This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I think I am infected with something

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, there have been emails that have been sent from my email address but I did not send them, I have macafee and it says things are fine.
I did the 1st step suggested and this is what the OTL stuff says–
OTL logfile created on: 4/20/2011 11:41:57 AM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\christopher\Documents\My Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 283.40 Gb Total Space | 224.82 Gb Free Space | 79.33% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 4.94 Gb Free Space | 33.70% Space Free | Partition Type: NTFS

Computer Name: CHRISTOPHER-PC | User Name: christopher | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/04/19 23:30:19 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\christopher\Documents\My Downloads\OTL.exe
PRC - [2011/01/17 17:15:32 | 001,193,848 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2010/10/13 23:28:54 | 000,188,136 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2010/10/13 23:28:54 | 000,171,168 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2010/10/13 23:28:54 | 000,141,792 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe
PRC - [2010/03/10 11:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2009/08/25 13:31:38 | 000,202,752 | —- | M] (Microsoft Corporation.) – C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe
PRC - [2009/08/25 13:31:38 | 000,186,368 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe
PRC - [2008/01/20 19:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe


========== Modules (SafeList) ==========

MOD - [2011/04/19 23:30:19 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\christopher\Documents\My Downloads\OTL.exe
MOD - [2011/03/09 16:54:14 | 000,018,176 | —- | M] (McAfee, Inc.) – c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2008/01/20 19:23:44 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/10/13 23:28:54 | 000,188,136 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV - [2010/10/13 23:28:54 | 000,171,168 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV - [2010/10/13 23:28:54 | 000,141,792 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe – (mfevtp)
SRV - [2010/10/07 21:34:28 | 000,364,216 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2010/03/10 11:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV - [2010/03/10 11:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - [2010/03/10 11:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Disabled | Stopped] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McOobeSv)
SRV - [2010/03/10 11:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - [2010/03/10 11:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - [2010/03/10 11:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - [2010/03/10 11:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - [2010/03/10 11:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV - [2008/01/20 19:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - [2010/10/13 23:28:54 | 000,386,840 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2010/10/13 23:28:54 | 000,313,288 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfefirek.sys – (mfefirek)
DRV - [2010/10/13 23:28:54 | 000,164,840 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\mfewfpk.sys – (mfewfpk)
DRV - [2010/10/13 23:28:54 | 000,152,960 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2010/10/13 23:28:54 | 000,095,600 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2010/10/13 23:28:54 | 000,084,264 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mferkdet.sys – (mferkdet)
DRV - [2010/10/13 23:28:54 | 000,064,304 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\mfenlfk.sys – (mfenlfk)
DRV - [2010/10/13 23:28:54 | 000,055,840 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\cfwids.sys – (cfwids)
DRV - [2010/10/13 23:28:54 | 000,052,104 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfebopk.sys – (mfebopk)
DRV - [2008/01/20 19:23:25 | 000,251,904 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\VSTBS23.SYS – (VSTHWBS2)
DRV - [2008/01/20 19:23:25 | 000,220,672 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\e1e6032.sys – (e1express) Intel®


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/03/28 11:52:00 | 000,000,000 | —D | M]


O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20110227201620.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: //@install.mar@/ ([]msni in Computer)
O15 - HKCU\..Trusted Domains: //@mail.mar@/ ([]msni in Local intranet)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img21.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img21.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2004/04/30 14:01:00 | 000,000,053 | -HS- | M] () - D:\AUTORUN.INF – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\Windows\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/04/20 11:10:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/04/14 09:51:50 | 000,000,000 | —D | C] – C:\Program Files\Hawai'i Volcanoes National Park
[2011/04/13 17:58:36 | 000,000,000 | —D | C] – C:\Users\christopher\Documents\PRECRAcked-WinRAR.3.71.part1
[2011/04/12 23:43:48 | 000,000,000 | —D | C] – C:\Users\christopher\AppData\Roaming\NCH Swift Sound
[2011/04/12 23:40:54 | 000,000,000 | —D | C] – C:\ProgramData\NCH Swift Sound
[2011/04/12 23:40:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2011/04/12 23:40:31 | 000,000,000 | —D | C] – C:\Program Files\NCH Software
[2011/04/12 23:40:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs
[2011/04/12 23:40:30 | 000,000,000 | —D | C] – C:\Program Files\NCH Swift Sound
[2011/04/09 17:23:28 | 000,000,000 | —D | C] – C:\Users\christopher\Documents\New Folder
[2011/04/09 09:31:54 | 000,000,000 | —D | C] – C:\Users\christopher\Documents\paypal add to cart
[2011/03/23 09:19:09 | 000,000,000 | —D | C] – C:\ProgramData\Roxio
[2011/03/23 09:19:08 | 000,000,000 | —D | C] – C:\Users\christopher\AppData\Roaming\Roxio
[2011/03/23 09:16:30 | 000,000,000 | —D | C] – C:\ProgramData\Uninstall
[2011/03/23 09:16:23 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SureThing Shared
[2011/03/23 09:14:24 | 000,000,000 | —D | C] – C:\ProgramData\Sonic
[2011/03/23 09:14:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio Creator DE
[2011/03/23 09:14:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PX Storage Engine
[2011/03/23 09:14:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Sonic Shared
[2011/03/23 09:12:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Roxio Shared
[2011/03/23 09:12:22 | 000,000,000 | —D | C] – C:\ProgramData\InstallShield
[2011/03/23 09:12:17 | 000,000,000 | —D | C] – C:\Program Files\Roxio
[2011/03/23 09:02:08 | 000,000,000 | —D | C] – C:\Program Files\Ahead
[2011/03/23 09:02:01 | 000,254,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmclien.dll

========== Files - Modified Within 30 Days ==========

[2011/04/20 11:17:35 | 000,594,698 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/20 11:17:35 | 000,100,766 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/20 11:17:13 | 000,000,680 | —- | M] () – C:\Users\christopher\AppData\Local\d3d9caps.dat
[2011/04/20 11:10:18 | 000,001,735 | —- | M] () – C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2011/04/20 11:10:04 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/20 11:10:04 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/20 11:10:02 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2011/04/20 11:09:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/20 11:09:56 | 3207,819,264 | -HS- | M] () – C:\hiberfil.sys
[2011/04/14 09:51:53 | 000,000,795 | —- | M] () – C:\Users\christopher\Desktop\Hawai'i Volcanoes National Park.lnk
[2011/04/13 17:58:01 | 001,457,787 | —- | M] () – C:\Users\christopher\Documents\PRECRAcked-WinRAR.3.71.part1.zip
[2011/04/12 23:43:49 | 000,000,942 | —- | M] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2011/04/12 23:40:31 | 000,000,954 | —- | M] () – C:\Users\Public\Desktop\Express Rip.lnk
[2011/04/12 22:49:03 | 000,000,044 | —- | M] () – C:\Users\christopher\Documents\Track12.cda
[2011/03/23 09:25:40 | 000,000,552 | —- | M] () – C:\Users\christopher\AppData\Local\d3d8caps.dat
[2011/03/23 09:14:20 | 000,002,085 | —- | M] () – C:\Users\Public\Desktop\Roxio Creator Home.lnk

========== Files Created - No Company Name ==========

[2011/04/14 09:51:53 | 000,000,795 | —- | C] () – C:\Users\christopher\Desktop\Hawai'i Volcanoes National Park.lnk
[2011/04/13 17:57:59 | 001,457,787 | —- | C] () – C:\Users\christopher\Documents\PRECRAcked-WinRAR.3.71.part1.zip
[2011/04/12 23:43:49 | 000,000,954 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Switch Sound File Converter.lnk
[2011/04/12 23:43:49 | 000,000,942 | —- | C] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2011/04/12 23:40:31 | 000,000,966 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Rip.lnk
[2011/04/12 23:40:31 | 000,000,954 | —- | C] () – C:\Users\Public\Desktop\Express Rip.lnk
[2011/04/12 22:49:03 | 000,000,044 | —- | C] () – C:\Users\christopher\Documents\Track12.cda
[2011/04/10 09:56:36 | 000,065,536 | —- | C] () – C:\Windows\System32\Ikeext.etl
[2011/03/23 09:25:40 | 000,000,552 | —- | C] () – C:\Users\christopher\AppData\Local\d3d8caps.dat
[2011/03/23 09:14:20 | 000,002,085 | —- | C] () – C:\Users\Public\Desktop\Roxio Creator Home.lnk
[2011/03/07 13:47:21 | 000,000,296 | —- | C] () – C:\Windows\dellstat.ini
[2011/02/21 17:50:28 | 000,011,264 | —- | C] () – C:\Users\christopher\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/18 01:27:06 | 000,000,680 | —- | C] () – C:\Users\christopher\AppData\Local\d3d9caps.dat
[2008/01/20 19:24:14 | 000,100,043 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,310,504 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,594,698 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,100,766 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/11/02 00:22:43 | 000,018,271 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2004/02/10 13:08:00 | 000,000,373 | —- | C] () – C:\Windows\System32\dlbccoin.ini
[2002/11/13 13:40:22 | 000,040,960 | —- | C] () – C:\Windows\System32\dlbcvs.dll

========== LOP Check ==========

[2011/02/18 19:20:50 | 000,000,000 | —D | M] – C:\Users\christopher\AppData\Roaming\MSNInstaller
[2011/04/12 23:46:05 | 000,000,000 | —D | M] – C:\Users\christopher\AppData\Roaming\NCH Swift Sound
[2011/04/20 10:55:33 | 000,032,600 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 14:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/24 11:22:12 | 000,000,211 | -H– | M] () – C:\Boot.BAK
[2009/07/24 14:13:40 | 000,000,355 | RHS- | M] () – C:\Boot.ini.saved
[2008/01/20 19:24:42 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2011/02/18 01:12:54 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/04/20 11:09:56 | 3207,819,264 | -HS- | M] () – C:\hiberfil.sys
[2009/07/24 11:26:23 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/07/24 11:26:23 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 03:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 03:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/04/20 11:09:56 | 3523,690,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 05:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/07/29 07:27:40 | 000,078,336 | —- | M] () – C:\Windows\System32\spool\prtprocs\w32x86\DLBCPP5C.DLL
[2008/01/20 19:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 20:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 20:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 20:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/03/23 09:12:21 | 000,000,444 | -HS- | M] () – C:\Users\christopher\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-21 01:02:33

< End of report >

Any help would be great, let me know if you have any questions or what I need to do next.

Kalai
Hi Kalai,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Let's see if we can find anything lurking on your system.

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
===================================================

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also please describe how your computer behaves at the moment.
Ok, I will do all you say, right now my computer is slow and as lon as I have contacts in my email list then spam will be sent from my address and I am not doing it, that is all the symptoms I notice. I have dial up so it might take a bit of time to download all this stuff but I will post when I am done and I will check back here to give you updates, thanks and aloha from Hawaii Kalai
Hi, I downloaded the GMER Rootkit Scanner and did wat you said and while it was scanning a window poped up and said that GMER has stopped msn from working and then sut it down so it did not complete the scan, what should I do now. aloha Kalai
Hi this is from the 2nd scan– MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows Vista Home Premium Edition Windows Information: Service Pack 1 (build 6001), 32-bit Base Board Manufacturer: Dell Inc. BIOS Manufacturer: Dell Inc. System Manufacturer: Dell Inc. System Product Name: Inspiron 530 Logical Drives Mask: 0x0000001c Kernel Drivers (total 139): 0x81E06000 \SystemRoot\system32\ntkrnlpa.exe 0x821BF000 \SystemRoot\system32\hal.dll 0x80404000 \SystemRoot\system32\kdcom.dll 0x8040C000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x8046C000 \SystemRoot\system32\PSHED.dll 0x8047D000 \SystemRoot\system32\BOOTVID.dll 0x80485000 \SystemRoot\system32\CLFS.SYS 0x804C6000 \SystemRoot\system32\CI.dll 0x80602000 \SystemRoot\system32\drivers\Wdf01000.sys 0x8067E000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x8068B000 \SystemRoot\system32\drivers\acpi.sys 0x806D1000 \SystemRoot\system32\drivers\WMILIB.SYS 0x806DA000 \SystemRoot\system32\drivers\msisadrv.sys 0x806E2000 \SystemRoot\system32\drivers\pci.sys 0x80709000 \SystemRoot\System32\drivers\partmgr.sys 0x80718000 \SystemRoot\system32\drivers\volmgr.sys 0x80727000 \SystemRoot\System32\drivers\volmgrx.sys 0x80771000 \SystemRoot\system32\drivers\pciide.sys 0x80778000 \SystemRoot\system32\drivers\PCIIDEX.SYS 0x80786000 \SystemRoot\System32\drivers\mountmgr.sys 0x80796000 \SystemRoot\system32\drivers\atapi.sys 0x8079E000 \SystemRoot\system32\drivers\ataport.SYS 0x807BC000 \SystemRoot\system32\drivers\fltmgr.sys 0x807EE000 \SystemRoot\system32\drivers\fileinfo.sys 0x89E05000 \SystemRoot\system32\drivers\mfehidk.sys 0x89E62000 \SystemRoot\System32\Drivers\PxHelp20.sys 0x89E6B000 \SystemRoot\System32\Drivers\ksecdd.sys 0x89EDC000 \SystemRoot\system32\drivers\ndis.sys 0x805A6000 \SystemRoot\system32\drivers\msrpc.sys 0x8A00A000 \SystemRoot\system32\drivers\NETIO.SYS 0x8A044000 \SystemRoot\System32\drivers\tcpip.sys 0x8A12B000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x8A204000 \SystemRoot\System32\Drivers\Ntfs.sys 0x8A313000 \SystemRoot\system32\drivers\volsnap.sys 0x8A34C000 \SystemRoot\System32\Drivers\spldr.sys 0x8A354000 \SystemRoot\System32\Drivers\mup.sys 0x8A363000 \SystemRoot\System32\drivers\ecache.sys 0x8A38A000 \SystemRoot\system32\drivers\disk.sys 0x8A39B000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x8A3BC000 \SystemRoot\system32\drivers\crcdisk.sys 0x8A3E5000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x8A3F0000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x8A146000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x8A155000 \SystemRoot\system32\DRIVERS\vgapnp.sys 0x8A161000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0x8A182000 \SystemRoot\system32\DRIVERS\watchdog.sys 0x8A18F000 \SystemRoot\system32\DRIVERS\e1e6032.sys 0x8A1C9000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x8DE01000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x8DE3F000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x8DE4E000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x8DE60000 \SystemRoot\system32\DRIVERS\VSTBS23.SYS 0x8DEA8000 \SystemRoot\system32\DRIVERS\ks.sys 0x8DED2000 \SystemRoot\system32\DRIVERS\VSTDPV3.SYS 0x8E402000 \SystemRoot\system32\DRIVERS\VSTCNXT3.SYS 0x8E4B5000 \SystemRoot\system32\drivers\modem.sys 0x8E4C2000 \SystemRoot\system32\DRIVERS\fdc.sys 0x8E4CD000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x8E4E5000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x8E513000 \SystemRoot\system32\DRIVERS\storport.sys 0x8E554000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8E55F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8E576000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8E581000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8E5A4000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8E5B3000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8E5C7000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8E5DC000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8E5EC000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x8DFD6000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x8E5F7000 \SystemRoot\system32\DRIVERS\swenum.sys 0x8DFE1000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8DFEB000 \SystemRoot\system32\DRIVERS\umbus.sys 0x8E60C000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x8E640000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8E651000 \SystemRoot\system32\drivers\HdAudio.sys 0x8E690000 \SystemRoot\system32\drivers\portcls.sys 0x8E6BD000 \SystemRoot\system32\drivers\drmk.sys 0x8E6E2000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x8E6EB000 \SystemRoot\System32\Drivers\Null.SYS 0x8E6F2000 \SystemRoot\System32\Drivers\Beep.SYS 0x8E702000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x8E709000 \SystemRoot\System32\drivers\vga.sys 0x8E715000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8E71D000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8E725000 \SystemRoot\System32\Drivers\Msfs.SYS 0x8E730000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8E73E000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x8E747000 \SystemRoot\system32\DRIVERS\tdx.sys 0x8E75D000 \SystemRoot\system32\drivers\mfewfpk.sys 0x8E784000 \SystemRoot\system32\DRIVERS\smb.sys 0x8E798000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8E806000 \SystemRoot\system32\drivers\afd.sys 0x8E84E000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8E864000 \SystemRoot\system32\DRIVERS\mfenlfk.sys 0x8E872000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8E880000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8E893000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8E8CF000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8E8D9000 \SystemRoot\System32\Drivers\dfsc.sys 0x8E8F0000 \SystemRoot\system32\drivers\mfeavfk.sys 0x8E914000 \SystemRoot\system32\drivers\mfefirek.sys 0x8E95F000 \SystemRoot\System32\Drivers\crashdmp.sys 0x8E96C000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x8E977000 \SystemRoot\System32\Drivers\dump_atapi.sys 0x8E97F000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x8E988000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x8E998000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x8E99A000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x936A0000 \SystemRoot\System32\win32k.sys 0x8E9A3000 \SystemRoot\System32\drivers\Dxapi.sys 0x8E9AD000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x938B0000 \SystemRoot\System32\drivers\dxg.sys 0x8E9B5000 \SystemRoot\system32\DRIVERS\monitor.sys 0x938E0000 \SystemRoot\System32\TSDDD.dll 0x93960000 \SystemRoot\System32\framebuf.dll 0x8E9C4000 \SystemRoot\system32\drivers\luafv.sys 0x96203000 \SystemRoot\system32\drivers\spsys.sys 0x962B2000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x962C2000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x962D5000 \SystemRoot\system32\drivers\HTTP.sys 0x96340000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x9635D000 \SystemRoot\system32\DRIVERS\bowser.sys 0x96376000 \SystemRoot\System32\drivers\mpsdrv.sys 0x9638B000 \SystemRoot\system32\drivers\mrxdav.sys 0x963AB000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x9680E000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x96847000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x9685F000 \SystemRoot\System32\DRIVERS\srv2.sys 0x96886000 \SystemRoot\System32\DRIVERS\srv.sys 0x968D2000 \SystemRoot\System32\Drivers\fastfat.SYS 0x968FA000 \SystemRoot\system32\drivers\peauth.sys 0x969D8000 \SystemRoot\System32\Drivers\secdrv.SYS 0x969E2000 \SystemRoot\System32\drivers\tcpipreg.sys 0x969EE000 \SystemRoot\system32\drivers\cfwids.sys 0x963CA000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x96800000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0x963E0000 \SystemRoot\system32\drivers\mfeapfk.sys 0x76F60000 \Windows\System32\ntdll.dll Processes (total 52): 0 System Idle Process 4 System 512 C:\Windows\System32\smss.exe 588 csrss.exe 632 C:\Windows\System32\wininit.exe 644 csrss.exe 676 C:\Windows\System32\services.exe 692 C:\Windows\System32\lsass.exe 700 C:\Windows\System32\lsm.exe 736 C:\Windows\System32\winlogon.exe 888 C:\Windows\System32\svchost.exe 952 C:\Windows\System32\svchost.exe 988 C:\Windows\System32\svchost.exe 1076 C:\Windows\System32\svchost.exe 1096 C:\Windows\System32\svchost.exe 1180 C:\Windows\System32\audiodg.exe 1228 C:\Windows\System32\SLsvc.exe 1288 C:\Windows\System32\svchost.exe 1448 C:\Windows\System32\svchost.exe 1576 C:\Windows\System32\LEXBCES.EXE 1596 C:\Windows\System32\LEXPPS.EXE 1640 C:\Windows\System32\spoolsv.exe 1688 C:\Windows\System32\svchost.exe 1920 C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe 1972 C:\Program Files\Common Files\Mcafee\SystemCore\mfevtps.exe 180 C:\Windows\System32\svchost.exe 348 C:\Windows\System32\svchost.exe 484 C:\Windows\System32\svchost.exe 548 C:\Windows\System32\SearchIndexer.exe 752 C:\Windows\System32\rundll32.exe 1092 C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe 1388 C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe 2604 C:\Windows\System32\taskeng.exe 2636 C:\Windows\System32\dwm.exe 2724 C:\Windows\explorer.exe 2920 C:\Program Files\McAfee.com\Agent\mcagent.exe 3020 C:\Windows\System32\taskeng.exe 3036 C:\Program Files\MSN Messenger\msnmsgr.exe 3044 C:\Program Files\Windows Media Player\wmpnscfg.exe 3096 C:\Windows\ehome\ehtray.exe 3184 C:\Windows\ehome\ehmsas.exe 3236 C:\Program Files\Windows Media Player\wmpnetwk.exe 3544 C:\Windows\System32\wbem\unsecapp.exe 3608 WmiPrvSE.exe 3808 C:\Program Files\MSN\MSNCoreFiles\msn.exe 3964 C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe 3988 C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe 4908 C:\Program Files\Common Files\Mcafee\Core\mchost.exe 5872 C:\Windows\System32\SearchProtocolHost.exe 5884 C:\Windows\System32\SearchFilterHost.exe 5960 taskeng.exe 1728 C:\Users\christopher\Documents\My Downloads\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000003`ac000000 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000000`02800000 (NTFS) PhysicalDrive0 Model Number: ST3320613AS, Rev: CC4H Size Device Name MBR Status ——————————————– 298 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979 Done! I will do the 3rd scan now, aloha Chris
This is the 3rd scan results– Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5363 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 4/20/2011 8:00:09 PM mbam-log-2011-04-20 (20-00-09).txt Scan type: Quick scan Objects scanned: 139439 Time elapsed: 4 minute(s), 31 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Let me know if there is more I need to do, thanks and aloha. Kalai
Kalai,

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your  Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: 
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
Hi this is from the combofix scan–ComboFix 11-04-20.01 - christopher 04/21/2011 9:23.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3060.2458 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-03-21 to 2011-04-21 )))))))))))))))))))))))))))))))
.
.
2011-04-21 16:25 . 2011-04-21 16:26 ——– d—–w- c:\users\christopher\AppData\Local\temp
2011-04-21 02:47 . 2011-04-21 02:47 ——– d—–w- c:\users\christopher\AppData\Roaming\Malwarebytes
2011-04-21 02:47 . 2011-04-21 02:47 ——– d—–w- c:\programdata\Malwarebytes
2011-04-21 02:47 . 2011-04-21 16:16 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-04-14 16:51 . 2011-04-14 16:51 ——– d—–w- c:\program files\Hawai'i Volcanoes National Park
2011-04-13 06:43 . 2011-04-13 06:46 ——– d—–w- c:\users\christopher\AppData\Roaming\NCH Swift Sound
2011-04-13 06:40 . 2011-04-14 03:47 ——– d—–w- c:\programdata\NCH Swift Sound
2011-04-13 06:40 . 2011-04-13 06:40 ——– d—–w- c:\program files\NCH Software
2011-04-13 06:40 . 2011-04-13 06:43 ——– d—–w- c:\program files\NCH Swift Sound
2011-03-23 16:19 . 2011-04-13 15:16 ——– d—–w- c:\programdata\Roxio
2011-03-23 16:19 . 2011-03-23 16:19 ——– d—–w- c:\users\christopher\AppData\Roaming\Roxio
2011-03-23 16:16 . 2011-03-23 16:16 ——– d—–w- c:\programdata\Uninstall
2011-03-23 16:02 . 2011-03-23 16:10 ——– d—–w- c:\program files\Ahead
2011-03-23 16:02 . 2011-03-23 16:02 ——– d-sh–w- c:\users\Public\DRM
2011-03-23 16:02 . 2000-08-08 19:31 254224 —-a-w- c:\windows\system32\drmclien.dll
2011-03-23 16:00 . 2011-03-23 16:00 53248 ——w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\msihook.dll
2011-03-23 16:00 . 2011-03-23 16:00 126976 ——w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\knlwrap.exe
2011-03-23 16:00 . 2011-03-23 16:00 114688 ——w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\scpthdlr.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-20 22:11 . 2009-07-24 11:13 253353444 —-a-w- c:\windows\DUMP2f3a.tmp
2011-02-18 08:30 . 2011-02-18 08:30 45056 —-a-r- c:\users\christopher\AppData\Roaming\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-09-05 6856704]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2008-01-21 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2008-01-21 251904]
.
.
.
——- Supplementary Scan ——-
.
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-21 09:26
Windows 6.0.6001 Service Pack 1 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-04-21 09:27:21
ComboFix-quarantined-files.txt 2011-04-21 16:27
.
Pre-Run: 242,525,798,400 bytes free
Post-Run: 242,505,240,576 bytes free
.
- - End Of File - - 72297D9F6C8CFB1286CCD4EE99E17808


let me know what els I need to do, aloha.

Kalai
Kalai,

No signs of malware so far… Let's run one more test to make sure we got everything, perform some updates, and send you on your way.


ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI