This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

This is scarey

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Jeff,

Here is the latest Combo Fix scan. I merged the .txt file into it, but then it ran off and downloaded/installed an update. Don't know if that affected the .txt file.

ComboFix 11-07-21.02 - Owner 07/21/2011 7:42.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.463 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Windows XP Fix Utilities\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\Windows XP Fix Utilities\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2011-06-21 to 2011-07-21 )))))))))))))))))))))))))))))))
.
.
2011-07-21 12:07 . 2011-07-21 12:07 28752 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0B8B8D4B-6EC0-473F-987F-373EACBF5D55}\MpKsld58d0842.sys
2011-07-21 04:49 . 2011-07-21 04:49 28752 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0B8B8D4B-6EC0-473F-987F-373EACBF5D55}\MpKsl0aec1ac5.sys
2011-07-21 04:47 . 2011-06-07 15:55 7074640 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0B8B8D4B-6EC0-473F-987F-373EACBF5D55}\mpengine.dll
2011-07-18 13:50 . 2011-07-18 13:50 ——– d—–w- c:\documents and settings\LocalService\Application Data\Malwarebytes
2011-07-11 13:25 . 2011-06-07 15:55 7074640 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-07-10 23:25 . 2011-07-10 23:25 ——– d—–w- c:\windows\system32\wbem\Repository
2011-07-05 00:43 . 2011-07-05 12:31 ——– d—–w- c:\documents and settings\Owner\Application Data\Anti-Malware Lab
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-07 00:52 . 2010-12-11 00:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-07 00:52 . 2010-12-11 00:42 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-19 23:07 . 2011-05-23 14:05 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-10 21:42 . 2009-03-27 12:34 398760 —-a-r- c:\windows\system32\cpnprt2.cid
2011-06-07 15:55 . 2009-12-18 07:44 7074640 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-06-02 14:02 . 2007-03-19 17:21 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-14 00:05 . 2011-05-14 00:06 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-14 00:05 . 2011-05-14 00:06 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-05-02 15:31 . 2007-03-19 17:18 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2007-03-19 17:20 151552 —-a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2007-03-19 17:19 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07 . 2007-03-19 17:21 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-04-26 11:07 . 2007-03-19 17:17 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-04-25 16:11 . 2007-03-19 17:21 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2007-03-19 17:19 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2007-03-19 17:18 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2007-03-19 17:18 385024 —-a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2011-03-02 160328]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-02-16 1169776]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-02-16 1945960]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-07 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 68856]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2007-4-19 45056]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2007-02-16 23:49 149024 —-a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eBayToolbar]
2009-04-21 02:34 632048 —-a-w- c:\program files\eBay\eBay Toolbar2\eBayTBDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-18 18:37 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DW4"="c:\program files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"SUPERAntiSpyware"=c:\downloads\SUPERAntiSpyware\SUPERAntiSpyware.exe
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe"
"Aim"="c:\program files\AIM\aim.exe" /d locale=en-US
"SmileboxTray"="c:\documents and settings\Owner\Application Data\Smilebox\SmileboxTray.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CHotkey"=zHotkey.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" BOOT
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe"
"LifeScape Media Detector"=c:\program files\Picasa\PicasaMediaDetector.exe
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"PayPal Virtual Debit Card"=c:\program files\PayPal\PayPal Virtual Debit Card\PayPalVDC.exe StartUp /dontopenmycards /AutoStart
"Persistence"=c:\windows\system32\igfxpers.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Recguard"=%WINDIR%\SMINST\RECGUARD.EXE
"REGSHAVE"=c:\program files\REGSHAVE\REGSHAVE.EXE /AUTORUN
"Reminder"=%WINDIR%\Creator\Remind_XP.exe
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
"SunKistEM"=c:\program files\Digital Media Reader\shwiconem.exe
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Nectar\\Nectarphone\\nectarphone.exe"=
.
R1 MpKsl0aec1ac5;MpKsl0aec1ac5;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0B8B8D4B-6EC0-473F-987F-373EACBF5D55}\MpKsl0aec1ac5.sys [7/20/2011 11:49 PM 28752]
R1 MpKsld58d0842;MpKsld58d0842;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0B8B8D4B-6EC0-473F-987F-373EACBF5D55}\MpKsld58d0842.sys [7/21/2011 7:07 AM 28752]
R1 SASDIFSV;SASDIFSV;c:\downloads\SUPERAntiSpyware\sasdifsv.sys [7/4/2009 2:31 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\downloads\SUPERAntiSpyware\SASKUTIL.SYS [7/4/2009 2:31 PM 72944]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/10/2010 7:42 PM 366640]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/10/2010 7:42 PM 22712]
S1 MpKsl047490ec;MpKsl047490ec;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsl047490ec.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsl047490ec.sys [?]
S1 MpKsl09423042;MpKsl09423042;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F570AAE5-0295-417A-B806-BB983DCD1040}\MpKsl09423042.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F570AAE5-0295-417A-B806-BB983DCD1040}\MpKsl09423042.sys [?]
S1 MpKsl09a4395d;MpKsl09a4395d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FC8B638B-B884-47E2-AEBB-59748AC97B64}\MpKsl09a4395d.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FC8B638B-B884-47E2-AEBB-59748AC97B64}\MpKsl09a4395d.sys [?]
S1 MpKsl1aa4e36b;MpKsl1aa4e36b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl1aa4e36b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl1aa4e36b.sys [?]
S1 MpKsl1ae9b355;MpKsl1ae9b355;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{19AAF8D4-ACF5-426E-8E2D-E94525358EE8}\MpKsl1ae9b355.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{19AAF8D4-ACF5-426E-8E2D-E94525358EE8}\MpKsl1ae9b355.sys [?]
S1 MpKsl216e3cce;MpKsl216e3cce;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl216e3cce.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl216e3cce.sys [?]
S1 MpKsl2637072d;MpKsl2637072d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{176E9C39-E12D-4370-9BB2-19FCADB306D7}\MpKsl2637072d.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{176E9C39-E12D-4370-9BB2-19FCADB306D7}\MpKsl2637072d.sys [?]
S1 MpKsl2682e869;MpKsl2682e869;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E09D0571-DDA9-4EB4-965E-EE3CD70C5E81}\MpKsl2682e869.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E09D0571-DDA9-4EB4-965E-EE3CD70C5E81}\MpKsl2682e869.sys [?]
S1 MpKsl2a38b170;MpKsl2a38b170;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl2a38b170.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl2a38b170.sys [?]
S1 MpKsl2bdec5dd;MpKsl2bdec5dd;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{08575D7D-01F2-40CB-9408-AEF25FFE4C06}\MpKsl2bdec5dd.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{08575D7D-01F2-40CB-9408-AEF25FFE4C06}\MpKsl2bdec5dd.sys [?]
S1 MpKsl2cee34c7;MpKsl2cee34c7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01A14296-5B6A-453F-83AD-08A0401912C6}\MpKsl2cee34c7.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01A14296-5B6A-453F-83AD-08A0401912C6}\MpKsl2cee34c7.sys [?]
S1 MpKsl30992498;MpKsl30992498;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl30992498.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl30992498.sys [?]
S1 MpKsl31f4a9de;MpKsl31f4a9de;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsl31f4a9de.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsl31f4a9de.sys [?]
S1 MpKsl348f8107;MpKsl348f8107;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsl348f8107.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsl348f8107.sys [?]
S1 MpKsl35402007;MpKsl35402007;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsl35402007.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsl35402007.sys [?]
S1 MpKsl36dcea12;MpKsl36dcea12;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl36dcea12.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl36dcea12.sys [?]
S1 MpKsl3a39af3b;MpKsl3a39af3b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl3a39af3b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl3a39af3b.sys [?]
S1 MpKsl3d9619fe;MpKsl3d9619fe;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsl3d9619fe.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsl3d9619fe.sys [?]
S1 MpKsl3e9eb9d4;MpKsl3e9eb9d4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2058A846-D2EE-4344-A8D1-EB809ED84F0D}\MpKsl3e9eb9d4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2058A846-D2EE-4344-A8D1-EB809ED84F0D}\MpKsl3e9eb9d4.sys [?]
S1 MpKsl4363867d;MpKsl4363867d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsl4363867d.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsl4363867d.sys [?]
S1 MpKsl48649954;MpKsl48649954;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2058A846-D2EE-4344-A8D1-EB809ED84F0D}\MpKsl48649954.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2058A846-D2EE-4344-A8D1-EB809ED84F0D}\MpKsl48649954.sys [?]
S1 MpKsl4dbd4aff;MpKsl4dbd4aff;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{793257EE-9FD3-4B86-A64E-1CC5B2A00C5F}\MpKsl4dbd4aff.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{793257EE-9FD3-4B86-A64E-1CC5B2A00C5F}\MpKsl4dbd4aff.sys [?]
S1 MpKsl55ca6344;MpKsl55ca6344;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl55ca6344.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl55ca6344.sys [?]
S1 MpKsl5904d9ae;MpKsl5904d9ae;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2058A846-D2EE-4344-A8D1-EB809ED84F0D}\MpKsl5904d9ae.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2058A846-D2EE-4344-A8D1-EB809ED84F0D}\MpKsl5904d9ae.sys [?]
S1 MpKsl60e2329a;MpKsl60e2329a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E09D0571-DDA9-4EB4-965E-EE3CD70C5E81}\MpKsl60e2329a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E09D0571-DDA9-4EB4-965E-EE3CD70C5E81}\MpKsl60e2329a.sys [?]
S1 MpKsl637e925e;MpKsl637e925e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{734E2897-8F9C-48E5-94D6-3758F672195C}\MpKsl637e925e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{734E2897-8F9C-48E5-94D6-3758F672195C}\MpKsl637e925e.sys [?]
S1 MpKsl63f62c2a;MpKsl63f62c2a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsl63f62c2a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsl63f62c2a.sys [?]
S1 MpKsl69ffebc8;MpKsl69ffebc8;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl69ffebc8.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl69ffebc8.sys [?]
S1 MpKsl6e01fb22;MpKsl6e01fb22;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsl6e01fb22.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsl6e01fb22.sys [?]
S1 MpKsl76caee40;MpKsl76caee40;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{34FE2876-BFC2-45AE-8433-FFA02FCC5A49}\MpKsl76caee40.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{34FE2876-BFC2-45AE-8433-FFA02FCC5A49}\MpKsl76caee40.sys [?]
S1 MpKsl7e066bb1;MpKsl7e066bb1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl7e066bb1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl7e066bb1.sys [?]
S1 MpKsl85b8a520;MpKsl85b8a520;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FB143ADF-92CF-40FB-8BA8-0885CFA1F393}\MpKsl85b8a520.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FB143ADF-92CF-40FB-8BA8-0885CFA1F393}\MpKsl85b8a520.sys [?]
S1 MpKsl86bbd322;MpKsl86bbd322;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl86bbd322.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl86bbd322.sys [?]
S1 MpKsl86e50058;MpKsl86e50058;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl86e50058.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl86e50058.sys [?]
S1 MpKsl88032c2a;MpKsl88032c2a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7CDD5312-665F-4999-9524-9865215F79E3}\MpKsl88032c2a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7CDD5312-665F-4999-9524-9865215F79E3}\MpKsl88032c2a.sys [?]
S1 MpKsl89c66046;MpKsl89c66046;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B620B828-4313-418A-BC26-CDE2877B4264}\MpKsl89c66046.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B620B828-4313-418A-BC26-CDE2877B4264}\MpKsl89c66046.sys [?]
S1 MpKsl8a1df042;MpKsl8a1df042;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CA04B5A7-FE46-49F3-AB2E-B384F4B9F258}\MpKsl8a1df042.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CA04B5A7-FE46-49F3-AB2E-B384F4B9F258}\MpKsl8a1df042.sys [?]
S1 MpKsl8ddd704d;MpKsl8ddd704d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl8ddd704d.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl8ddd704d.sys [?]
S1 MpKsl954807d9;MpKsl954807d9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl954807d9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKsl954807d9.sys [?]
S1 MpKsl96501a3e;MpKsl96501a3e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsl96501a3e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsl96501a3e.sys [?]
S1 MpKsl96f93473;MpKsl96f93473;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl96f93473.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsl96f93473.sys [?]
S1 MpKsl99df906c;MpKsl99df906c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsl99df906c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsl99df906c.sys [?]
S1 MpKsla6c2541e;MpKsla6c2541e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsla6c2541e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKsla6c2541e.sys [?]
S1 MpKslaaac1c48;MpKslaaac1c48;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C04B5A2F-26C3-49E7-83E6-D6C2C03A5177}\MpKslaaac1c48.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C04B5A2F-26C3-49E7-83E6-D6C2C03A5177}\MpKslaaac1c48.sys [?]
S1 MpKslaaef1929;MpKslaaef1929;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslaaef1929.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslaaef1929.sys [?]
S1 MpKslb2ba39af;MpKslb2ba39af;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKslb2ba39af.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKslb2ba39af.sys [?]
S1 MpKslb4f8dec6;MpKslb4f8dec6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslb4f8dec6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslb4f8dec6.sys [?]
S1 MpKslbe3d7fa9;MpKslbe3d7fa9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslbe3d7fa9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslbe3d7fa9.sys [?]
S1 MpKslbfaa2276;MpKslbfaa2276;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKslbfaa2276.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKslbfaa2276.sys [?]
S1 MpKslc55ece64;MpKslc55ece64;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslc55ece64.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslc55ece64.sys [?]
S1 MpKslc6b76972;MpKslc6b76972;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKslc6b76972.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKslc6b76972.sys [?]
S1 MpKslcbd25cd7;MpKslcbd25cd7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKslcbd25cd7.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKslcbd25cd7.sys [?]
S1 MpKslcf207d9a;MpKslcf207d9a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B620B828-4313-418A-BC26-CDE2877B4264}\MpKslcf207d9a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B620B828-4313-418A-BC26-CDE2877B4264}\MpKslcf207d9a.sys [?]
S1 MpKslcf8e1307;MpKslcf8e1307;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslcf8e1307.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslcf8e1307.sys [?]
S1 MpKsld853f668;MpKsld853f668;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsld853f668.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsld853f668.sys [?]
S1 MpKsldbfa47d1;MpKsldbfa47d1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1DABB65D-E554-4A14-BF17-1FD0512F2A77}\MpKsldbfa47d1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1DABB65D-E554-4A14-BF17-1FD0512F2A77}\MpKsldbfa47d1.sys [?]
S1 MpKslde05946c;MpKslde05946c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKslde05946c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKslde05946c.sys [?]
S1 MpKsldfb3ba3e;MpKsldfb3ba3e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsldfb3ba3e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKsldfb3ba3e.sys [?]
S1 MpKsle6f2dd5e;MpKsle6f2dd5e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsle6f2dd5e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{181A5487-6A75-4629-AC01-B77AC3374615}\MpKsle6f2dd5e.sys [?]
S1 MpKslfb06f11a;MpKslfb06f11a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKslfb06f11a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKslfb06f11a.sys [?]
S1 MpKslfb223bd3;MpKslfb223bd3;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKslfb223bd3.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8557FC39-A380-425B-89B2-0F95964496EB}\MpKslfb223bd3.sys [?]
S1 MpKslfd55e01f;MpKslfd55e01f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E09D0571-DDA9-4EB4-965E-EE3CD70C5E81}\MpKslfd55e01f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E09D0571-DDA9-4EB4-965E-EE3CD70C5E81}\MpKslfd55e01f.sys [?]
S1 MpKslfe9d748b;MpKslfe9d748b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{34FE2876-BFC2-45AE-8433-FFA02FCC5A49}\MpKslfe9d748b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{34FE2876-BFC2-45AE-8433-FFA02FCC5A49}\MpKslfe9d748b.sys [?]
S1 MpKslfff094f7;MpKslfff094f7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKslfff094f7.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6DED3974-3AE7-4741-AED7-954511664276}\MpKslfff094f7.sys [?]
S1 MpKslfff8066c;MpKslfff8066c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslfff8066c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF30EE57-14D7-4F04-872E-6C9A568AE709}\MpKslfff8066c.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/3/2010 11:35 PM 135664]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49 AM 227232]
S3 SASENUM;SASENUM;c:\downloads\SUPERAntiSpyware\SASENUM.SYS [7/4/2009 2:31 PM 7408]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/3/2010 11:35 PM 135664]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLD58D0842
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 09:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-15 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2004\SystemOptimizer.exe [2004-08-11 23:44]
.
2011-07-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-20 14:33]
.
2011-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-04 04:35]
.
2011-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-04 04:35]
.
2007-03-19 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2007-03-19 00:12]
.
2007-03-19 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2007-03-19 00:12]
.
2007-03-19 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2007-03-19 00:12]
.
2011-07-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
.
2011-07-21 c:\windows\Tasks\User_Feed_Synchronization-{152C0A29-12ED-4E1E-977C-AA2DF2506598}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: &Webshots Photo Search - c:\program files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: SnipeIt! eSnipe - http://www.esnipe.com/SnipeIt/SnipeItOpen3.asp
TCP: DhcpNameServer = 192.168.1.254
DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} - hxxp://stories.scrapbooksetc.com/create/DragDropUploader.cab
DPF: {F84E0B64-1E86-4640-8094-5B38CEB28C1E} - hxxps://skyfex.com/download/SkyFexClient.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\bcxcrvpz.Barbara Profile\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Ask Toolbar: [removed] - %profile%\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: AI Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - c:\program files\Siber Systems\AI RoboForm\Firefox
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-21 07:49
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1913649232-1903779106-1315696893-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(608)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-07-21 07:52:35
ComboFix-quarantined-files.txt 2011-07-21 12:52
ComboFix2.txt 2011-07-19 18:53
ComboFix3.txt 2010-03-07 19:21
ComboFix4.txt 2010-03-07 14:27
.
Pre-Run: 104,654,962,688 bytes free
Post-Run: 104,672,329,728 bytes free
.
- - End Of File - - DE512E91426A44F777D3AD7C47AAC3C3
Hi tboneman,

I notice that you have Malwarebytes on your system already. Please update the program and then run a Quick Scan. Malwarebytes, when complete, will create a log that I will need in your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs created by both Malwarebytes and ESET Online Scanner.
Jeff, Ran the Eset scan. It didn't find anything. When I closed the program if it created a log file, I couldn't find it. I also ran the long MBam scan. It didn't find anything, either. From what I saw, Combo Fix was the only program to delete files and folders. How important this is, you would have to determine that. I'm done scanning, Jeff. If none of these programs was able to find anything, there's probably nothing to find. Which brings us back to my first post, which asked the question: how or what virus was able to shut down Microsft Essentials, on the fly, and take over the computer? tbone
Hi tboneman,

As for your question about what could have caused this it is hard to tell since your went to an earlier restore point. There are many viruses that could have done this, but removing your third-party permissions as you did earlier is one way to help prevent future infections.
———-

I see that you have downloaded ComboFix to here

c:\documents and settings\Owner\Desktop\Windows XP Fix Utilities\ComboFix.exe

Please delete this by right-clicking the ComboFix icon and selecting delete. Then I want you to download a fresh version from here and be sure to download it directly to your DESKTOP.
———-


You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 8.1.2 first. Be sure to move any PDF documents to another folder first though.
———-

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-

Now run another DDS scan and post the logs created into your next reply.
Hey, "I see that you have downloaded ComboFix to here c:\documents and settings\Owner\Desktop\Windows XP Fix Utilities\ComboFix.exe" Actually, every file we download. goes to a folder called Download. This way, we always know where our downloads are. From there, they are installed. The XPFix Utilities folder sits on the Desktop. Downloading another copy of Combo Fix is pointless, as whatever version I have is automatically updated before CF does its scan. Your insistence of having everything DLd to the Desktop is for newbies. I've been out here for 15 years. I know what a folder is, and a directory and lots of other stuff. I put programs in folders that make sense to me, for my own reasons. FoxIt Reader is already the default PDF reader on my computer, but not on hers. I think this is not a biggie, one way or another. I can update her version of Adobe Reader. And as far as Java Ra is concerned, I don't think I'll be doing that. As I said, there have already been a half dozen scans done with nothing found. Java Ra is not likely to change that. So what I hear (read) you saying is, you just don't know how the virus came on board. I really appreciate your making the effort. Some things just aren''t solveable, I guess. Best, tbone
Hi tboneman,

Downloading another copy of Combo Fix is pointless, as whatever version I have is automatically updated before CF does its scan. Your insistence of having everything DLd to the Desktop is for newbies.

Actually the reason has nothing to do with experience level when using ComboFix. Whether it be someone with 1 year or 15 years (such as yourself) we have ComboFix downloaded directly to the DESKTOP due to uninstall procedures of the tool. So please, if you don't mind, either delete the icon from the location you have it at now and download a new copy from the link in my previous post or move the icon to your Desktop so that we can properly remove it when we have finished.

FoxIt Reader is already the default PDF reader on my computer, but not on hers. I think this is not a biggie, one way or another. I can update her version of Adobe Reader.

That is great that you are able to keep Adobe updated. Good Job!! It is always a good idea to keep your software up to date as having out-dated software will always create security vulnerabilities that could invite future infections. Right now you are using Adobe Reader 8.1.2 which is out of date as the most current version is Adobe Reader X (10.1.0). I would highly recommend that you at some time get the new version found here, but be sure to uninstall the old version, Adobe Reader 8.1.2, so that you do not have two versions of Adobe Reader on your system.

And as far as Java Ra is concerned, I don't think I'll be doing that. As I said, there have already been a half dozen scans done with nothing found. Java Ra is not likely to change that.

JavaRa is a tool to simply help with removing older version of Java that are on your system. Presently you are using Java™ 6 Update 22 which is an outdated version of software. As with what I noted above with Adobe, out-dated versions of Java create security vulnerabilities that can allow access to your system and cause future infections. The current version of Java is Java™ 6 Update 26.

Once you get ComboFix moved to the desktop just let me know and we can continue on. :)
Hi tboneman,

Glad that I could be of assistance. :)
———-

The following will implement some cleanup procedures as well as reset System Restore points (as a note, this will ONLY work if you have ComboFix on your desktop):

Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.
———-

As you asked about third party permissions earlier, I like to use on my FireFox browser two add-ons that help with the security of your system by not allowing specific types of ads and automatic startup of Java screens. They are Ad-Block and NoScript. I use them on all of my systems and may help you as well.
———-

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
3. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here.
**Do not install more than one firewall program because they will conflict with each other**

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

7. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

8. WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop
WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

9. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware

10. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?


Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI