This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Jump virus/search engine redirect

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HippieMama

I went into Control Panel then Add and Delete Programs and deleted the Ask Toolbar. Is that all I need to do to get rid of it?

We’ll check that before we finish

Before I download the Malaware thing I just wanted to ask you if it's compatible with the PC Tools Spyware Doctor that I have now. Is there a way to find out if they'd be okay to have together?

Malwarebytes has different functions. I’m aware of what is on your computer and if it was not compatible, I would not have asked you to run it.

Please follow the previous instructions to run Malwarebytes.

Satchfan
Dear Satchfan, I hope I'm doing this right. I copied the log and now I'm going to reboot. Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Database version: 6822 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 6/9/2011 8:39:52 PM mbam-log-2011-06-09 (20-39-52).txt Scan type: Quick scan Objects scanned: 139218 Time elapsed: 4 minute(s), 40 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 3 Files Infected: 7 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\mmagootlf.dll (PUP.MightyMagoo) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\APPID\MightyMagooText.DLL (PUP.MightyMagoo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\AppDataLow\mmagootl (PUP.MightyMagoo) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] (PUP.MightyMagoo) -> Delete on reboot. c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome (PUP.MightyMagoo) -> Quarantined and deleted successfully. c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components (PUP.MightyMagoo) -> Delete on reboot. Files Infected: c:\documents and settings\dx\my documents\downloads\webfetti(2).exe (Adware.FunWeb) -> Quarantined and deleted successfully. c:\documents and settings\dx\my documents\downloads\Webfetti.exe (Adware.FunWeb) -> Quarantined and deleted successfully. c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome.manifest (PUP.MightyMagoo) -> Quarantined and deleted successfully. c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\install.rdf (PUP.MightyMagoo) -> Quarantined and deleted successfully. c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\mmtextlinks.jar (PUP.MightyMagoo) -> Quarantined and deleted successfully. c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\mmagootlf.dll (PUP.MightyMagoo) -> Delete on reboot. c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\mmagootlf.xpt (PUP.MightyMagoo) -> Quarantined and deleted successfully. Okay, I rebooted. What's my next move? Thanks for all the help!!!
Hippie Mama

Submit a file to VirusTotal

Go to VirusTotal and submit this file for analysis:

c:\windows\system32\sfcfiles.dllβ€’ Click on Browse
β€’ Click on the arrow and choose Local Disc (C:)
πŸ–ΌClick to load external image (Posted Image)
β€’ Below, double-click on Windows
β€’ Double-click on the System32folder
β€’ Locate the file sfcfiles.dll click on it and then on Open
β€’ Click on Send File.
You will get a report back; post the report in the next post.

===================================================

Run ComboFix

I’d like a look at a current log from ComboFix now that you have uninstalled the Ask toolbar.

Double click on combofix.exe and follow the prompts.

When finished, it will produce a report for you. Please include it in your next reply.

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall

===================================================

Please re-run Malwarebytes and let the computer reboot before sending the log.

Can you tell me what problems remain

Thanks

Satchfan
Dear Satchfan,

I hope this is the proper report:

File name:
sfcfiles.dll
Submission date:
2011-06-10 17:44:00 (UTC)
Current status:
queued queued (#32) analysing finished
Result:
0/ 42 (0.0%)

VT Community

not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.06.11.00 2011.06.10 -
AntiVir 7.11.9.156 2011.06.10 -
Antiy-AVL 2.0.3.7 2011.06.10 -
Avast 4.8.1351.0 2011.06.10 -
Avast5 5.0.677.0 2011.06.10 -
AVG 10.0.0.1190 2011.06.10 -
BitDefender 7.2 2011.06.10 -
CAT-QuickHeal 11.00 2011.06.10 -
ClamAV 0.97.0.0 2011.06.10 -
Commtouch 5.3.2.6 2011.06.10 -
Comodo 9016 2011.06.10 -
DrWeb 5.0.2.03300 2011.06.10 -
eSafe 7.0.17.0 2011.06.09 -
eTrust-Vet 36.1.8379 2011.06.10 -
F-Prot 4.6.2.117 2011.06.10 -
F-Secure 9.0.16440.0 2011.06.10 -
Fortinet 4.2.257.0 2011.06.10 -
GData 22 2011.06.10 -
Ikarus T3.1.1.104.0 2011.06.10 -
Jiangmin 13.0.900 2011.06.10 -
K7AntiVirus 9.106.4798 2011.06.10 -
Kaspersky 9.0.0.837 2011.06.10 -
McAfee 5.400.0.1158 2011.06.10 -
McAfee-GW-Edition 2010.1D 2011.06.10 -
Microsoft 1.6903 2011.06.10 -
NOD32 6196 2011.06.10 -
Norman 6.07.10 2011.06.10 -
nProtect 2011-06-10.01 2011.06.10 -
Panda 10.0.3.5 2011.06.10 -
PCTools 7.0.3.5 2011.06.10 -
Prevx 3.0 2011.06.10 -
Rising 23.61.04.07 2011.06.10 -
Sophos 4.66.0 2011.06.10 -
SUPERAntiSpyware 4.40.0.1006 2011.06.10 -
Symantec 20111.1.0.186 2011.06.10 -
TheHacker 6.7.0.1.227 2011.06.10 -
TrendMicro 9.200.0.1012 2011.06.10 -
TrendMicro-HouseCall 9.200.0.1012 2011.06.10 -
VBA32 3.12.16.1 2011.06.10 -
VIPRE 9543 2011.06.10 -
ViRobot 2011.6.10.4505 2011.06.10 -
VirusBuster 14.0.75.2 2011.06.10 -
Additional information
Show all
MD5 : 600d58665d16bfbb776efefb0e80532d
SHA1 : c9719f14eab06cf0b5422bad7bee950a7c308768
SHA256: bc43d953e24b76a86aa7252a35ce408341fc14e6b1cb5a0c592a92ba4f9325ae
ssdeep: 3072:4UeE8F3PH/mvTKJrhqCaDfzqdK2D+P7KsLxvmzmekuNrR4:4w8FlmfzqQHLxvmzy
File size : 1614848 bytes
First seen: 2010-01-09 19:41:50
Last seen : 2011-06-10 17:44:00
TrID:
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher….: Microsoft Corporation
copyright….: Β© Microsoft Corporation. All rights reserved.
product……: Microsoft_ Windows_ Operating System
description..: Windows 2000 System File Checker
original name:
internal name:
file version.: 5.1.2600.5512 (xpsp.080413-2111)
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x120D
timedatestamp….: 0x48025222 (Sun Apr 13 18:34:10 2008)
machinetype……: 0x14c (I386)

[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0xCBF, 0xE00, 5.90, d3fe89394e3542961bec08f951a2b772
.data, 0x2000, 0x17E730, 0x17E800, 3.28, 5d80ab7c2b8cdbd61fd93d0e84a79990
.rsrc, 0x181000, 0x408, 0x600, 2.49, 6ad33d817c21d5547a4921c76c19efff
.reloc, 0x182000, 0xA230, 0xA400, 5.76, 31a909823c459f02f7ee7c2c9f09fc93

[[ 1 import(s) ]]
ntdll.dll: LdrDisableThreadCalloutsForDll, NtClose, NtQueryValueKey, NtOpenKey, RtlInitUnicodeString, RtlGetVersion, NtTerminateProcess, RtlUnhandledExceptionFilter, RtlUnwind, NtQueryVirtualMemory

[[ 1 export(s) ]]
SfcGetFiles
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 3584
CompanyName: Microsoft Corporation
EntryPoint: 0x120d
FileDescription: Windows 2000 System File Checker
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 1577 kB
FileSubtype: 0
FileType: Win32 DLL
FileVersion: 5.1.2600.5512 (xpsp.080413-2111)
FileVersionNumber: 5.1.2600.5512
ImageVersion: 5.1
InitializedDataSize: 1610240
InternalName:
LanguageCode: English (U.S.)
LinkerVersion: 7.1
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 5.1
ObjectFileType: Executable application
PEType: PE32
ProductVersionNumber: 5.1.2600.5512
Subsystem: Windows command line
SubsystemVersion: 4.1
Tag26005512: D
TimeStamp: 2008:04:13 20:34:10+02:00
UninitializedDataSize: 0
filesdll: j%ProductName
icrosoftCorporationAllrightsreserved: B OriginalFilename
lesdll: .LegalCopyright
rosoftWindowsOperatingSystem: @ProductVersion

VT Community



Now combofix:

ComboFix 11-06-06.07 - dx 06/10/2011 14:06:07.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.292 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-05-10 to 2011-06-10 )))))))))))))))))))))))))))))))
.
.
2011-06-10 00:33 . 2011-06-10 00:33 ——– d—–w- c:\documents and settings\dx\Application Data\Malwarebytes
2011-06-10 00:33 . 2011-05-29 13:11 39984 β€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-10 00:33 . 2011-06-10 00:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-10 00:33 . 2011-06-10 00:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-10 00:33 . 2011-05-29 13:11 22712 β€”-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-09 00:36 . 2011-06-09 00:55 ——– d—–w- c:\program files\Microsoft ActiveSync
2011-06-07 16:18 . 2011-06-10 18:01 ——– d—–w- C:\32788R22FWJFW
2011-06-06 18:49 . 2011-06-06 18:49 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2011-06-06 18:49 . 2011-06-06 18:49 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-06-06 03:20 . 2011-06-06 03:20 388096 β€”-a-r- c:\documents and settings\dx\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-06-06 03:20 . 2011-06-06 03:20 ——– d—–w- C:\Trend Micro
2011-06-05 04:04 . 2011-06-05 04:04 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-06-04 23:24 . 2011-06-04 23:24 ——– d—–w- c:\program files\Common Files\Java
2011-06-04 22:02 . 2001-08-18 02:36 5632 β€”-a-w- c:\windows\system32\ptpusb.dll
2011-06-04 22:02 . 2008-04-14 09:42 159232 β€”-a-w- c:\windows\system32\ptpusd.dll
2011-06-04 17:41 . 2011-06-04 17:41 ——– d-sβ€”w- c:\documents and settings\NetworkService\UserData
2011-06-04 04:36 . 2011-06-04 04:36 ——– d—–w- c:\documents and settings\dx\Application Data\894E5449700F3D86AF876350C9266F39
2011-06-04 04:31 . 2011-06-04 21:10 ——– d—–w- c:\program files\7-Zip
2011-05-25 03:01 . 2011-05-25 03:01 ——– d—–w- c:\documents and settings\dx\Application Data\Unity
2011-05-25 02:10 . 2011-05-25 02:10 ——– d—–w- c:\documents and settings\dx\Local Settings\Application Data\Unity
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-12 14:44 . 2011-05-03 17:02 149456 β€”-a-w- c:\windows\SGDetectionTool.dll
2011-04-12 14:44 . 2011-05-03 17:02 2074576 β€”-a-w- c:\windows\PCTBDCore.dll
2011-04-12 14:44 . 2011-05-03 17:02 1533904 β€”-a-w- c:\windows\PCTBDRes.dll
2011-04-12 14:44 . 2011-05-03 17:02 767952 β€”-a-w- c:\windows\BDTSupport.dll
2011-04-25 16:43 . 2011-04-25 16:43 289592 β€”-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
.
.
β€”β€”- Sigcheck β€”β€”-
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-05-09 . 600D58665D16BFBB776EFEFB0E80532D . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-06-07_16.51.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-09-23 05:16 . 2005-09-23 05:16 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2005-09-23 05:16 . 2005-09-23 05:16 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2011-06-10 17:38 . 2011-06-10 17:38 16384 c:\windows\Temp\Perflib_Perfdata_430.dat
+ 2011-06-10 17:46 . 2011-06-10 17:46 16384 c:\windows\Temp\Perflib_Perfdata_15c.dat
+ 2010-12-03 00:16 . 2011-06-10 17:50 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-03 00:16 . 2011-06-10 17:50 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2011-06-09 01:53 . 2011-06-10 17:50 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2005-09-23 03:48 . 2005-09-23 03:48 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2005-09-23 03:48 . 2005-09-23 03:48 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-23 03:48 . 2005-09-23 03:48 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2005-09-23 05:16 . 2005-09-23 05:16 1079808 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2005-09-23 05:16 . 2005-09-23 05:16 1093632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor with AntiVirus"="c:\documents and settings\dx\Desktop\sdasetup(2).exe" [2011-05-03 513032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-08-15 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-08-10 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"ISTray"="c:\program files\Spyware Doctor\pctsGui.exe" [2011-04-12 1600984]
"PCTools FGuard"="c:\program files\Spyware Doctor\BDT\FGuard.exe" [2011-04-12 247760]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [5/3/2011 1:01 PM 263888]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [5/3/2011 1:27 PM 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [5/3/2011 1:27 PM 656320]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [5/3/2011 2:13 PM 51984]
R0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [5/3/2011 2:13 PM 69392]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [5/3/2011 1:01 PM 251560]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [5/3/2011 1:27 PM 233976]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [5/3/2011 1:02 PM 337872]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/9/2011 8:33 PM 366640]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [5/3/2011 1:26 PM 371472]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/9/2011 8:33 PM 22712]
R3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [5/3/2011 1:01 PM 70536]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [5/3/2011 2:13 PM 33552]
R3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service –> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/9/2011 8:33 PM 39984]
.
β€” Other Services/Drivers In Memory β€”
.
*Deregistered* - PCTSDInjDriver32
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
.
β€”β€”- Supplementary Scan β€”β€”-
.
uStart Page = https://login.yahoo.com/config/login_verify2?&.src=ym
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = 192.168.1.1 [removed]
FF - ProfilePath - c:\documents and settings\dx\Application Data\Mozilla\Firefox\Profiles\1t2fqt2o.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxps://login.yahoo.com/config/login_verify2?.intl=us&.src=ym
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Browser Defender Toolbar: {cb84136f-9c44-433a-9048-c5cd9df1dc16} - c:\program files\Spyware Doctor\BDT\Firefox
FF - Ext: BlockSite: {dd3d7613-0246-469d-bc65-2a3cc1668adc} - %profile%\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-10 14:23
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€”
.
- - - - - - - > 'winlogon.exe'(684)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
c:\program files\Spyware Doctor\TFEngine\TFNI.dll
.
- - - - - - - > 'lsass.exe'(740)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
.
- - - - - - - > 'explorer.exe'(6328)
c:\program files\Spyware Doctor\TFEngine\TfWah.dll
c:\program files\Spyware Doctor\TFEngine\TFNI.dll
c:\windows\system32\WSOCK32.dll
.
Completion time: 2011-06-10 14:33:00
ComboFix-quarantined-files.txt 2011-06-10 18:32
ComboFix2.txt 2011-06-09 01:53
ComboFix3.txt 2011-06-07 17:01
.
Pre-Run: 69,619,462,144 bytes free
Post-Run: 69,612,871,680 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 124056772631B8CA0505BDC7E48D0335

Malwarebytes:

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6822

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

6/10/2011 2:45:14 PM
mbam-log-2011-06-10 (14-45-07).txt

Scan type: Quick scan
Objects scanned: 138984
Time elapsed: 3 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] (PUP.MightyMagoo) -> No action taken.

Files Infected:
(No malicious items detected)


I can see there's one file there that needs to be removed but I didn't want to remove it without your okay, so please just let me know what to do next. Thanks!

Also, the Ask toolbar is still here. Before, it wasn't showing up but now it's displayed right next to the address bar. It seems I've somehow made is worse, not better. Still, I can now use Google, click on links, and actually go where I'm supposed to, so that's a huge improvement. Thanks for bearing with me!!!
Hi Hippie Mama

Glad to hear things are running better.

Open ComboFix

Please do the following:β€’ Close any open browsers.
β€’ Close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
β€’ Open notepad and copy/paste the text in the codebox below into it:
Firefox::
FF - ProfilePath - c:\documents and settings\dx\Application Data\Mozilla\Firefox\Profiles\1t2fqt2o.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

===================================================

Re-run Malwarebytes and allow it to fix anything it finds then reboot your computer.

Please include both logs in your reply

Satchfan
Okay, Satchfan, here's the ComboFix log:

ComboFix 11-06-06.07 - dx 06/11/2011 14:27:27.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.282 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\dx\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-05-11 to 2011-06-11 )))))))))))))))))))))))))))))))
.
.
2011-06-10 00:33 . 2011-06-10 00:33 ——– d—–w- c:\documents and settings\dx\Application Data\Malwarebytes
2011-06-10 00:33 . 2011-05-29 13:11 39984 β€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-10 00:33 . 2011-06-10 00:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-10 00:33 . 2011-06-10 18:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-10 00:33 . 2011-05-29 13:11 22712 β€”-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-09 00:36 . 2011-06-09 00:55 ——– d—–w- c:\program files\Microsoft ActiveSync
2011-06-07 16:18 . 2011-06-11 18:22 ——– d—–w- C:\32788R22FWJFW
2011-06-06 18:49 . 2011-06-06 18:49 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2011-06-06 18:49 . 2011-06-06 18:49 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-06-06 03:20 . 2011-06-06 03:20 388096 β€”-a-r- c:\documents and settings\dx\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-06-06 03:20 . 2011-06-06 03:20 ——– d—–w- C:\Trend Micro
2011-06-05 04:04 . 2011-06-05 04:04 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-06-04 23:24 . 2011-06-04 23:24 ——– d—–w- c:\program files\Common Files\Java
2011-06-04 22:02 . 2001-08-18 02:36 5632 β€”-a-w- c:\windows\system32\ptpusb.dll
2011-06-04 22:02 . 2008-04-14 09:42 159232 β€”-a-w- c:\windows\system32\ptpusd.dll
2011-06-04 17:41 . 2011-06-04 17:41 ——– d-sβ€”w- c:\documents and settings\NetworkService\UserData
2011-06-04 04:36 . 2011-06-04 04:36 ——– d—–w- c:\documents and settings\dx\Application Data\894E5449700F3D86AF876350C9266F39
2011-06-04 04:31 . 2011-06-04 21:10 ——– d—–w- c:\program files\7-Zip
2011-05-25 03:01 . 2011-05-25 03:01 ——– d—–w- c:\documents and settings\dx\Application Data\Unity
2011-05-25 02:10 . 2011-05-25 02:10 ——– d—–w- c:\documents and settings\dx\Local Settings\Application Data\Unity
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-12 14:44 . 2011-05-03 17:02 149456 β€”-a-w- c:\windows\SGDetectionTool.dll
2011-04-12 14:44 . 2011-05-03 17:02 2074576 β€”-a-w- c:\windows\PCTBDCore.dll
2011-04-12 14:44 . 2011-05-03 17:02 1533904 β€”-a-w- c:\windows\PCTBDRes.dll
2011-04-12 14:44 . 2011-05-03 17:02 767952 β€”-a-w- c:\windows\BDTSupport.dll
2011-04-25 16:43 . 2011-04-25 16:43 289592 β€”-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
.
.
β€”β€”- Sigcheck β€”β€”-
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-05-09 . 600D58665D16BFBB776EFEFB0E80532D . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-06-07_16.51.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-09-23 05:16 . 2005-09-23 05:16 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2005-09-23 05:16 . 2005-09-23 05:16 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2011-06-11 18:19 . 2011-06-11 18:19 16384 c:\windows\Temp\Perflib_Perfdata_434.dat
+ 2011-06-11 18:31 . 2011-06-11 18:31 16384 c:\windows\Temp\Perflib_Perfdata_1b4.dat
+ 2010-12-03 00:16 . 2011-06-11 18:19 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-03 00:16 . 2011-06-11 18:19 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2011-06-10 18:33 . 2011-06-11 18:19 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2005-09-23 03:48 . 2005-09-23 03:48 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2005-09-23 03:48 . 2005-09-23 03:48 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-23 03:48 . 2005-09-23 03:48 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2005-09-23 05:16 . 2005-09-23 05:16 1079808 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2005-09-23 05:16 . 2005-09-23 05:16 1093632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor with AntiVirus"="c:\documents and settings\dx\Desktop\sdasetup(2).exe" [2011-05-03 513032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-08-15 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-08-10 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"ISTray"="c:\program files\Spyware Doctor\pctsGui.exe" [2011-04-12 1600984]
"PCTools FGuard"="c:\program files\Spyware Doctor\BDT\FGuard.exe" [2011-04-12 247760]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [5/3/2011 1:01 PM 263888]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [5/3/2011 1:27 PM 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [5/3/2011 1:27 PM 656320]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [5/3/2011 2:13 PM 51984]
R0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [5/3/2011 2:13 PM 69392]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [5/3/2011 1:01 PM 251560]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [5/3/2011 1:27 PM 233976]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [5/3/2011 1:02 PM 337872]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/9/2011 8:33 PM 366640]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [5/3/2011 1:26 PM 371472]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/9/2011 8:33 PM 22712]
R3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [5/3/2011 1:01 PM 70536]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [5/3/2011 2:13 PM 33552]
R3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service –> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/9/2011 8:33 PM 39984]
.
β€” Other Services/Drivers In Memory β€”
.
*Deregistered* - PCTSDInjDriver32
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
.
β€”β€”- Supplementary Scan β€”β€”-
.
uStart Page = https://login.yahoo.com/config/login_verify2?&.src=ym
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = 192.168.1.1 [removed]
FF - ProfilePath - c:\documents and settings\dx\Application Data\Mozilla\Firefox\Profiles\1t2fqt2o.default\
FF - prefs.js: browser.startup.homepage - hxxps://login.yahoo.com/config/login_verify2?.intl=us&.src=ym
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Browser Defender Toolbar: {cb84136f-9c44-433a-9048-c5cd9df1dc16} - c:\program files\Spyware Doctor\BDT\Firefox
FF - Ext: BlockSite: {dd3d7613-0246-469d-bc65-2a3cc1668adc} - %profile%\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-11 14:45
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€”
.
- - - - - - - > 'winlogon.exe'(676)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
c:\program files\Spyware Doctor\TFEngine\TFNI.dll
.
- - - - - - - > 'lsass.exe'(732)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
.
- - - - - - - > 'explorer.exe'(6252)
c:\program files\Spyware Doctor\TFEngine\TfWah.dll
c:\program files\Spyware Doctor\TFEngine\TFNI.dll
c:\windows\system32\WSOCK32.dll
.
Completion time: 2011-06-11 14:55:30
ComboFix-quarantined-files.txt 2011-06-11 18:55
ComboFix2.txt 2011-06-10 18:33
ComboFix3.txt 2011-06-09 01:53
ComboFix4.txt 2011-06-07 17:01
.
Pre-Run: 69,528,068,096 bytes free
Post-Run: 69,522,014,208 bytes free
.
- - End Of File - - AED09C99BEEB1E6566FE7846B3CA9E0C


And here's Malwarebytes:

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6832

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

6/11/2011 3:36:01 PM
mbam-log-2011-06-11 (15-36-01).txt

Scan type: Quick scan
Objects scanned: 139048
Time elapsed: 4 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



The Ask toolbar is still there, but other than that, everything seems to be working right. I really appreciate your patience. :-)
Hippie Mama

The Ask toolbar is still there

Where is it exactly? Is it in the search box in the top right corner? If not, please explain where you are seeing it

Satchfan
You should be able to remove that entry quite easily:β€’ click on the downward arrow to show the list
β€’ choose Manage Search Engines
β€’ click on Ask, (or anything with Ask in it), and then on Remove

Satchfan
Dear Satchfan, I did that, and it's gone. Woo hoo! So is my computer all clear now? Is there anything else I need to do? I had no idea removing t his virus/malware/whatever it is would be so complex. Thanks so much for walking me through it all. I don't know what I would have done without your help. Peace, Hippie Mama
Good work :thumbup:

Let’s do one more scan to make sure that all is well and then we can clear up the tools we’ve used

Run ESET Online Scan

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

β€’ Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
β€’ Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.
Hi, Satchfan. Here are the results of the scan: C:\Documents and Settings\dx\Application Data\Sun\Java\Deployment\cache\6.0\20\257e0a14-493a2676 probably a variant of Java/Agent.BR trojan C:\Documents and Settings\dx\Application Data\Sun\Java\Deployment\cache\6.0\41\3aff5a9-17582855 a variant of Java/Agent.BR trojan C:\Qoobox\Quarantine\C\Program Files\Mighty Magoo\mightymagoo32.exe.vir a variant of Win32/Adware.Gamevance.AW application C:\Qoobox\Quarantine\C\Program Files\Mighty Magoo\mmagooun.exe.vir a variant of Win32/Adware.Gamevance.AV application C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP129\A0015327.exe a variant of Win32/Adware.Gamevance.AW application C:\System Volume Information\_restore{C32DC508-B147-48EB-8080-871826FE9F00}\RP129\A0015330.exe a variant of Win32/Adware.Gamevance.AV application What do we do next? Thanks!
Hi Hippie Mama

Looks like that cleared up a few stragglers.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

===================================================

Uninstall Combofix

Follow these steps to uninstall Combofixβ€’ Click START then RUN
β€’ Now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
πŸ–ΌClick to load external image (Posted Image)
β€’ Please follow the prompts to uninstall Combofix.
β€’ Once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.
===================================================

Firewall

You only appear to have Windows Firewall which is not enabled and is not adequate protection anyway. The main reason you should use a third-party firewall over the Windows XP Firewall is because Windows Firewall only stops incoming signals from accessing your computer. However, it will not stop Outgoing signals (possibly ones that could intrude your privacy) from sending information to the Internet or to other networks. That means if malware happens to compromise your PC again, it will be able to SEND OUT out your credit card data and any other personal information.

I suggest you install a robust third party firewall that filters both incoming and outgoing traffic.

Download and install one of the following freeware firewalls from below:

Sygate Personal Firewall Free Edition:
Zone Alarm Free:
Comodo Personal Firewall:

NOTE only install one firewall. Having more than one could cause many programs to stop working altogether. Also, the firewalls may get in each others' way and cause some security holes that would not be there with just one firewall.

You should take the time to read Understanding and Using Firewalls

===================================================

Update installed programs

Your version of Flash Player is out-of-date and the Flash player included with SP3 is also old.

Go here and download the latest version.

NEXT

Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 26 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 26 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u26 with JavaFX 1 License Agreement". Click on Continue. The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Javaβ„’ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u26-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.

===================================================

Internet Explorer 6

You should upgrade to Internet Explorer 8. It has many new and improved features. The most important of these featuures is that older browsers will not be able to access some of those written in the new HTML5 standard and earlier browsers may not comply with security requirements of some sites including banking sites.

Microsoft has created a Web site devoted to encouraging users of Internet Explorer 6 (IE6) to upgrade to a newer browser called the Internet Explorer 6 Countdown

Go here to download IE8

===================================================

Set your computer to automatically check for Windows updates.

To turn on Automatic Updates:β€’ Click Start, Settings and then click Control Panel.
β€’ Double-click Automatic Updates.
β€’ Choose Automatic (recommended).
===================================================

Recommended programs

SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.

===================================================

Update and run Malwarebytes. This really is an excellent program that you should update and run on a regular basis, probably weekly.

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

Safe computing

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI