hello…
I was able to uninstall AVG using the online uninstall tool. I was unable to run Combofix in normal mode (same errors) so I rebooted into safe mode with networking so I could establish an internet connection while in safe mode. The internet connection was needed to repair the system restore problem that Combofix identified. Combofix connected to the Microsoft download site and indicated that the system restore problem has been corrected.
Combofix then ran through the different stages and auotomatically rebooted without providing an option to save a log file.
The only log file that I can find in the Combofix folder is below
ComboFix 10-11-05.05 - Administrator 11/06/2010 10:42:13.2.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.804 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
when I executed the combofix program from desktop it created a seperate folder under the C drive named C:\Combofix. When I run Combofix in safe mode i have to select the "administrator" as the user from the windows start up screen in order to get Combofix to run. I tried to select "JM" (primary user profile) as the user from the Windows start up screen while in safe mode. When I use this user profile I get the same error messages as before when I try to run Combofix, even in safe mode.
After conducting a search of the hard drive for the Combo fix log I have only been able to find the 1 log file in this Combofix folder named Combofix.txt.ComboFix
10-11-05.05 - Administrator 11/06/2010 10:42:13.2.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.804 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
I was able to locate the Qoobox folder under the C: drive however there are no log files located in that folder that I could find.
I updated and ran malewarebytes and it did not find any malicious items. Log is below:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 5062
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
11/6/2010 1:24:12 PM
mbam-log-2010-11-06 (13-24-12).txt
Scan type: Quick scan
Objects scanned: 175949
Time elapsed: 14 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
good evening mowman…eset scan log is below. Laptop computer is running better with no "redirects" during browser sessions. I have also been using IExplorer for the last number of posts. Prior to our efforts I was unable to use IExplorer as a browser due to virus, etc. Seems we are making progress. Thank you for your efforts.
C:\Documents and Settings\John Hurst\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\gvtlf.dll Win32/Adware.Gamevance.AI application
C:\Documents and Settings\John Hurst\Application Data\Mozilla\Firefox\Profiles\x3d7xoxa.default\prefs.js Win32/Agent.RQD.Gen trojan
C:\_OTL\MovedFiles\11032010_213040\C_Documents and Settings\JM\Application Data\Microsoft\svchost.exe a variant of Win32/Kryptik.HVW trojan
C:\_OTL\MovedFiles\11032010_213040\C_Documents and Settings\JM\Application Data\Microsoft\Windows\shell.exe a variant of Win32/Kryptik.HVW trojan
C:\_OTL\MovedFiles\11032010_213040\C_Documents and Settings\JM\Local Settings\Temp\dwm.exe a variant of Win32/Kryptik.HVW trojan
C:\_OTL\MovedFiles\11032010_213040\C_Program Files\Gamevance\gvtl.dll Win32/Adware.Gamevance.AI application
Close all other programs apart from OTL as this step will require a reboot
On the OTL main screen, press the CLEANUP button
Say Yes to the prompt and then allow the program to reboot your computer.
[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
Download the latest version of Java Runtime Environment (JRE) 22 and save it to your desktop.
Scroll down to where it says JDK 6 Update 22 (JDK or JRE)
Click the Download JRE button to the right
Select the Windows platform from the dropdown menu.
Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u22 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
Click on the link to download Windows Offline Installation and save the file to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u22-windows-i586-p.exe to install the newest version.
After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
On the General tab, under Temporary Internet Files, click the Settings button.
Next, click on the Delete Files button
There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
Trace and Log Files
Click OK on Delete Temporary Files Window Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
Click OK to leave the Temporary Files Window
Click OK to leave the Java Control Panel.
Here are some recommendations to help you stay clean.
Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must. Please read this article 'Safe Computing Practices'. So how did I get infected in the first place.
Preventing Infections in the Future
Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:
Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to asmörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.
Update Non-Microsoft Programs
It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.
Good evening mowman.
I have followed your instructions and removed Combofix (still had to go to safe mode and use administration profile to execute uninstall), OTL, JAVA 6, and reinstalled JRE 22.
I have alos downloaded the avast anti virus and will give it a try as well as review the other prevention suggestions. Most importatntly, I will educate my son on the rules of safe browsing as I believe it was most likely a P2P program that infected his laptop computer.
Lastly I would like to thank you for your advice and patience in working with me throughout this clean-up process. This was one of the more tedious and lengthy clean-up processes that I've been through and I appreciate your time and patience.
Regards,
jhurst