This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Sluggish computer, browser redirects and possible rootkit maybe?

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

COMODO is periodically reporting that I have a Win32.Powp.Gen1 virus, however even though I select clean it keeps re-appearing. It is an XP computer. The browsers and the computer generally is sluggish. Random links appear on browser clicks. Thanks in advance for anyone's assistance! DDS.txt is: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 23:24:50.96 on Thu 03/02/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23 ============== Running Processes =============== ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com.au/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - d:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~2\office14\GROOVEEX.DLL BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - d:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - d:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - d:\progra~1\micros~2\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - d:\program files\google\google toolbar\GoogleToolbar_32.dll EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - d:\windows\system32\Shdocvw.dll uRun: [CTFMON.EXE] d:\windows\system32\ctfmon.exe uRun: [swg] "d:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [OM2_Monitor] "d:\program files\olympus\olympus master 2\MMonitor.exe" uRun: [Google Update] "d:\documents and settings\hugh\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [igfxtray] d:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] d:\windows\system32\hkcmd.exe mRun: [igfxpers] d:\windows\system32\igfxpers.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [SSBkgdUpdate] "d:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [OpwareSE4] "d:\program files\scansoft\omnipagese4.0\OpwareSE4.exe" mRun: [BigDogPath] d:\windows\VM_STI.EXE VIMICRO USB PC Camera 301x mRun: [ecc] d:\program files\telstra\bigpond assist\assist.exe mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "d:\program files\common files\java\java update\jusched.exe" mRun: [COMODO Internet Security] "d:\program files\comodo\comodo internet security\cfp.exe" -h mRun: [QuickTime Task] "d:\program files\quicktime\qttask.exe" -atboottime dRun: [CTFMON.EXE] d:\windows\system32\CTFMON.EXE IE: Add to Google Photos Screensa&ver - d:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: Google Sidewiki… - d:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html IE: Se&nd to OneNote - d:\progra~1\micros~2\office14\ONBttnIE.dll/105 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - d:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll Trusted Zone: bigpond.com Trusted Zone: bigpond.com\www Trusted Zone: com.au\*.seek Trusted Zone: com.au\www.seek Trusted Zone: custhelp.com Trusted Zone: microsoft.com Trusted Zone: microsoft.com\*.update Trusted Zone: microsoft.com\*.windowsupdate Trusted Zone: microsoft.com\www.update Trusted Zone: windowsupdate.com DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813 DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file://d:\program files\monopoly\images\stg_drm.ocx DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.fujifilmimagine.com/imagine/ax/ImageUploader5.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1229819345734 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file://d:\program files\monopoly\images\armhelper.ocx DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://boeing.webex.com/client/T23LBA/webex/ieatgpc.cab DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://sslvpn.boeing.com/dana-cached/setup/JuniperSetupSP1.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - d:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - d:\windows\downloaded program files\mimectl.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: d:\windows\system32\guard32.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~2\office14\GROOVEEX.DLL ================= FIREFOX =================== FF - ProfilePath - d:\docume~1\hugh\applic~1\mozilla\firefox\profiles\wvdk3jbo.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/ FF - plugin: d:\documents and settings\hugh\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: d:\progra~1\micros~2\office14\NPAUTHZ.DLL FF - plugin: d:\progra~1\micros~2\office14\NPSPWRAP.DLL FF - plugin: d:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: d:\program files\google\picasa3\npPicasa3.dll FF - plugin: d:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: d:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll FF - plugin: d:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: d:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: d:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: d:\program files\virtools\3d life player\npvirtools.dll FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} —- FIREFOX POLICIES —- d:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); d:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); d:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); d:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); d:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); d:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); d:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); d:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); d:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); d:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); d:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); d:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); d:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); d:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); d:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); d:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); d:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); d:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); d:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); d:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2011-02-03 14:16 664 a——- d:\windows\system32\d3d9caps.dat 2011-01-09 13:38 238,936 a——- d:\windows\system32\xactengine3_5.dll 2011-01-09 13:36 –d—– d:\windows\Logs 2011-01-09 12:53 2,297,552 a——- d:\windows\system32\d3dx9_26.dll 2011-01-09 11:04 124 a——- d:\windows\JORACLE.INI 2011-01-09 11:04 –d—– D:\JEWELS 2011-01-09 10:59 –d—– d:\program files\Microsoft Games 2011-01-09 10:56 132,096 a——- d:\windows\system32\eaexec.exe 2011-01-09 10:56 24,576 a——- d:\windows\system32\ealtest.exe 2011-01-09 10:55 –d—– D:\JANES 2011-01-09 10:53 –d—– d:\documents and settings\hugh\WINDOWS ==================== Find3M ==================== 2011-02-03 23:04 285,480 a——- d:\windows\system32\guard32.dll 2011-02-03 23:04 27,576 a——- d:\windows\system32\drivers\cmdhlp.sys 2011-02-03 23:04 15,592 a——- d:\windows\system32\drivers\cmderd.sys 2011-02-03 23:04 239,368 a——- d:\windows\system32\drivers\cmdGuard.sys 2011-02-03 22:13 1,474,832 a——- d:\windows\system32\drivers\sfi.dat 2010-11-19 04:12 81,920 a——- d:\windows\system32\isign32.dll 2010-11-12 18:53 472,808 a——- d:\windows\system32\deployJava1.dll 2010-11-10 00:52 249,856 a——- d:\windows\system32\odbc32.dll 2010-11-06 10:26 916,480 a——- d:\windows\system32\wininet.dll 2010-11-06 10:26 43,520 a——- d:\windows\system32\licmgr10.dll 2008-01-06 09:16 32 a——- d:\docume~1\alluse~1\applic~1\ezsid.dat ============= FINISH: 23:27:46.40 ===============

Attachments:

Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post








Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Thanks for looking into this - here's the log: 2011/02/04 20:36:50.0296 0312 TDSS rootkit removing tool 2.4.16.0 Feb 1 2011 10:34:03 2011/02/04 20:36:50.0359 0312 ================================================================================ 2011/02/04 20:36:50.0359 0312 SystemInfo: 2011/02/04 20:36:50.0359 0312 2011/02/04 20:36:50.0359 0312 OS Version: 5.1.2600 ServicePack: 3.0 2011/02/04 20:36:50.0359 0312 Product type: Workstation 2011/02/04 20:36:50.0359 0312 ComputerName: WEBSTER-MAIN 2011/02/04 20:36:50.0359 0312 UserName: Hugh 2011/02/04 20:36:50.0359 0312 Windows directory: D:\WINDOWS 2011/02/04 20:36:50.0359 0312 System windows directory: D:\WINDOWS 2011/02/04 20:36:50.0359 0312 Processor architecture: Intel x86 2011/02/04 20:36:50.0359 0312 Number of processors: 2 2011/02/04 20:36:50.0359 0312 Page size: 0x1000 2011/02/04 20:36:50.0359 0312 Boot type: Safe boot with network 2011/02/04 20:36:50.0359 0312 ================================================================================ 2011/02/04 20:36:50.0812 0312 Initialize success 2011/02/04 20:37:02.0218 0452 ================================================================================ 2011/02/04 20:37:02.0218 0452 Scan started 2011/02/04 20:37:02.0218 0452 Mode: Manual; 2011/02/04 20:37:02.0218 0452 ================================================================================ 2011/02/04 20:37:03.0750 0452 61883 (914a9709fc3bf419ad2f85547f2a4832) D:\WINDOWS\system32\DRIVERS\61883.sys 2011/02/04 20:37:03.0953 0452 ACPI (8fd99680a539792a30e97944fdaecf17) D:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/02/04 20:37:04.0109 0452 ACPIEC (9859c0f6936e723e4892d7141b1327d5) D:\WINDOWS\system32\drivers\ACPIEC.sys 2011/02/04 20:37:04.0250 0452 aec (8bed39e3c35d6a489438b8141717a557) D:\WINDOWS\system32\drivers\aec.sys 2011/02/04 20:37:04.0343 0452 AFD (7e775010ef291da96ad17ca4b17137d7) D:\WINDOWS\System32\drivers\afd.sys 2011/02/04 20:37:04.0687 0452 ALCXWDM (34fc779e3ce6964546e02596acc8ff48) D:\WINDOWS\system32\drivers\ALCXWDM.SYS 2011/02/04 20:37:05.0015 0452 Arp1394 (b5b8a80875c1dededa8b02765642c32f) D:\WINDOWS\system32\DRIVERS\arp1394.sys 2011/02/04 20:37:05.0187 0452 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) D:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/02/04 20:37:05.0234 0452 atapi (9f3a2f5aa6875c72bf062c712cfa2674) D:\WINDOWS\system32\DRIVERS\atapi.sys 2011/02/04 20:37:05.0343 0452 Atmarpc (9916c1225104ba14794209cfa8012159) D:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/02/04 20:37:05.0421 0452 audstub (d9f724aa26c010a217c97606b160ed68) D:\WINDOWS\system32\DRIVERS\audstub.sys 2011/02/04 20:37:05.0500 0452 Avc (f8e6956a614f15a0860474c5e2a7de6b) D:\WINDOWS\system32\DRIVERS\avc.sys 2011/02/04 20:37:05.0593 0452 Beep (da1f27d85e0d1525f6621372e7b685e9) D:\WINDOWS\system32\drivers\Beep.sys 2011/02/04 20:37:05.0687 0452 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) D:\WINDOWS\system32\drivers\cbidf2k.sys 2011/02/04 20:37:05.0765 0452 CCDECODE (0be5aef125be881c4f854c554f2b025c) D:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/02/04 20:37:05.0921 0452 Cdaudio (c1b486a7658353d33a10cc15211a873b) D:\WINDOWS\system32\drivers\Cdaudio.sys 2011/02/04 20:37:05.0953 0452 Cdfs (c885b02847f5d2fd45a24e219ed93b32) D:\WINDOWS\system32\drivers\Cdfs.sys 2011/02/04 20:37:06.0000 0452 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) D:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/02/04 20:37:06.0140 0452 cmderd (61b20ca85950870fa23587b26f3e4d7d) D:\WINDOWS\system32\DRIVERS\cmderd.sys 2011/02/04 20:37:06.0250 0452 cmdGuard (dd530ee7d9efbb0ec42aebe7226b8a93) D:\WINDOWS\system32\DRIVERS\cmdguard.sys 2011/02/04 20:37:06.0328 0452 cmdHlp (07cbbe993ed08a52dafac1e6cf27b6a5) D:\WINDOWS\system32\DRIVERS\cmdhlp.sys 2011/02/04 20:37:06.0656 0452 Disk (044452051f3e02e7963599fc8f4f3e25) D:\WINDOWS\system32\DRIVERS\disk.sys 2011/02/04 20:37:06.0765 0452 dmboot (d992fe1274bde0f84ad826acae022a41) D:\WINDOWS\system32\drivers\dmboot.sys 2011/02/04 20:37:06.0859 0452 dmio (7c824cf7bbde77d95c08005717a95f6f) D:\WINDOWS\system32\drivers\dmio.sys 2011/02/04 20:37:06.0968 0452 dmload (e9317282a63ca4d188c0df5e09c6ac5f) D:\WINDOWS\system32\drivers\dmload.sys 2011/02/04 20:37:07.0062 0452 DMusic (8a208dfcf89792a484e76c40e5f50b45) D:\WINDOWS\system32\drivers\DMusic.sys 2011/02/04 20:37:07.0203 0452 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) D:\WINDOWS\system32\drivers\drmkaud.sys 2011/02/04 20:37:07.0343 0452 Fastfat (38d332a6d56af32635675f132548343e) D:\WINDOWS\system32\drivers\Fastfat.sys 2011/02/04 20:37:07.0468 0452 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) D:\WINDOWS\system32\drivers\Fdc.sys 2011/02/04 20:37:07.0515 0452 Fips (d45926117eb9fa946a6af572fbe1caa3) D:\WINDOWS\system32\drivers\Fips.sys 2011/02/04 20:37:07.0562 0452 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) D:\WINDOWS\system32\drivers\Flpydisk.sys 2011/02/04 20:37:07.0671 0452 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) D:\WINDOWS\system32\drivers\fltmgr.sys 2011/02/04 20:37:07.0781 0452 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) D:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/02/04 20:37:07.0812 0452 Ftdisk (6ac26732762483366c3969c9e4d2259d) D:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/02/04 20:37:07.0875 0452 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) D:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 2011/02/04 20:37:07.0984 0452 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) D:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/02/04 20:37:08.0203 0452 HTTP (f80a415ef82cd06ffaf0d971528ead38) D:\WINDOWS\system32\Drivers\HTTP.sys 2011/02/04 20:37:08.0359 0452 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) D:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/02/04 20:37:08.0546 0452 ialm (9a883c3c4d91292c0d09de7c728e781c) D:\WINDOWS\system32\DRIVERS\ialmnt5.sys 2011/02/04 20:37:08.0859 0452 Imapi (083a052659f5310dd8b6a6cb05edcf8e) D:\WINDOWS\system32\DRIVERS\imapi.sys 2011/02/04 20:37:09.0078 0452 Inspect (8154a2c13b72b08db11157673c60c3eb) D:\WINDOWS\system32\DRIVERS\inspect.sys 2011/02/04 20:37:09.0171 0452 IntelIde (b5466a9250342a7aa0cd1fba13420678) D:\WINDOWS\system32\DRIVERS\intelide.sys 2011/02/04 20:37:09.0250 0452 intelppm (8c953733d8f36eb2133f5bb58808b66b) D:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/02/04 20:37:09.0296 0452 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) D:\WINDOWS\system32\drivers\ip6fw.sys 2011/02/04 20:37:09.0375 0452 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) D:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/02/04 20:37:09.0500 0452 IpInIp (b87ab476dcf76e72010632b5550955f5) D:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/02/04 20:37:09.0562 0452 IpNat (cc748ea12c6effde940ee98098bf96bb) D:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/02/04 20:37:09.0625 0452 IPSec (23c74d75e36e7158768dd63d92789a91) D:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/02/04 20:37:09.0671 0452 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) D:\WINDOWS\system32\DRIVERS\irenum.sys 2011/02/04 20:37:09.0781 0452 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) D:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/02/04 20:37:09.0859 0452 JL2005C (b12f5ff3a2221987ac3a81ce1fe76cc6) D:\WINDOWS\system32\Drivers\jl2005c.sys 2011/02/04 20:37:09.0906 0452 Kbdclass (463c1ec80cd17420a542b7f36a36f128) D:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/02/04 20:37:10.0000 0452 kmixer (692bcf44383d056aed41b045a323d378) D:\WINDOWS\system32\drivers\kmixer.sys 2011/02/04 20:37:10.0093 0452 KSecDD (b467646c54cc746128904e1654c750c1) D:\WINDOWS\system32\drivers\KSecDD.sys 2011/02/04 20:37:10.0312 0452 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) D:\WINDOWS\system32\drivers\mnmdd.sys 2011/02/04 20:37:10.0406 0452 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) D:\WINDOWS\system32\drivers\Modem.sys 2011/02/04 20:37:10.0500 0452 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) D:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/02/04 20:37:10.0531 0452 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) D:\WINDOWS\system32\drivers\MountMgr.sys 2011/02/04 20:37:10.0609 0452 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) D:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/02/04 20:37:10.0703 0452 MRxSmb (f3aefb11abc521122b67095044169e98) D:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/02/04 20:37:10.0812 0452 MSDV (1477849772712bac69c144dcf2c9ce81) D:\WINDOWS\system32\DRIVERS\msdv.sys 2011/02/04 20:37:10.0859 0452 Msfs (c941ea2454ba8350021d774daf0f1027) D:\WINDOWS\system32\drivers\Msfs.sys 2011/02/04 20:37:10.0953 0452 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) D:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/02/04 20:37:11.0046 0452 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) D:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/02/04 20:37:11.0093 0452 MSPQM (bad59648ba099da4a17680b39730cb3d) D:\WINDOWS\system32\drivers\MSPQM.sys 2011/02/04 20:37:11.0187 0452 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) D:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/02/04 20:37:11.0234 0452 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) D:\WINDOWS\system32\drivers\MSTEE.sys 2011/02/04 20:37:11.0296 0452 Mup (2f625d11385b1a94360bfc70aaefdee1) D:\WINDOWS\system32\drivers\Mup.sys 2011/02/04 20:37:11.0343 0452 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/02/04 20:37:11.0453 0452 NDIS (1df7f42665c94b825322fae71721130d) D:\WINDOWS\system32\drivers\NDIS.sys 2011/02/04 20:37:11.0562 0452 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) D:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/02/04 20:37:11.0640 0452 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) D:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/02/04 20:37:11.0687 0452 Ndisuio (f927a4434c5028758a842943ef1a3849) D:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/02/04 20:37:11.0734 0452 NdisWan (edc1531a49c80614b2cfda43ca8659ab) D:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/02/04 20:37:11.0812 0452 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) D:\WINDOWS\system32\drivers\NDProxy.sys 2011/02/04 20:37:11.0890 0452 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) D:\WINDOWS\system32\DRIVERS\netbios.sys 2011/02/04 20:37:11.0937 0452 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) D:\WINDOWS\system32\DRIVERS\netbt.sys 2011/02/04 20:37:12.0078 0452 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) D:\WINDOWS\system32\DRIVERS\nic1394.sys 2011/02/04 20:37:12.0140 0452 Npfs (3182d64ae053d6fb034f44b6def8034a) D:\WINDOWS\system32\drivers\Npfs.sys 2011/02/04 20:37:12.0218 0452 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) D:\WINDOWS\system32\drivers\Ntfs.sys 2011/02/04 20:37:12.0328 0452 Null (73c1e1f395918bc2c6dd67af7591a3ad) D:\WINDOWS\system32\drivers\Null.sys 2011/02/04 20:37:12.0406 0452 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) D:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/02/04 20:37:12.0468 0452 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) D:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/02/04 20:37:12.0562 0452 ohci1394 (ca33832df41afb202ee7aeb05145922f) D:\WINDOWS\system32\DRIVERS\ohci1394.sys 2011/02/04 20:37:12.0703 0452 Parport (5575faf8f97ce5e713d108c2a58d7c7c) D:\WINDOWS\system32\DRIVERS\parport.sys 2011/02/04 20:37:12.0796 0452 PartMgr (beb3ba25197665d82ec7065b724171c6) D:\WINDOWS\system32\drivers\PartMgr.sys 2011/02/04 20:37:12.0875 0452 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) D:\WINDOWS\system32\drivers\ParVdm.sys 2011/02/04 20:37:12.0906 0452 PCI (a219903ccf74233761d92bef471a07b1) D:\WINDOWS\system32\DRIVERS\pci.sys 2011/02/04 20:37:13.0015 0452 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) D:\WINDOWS\system32\DRIVERS\pciide.sys 2011/02/04 20:37:13.0093 0452 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) D:\WINDOWS\system32\drivers\Pcmcia.sys 2011/02/04 20:37:13.0531 0452 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) D:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/02/04 20:37:13.0578 0452 PSched (09298ec810b07e5d582cb3a3f9255424) D:\WINDOWS\system32\DRIVERS\psched.sys 2011/02/04 20:37:13.0625 0452 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) D:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/02/04 20:37:13.0875 0452 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) D:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/02/04 20:37:13.0937 0452 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) D:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/02/04 20:37:13.0968 0452 RasPppoe (5bc962f2654137c9909c3d4603587dee) D:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/02/04 20:37:14.0015 0452 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) D:\WINDOWS\system32\DRIVERS\raspti.sys 2011/02/04 20:37:14.0109 0452 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) D:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/02/04 20:37:14.0156 0452 RDPCDD (4912d5b403614ce99c28420f75353332) D:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/02/04 20:37:14.0296 0452 RDPWD (6728e45b66f93c08f11de2e316fc70dd) D:\WINDOWS\system32\drivers\RDPWD.sys 2011/02/04 20:37:14.0390 0452 redbook (f828dd7e1419b6653894a8f97a0094c5) D:\WINDOWS\system32\DRIVERS\redbook.sys 2011/02/04 20:37:14.0468 0452 RimUsb (f17713d108aca124a139fde877eef68a) D:\WINDOWS\system32\Drivers\RimUsb.sys 2011/02/04 20:37:14.0625 0452 RTL8023xp (cf84b1f0e8b14d4120aaf9cf35cbb265) D:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 2011/02/04 20:37:14.0718 0452 rtl8139 (d507c1400284176573224903819ffda3) D:\WINDOWS\system32\DRIVERS\RTL8139.SYS 2011/02/04 20:37:14.0859 0452 Secdrv (90a3935d05b494a5a39d37e71f09a677) D:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/02/04 20:37:14.0984 0452 serenum (0f29512ccd6bead730039fb4bd2c85ce) D:\WINDOWS\system32\DRIVERS\serenum.sys 2011/02/04 20:37:15.0031 0452 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) D:\WINDOWS\system32\DRIVERS\serial.sys 2011/02/04 20:37:15.0140 0452 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) D:\WINDOWS\system32\drivers\Sfloppy.sys 2011/02/04 20:37:15.0296 0452 SLIP (866d538ebe33709a5c9f5c62b73b7d14) D:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/02/04 20:37:15.0421 0452 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) D:\WINDOWS\system32\drivers\splitter.sys 2011/02/04 20:37:15.0515 0452 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) D:\WINDOWS\system32\DRIVERS\sr.sys 2011/02/04 20:37:15.0578 0452 Srv (0f6aefad3641a657e18081f52d0c15af) D:\WINDOWS\system32\DRIVERS\srv.sys 2011/02/04 20:37:15.0687 0452 streamip (77813007ba6265c4b6098187e6ed79d2) D:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/02/04 20:37:15.0750 0452 swenum (3941d127aef12e93addf6fe6ee027e0f) D:\WINDOWS\system32\DRIVERS\swenum.sys 2011/02/04 20:37:15.0828 0452 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) D:\WINDOWS\system32\drivers\swmidi.sys 2011/02/04 20:37:16.0031 0452 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) D:\WINDOWS\system32\drivers\sysaudio.sys 2011/02/04 20:37:16.0171 0452 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) D:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/02/04 20:37:16.0250 0452 TDPIPE (6471a66807f5e104e4885f5b67349397) D:\WINDOWS\system32\drivers\TDPIPE.sys 2011/02/04 20:37:16.0328 0452 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) D:\WINDOWS\system32\drivers\TDTCP.sys 2011/02/04 20:37:16.0390 0452 TermDD (88155247177638048422893737429d9e) D:\WINDOWS\system32\DRIVERS\termdd.sys 2011/02/04 20:37:16.0546 0452 tmcomm (df8444a8fa8fd38d8848bdd40a8403b3) D:\WINDOWS\system32\drivers\tmcomm.sys 2011/02/04 20:37:16.0703 0452 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) D:\WINDOWS\system32\drivers\Udfs.sys 2011/02/04 20:37:16.0859 0452 Update (402ddc88356b1bac0ee3dd1580c76a31) D:\WINDOWS\system32\DRIVERS\update.sys 2011/02/04 20:37:16.0953 0452 USBAAPL (e8c1b9ebac65288e1b51e8a987d98af6) D:\WINDOWS\system32\Drivers\usbaapl.sys 2011/02/04 20:37:17.0031 0452 usbccgp (173f317ce0db8e21322e71b7e60a27e8) D:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/02/04 20:37:17.0125 0452 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) D:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/02/04 20:37:17.0203 0452 usbhub (1ab3cdde553b6e064d2e754efe20285c) D:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/02/04 20:37:17.0234 0452 usbprint (a717c8721046828520c9edf31288fc00) D:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/02/04 20:37:17.0281 0452 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) D:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/02/04 20:37:17.0328 0452 usbstor (a32426d9b14a089eaa1d922e0c5801a9) D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/02/04 20:37:17.0421 0452 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) D:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/02/04 20:37:17.0484 0452 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) D:\WINDOWS\System32\drivers\vga.sys 2011/02/04 20:37:17.0578 0452 VolSnap (4c8fcb5cc53aab716d810740fe59d025) D:\WINDOWS\system32\drivers\VolSnap.sys 2011/02/04 20:37:17.0656 0452 Wanarp (e20b95baedb550f32dd489265c1da1f6) D:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/02/04 20:37:17.0781 0452 wdmaud (6768acf64b18196494413695f0c3a00f) D:\WINDOWS\system32\drivers\wdmaud.sys 2011/02/04 20:37:17.0968 0452 WSTCODEC (c98b39829c2bbd34e454150633c62c78) D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/02/04 20:37:18.0078 0452 ZSMC301b (617c6711ea9049f39043cab2886418bf) D:\WINDOWS\system32\Drivers\usbVM31b.sys 2011/02/04 20:37:18.0171 0452 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0) 2011/02/04 20:37:18.0281 0452 ================================================================================ 2011/02/04 20:37:18.0281 0452 Scan finished 2011/02/04 20:37:18.0281 0452 ================================================================================ 2011/02/04 20:37:18.0312 0368 Detected object count: 1 2011/02/04 20:37:39.0687 0368 \HardDisk0 - will be cured after reboot 2011/02/04 20:37:39.0687 0368 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure 2011/02/04 20:37:45.0031 0304 Deinitialize success
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Here's the ComboFix.txt log:


ComboFix 11-01-31.02 - Hugh 05/02/2011 8:17.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.1007.608 [GMT 10:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: COMODO Antivirus *Disabled/Updated* {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *Disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\documents and settings\Hugh\Local Settings\Temporary Internet Files\webex.ini
d:\documents and settings\Hugh\Recent\Thumbs.db
d:\documents and settings\NetworkService\Application Data\38DF5031EBDEE07B11EEDF512AC9141F
d:\documents and settings\NetworkService\Application Data\38DF5031EBDEE07B11EEDF512AC9141F\e124codecset.exe
d:\documents and settings\NetworkService\Application Data\38DF5031EBDEE07B11EEDF512AC9141F\enemies-names.txt
d:\documents and settings\NetworkService\Application Data\38DF5031EBDEE07B11EEDF512AC9141F\local.ini

.
((((((((((((((((((((((((( Files Created from 2011-01-04 to 2011-02-04 )))))))))))))))))))))))))))))))
.

2011-02-04 10:32 . 2011-02-04 10:50 ——– d—–w- D:\S
2011-02-03 14:01 . 2011-02-03 14:03 ——– d—–w- d:\documents and settings\Administrator
2011-02-03 13:38 . 2011-02-03 13:38 ——– d—–w- D:\Adobe
2011-02-03 13:37 . 2011-02-03 13:37 ——– d—–w- d:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-02-03 12:57 . 2011-02-03 12:57 ——– d—–w- d:\documents and settings\Hugh\Local Settings\Application Data\Opera
2011-02-03 11:08 . 2011-02-03 11:08 ——– d—–w- d:\documents and settings\Kim\Local Settings\Application Data\COMODO
2011-01-17 06:35 . 2011-01-17 06:35 ——– d—–w- d:\documents and settings\James
2011-01-16 21:05 . 2011-01-16 21:06 ——– d—–w- d:\documents and settings\Paul
2011-01-09 03:38 . 2009-09-04 07:44 238936 —-a-w- d:\windows\system32\xactengine3_5.dll
2011-01-09 03:36 . 2011-01-09 03:36 ——– d—–w- d:\windows\Logs
2011-01-09 02:53 . 2005-05-26 05:34 2297552 —-a-w- d:\windows\system32\d3dx9_26.dll
2011-01-09 01:05 . 1995-06-15 16:03 17536 —-a-r- d:\windows\VIEWENU.DLL
2011-01-09 01:05 . 1995-06-15 16:03 16912 —-a-r- d:\windows\PLAYENU.DLL
2011-01-09 01:05 . 1995-06-15 16:03 141206 —-a-r- d:\windows\README.EXE
2011-01-09 01:05 . 1995-06-15 16:03 61024 —-a-r- d:\windows\PLAYER.EXE
2011-01-09 01:05 . 1995-06-15 16:03 47776 —-a-r- d:\windows\VIEWER.EXE
2011-01-09 01:05 . 1995-06-15 16:03 4160 —-a-r- d:\windows\system\QTNOTIFY.EXE
2011-01-09 01:05 . 1995-06-15 16:03 8384 —-a-r- d:\windows\system\QTHNDLR.DLL
2011-01-09 01:05 . 1995-06-15 16:03 73456 —-a-r- d:\windows\system\QTOLE.DLL
2011-01-09 01:05 . 1995-06-15 16:03 358192 —-a-r- d:\windows\system\QTIM.DLL
2011-01-09 01:05 . 1995-06-15 16:03 41376 —-a-r- d:\windows\system\MCIQTW.DRV
2011-01-09 01:05 . 1995-06-15 16:03 3920 —-a-r- d:\windows\system\MCIQTENU.DLL
2011-01-09 01:05 . 1995-06-15 16:03 14400 —-a-r- d:\windows\system\QTIMCMGR.DLL
2011-01-09 01:04 . 2011-01-09 01:04 ——– d—–w- D:\JEWELS
2011-01-09 00:59 . 2011-01-09 01:54 ——– d—–w- d:\program files\Microsoft Games
2011-01-09 00:56 . 1998-06-02 00:25 24576 —-a-w- d:\windows\system32\ealtest.exe
2011-01-09 00:56 . 1998-06-02 00:25 132096 —-a-w- d:\windows\system32\eaexec.exe
2011-01-09 00:55 . 2011-01-09 00:55 ——– d—–w- D:\JANES
2011-01-09 00:53 . 2011-01-09 00:53 ——– d—–w- d:\documents and settings\Hugh\WINDOWS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 13:04 . 2010-06-01 09:00 285480 —-a-w- d:\windows\system32\guard32.dll
2011-02-03 13:04 . 2010-06-01 09:00 94784 —-a-w- d:\windows\system32\drivers\inspect.sys
2011-02-03 13:04 . 2010-06-01 09:00 27576 —-a-w- d:\windows\system32\drivers\cmdhlp.sys
2011-02-03 13:04 . 2010-06-01 09:00 15592 —-a-w- d:\windows\system32\drivers\cmderd.sys
2011-02-03 13:04 . 2010-06-04 01:55 239368 —-a-w- d:\windows\system32\drivers\cmdGuard.sys
2010-11-18 18:12 . 2008-01-03 11:24 81920 —-a-w- d:\windows\system32\isign32.dll
2010-11-12 08:53 . 2010-05-15 23:43 472808 —-a-w- d:\windows\system32\deployJava1.dll
2010-11-12 06:34 . 2010-05-15 23:43 73728 —-a-w- d:\windows\system32\javacpl.cpl
2010-11-09 14:52 . 2006-02-28 12:00 249856 —-a-w- d:\windows\system32\odbc32.dll
.

——- Sigcheck ——-

[-] 2002-08-29 . A0EE5C06390357FEE7B7949DBCA156D3 . 165376 . . [5.1.2600.1106] . . d:\windows\system32\appmgmts.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-26 68856]
"OM2_Monitor"="d:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-09-11 95536]
"Google Update"="d:\documents and settings\Hugh\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-14 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="d:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="d:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="d:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]
"SSBkgdUpdate"="d:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
"OpwareSE4"="d:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"BigDogPath"="d:\windows\VM_STI.EXE" [2003-01-21 40960]
"ecc"="d:\program files\Telstra\BigPond Assist\assist.exe" [2008-01-20 278528]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"SunJavaUpdateSched"="d:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"COMODO Internet Security"="d:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-02-03 2548552]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2010-03-17 421888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=d:\windows\system32\guard32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-04-28 05:06 142120 —-a-w- d:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 11:53 421888 —-a-w- d:\program files\QuickTime\QTTask.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Opera\\opera.exe"=
"d:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R1 cmderd;COMODO Internet Security Eradication Driver;d:\windows\system32\drivers\cmderd.sys [1/06/2010 7:00 PM 15592]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;d:\windows\system32\drivers\cmdGuard.sys [4/06/2010 11:55 AM 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;d:\windows\system32\drivers\cmdhlp.sys [1/06/2010 7:00 PM 27576]
S2 gupdate;Google Update Service (gupdate);d:\program files\Google\Update\GoogleUpdate.exe [8/02/2010 8:59 AM 135664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;d:\program files\Microsoft Office\Office14\GROOVE.EXE [25/03/2010 10:25 AM 30969208]
S3 osppsvc;Office Software Protection Platform;d:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/01/2010 9:37 PM 4640000]
.
Contents of the 'Scheduled Tasks' folder

2011-02-04 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 22:59]

2011-02-04 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 22:59]

2010-12-20 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1708537768-839522115-1004Core.job
- d:\documents and settings\Hugh\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-14 10:09]

2011-02-04 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1708537768-839522115-1004UA.job
- d:\documents and settings\Hugh\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-14 10:09]

2011-02-04 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1708537768-839522115-1005Core.job
- d:\documents and settings\Kim\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-09 03:11]

2011-02-04 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1708537768-839522115-1005UA.job
- d:\documents and settings\Kim\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-09 03:11]

2011-02-03 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1708537768-839522115-1006Core.job
- d:\documents and settings\Abbey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-04 03:11]

2011-02-04 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1708537768-839522115-1006UA.job
- d:\documents and settings\Abbey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-04 03:11]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - d:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Google Sidewiki… - d:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Se&nd to OneNote - d:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
Trusted Zone: bigpond.com
Trusted Zone: bigpond.com\www
Trusted Zone: com.au\*.seek
Trusted Zone: com.au\www.seek
Trusted Zone: custhelp.com
Trusted Zone: microsoft.com
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\www.update
Trusted Zone: windowsupdate.com
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - d:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
FF - ProfilePath - d:\documents and settings\Hugh\Application Data\Mozilla\Firefox\Profiles\wvdk3jbo.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - d:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - d:\program files\Java\jre6\lib\deploy\jqs\ff
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-05 08:26
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose, ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(772)
d:\windows\system32\guard32.dll
.
Completion time: 2011-02-05 08:29:00
ComboFix-quarantined-files.txt 2011-02-04 22:28

Pre-Run: 19,064,496,128 bytes free
Post-Run: 19,120,586,752 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 8BE6D9FE14F155FFE57D4DCC2302060A
Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please












Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Here's the MBAM log: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5683 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 5/02/2011 8:04:56 PM mbam-log-2011-02-05 (20-04-56).txt Scan type: Quick scan Objects scanned: 194705 Time elapsed: 6 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Here's the ESET log. At the end of the scan there was a check-mark that said 'delete files in Quarantine' - since you're instructions didn't mention anything about this I didn't delete them. Can you please advise whether I need to delete the files in Quarantine? Thankyou. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=68d190036572d24b893e347694783705 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-02-05 03:58:33 # local_time=2011-02-06 01:58:33 (+1000, E. Australia Standard Time) # country="Australia" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=3073 16777173 80 75 45818 166726 0 0 # compatibility_mode=8192 67108863 100 0 4184 4184 0 0 # scanned=174090 # found=11 # cleaned=11 # scan_time=16753 D:\Documents and Settings\Abbey\Application Data\Sun\Java\Deployment\cache\6.0\46\32dcefee-58701ab7 probably a variant of Win32/Agent.RPSVWU trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\Qoobox\Quarantine\D\Documents and Settings\NetworkService\Application Data\38DF5031EBDEE07B11EEDF512AC9141F\e124codecset.exe.vir Win32/Adware.AntimalwareDoctor application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\Qoobox\Quarantine\D\Documents and Settings\NetworkService\Application Data\38DF5031EBDEE07B11EEDF512AC9141F\enemies-names.txt.vir Win32/Adware.AntimalwareDoctor.AE.Gen application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\Qoobox\Quarantine\D\Documents and Settings\NetworkService\Application Data\38DF5031EBDEE07B11EEDF512AC9141F\local.ini.vir Win32/Adware.AntimalwareDoctor.AE.Gen application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\System Volume Information\_restore{9E767AB0-7D39-4EF4-8510-218DA46AB77A}\RP192\A0165982.exe Win32/Adware.SpywareProtect2009 application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\System Volume Information\_restore{9E767AB0-7D39-4EF4-8510-218DA46AB77A}\RP192\A0165985.exe Win32/TrojanDownloader.Small.OVG trojan (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C D:\System Volume Information\_restore{9E767AB0-7D39-4EF4-8510-218DA46AB77A}\RP192\A0170033.exe a variant of Win32/Kryptik.JYH trojan (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C D:\System Volume Information\_restore{9E767AB0-7D39-4EF4-8510-218DA46AB77A}\RP192\A0170034.exe a variant of Win32/Kryptik.JYH trojan (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C D:\System Volume Information\_restore{9E767AB0-7D39-4EF4-8510-218DA46AB77A}\RP192\A0170035.exe a variant of Win32/Kryptik.JYH trojan (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C D:\System Volume Information\_restore{9E767AB0-7D39-4EF4-8510-218DA46AB77A}\RP193\A0171179.exe Win32/Adware.AntimalwareDoctor application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\System Volume Information\_restore{9E767AB0-7D39-4EF4-8510-218DA46AB77A}\RP193\A0171180.ini Win32/Adware.AntimalwareDoctor.AE.Gen application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
Hi - here's the latest DDS log file. Since running the TDDSKiller I haven't seen any browser redirects, and the PC is not exhibiting any signs of sluggishness (if anything IE runs a little faster now). What's the likelihood that everything's sorted now and we can use the PC for things like internet banking etc? DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 12:29:53.62 on Sun 06/02/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23 Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.1007.631 [GMT 10:00] AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B} FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} ============== Running Processes =============== D:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe D:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe D:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe D:\WINDOWS\system32\spoolsv.exe svchost.exe D:\Program Files\Bonjour\mDNSResponder.exe D:\Program Files\Java\jre6\bin\jqs.exe D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe D:\WINDOWS\System32\snmp.exe D:\WINDOWS\system32\svchost.exe -k imgsvc D:\WINDOWS\Explorer.EXE D:\WINDOWS\system32\igfxpers.exe D:\WINDOWS\SOUNDMAN.EXE D:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe D:\WINDOWS\VM_STI.EXE D:\Program Files\Telstra\BigPond Assist\assist.exe D:\WINDOWS\system32\ctfmon.exe D:\Program Files\Common Files\Java\Java Update\jusched.exe D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe D:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe D:\WINDOWS\system32\wscntfy.exe D:\Documents and Settings\Hugh\My Documents\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com.au/ uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - d:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~2\office14\GROOVEEX.DLL BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - d:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - d:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - d:\progra~1\micros~2\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - d:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [swg] "d:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [OM2_Monitor] "d:\program files\olympus\olympus master 2\MMonitor.exe" uRun: [Google Update] "d:\documents and settings\hugh\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe mRun: [igfxtray] d:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] d:\windows\system32\hkcmd.exe mRun: [igfxpers] d:\windows\system32\igfxpers.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [SSBkgdUpdate] "d:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [OpwareSE4] "d:\program files\scansoft\omnipagese4.0\OpwareSE4.exe" mRun: [BigDogPath] d:\windows\VM_STI.EXE VIMICRO USB PC Camera 301x mRun: [ecc] d:\program files\telstra\bigpond assist\assist.exe mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "d:\program files\common files\java\java update\jusched.exe" mRun: [COMODO Internet Security] "d:\program files\comodo\comodo internet security\cfp.exe" -h mRun: [QuickTime Task] "d:\program files\quicktime\qttask.exe" -atboottime dRun: [CTFMON.EXE] d:\windows\system32\CTFMON.EXE IE: Add to Google Photos Screensa&ver - d:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: Google Sidewiki… - d:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html IE: Se&nd to OneNote - d:\progra~1\micros~2\office14\ONBttnIE.dll/105 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - d:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll Trusted Zone: bigpond.com Trusted Zone: bigpond.com\www Trusted Zone: com.au\*.seek Trusted Zone: com.au\www.seek Trusted Zone: custhelp.com Trusted Zone: microsoft.com Trusted Zone: microsoft.com\*.update Trusted Zone: microsoft.com\*.windowsupdate Trusted Zone: microsoft.com\www.update Trusted Zone: windowsupdate.com DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813 DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file://d:\program files\monopoly\images\stg_drm.ocx DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.fujifilmimagine.com/imagine/ax/ImageUploader5.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1229819345734 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file://d:\program files\monopoly\images\armhelper.ocx DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://boeing.webex.com/client/T23LBA/webex/ieatgpc.cab DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://sslvpn.boeing.com/dana-cached/setup/JuniperSetupSP1.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - d:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - d:\windows\downloaded program files\mimectl.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: d:\windows\system32\guard32.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~2\office14\GROOVEEX.DLL ================= FIREFOX =================== FF - ProfilePath - d:\docume~1\hugh\applic~1\mozilla\firefox\profiles\wvdk3jbo.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/ FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} —- FIREFOX POLICIES —- d:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); d:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); d:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); d:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); d:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); d:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); d:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); d:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); d:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); d:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); d:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); d:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); d:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); d:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); d:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); d:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); d:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); d:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); d:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); d:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 cmderd;COMODO Internet Security Eradication Driver;d:\windows\system32\drivers\cmderd.sys [2010-6-1 15592] R1 cmdGuard;COMODO Internet Security Sandbox Driver;d:\windows\system32\drivers\cmdGuard.sys [2010-6-4 239368] R1 cmdHlp;COMODO Internet Security Helper Driver;d:\windows\system32\drivers\cmdhlp.sys [2010-6-1 27576] R2 cmdAgent;COMODO Internet Security Helper Service;d:\program files\comodo\comodo internet security\cmdagent.exe [2010-6-1 1803224] S2 gupdate;Google Update Service (gupdate);d:\program files\google\update\GoogleUpdate.exe [2010-2-8 135664] S3 JL2005C;Dual Mode Camera;d:\windows\system32\drivers\jl2005c.sys [2008-12-27 68922] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;d:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208] S3 osppsvc;Office Software Protection Platform;d:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] =============== Created Last 30 ================ 2011-02-05 20:09 –d—– d:\program files\ESET 2011-02-05 19:58 –d—– d:\docume~1\hugh\applic~1\Malwarebytes 2011-02-05 19:58 38,224 a——- d:\windows\system32\drivers\mbamswissarmy.sys 2011-02-05 19:58 –d—– d:\docume~1\alluse~1\applic~1\Malwarebytes 2011-02-05 19:57 20,952 a——- d:\windows\system32\drivers\mbam.sys 2011-02-05 19:57 –d—– d:\program files\Malwarebytes' Anti-Malware 2011-02-05 08:04 256,512 a——- d:\windows\PEV.exe 2011-02-05 08:04 161,792 a——- d:\windows\SWREG.exe 2011-02-05 08:04 98,816 a——- d:\windows\sed.exe 2011-02-05 08:04 89,088 a——- d:\windows\MBR.exe 2011-02-04 20:32 –d—– D:\S 2011-02-03 23:38 –d—– D:\Adobe 2011-02-03 14:16 1,324 a——- d:\windows\system32\d3d9caps.dat 2011-01-09 13:38 238,936 a——- d:\windows\system32\xactengine3_5.dll 2011-01-09 13:36 –d—– d:\windows\Logs 2011-01-09 12:53 2,297,552 a——- d:\windows\system32\d3dx9_26.dll 2011-01-09 11:04 124 a——- d:\windows\JORACLE.INI 2011-01-09 11:04 –d—– D:\JEWELS 2011-01-09 10:59 –d—– d:\program files\Microsoft Games 2011-01-09 10:56 132,096 a——- d:\windows\system32\eaexec.exe 2011-01-09 10:56 24,576 a——- d:\windows\system32\ealtest.exe 2011-01-09 10:55 –d—– D:\JANES 2011-01-09 10:53 –d—– d:\documents and settings\hugh\WINDOWS ==================== Find3M ==================== 2011-02-06 09:32 1,474,832 a——- d:\windows\system32\drivers\sfi.dat 2011-02-03 23:04 285,480 a——- d:\windows\system32\guard32.dll 2011-02-03 23:04 27,576 a——- d:\windows\system32\drivers\cmdhlp.sys 2011-02-03 23:04 15,592 a——- d:\windows\system32\drivers\cmderd.sys 2011-02-03 23:04 239,368 a——- d:\windows\system32\drivers\cmdGuard.sys 2010-11-19 04:12 81,920 a——- d:\windows\system32\isign32.dll 2010-11-12 18:53 472,808 a——- d:\windows\system32\deployJava1.dll 2010-11-10 00:52 249,856 a——- d:\windows\system32\odbc32.dll 2008-01-06 09:16 32 a——- d:\docume~1\alluse~1\applic~1\ezsid.dat ============= FINISH: 12:31:06.26 ===============
Sorry forgot the Attach DDS log also: ==== Installed Programs ====================== 3DVIA Player 4.1 Ad-Aware SE Personal ADM Files For XP SP2 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.1.4 Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft PhotoImpression 4 ArcSoft PhotoStudio 5.5 Bicycle Board Games BigPond Assist Bonjour Canon MP Navigator 3.0 Canon MP160 COMODO Internet Security Compatibility Pack for the 2007 Office system Definition update for Microsoft Office 2010 (KB982726) DVD Flick e-tax 2008 e-tax 2009 e-tax 2010 Emirates TravelDesk ESET Online Scanner v3 FileZilla Client [removed] FinalBurner Free v1.29.0.125 Google Chrome Google Earth Google Gears Google SketchUp 7 Google Toolbar for Internet Explorer Google Update Helper HijackThis 1.99.1 Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HouseCall 6.6 Intel® Extreme Graphics 2 Driver iTunes Java Auto Updater Java™ 6 Update 23 Longbow Anthology Malwarebytes' Anti-Malware Microsoft Flight Simulator X Microsoft Flight Simulator X Service Pack 1 Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Office XP Media Content Microsoft Outlook Web Access S/MIME Microsoft Silverlight Microsoft Software Update for Web Folders (English) 14 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Windows Script 5.7 Mozilla Firefox (3.6.10) Mozilla Thunderbird (2.0.0.9) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK MSXML 6.0 Parser (KB933579) OGA Notifier 1.7.0105.35.0 OLYMPUS Master 2 oneworld Timetables Opera 10.54 PDFCreator pdfsam Photo Viewer 2.23 Picasa 3 QuickTime RealPlayer Basic Realtek AC'97 Audio REALTEK GbE & FE Ethernet PCI NIC Driver ScanSoft OmniPage SE 4.0 Security Update for CAPICOM (KB931906) Security Update for Microsoft Office 2010 (KB2289078) Security Update for Microsoft Office 2010 (KB2289161) Security Update for Microsoft Publisher 2010 (KB2409055) Security Update for Microsoft Word 2010 (KB2345000) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Skype™ 3.6 SkyTeam Travel Timetable SmartFTP Client 2.0 Star Alliance TravelDesk Studio Uninstall Dual Mode Camera Update for Microsoft Office 2010 (KB2202188) Update for Microsoft Office 2010 (KB2413186) Update for Microsoft OneNote 2010 (KB2433299) Update for Microsoft Outlook Social Connector (KB2289116) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Vimicro USB PC Camera 301x WebEx WebEye WebFldrs XP Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Media Format Runtime Windows Media Format SDK Hotfix - KB891122 Windows XP Junglebook Compatiblity Fix Windows XP Service Pack 3 ==== End Of File ===========================
You appear clean of infections,if you are going to do internet banking i would change your passwords to be on the safe side.

Please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)








Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.








Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
Thankyou, really appreciate the assistance. If there's some way we can pay you for the time or donate to your favourite charity please let us know.
You're welcome,glad we could help :)

No need for donations,my help is free.


Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI