Contents of the 'Scheduled Tasks' folder

2010-09-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-09-25 c:\windows\Tasks\User_Feed_Synchronization-{0E929A34-4507-4B01-A168-A736698DB66A}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 10:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ask.com?o=14196&l;=dis
uDefault_Search_URL = hxxp://srch-qus8.hpwis.com/
mSearch Bar = hxxp://srch-qus8.hpwis.com/
uInternet Connection Wizard,ShellNext = hxxp://qus8.hpwis.com/
uInternet Settings,ProxyOverride = ;*.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: microsoft.com\www
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ljbhrpug.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://search.yahoo.com/web?fr=yfp-t-701
FF - plugin: c:\documents and settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

BHO-{0CD27A2A-6764-4063-A22A-A6AEA886B7Ab} - c:\windows\system32\batt32.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-RocketDock - c:\program files\RocketDock\RocketDock.exe
Notify-906cddc1942 - c:\windows\system32\ciadmin32.dll
Notify-GoToMyPC - c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
AddRemove-CCleaner - c:\documents and settings\Owner\Desktop\CCleaner\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-25 16:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-09-25 16:56:21
ComboFix-quarantined-files.txt 2010-09-25 22:55

Pre-Run: 5,928,583,168 bytes free
Post-Run: 6,931,791,872 bytes free

- - End Of File - - 64A4913AA61D6B10D9EA0A5E2353A89A


and here is the Add-Remove Programs.txt:

7-Zip 4.57
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3
Adobe Shockwave Player 11.5
ANIO Service
ANIWZCS2 Service
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AVG Free 9.0
Bonjour
CCleaner
D-Link Wireless N DWA-130
Facebook Plug-In
FARO LS 1.1.406.58
FrostWire 4.20.9
FSEdit SDK
HijackThis 2.0.4
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB942288-v3)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB958655-v2)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Deskjet printer preloaded drivers
HpSdpAppCoreApp
ImgBurn
Intel® Extreme Graphics Driver
InterVideo WinDVD Player
iTunes
Java Auto Updater
Java™ 6 Update 21
KBD
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Flight Simulator 2004 A Century of Flight
Microsoft Help Viewer 1.0
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft UI Engine
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Works 7.0
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
MobileMe Control Panel
Mozilla Firefox (3.6.10)
Mp3tag v2.46a
MSN Toolbar
MSN Toolbar Platform
MyBabylon-English Toolbar
Network Magic
NVIDIA Windows 2000/XP Display Drivers
PS2
Python 2.2 combined Win32 extensions
Python 2.2.1
QuickTime
RecordNow
S3Display
S3Gamma2
S3Info2
S3Overlay
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB978380)
Security Update for Microsoft Office Excel 2007 (KB978382)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB980470)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980232)
Simple Installer - Multilanguage Version
SketchUp DWG Importer
Sonic Update Manager
TI Connect 1.6
Update for 2007 Microsoft Office System (KB967642)
Update for 2007 Microsoft Office System (KB981715)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Windows (KB971513)
Update for Outlook 2007 Junk Email Filter (kb981726)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Driver Package - Pure Networks, Inc. Network Magic Device Discovery Driver (03/23/2007 4.1.7082.0)
Windows Driver Package - Pure Networks, Inc. Network Magic Wireless Driver (03/23/2007 4.1.7082.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live ID Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3

Thanks for the help that is to come!
Hi Ben B.,

FrostWire 4.20.9

You have FrostWire 4.20.9, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall FrostWire 4.20.9, however that choice is up to you. If you choose to remove this program, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.



Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - Startup: PowerReg Scheduler.exe


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



Next, clear the java cache, this will take care of the exploits detected.

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK
Reboot the computer.


Next

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • MBAM log
  • new HJT log taken after all other steps
How's the computer? Any problems?

Thanks
Ok here is the mbam log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4705

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

9/27/2010 4:04:44 PM
mbam-log-2010-09-27 (16-04-44).txt

Scan type: Quick scan
Objects scanned: 148035
Time elapsed: 17 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

~~~~~~~~~~~~~~~~~~~~

And here is the Hijack this log:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:06:53 PM, on 9/27/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ANIWConnService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\lxducoms.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\D-Link\DWA-130\AirNCFG.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8.hpwis.com/
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: MSN Toolbar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: MSN Toolbar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [D-Link D-Link Wireless N DWA-130] C:\Program Files\D-Link\DWA-130\AirNCFG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1258433462562
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1258433356218
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ANIWConn Service (ANIWConnService) - Unknown owner - C:\WINDOWS\system32\ANIWConnService.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToMyPC - Unknown owner - C:\Program Files\Citrix\GoToMyPC\g2svc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxdu_device - - C:\WINDOWS\System32\lxducoms.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Presentation Foundation Font Cache 4.0.0.0 (WPFFontCache_v0400) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (file missing)

–
End of file - 10156 bytes


~~~~~~~~~~~~~~~~~~~~~~~~~~~
What did you say about the ms outlook thing?

Thanks
Hi Ben B.,

How is the computer?


What did you say about the ms outlook thing?

There were some detections in OutLook. I can't tell you which emails were detected as the entire OutLook data base is like one huge file. You will need to go through the mail and delete anything you don't want or was unsolicited. The offending email are usually one that have attachments. After you have deleted any mail empty the Deleted Items folder then compact the folders. I posted a link to the instruction for compacting the OutLook folders in Post #2.
ive never used outlook before so there are no accounts and no messages or mail. and when i opened to C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx it showed under deleted items.dbx "AutoCAD Database Extension" which i thought was weird for a outlook file!?
Hi Ben B.,

ive never used outlook before so there are no accounts and no messages or mail.

Hmm…must be an account somewhere as Kaspersky found it. Did you open the program and look?

and when i opened to C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx
it showed under deleted items.dbx "AutoCAD Database Extension" which i thought was weird for a outlook file!?

Not really. autoCad must have been installed on this computer as there is another file assocation set to AutoCad.

Generally when you see this this is what has happened. .dbx files are associated with OutLook Express (OE) by default. The .dbx extention is also associated with autocad once autocad is installed on the computer. This isn't a problem as when you view OutLook Express' .dbx files you are doing so from within OutLook Express. It's only when you attempt to view OE's file from outside of OE such as in Windows Explorer that you will see "AutoCAD Database Extension".

The correct way to empty the Deleted Item folder is from within the program itself. All of the detections are in one account but if you have multiple accounts on the computer you will need to empty the Deleted Items folder in all accounts.

How's the computer?
I opened outlook and… nothing, no mail, no deleted items, and no accounts. weird. the computer seems fine, which when we started, seemed fine also. But i did the scan and saw bad stuff, so i just wanted to be sure.
Hi Ben B.,

We can see if other scanners find anything wrong with the Outlook folder. This multi scanner can accept files that are less than 20mb in size. Check in Windows Explorer for the file size of

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst

If it's less than 20mb submit it and let's see what come back.


  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time if more than file is listed, into the "Suspicious files to scan" box on the top of the page:

    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst

  • Click on the Upload button
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Everything looks fine here. We can clean up the tools you used. Let me know the results of the Virscan. I find this rather interesting.

From your desktop, please delete
  • any notepads/logs that we created

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Just add a firewall and a resident antispyware program.

I suggest either

Windows Defender
OR
Winpatrol

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0

-More tips and programs can be found HERE

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879
Hi, the outlook.pst file is 1.74 GB (1,875,452,928 bytes). by the way i got this from someone who did use outlook, but i deleted the accounts. is there any way to delete all the data from outlook except for the actual program? and when i try to uninstall combofix, it says that it cant find it. but i dont think there was a installation. should i just delete the combofix.exe file? i installed online armor 4.5 free and spyware blaster. do i have to keep those running in the tray and if so, how? thanks for your help
o yeah, on online armor it says when i did the "Safety Check Wizard", it says Exploring start menu : needs attention Checking autoruns : needs attention Scanning internet extensions : needs attention i dont know if it is serious but i just want to be sure. im planning on doing a Kaspersky scan, but i want to make sure everything is off, so when you tell me, i will

by the way i got this from someone who did use outlook, but i deleted the accounts. is there any way to delete all the data from outlook except for the actual program?


by the way i got this computer from someone who did use outlook, but i deleted the accounts. is there any way to delete all the data from outlook except for the actual program?
Hi Ben B.,

Let's take this one step at a time.

and when i try to uninstall combofix, it says that it cant find it. but i dont think there was a installation. should i just delete the combofix.exe file?

Delete the copy you have from your desktop. Then download a new copy from Here1 and save it directly to your desktop. Do not run it.

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK

Combofix /uninstall

That command does a few other thing besides remove combofix so let me know if it worked this time. If not we will need to do an additional step.

by the way i got this from someone who did use outlook, but i deleted the accounts. is there any way to delete all the data from outlook except for the actual program?

That I'm not sure of as the files are usually accessed via the account. How did you delete the accounts? You could ask HERE

o yeah, on online armor it says when i did the "Safety Check Wizard", it says
Exploring start menu : needs attention
Checking autoruns : needs attention
Scanning internet extensions : needs attention

The firewall has found progrms that it's not sure of allowing internet access to. You will need to configure the settings for those programs.

"Items passed successfully Passed appear in green, those who must apply for verification with the words appear Needs Attention. "
http://translate.google.ca/translate?hl=en…09%26prmd%3Dvfd

You can find online help HERE and the Online Armor forum HERE Check ouy the above link as it has some very good information.
Hi i tried runing combofix /uninstall and it cant find it again. but i did a kaspersky scan and here are the results: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, September 30, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, September 29, 2010 19:57:47 Records in database: 4257860 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 178399 Threats found: 29 Infected objects found: 51 Suspicious objects found: 0 Scan duration: 08:19:59 File name / Threat / Threats count C:\Documents and Settings\LocalService\Application Data\Sun\Java\Deployment\cache\6.0\12\20c3828c-7dc155c2 Infected: Exploit.Java.Agent.cw 1 C:\Documents and Settings\LocalService\Application Data\Sun\Java\Deployment\cache\6.0\12\20c3828c-7dc155c2 Infected: Exploit.Java.Agent.cu 1 C:\Documents and Settings\LocalService\Application Data\Sun\Java\Deployment\cache\6.0\12\20c3828c-7dc155c2 Infected: Exploit.Java.Agent.cv 1 C:\Documents and Settings\LocalService\Application Data\Sun\Java\Deployment\cache\6.0\53\2eb68b5-45a027e7 Infected: Exploit.Java.CVE-2009-3867.j 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\10\653a8b4a-62813b50 Infected: Exploit.Java.Agent.bu 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\16\7de60ad0-55eccd24 Infected: Exploit.Java.Agent.n 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\21\210921d5-2f533d26 Infected: Trojan-Downloader.Java.Agent.cf 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\24\1ba84018-2d3a1828 Infected: Trojan.Java.Agent.ab 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\24\1ba84018-2d3a1828 Infected: Trojan.Java.Agent.aa 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\24\1ba84018-2d3a1828 Infected: Trojan.Java.Agent.ac 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\3\4e84bf83-3044ec3c Infected: Trojan-Downloader.Java.Agent.fx 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\3\4e84bf83-3044ec3c Infected: Exploit.Java.Agent.f 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\3\4e84bf83-3044ec3c Infected: Trojan-Downloader.Java.Agent.fy 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\33\6ca560a1-6f0249db Infected: Trojan-Downloader.Java.Agent.cf 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\35\41e8aee3-7e2e29f4 Infected: Exploit.Java.Agent.bu 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\43\35fae22b-3968fb1b Infected: Trojan-Downloader.Java.Agent.fx 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\43\35fae22b-3968fb1b Infected: Exploit.Java.Agent.f 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\43\35fae22b-3968fb1b Infected: Trojan-Downloader.Java.Agent.fy 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\34db286c-7ae3c5c9 Infected: Trojan.Java.Agent.ab 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\34db286c-7ae3c5c9 Infected: Trojan.Java.Agent.aa 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\34db286c-7ae3c5c9 Infected: Trojan.Java.Agent.ac 1 C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\48\4084a7b0-37a477ea Infected: Exploit.Java.Agent.bu 2 C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\49\30d59331-19524a5f Infected: Trojan.Java.Agent.l 1 C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\49\30d59331-19524a5f Infected: Trojan-Downloader.Java.Agent.do 1 C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\49\30d59331-19524a5f Infected: Trojan-Downloader.Java.Agent.dn 1 C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Email-Worm.Win32.Bagle.b 1 C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Email-Worm.Win32.NetSky.c 3 C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Email-Worm.Win32.Bagle.n 1 C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Email-Worm.Win32.Bagle.ai 1 C:\Documents and Settings\Owner\Local Settings\Application Data\Identities\{42B61E98-3EA4-4171-9489-6DE0F49472BA}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Trojan-Spy.HTML.Citifraud.ai 2 C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\archive.pst Infected: Trojan-Spy.HTML.Bankfraud.w 2 C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\archive.pst Infected: Trojan-Spy.HTML.Smitfraud.a 2 C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\archive.pst Infected: Trojan-Spy.HTML.Smitfraud.c 2 C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\archive.pst Infected: Trojan-Spy.HTML.Bankfraud.ci 2 C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Trojan-Spy.HTML.Bayfraud.hn 6 C:\hp\region\EN_US-ie.reg Infected: Trojan.WinREG.StartPage 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\serial.sys.vir Infected: Virus.Win32.TDSS.b 1 C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP312\A0191067.exe Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.a.ax 1 Selected area has been scanned. thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI