I will begin this as soon as I get home today. Thank you very much.
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=1
esets_scanner_update returned -1 esets_gle=1
esets_scanner_update returned -1 esets_gle=1
esets_scanner_update returned -1 esets_gle=1
esets_scanner_update returned -1 esets_gle=1
esets_scanner_update returned -1 esets_gle=1
esets_scanner_update returned -1 esets_gle=1
esets_scanner_update returned -1 esets_gle=1
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6419
# api_version=3.0.2
# EOSSerial=bdcb6cb29db0524ca19dc85eecefdf85
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-02-04 02:45:14
# local_time=2011-02-03 07:45:14 (-0700, Mountain Standard Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776574 100 100 0 133374364 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=278515
# found=11
# cleaned=0
# scan_time=20677
C:\Program Files\Uniblue\RegistryBooster\Launcher.exe a variant of Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I
C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Windows\system32\Drivers\afd.sys.vir Win32/Olmarik.ZC trojan (unable to clean) 00000000000000000000000000000000 I
C:\Users\Owner\Desktop\powersuite.exe multiple threats (unable to clean) 00000000000000000000000000000000 I
C:\Users\Owner\Music\Autodesk Revit Architecture.iso probably a variant of Win32/Agent.EMANMCD trojan (unable to clean) 00000000000000000000000000000000 I
C:\Users\Owner\Music\Autodesk.AutoCAD.Architecture.2011.Win32-ISO\Autodesk AutoCAD Architecture v2011 x86.iso probably a variant of Win32/Agent.EMANMCD trojan (unable to clean) 00000000000000000000000000000000 I
C:\Users\Owner\Music\Google SketchUp Pro 8.0.3117 With Crack\Google SketchUp Pro 8.0.3117 With Crack.rar multiple threats (unable to clean) 00000000000000000000000000000000 I
C:\Users\Owner\Music\Informatix Piranesi 5.0\Informatix.Piranesi.v5.iSO-ENGiNE.[sharethefiles.com].iso a variant of Win32/HackTool.Patcher.A application (unable to clean) 00000000000000000000000000000000 I
C:\Windows\System32\drivers\pmpqnmsxz.sys Win32/Bubnix.BK trojan (unable to clean) 00000000000000000000000000000000 I
C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18005_none_d9d3bb9e5b8eea9c\afd.sys Win32/Olmarik.ZC trojan (unable to clean) 00000000000000000000000000000000 I
lehmbergj,
It appears that you have at least one pirated program on there that may be at the root of all your troubles.
Your computer appears to have been infected by a
backdoor trojan . These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use. Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account. Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.
If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.
Odds are also fairly good that people in your address book have been receiving spam mail from you. Because part of the payload that the backdoor trojan "steals" is your address book, there is a fair chance that they will continue to receive spam mail even after we have cleaned the trojan off of your system.
COMBOFIX-Script
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 11-02-05.01 - Owner 02/05/2011 13:55:50.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2939.1990 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FILE ::
"c:\users\Owner\Desktop\powersuite.exe"
"c:\users\Owner\Music\Autodesk Revit Architecture.iso"
"c:\users\Owner\Music\Autodesk.AutoCAD.Architecture.2011.Win32-ISO\Autodesk AutoCAD Architecture v2011 x86.iso"
"c:\windows\System32\drivers\pmpqnmsxz.sys"
"c:\windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18005_none_d9d3bb9e5b8eea9c\afd.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Uniblue\RegistryBooster
c:\program files\Uniblue\RegistryBooster\cache.dll
c:\program files\Uniblue\RegistryBooster\cwebpage.dll
c:\program files\Uniblue\RegistryBooster\InstallerExtensions.dll
c:\program files\Uniblue\RegistryBooster\intermediate_views.dat
c:\program files\Uniblue\RegistryBooster\Launcher.exe
c:\program files\Uniblue\RegistryBooster\library.dat
c:\program files\Uniblue\RegistryBooster\locale\dk\dk.dll
c:\program files\Uniblue\RegistryBooster\locale\dk\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\dk\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\dk\messages.dk.po
c:\program files\Uniblue\RegistryBooster\locale\en\en.dll
c:\program files\Uniblue\RegistryBooster\locale\en\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\en\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\en\messages.en.po
c:\program files\Uniblue\RegistryBooster\locale\es\es.dll
c:\program files\Uniblue\RegistryBooster\locale\es\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\es\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\es\messages.es.po
c:\program files\Uniblue\RegistryBooster\locale\fr\fr.dll
c:\program files\Uniblue\RegistryBooster\locale\fr\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\fr\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\fr\messages.fr.po
c:\program files\Uniblue\RegistryBooster\locale\gr\gr.dll
c:\program files\Uniblue\RegistryBooster\locale\gr\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\gr\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\gr\messages.gr.po
c:\program files\Uniblue\RegistryBooster\locale\it\it.dll
c:\program files\Uniblue\RegistryBooster\locale\it\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\it\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\it\messages.it.po
c:\program files\Uniblue\RegistryBooster\locale\jp\jp.dll
c:\program files\Uniblue\RegistryBooster\locale\jp\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\jp\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\jp\messages.jp.po
c:\program files\Uniblue\RegistryBooster\locale\nl\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\nl\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\nl\messages.nl.po
c:\program files\Uniblue\RegistryBooster\locale\nl\nl.dll
c:\program files\Uniblue\RegistryBooster\locale\no\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\no\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\no\messages.no.po
c:\program files\Uniblue\RegistryBooster\locale\no\no.dll
c:\program files\Uniblue\RegistryBooster\locale\pt\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\pt\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\pt\messages.pt.po
c:\program files\Uniblue\RegistryBooster\locale\pt\pt.dll
c:\program files\Uniblue\RegistryBooster\locale\ru\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\ru\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\ru\messages.ru.po
c:\program files\Uniblue\RegistryBooster\locale\ru\pt.dll
c:\program files\Uniblue\RegistryBooster\locale\ru\ru.dll
c:\program files\Uniblue\RegistryBooster\locale\se\LC_MESSAGES\messages.mo
c:\program files\Uniblue\RegistryBooster\locale\se\LC_MESSAGES\rbmessages.mo
c:\program files\Uniblue\RegistryBooster\locale\se\messages.se.po
c:\program files\Uniblue\RegistryBooster\locale\se\se.dll
c:\program files\Uniblue\RegistryBooster\Microsoft.VC90.CRT.manifest
c:\program files\Uniblue\RegistryBooster\msvcp90.dll
c:\program files\Uniblue\RegistryBooster\msvcr90.dll
c:\program files\Uniblue\RegistryBooster\registrybooster.exe
c:\program files\Uniblue\RegistryBooster\repair_transform.xsl
c:\program files\Uniblue\RegistryBooster\ui_dll.dll
c:\program files\Uniblue\RegistryBooster\unins000.dat
c:\program files\Uniblue\RegistryBooster\unins000.exe
c:\program files\Uniblue\RegistryBooster\views.dat
c:\program files\Uniblue\SpeedUpMyPC
c:\program files\Uniblue\SpeedUpMyPC\cache.dll
c:\program files\Uniblue\SpeedUpMyPC\cwebpage.dll
c:\program files\Uniblue\SpeedUpMyPC\InstallerExtensions.dll
c:\program files\Uniblue\SpeedUpMyPC\intermediate_views.dat
c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
c:\program files\Uniblue\SpeedUpMyPC\library.dat
c:\program files\Uniblue\SpeedUpMyPC\locale\br\br.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\br\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\de\de.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\de\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\dk\dk.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\dk\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\en\en.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\en\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\en\LC_MESSAGES\sumpmessages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\es\es.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\es\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\fi\fi.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\fi\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\fr\fr.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\fr\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\gr\gr.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\gr\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\it\it.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\it\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\it\LC_MESSAGES\sumpmessages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\jp\jp.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\jp\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\nl\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\nl\nl.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\no\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\no\no.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\pl\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\pl\pl.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\pt\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\pt\pt.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\ru\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\ru\ru.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\se\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\se\se.dll
c:\program files\Uniblue\SpeedUpMyPC\locale\tr\LC_MESSAGES\messages.mo
c:\program files\Uniblue\SpeedUpMyPC\locale\tr\tr.dll
c:\program files\Uniblue\SpeedUpMyPC\Microsoft.VC90.CRT.manifest
c:\program files\Uniblue\SpeedUpMyPC\msvcp90.dll
c:\program files\Uniblue\SpeedUpMyPC\msvcr90.dll
c:\program files\Uniblue\SpeedUpMyPC\st.dat
c:\program files\Uniblue\SpeedUpMyPC\sump.exe
c:\program files\Uniblue\SpeedUpMyPC\unins000.dat
c:\program files\Uniblue\SpeedUpMyPC\unins000.exe
c:\program files\Uniblue\SpeedUpMyPC\views.dat
c:\users\Owner\AppData\Local\Temp\6EF7.tmp
c:\users\Owner\Desktop\powersuite.exe
c:\users\Owner\Music\Autodesk Revit Architecture.iso
c:\users\Owner\Music\Autodesk.AutoCAD.Architecture.2011.Win32-ISO\Autodesk AutoCAD Architecture v2011 x86.iso
c:\users\Owner\Music\Google SketchUp Pro 8.0.3117 With Crack
c:\users\Owner\Music\Google SketchUp Pro 8.0.3117 With Crack\Google SketchUp Pro 8.0.3117 With Crack.rar
c:\users\Owner\Music\Informatix Piranesi 5.0
c:\users\Owner\Music\Informatix Piranesi 5.0\Informatix.Piranesi.v5.iSO-ENGiNE.[sharethefiles.com].iso
c:\users\Owner\Music\Informatix Piranesi 5.0\Torrent downloaded from Demonoid.com.txt
c:\windows\System32\drivers\pmpqnmsxz.sys
c:\windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18005_none_d9d3bb9e5b8eea9c\afd.sys
.
((((((((((((((((((((((((( Files Created from 2011-01-05 to 2011-02-05 )))))))))))))))))))))))))))))))
.
2011-02-05 21:01 . 2011-02-05 21:02 ——– d—–w- c:\users\Owner\AppData\Local\temp
2011-02-05 21:01 . 2011-02-05 21:01 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-02-03 20:12 . 2011-02-03 20:12 ——– d—–w- c:\windows\Sun
2011-02-03 19:47 . 2011-02-03 19:47 ——– d—–w- c:\program files\ESET
2011-02-03 19:44 . 2011-02-03 19:44 ——– d—–w- c:\program files\Common Files\Java
2011-02-03 19:43 . 2011-02-03 19:43 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-03 19:43 . 2011-02-03 19:43 472808 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-02-01 09:11 . 2011-01-20 17:39 5890896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{11789360-86F4-4CA1-B47C-2AD21A40A891}\mpengine.dll
2011-02-01 04:59 . 2011-02-01 04:59 ——– d—–w- C:\8982a9c9ce2175880827
2011-01-25 23:25 . 2009-06-05 01:43 330264 —-a-w- c:\windows\system32\drivers\iaStor.sys
2011-01-24 05:49 . 2011-01-24 05:49 ——– d—–w- c:\users\Owner\AppData\Roaming\Malwarebytes
2011-01-24 05:49 . 2010-12-21 01:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-24 05:49 . 2011-01-24 05:49 ——– d—–w- c:\programdata\Malwarebytes
2011-01-24 05:49 . 2011-01-24 05:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-01-24 05:49 . 2010-12-21 01:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-01-24 05:21 . 2011-01-24 05:37 ——– d—–w- c:\program files\Wise Disk Cleaner
2011-01-24 05:13 . 2011-01-24 05:19 ——– d—–w- c:\program files\Wise Registry Cleaner
2011-01-24 04:55 . 2011-01-24 04:55 ——– d—–w- c:\users\Owner\AppData\Roaming\Uniblue
2011-01-24 04:55 . 2011-02-05 21:01 ——– d—–w- c:\program files\Uniblue
2011-01-16 09:37 . 2011-01-16 09:37 ——– d—–w- c:\programdata\WindowsSearch
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TWebCamera"="%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe autorun" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-13 150040]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-13 154136]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-13 6965792]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-18 1451304]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe" [2009-03-24 1007616]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-13 178712]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-04-02 1283384]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-11 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
DRSpawner.lnk - c:\programdata\ASGvis\DRSpawner\DRSpawner.exe [2010-11-29 2076672]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
R0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys [x]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 CFcatchme;CFcatchme;c:\users\Owner\AppData\Local\Temp\CFcatchme.sys [x]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 Partner Service;Partner Service;c:\programdata\Partner\partner.exe [2009-06-16 110576]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 camsvc;TOSHIBA Web Camera Service;c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe [2009-04-17 20544]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
S2 RSELSVC;TOSHIBA Modem region select service;c:\program files\TOSHIBA\RSelect\RSelSvc.exe [2009-02-19 57344]
S2 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-04-02 62776]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-04-15 176128]
S2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-03-17 73728]
S2 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-04-10 656752]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-03-21 12920]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [2009-03-18 22272]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\hc3cvsps.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - ORPHANS REMOVED - - - -
AddRemove-{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1 - c:\program files\Uniblue\SpeedUpMyPC\unins000.exe
AddRemove-{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1 - c:\program files\Uniblue\RegistryBooster\unins000.exe
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
———————— Other Running Processes ————————
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\iPod\bin\iPodService.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2011-02-05 14:08:36 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-05 21:08
ComboFix2.txt 2011-02-02 04:51
ComboFix3.txt 2011-02-02 02:29
ComboFix4.txt 2011-01-26 23:19
Pre-Run: 143,613,288,448 bytes free
Post-Run: 143,572,238,336 bytes free
- - End Of File - - 13C90050EF5DDCA80EE6640A96F9FA28
lehmbergj,
Please print me a new set of DDS logs and let me know how things are running now?
Will do just tell me what scans to use and what logs to use. I will start using the computer now to see if the fix worked. Ty
DDS is the tool that you downloaded in post #2 (and had to rename). You provided the logs in post #5.
I would like to see new one.
I've been sick sorry, Will run DDS now and post log after. TY
DDS (Ver_10-12-12.02) - NTFSx86
Run by [removed] at 22:42:17.23 on Wed 02/09/2011
Internet Explorer: 8.0.6001.18999 BrowserJavaVersion: 1.6.0_23
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2939.1535 [GMT -7:00]
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Windows\system32\agrsmsvc.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Owner\Desktop\dds (2).com
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: MRI_DISABLED - No File
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10h_Plugin.exe -update plugin
mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe"
mRun: [Persistence] "c:\windows\system32\igfxpers.exe"
mRun: [RtHDVCpl] "c:\program files\realtek\audio\hda\RtHDVCpl.exe"
mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe"
mRun: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [TosSENotify] "c:\program files\toshiba\toshiba hdd ssd alert\TosSENotify.exe"
mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe"
mRun: [Adobe_ID0EYTHM] "c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\drspaw~1.lnk - c:\programdata\asgvis\drspawner\DRSpawner.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\hc3cvsps.default\
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\picasa2\npPicasa2.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
============= SERVICES / DRIVERS ===============
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 21504]
R2 camsvc;TOSHIBA Web Camera Service;c:\program files\toshiba\toshiba web camera application\TWebCameraSrv.exe [2009-6-15 20544]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 RSELSVC;TOSHIBA Modem region select service;c:\program files\toshiba\rselect\RSelSvc.exe [2009-2-19 57344]
R2 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2010-10-12 62776]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-4-14 176128]
R2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-3-17 73728]
R2 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-4-9 656752]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-3-20 12920]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-5-3 7168]
R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-11-17 3668480]
R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2009-6-15 22272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);"c:\program files\google\update\googleupdate.exe" /svc –> c:\program files\google\update\GoogleUpdate.exe [?]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 Partner Service;Partner Service;c:\programdata\partner\partner.exe [2009-6-15 110576]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== File Associations ===============
.scr=AutoCADScriptFile
=============== Created Last 30 ================
2011-02-05 21:12:14 ——– d—–w- c:\users\owner\appdata\local\temp
2011-02-05 21:08:04 ——– d-sh–w- C:\$RECYCLE.BIN
2011-02-03 19:47:45 ——– d—–w- c:\program files\ESET
2011-02-03 19:43:54 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-03 19:43:54 472808 —-a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-02-02 02:05:02 98816 —-a-w- c:\windows\sed.exe
2011-02-02 02:05:02 89088 —-a-w- c:\windows\MBR.exe
2011-02-02 02:05:02 256512 —-a-w- c:\windows\PEV.exe
2011-02-02 02:05:02 161792 —-a-w- c:\windows\SWREG.exe
2011-02-01 09:11:26 5890896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{11789360-86f4-4ca1-b47c-2ad21a40a891}\mpengine.dll
2011-02-01 04:59:30 ——– d—–w- C:\8982a9c9ce2175880827
2011-01-25 23:25:50 330264 —-a-w- c:\windows\system32\drivers\iaStor.sys
2011-01-24 05:49:49 ——– d—–w- c:\users\owner\appdata\roaming\Malwarebytes
2011-01-24 05:49:45 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-24 05:49:44 ——– d—–w- c:\progra~2\Malwarebytes
2011-01-24 05:49:42 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-01-24 05:49:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-01-24 05:21:06 ——– d—–w- c:\program files\Wise Disk Cleaner
2011-01-24 05:13:38 ——– d—–w- c:\program files\Wise Registry Cleaner
2011-01-24 04:55:49 ——– d—–w- c:\users\owner\appdata\roaming\Uniblue
2011-01-24 04:55:20 ——– d—–w- c:\program files\Uniblue
==================== Find3M ====================
2010-12-28 15:55:03 413696 —-a-w- c:\windows\system32\odbc32.dll
2010-12-14 14:49:23 1169408 —-a-w- c:\windows\system32\sdclt.exe
============= FINISH: 22:42:40.47 ===============
lehmbergj,
How do things seem to be running now?
Things are running smoothly so far. Thank you very much for all your help/ guidance, and support in fixing my pc issues. Are there any suggestions you could give me for anti-virus/ adware and daily security? Thanks again.
lehmbergj,
Absolutely.
Time for some housekeeping Click START then RUN Now type ComboFix /Uninstall in the runbox and click OK . Note the space between the X and the U , it needs to be there. [external image: Posted Image]
The above procedure will :
Implement some cleanup procedures. Reset System Restore.
Now to remove most of the tools that we have used in fixing your machine: Make sure you have an Internet Connection. Download OTC to your desktop and run it A list of tool components used in the cleanup of malware will be downloaded. If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so. Click Yes to begin the cleanup process and remove these components, including this application. You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.
Please re-enable any security that was disabled.
The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.
Please take time to read
Preventing Malware - Tools and Practices for Safe Computing . Very important information for your consideration is contained therein.
I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Also:
"How to prevent malware"
by miekiemoes
Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.