This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Remnants of a fake Windows Defender AV infection?

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

NoodleTech- THANK YOU for your assistance! I hope you are not under the impression that my post โ€œMalware Trace registry infectionโ€ was related to this problem and that I double posted the same problem in search of a resolution. Actually that post is for a different infection that is on my laptop and a separate infection. In correspondence with one of the classroom moderators on the forum this was something I was hoping we could look at when we have my parentโ€™s laptop corrected. I did attach a DDS log with the malware trace registry infection on my laptop attached below. If that is okay with you I would really appreciate it! In regards to your instructions above (and for my parentโ€™s laptop) do I need to have a copy of the Windows Vista Home Premium CD or the system driver available to me before I run this script/Combofix solution? The reason I ask is that they purchased this laptop from a friend so I do not have a copy of Windows Vista Home Premium currently available to me. If you could just let me know if I need this in order to run the script/Combfix solution above I would appreciate it! Thanks again NoodleTech!
Hi ToddB, We recommend that you create separate threads for each of your computers/malware issues and it looks like another one of my fellow classmates is already helping you. Sorry, I should have clarified my instructions in the previous post. You do not need the Vista CD to run the Combofix script. However, we will need it later on to replace one of your infected system drivers, but go ahead and run the script right now while I consult with my instructor as to how we will replace the driver without the original CD. If you can find the CD, that would be great. If not, no worries. I will be waiting for your Combofix log.
NoodleTech-

I apologize for posting a separate issue with my machine with this thread. In thinking about it and the number of issues you are dealing with at any one time that more than likely adds to a degree of confusion for you. That issue is now being dealt with in another thread so I will make sure to keep these issues separate going forward. I have followed your instructions above and the ComboFix log is below.

I still have not had any luck in tracking down a CD for this machine so if you could think of a workaround in this area I would be most grateful.

Thanks again for your assistance and for the wonderful help offered on this GREAT forum!

ComboFix 11-01-08.05 - Jess 01/13/2011 20:13:21.3.2 - x86
Microsoftยฎ Windows Vistaโ„ข Home Premium 6.0.6002.2.1252.1.1033.18.1013.365 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Jess\Desktop\CFScript.txt
AV: BitDefender Antivirus *Disabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
FW: BitDefender Firewall *Enabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
SP: BitDefender Antispyware *Disabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Jess\AppData\Roaming\kzcuhh

.
((((((((((((((((((((((((( Files Created from 2010-12-14 to 2011-01-14 )))))))))))))))))))))))))))))))
.

2011-01-14 02:31 . 2011-01-14 02:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Jess\AppData\Local\temp
2011-01-14 02:31 . 2011-01-14 02:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Guest\AppData\Local\temp
2011-01-14 02:31 . 2011-01-14 02:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp
2011-01-08 21:43 . 2010-12-21 00:09 38224 โ€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-08 21:43 . 2011-01-08 21:43 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Malwarebytes' Anti-Malware
2011-01-08 21:43 . 2010-12-21 00:08 20952 โ€”-a-w- c:\windows\system32\drivers\mbam.sys
2011-01-04 23:07 . 2011-01-04 23:07 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Jess\AppData\Roaming\IObit
2011-01-04 23:07 . 2011-01-04 23:07 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\IObit
2011-01-04 19:21 . 2011-01-04 19:21 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\bdch
2011-01-03 20:40 . 2011-01-03 20:40 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Jess\AppData\Roaming\BitDefender
2011-01-03 20:39 . 2011-01-03 20:39 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\BitDefender
2011-01-03 20:27 . 2011-01-03 20:27 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Jess\AppData\Roaming\QuickScan
2011-01-03 20:26 . 2011-01-03 20:39 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Common Files\BitDefender
2011-01-03 20:25 . 2011-01-03 20:43 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\BitDefender
2011-01-03 20:24 . 2011-01-03 21:57 306104 โ€”-a-w- c:\windows\system32\drivers\trufos.sys
2011-01-03 20:24 . 2011-01-03 21:42 327368 โ€”-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2011-01-01 13:42 . 2010-11-10 04:33 6273872 โ€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{14CC78D0-E001-4F03-B7CA-7115E7846B3E}\mpengine.dll
2010-12-25 18:36 . 2010-12-25 18:36 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Jess\AppData\Roaming\Malwarebytes
2010-12-25 18:36 . 2010-12-25 18:36 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Malwarebytes
2010-12-16 00:50 . 2010-11-03 10:51 2409784 โ€”-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2010-12-16 00:49 . 2010-10-12 15:53 33280 โ€”-a-w- c:\program files\Windows Mail\wabfind.dll
2010-12-16 00:49 . 2010-10-12 13:41 66048 โ€”-a-w- c:\program files\Windows Mail\wabmig.exe
2010-12-16 00:49 . 2010-10-12 13:41 515584 โ€”-a-w- c:\program files\Windows Mail\wab.exe
2010-12-16 00:49 . 2010-10-18 13:37 81920 โ€”-a-w- c:\windows\system32\consent.exe
2010-12-16 00:48 . 2010-10-28 15:44 34304 โ€”-a-w- c:\windows\system32\atmlib.dll
2010-12-16 00:48 . 2010-10-28 13:27 292352 โ€”-a-w- c:\windows\system32\atmfd.dll
2010-12-16 00:48 . 2010-06-16 15:30 72704 โ€”-a-w- c:\windows\system32\fontsub.dll
2010-12-16 00:47 . 2010-10-28 13:20 2048 โ€”-a-w- c:\windows\system32\tzres.dll
2010-12-16 00:44 . 2010-11-04 18:56 345600 โ€”-a-w- c:\windows\system32\wmicmiplugin.dll
2010-12-16 00:44 . 2010-11-04 18:55 352768 โ€”-a-w- c:\windows\system32\taskschd.dll
2010-12-16 00:44 . 2010-11-04 18:55 601600 โ€”-a-w- c:\windows\system32\schedsvc.dll
2010-12-16 00:44 . 2010-11-04 16:34 171520 โ€”-a-w- c:\windows\system32\taskeng.exe
2010-12-16 00:44 . 2010-11-04 18:55 270336 โ€”-a-w- c:\windows\system32\taskcomp.dll
2010-12-16 00:25 . 2010-10-18 13:31 2038272 โ€”-a-w- c:\windows\system32\win32k.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-03 21:37 . 2010-06-18 22:11 72784 โ€”-a-w- c:\windows\system32\drivers\bdfndisf6.sys
2010-10-19 16:41 . 2009-11-14 11:59 222080 โ€”โ€”w- c:\windows\system32\MpSigStub.exe
2010-03-30 00:40 . 2010-03-30 00:40 100256 โ€”-a-w- c:\program files\Common Files\LinkInstaller.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXBUCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2007-02-22 73728]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2011\ieshow.exe" [2011-01-03 71216]
"BDAgent"="c:\program files\BitDefender\BitDefender 2011\bdagent.exe" [2011-01-03 1418456]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^w98Eject.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\w98Eject.lnk
backup=c:\windows\pss\w98Eject.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Jess^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Jess\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-12 03:16 39792 โ€”-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 โ€”-a-w- c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2009-12-11 19:37 30192 โ€”-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2006-11-29 03:17 106496 โ€”-a-w- c:\windows\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HWSetup]
2006-11-01 15:06 413696 โ€”-a-w- c:\program files\Toshiba\Utilities\HWSetup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2006-11-29 03:14 98304 โ€”-a-w- c:\windows\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeNotify]
2006-11-07 00:14 34352 โ€”-a-w- c:\program files\Toshiba\Utilities\KeNotify.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
2005-12-16 09:41 188416 โ€”-a-w- c:\program files\ltmoh\ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBUCATS]
2007-02-22 11:12 73728 โ€”-a-w- c:\windows\System32\spool\drivers\w32x86\3\lxbutime.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2006-11-29 03:13 81920 โ€”-a-w- c:\windows\System32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 05:08 417792 โ€”-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2006-11-09 17:57 3784704 โ€”-a-w- c:\windows\RtHDVCpl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVPWUTIL]
2006-01-18 23:06 421888 โ€”-a-w- c:\program files\Toshiba\Utilities\SVPWUTIL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-10-27 20:50 815104 โ€”-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

R1 SASDIFSV;SASDIFSV;c:\users\Jess\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS [x]
R1 SASKUTIL;SASKUTIL;c:\users\Jess\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.SYS [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-11 30192]
R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\DRIVERS\PTDWBus.sys [2007-04-06 27392]
R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\DRIVERS\PTDWMdm.sys [2007-04-06 41728]
R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\DRIVERS\PTDWVsp.sys [2007-04-06 39808]
R3 PWCTLDRV;The NECHostController Filter Driver; [x]
R3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\DRIVERS\pwi_bus.sys [x]
R3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\DRIVERS\pwi_mdfl.sys [x]
R3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\DRIVERS\pwi_mdm.sys [x]
R3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\DRIVERS\pwi_oflt.sys [x]
R3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\pwi_serd.sys [x]
R3 SASENUM;SASENUM;c:\users\Jess\AppData\Local\Temp\SAS_SelfExtract\SASENUM.SYS [x]
R3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [2009-05-25 32408]
R3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2011-01-03 307544]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [2010-06-28 633424]
R4 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [2010-06-28 970320]
S1 Bdfndisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [2011-01-03 72784]
S2 Updatesrv;BitDefender Desktop Update Service;c:\program files\BitDefender\BitDefender 2011\updatesrv.exe [2011-01-03 43424]
S3 BDFM;BDFM;c:\windows\system32\DRIVERS\bdfm.sys [2010-05-13 152528]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2011-01-14 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 22:39]
.
.
โ€”โ€”- Supplementary Scan โ€”โ€”-
.
uStart Page = hxxp://www.google.com/
mStart Page = about:blank
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {47C00A50-53CB-4FA4-94AC-3A61BB20BCC2} = 69.78.96.14 66.174.92.14
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-13 20:31
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes โ€ฆ

scanning hidden autostart entries โ€ฆ

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBUCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files โ€ฆ

scan completed successfully
hidden files: 0

**************************************************************************
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€”

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-01-13 20:38:28
ComboFix-quarantined-files.txt 2011-01-14 02:38
ComboFix2.txt 2011-01-10 22:09

Pre-Run: 65,749,237,760 bytes free
Post-Run: 65,719,988,224 bytes free

- - End Of File - - 4D1016E350617803A30E4CE8F30384D4
Hi ToddB,

No worries. It looks like we won't be needing the Vista CD at all. The infected driver is no longer showing up in your logs so ComboFix took care of it.

How is your computer running at the moment? Are you still having issues with BitDefender?

Let's try running the ESET scan now.

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
NoodleTech- Unfortunately over the last couple of days I have tried to run ESET but Bitdefender is still shutting down and the machine freezes. :pullhair: With the changes you directed me to make above I was thinking of uninstalling/re-installing Bitdefender but decided to get your direction before I took this step. Thanks!
Hi ToddB,

Go ahead and try uninstalling/reinstalling BitDefender.

Let's try a different online scanner in the meantime.

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC Now button
  • A new window will openโ€ฆclick the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    Post the contents of the ActiveScan report
Noodletech- After trying to get an online scan from ESET or Panda and having Bitdefender shut down and freeze the machine I finally decided to uninstall BD and then I carried out your first instructions and ran the ESET scan. The scan came up clean. The laptop seems to be running good but there are a number of things I am suspicious of. For some reason there is Norton 360 reporting in security center now. I have not loaded this and this laptop was not purchased new so it may have had Norton installed at some point but I do not remember seeing this when I initially installed BD for the first time. I also ran Appremover to try to remove this and it did not find any remnants or installations of Norton 360. I also did a file search on the machine and I cannot find any files with "norton". Also when I went to do the ESET scan it warned me that I had windows defender enabled when at that stage I had only enabled windows firewall. After I did the ESET scan I then enabled and updated windows defender. Finally, after I uninstalled BD and later went to do a scan with MBAM it has been disabled with a โ€œruntime error of 0โ€ and then โ€œruntime error of 440โ€. I have not re-installed BD and at this point the laptop is running good and performs well while on the internet so I am thinking that the Norton may be causing BD to shutdown? Do you believe this still a malware/virus issue and would you have any suggestions at this point? I ran and copied/pasted a current DDS report below. Thanks again for your assistance! DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 19:13:05.32 on Thu 01/20/2011 Internet Explorer: 8.0.6001.18999 Microsoftยฎ Windows Vistaโ„ข Home Premium 6.0.6002.2.1252.1.1033.18.1013.465 [GMT -6:00] AV: Norton 360 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Norton 360 *enabled* (Updated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A} FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agrsmsvc.exe C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\lxbucoms.exe C:\TOSHIBA\IVP\ISM\pinger.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\svchost.exe -k imgsvc c:\TOSHIBA\IVP\swupdate\swupdtmr.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\taskeng.exe C:\Program Files\Verizon Wireless\VZAccess Manager\Updates\SMUpdate.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Jess\Desktop\Virus Removal\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ mStart Page = about:blank BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: 1 (0x1) - No File TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll TB: {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - No File uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe mRun: [LXBUCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXBUtime.dll,_RunDLLEntry@16 mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab TCP: {05FFC61C-E73A-4B6D-A2D3-1195EAF06FE8} = 69.78.96.14 66.174.92.14 Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~1\GoogleDesktopNetwork3.dll ============= SERVICES / DRIVERS =============== R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312] R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680] R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [2009-12-3 27392] R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [2009-12-3 41728] R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [2009-12-3 39808] R3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\verizo~1\vzacce~1\SMSIVZAM5.SYS [2009-5-25 32408] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-7-25 21504] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-5-22 30192] S3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [2009-12-3 5888] S3 Update Server;BitDefender Update Server v2;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe โ€“> c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] =============== Created Last 30 ================ 2011-01-20 12:47 โ€“dโ€”โ€“ c:\program files\ESET 2011-01-13 20:37 โ€“dshโ€” C:\$RECYCLE.BIN 2011-01-13 10:44 413,696 aโ€”โ€”- c:\windows\system32\odbc32.dll 2011-01-13 10:38 1,169,408 aโ€”โ€”- c:\windows\system32\sdclt.exe 2011-01-09 20:44 256,512 aโ€”โ€”- c:\windows\PEV.exe 2011-01-09 20:44 161,792 aโ€”โ€”- c:\windows\SWREG.exe 2011-01-09 20:44 98,816 aโ€”โ€”- c:\windows\sed.exe 2011-01-09 20:44 89,088 aโ€”โ€”- c:\windows\MBR.exe 2011-01-08 15:43 38,224 aโ€”โ€”- c:\windows\system32\drivers\mbamswissarmy.sys 2011-01-08 15:43 20,952 aโ€”โ€”- c:\windows\system32\drivers\mbam.sys 2011-01-08 15:43 โ€“dโ€”โ€“ c:\program files\Malwarebytes' Anti-Malware 2011-01-04 17:07 โ€“dโ€”โ€“ c:\users\jess\appdata\roaming\IObit 2011-01-04 17:07 โ€“dโ€”โ€“ c:\program files\IObit 2011-01-04 13:21 โ€“dโ€”โ€“ c:\programdata\bdch 2011-01-04 13:21 โ€“dโ€”โ€“ c:\progra~2\bdch 2011-01-04 07:44 16 aโ€”โ€”- c:\windows\system32\asdict.dat 2011-01-03 14:27 โ€“dโ€”โ€“ c:\users\jess\appdata\roaming\QuickScan 2011-01-03 14:26 โ€“dโ€”โ€“ c:\program files\common files\BitDefender 2010-12-25 12:36 โ€“dโ€”โ€“ c:\users\jess\appdata\roaming\Malwarebytes 2010-12-25 12:36 โ€“dโ€”โ€“ c:\programdata\Malwarebytes 2010-12-25 12:36 โ€“dโ€”โ€“ c:\progra~2\Malwarebytes ==================== Find3M ==================== 2011-01-03 14:42 51,200 aโ€”โ€”- c:\windows\inf\infpub.dat 2011-01-03 14:42 143,360 aโ€”โ€”- c:\windows\inf\infstrng.dat 2011-01-03 14:42 143,360 aโ€”โ€”- c:\windows\inf\infstor.dat 2010-11-04 12:56 345,600 aโ€”โ€”- c:\windows\system32\wmicmiplugin.dll 2010-11-04 12:55 352,768 aโ€”โ€”- c:\windows\system32\taskschd.dll 2010-11-04 12:55 270,336 aโ€”โ€”- c:\windows\system32\taskcomp.dll 2010-11-04 12:55 601,600 aโ€”โ€”- c:\windows\system32\schedsvc.dll 2010-11-04 10:34 171,520 aโ€”โ€”- c:\windows\system32\taskeng.exe 2010-11-02 00:01 916,480 aโ€”โ€”- c:\windows\system32\wininet.dll 2010-11-01 23:57 43,520 aโ€”โ€”- c:\windows\system32\licmgr10.dll 2010-11-01 23:57 109,056 aโ€”โ€”- c:\windows\system32\iesysprep.dll 2010-11-01 23:57 71,680 aโ€”โ€”- c:\windows\system32\iesetup.dll 2010-11-01 22:26 133,632 aโ€”โ€”- c:\windows\system32\ieUnatt.exe 2010-10-28 09:44 34,304 aโ€”โ€”- c:\windows\system32\atmlib.dll 2010-10-28 07:27 292,352 aโ€”โ€”- c:\windows\system32\atmfd.dll 2010-10-28 07:20 2,048 aโ€”โ€”- c:\windows\system32\tzres.dll 2010-03-29 18:40 100,256 aโ€”โ€”- c:\program files\common files\LinkInstaller.exe 2010-01-08 16:00 665,600 aโ€”โ€”- c:\windows\inf\drvindex.dat 2009-06-28 12:50 174 aโ€“shโ€” c:\program files\desktop.ini 2008-03-20 12:18 884 aโ€”โ€”- c:\users\jess\appdata\roaming\wklnhst.dat 2007-05-22 16:29 262,144 aโ€”โ€”- c:\progra~2\ntuser.dat 2006-11-02 06:42 287,440 aโ€”โ€”- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 06:42 287,440 aโ€”โ€”- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 06:42 30,674 aโ€”โ€”- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 06:42 30,674 aโ€”โ€”- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 03:20 287,440 aโ€”โ€”- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 03:20 287,440 aโ€”โ€”- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 03:20 30,674 aโ€”โ€”- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 03:20 30,674 aโ€”โ€”- c:\windows\inf\perflib\0000\perfc.dat 2009-11-20 16:35 245,760 aโ€“shโ€” c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat 2010-09-19 08:49 262,144 aโ€“shโ€” c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat ============= FINISH: 19:14:49.32 ===============
Hi ToddB,

No problem!

Before we jump to any conclusions, let's give the Norton Removal Tool a run.
  • Download the Norton Removal Tool
  • On the Windows desktop, double-click the Norton Removal Tool icon.
  • Follow the on-screen instructions.
  • Restart your computer.
NoodleTech- Thank you for the above link as that did the trick on removing Norton. I have the latest DDS log below and there is something that I question. Before I ran and produced this log I turned off both windows firewall and windows defender so I am wondering why SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} is reporting as such? I shut off both windows firewall and defender, rebooted, verified they were both off, and then ran DDS. Is this by chance the fake windows defender that is reporting? My thinking is that if I have both turned off then nothing should be reporting as *enabled*? I had run SAS on this machine earlier so I know why the SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} is reporting. It is the Windows Defender reporting as *enabled* entry that concerns me. I ran MBAM quick scans normally and in safe mode with networking and they both came up clean. Thought I would pass this by you before I re-install Bitdefender. Thank You! DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 14:14:43.70 on Sun 01/23/2011 Internet Explorer: 8.0.6001.18999 Microsoftยฎ Windows Vistaโ„ข Home Premium 6.0.6002.2.1252.1.1033.18.1013.405 [GMT -6:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agrsmsvc.exe C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\lxbucoms.exe C:\TOSHIBA\IVP\ISM\pinger.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\svchost.exe -k imgsvc c:\TOSHIBA\IVP\swupdate\swupdtmr.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Jess\Desktop\Virus Removal\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ mStart Page = about:blank BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: 1 (0x1) - No File TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll TB: {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - No File uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe mRun: [LXBUCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXBUtime.dll,_RunDLLEntry@16 mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~1\GoogleDesktopNetwork3.dll ============= SERVICES / DRIVERS =============== R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312] R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680] R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [2009-12-3 27392] R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [2009-12-3 41728] R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [2009-12-3 39808] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-7-25 21504] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-5-22 30192] S3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [2009-12-3 5888] S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\verizo~1\vzacce~1\SMSIVZAM5.SYS [2009-5-25 32408] S3 Update Server;BitDefender Update Server v2;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe โ€“> c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] =============== Created Last 30 ================ 2011-01-20 12:47 โ€“dโ€”โ€“ c:\program files\ESET 2011-01-13 20:37 โ€“dshโ€” C:\$RECYCLE.BIN 2011-01-13 10:44 413,696 aโ€”โ€”- c:\windows\system32\odbc32.dll 2011-01-13 10:38 1,169,408 aโ€”โ€”- c:\windows\system32\sdclt.exe 2011-01-09 20:44 256,512 aโ€”โ€”- c:\windows\PEV.exe 2011-01-09 20:44 161,792 aโ€”โ€”- c:\windows\SWREG.exe 2011-01-09 20:44 98,816 aโ€”โ€”- c:\windows\sed.exe 2011-01-09 20:44 89,088 aโ€”โ€”- c:\windows\MBR.exe 2011-01-08 15:43 38,224 aโ€”โ€”- c:\windows\system32\drivers\mbamswissarmy.sys 2011-01-08 15:43 20,952 aโ€”โ€”- c:\windows\system32\drivers\mbam.sys 2011-01-08 15:43 โ€“dโ€”โ€“ c:\program files\Malwarebytes' Anti-Malware 2011-01-04 17:07 โ€“dโ€”โ€“ c:\users\jess\appdata\roaming\IObit 2011-01-04 17:07 โ€“dโ€”โ€“ c:\program files\IObit 2011-01-04 13:21 โ€“dโ€”โ€“ c:\programdata\bdch 2011-01-04 13:21 โ€“dโ€”โ€“ c:\progra~2\bdch 2011-01-04 07:44 16 aโ€”โ€”- c:\windows\system32\asdict.dat 2011-01-03 14:27 โ€“dโ€”โ€“ c:\users\jess\appdata\roaming\QuickScan 2011-01-03 14:26 โ€“dโ€”โ€“ c:\program files\common files\BitDefender 2010-12-25 12:36 โ€“dโ€”โ€“ c:\users\jess\appdata\roaming\Malwarebytes 2010-12-25 12:36 โ€“dโ€”โ€“ c:\programdata\Malwarebytes 2010-12-25 12:36 โ€“dโ€”โ€“ c:\progra~2\Malwarebytes ==================== Find3M ==================== 2011-01-03 14:42 51,200 aโ€”โ€”- c:\windows\inf\infpub.dat 2011-01-03 14:42 143,360 aโ€”โ€”- c:\windows\inf\infstrng.dat 2011-01-03 14:42 143,360 aโ€”โ€”- c:\windows\inf\infstor.dat 2010-11-04 12:56 345,600 aโ€”โ€”- c:\windows\system32\wmicmiplugin.dll 2010-11-04 12:55 352,768 aโ€”โ€”- c:\windows\system32\taskschd.dll 2010-11-04 12:55 270,336 aโ€”โ€”- c:\windows\system32\taskcomp.dll 2010-11-04 12:55 601,600 aโ€”โ€”- c:\windows\system32\schedsvc.dll 2010-11-04 10:34 171,520 aโ€”โ€”- c:\windows\system32\taskeng.exe 2010-11-02 00:01 916,480 aโ€”โ€”- c:\windows\system32\wininet.dll 2010-11-01 23:57 43,520 aโ€”โ€”- c:\windows\system32\licmgr10.dll 2010-11-01 23:57 109,056 aโ€”โ€”- c:\windows\system32\iesysprep.dll 2010-11-01 23:57 71,680 aโ€”โ€”- c:\windows\system32\iesetup.dll 2010-11-01 22:26 133,632 aโ€”โ€”- c:\windows\system32\ieUnatt.exe 2010-10-28 09:44 34,304 aโ€”โ€”- c:\windows\system32\atmlib.dll 2010-10-28 07:27 292,352 aโ€”โ€”- c:\windows\system32\atmfd.dll 2010-10-28 07:20 2,048 aโ€”โ€”- c:\windows\system32\tzres.dll 2010-03-29 18:40 100,256 aโ€”โ€”- c:\program files\common files\LinkInstaller.exe 2010-01-08 16:00 665,600 aโ€”โ€”- c:\windows\inf\drvindex.dat 2009-06-28 12:50 174 aโ€“shโ€” c:\program files\desktop.ini 2008-03-20 12:18 884 aโ€”โ€”- c:\users\jess\appdata\roaming\wklnhst.dat 2007-05-22 16:29 262,144 aโ€”โ€”- c:\progra~2\ntuser.dat 2006-11-02 06:42 287,440 aโ€”โ€”- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 06:42 287,440 aโ€”โ€”- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 06:42 30,674 aโ€”โ€”- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 06:42 30,674 aโ€”โ€”- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 03:20 287,440 aโ€”โ€”- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 03:20 287,440 aโ€”โ€”- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 03:20 30,674 aโ€”โ€”- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 03:20 30,674 aโ€”โ€”- c:\windows\inf\perflib\0000\perfc.dat 2009-11-20 16:35 245,760 aโ€“shโ€” c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat ============= FINISH: 14:15:44.22 ===============
Hi ToddB,

Your computer appears to be clean! I wouldn't worry about Windows Defender. It isn't the fake antispyware you were infected with previously.

How is your computer running at the moment?

===================================================

Go ahead and reinstall BitDefender. If it still gives you problems, uninstall it and download/install Microsoft Security Essentials instead. It is a free antivirus/antispyware program that I find to be most effective.

Download Microsoft Security Essentials
Link

Double click mseinstall.exe to start the installation.

Follow the prompts to install and update the program.

===================================================

Also, some of your programs are also outdated.

Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 23 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 23 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u23 with JavaFX 1 License Agreement". Click on Continue. The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Javaโ„ข 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u23-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
NoodlTech- Actually this is my parent laptop and it is running GREAT! I have not had the time to reinstall Bitdefender but will follow your direction above if I should have an issue with it when I re-install. I also will update ADOBE and Java as you directed. I was just concerned with way windows defender was showing in the last DDS log and thank you for setting my mind as ease here. I want to thank you for your GREAT assistance with this! I really appreciate the help that is offered here at WTT! :clap: You have my permission to close one if you are in agreement.
Hi ToddB,

No problem! :thumbup:

Now let's do some spring cleaning.

The following will implement some cleanup procedures as well as reset System Restore points:
[external image: Posted Image]
Click Start > Run and copy/paste the following bolded text into the Run box and click OK: ComboFix /Uninstall

===================================================

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • Click Start > Run
  • Type Inetcpl.cpl and click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected and Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to Prompt, and ("Initialize and Script ActiveX controls not marked as safe") to Disable.
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
NoodleTech- Completed your instructions above and thank you for the helpful advice. Your assistance with this matter is MUCH appreciated! ToddB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI