Think my PC is Infected with malware
75 min read
I'm Sunyata and I will be helping you with your computer problems.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.
Please read the following guidelines which will help to make cleaning your machine easier:
- Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
- The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
- Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
- Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
- PLEASE DO NOT install/uninstall any programs unless asked to.
- PLEASE DO NOT run any malware scans other than those requested.
- Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
- I will reply back shortly with instructions
Note to Vista and Windows 7 users:
- These tools MUST be run from the executable. (.exe) every time you run them
- These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
First,
Please post the log from the TDSSKiller run you previously executed. It can usually be found here:
C:\TDSSKiller.[Version]_[Date]_[Time]_log.txt, where "[Version]_[Date]_[Time]" is variable information.
Next,
Please download aswMBR to your desktop.
- Double click the aswMBR icon to run it.
Vista and Windows 7 users right click the icon and choose "Run as administrator".
- When asked if you want to download Avast's virus definitions please select Yes.
- Click the Scan button to start scan.
- When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
Please read through these instructions to familarize yourself with what to expect when this tool runs
Please download ComboFix from one of the following locations:
- LINK 1
- LINK 2
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link :How to Disable your Security Programs
- Double click on 'ComboFix.exe' & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message box:
[external image: Posted Image]
Click on 'Yes', to continue scanning for malware.
When finished, it will produce a log for you.
Please include the contents of C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making Internet Explorer the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please let me know.
5. ComboFix disconnects your machine from the internet. The connection is automatically restored before ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
In your next reply please post the log created by ComboFix.
I saved a txt file after it scanned to my desktop though and named it combofix, is this the correct log?
ComboFix 11-10-21.03 - Allyc 21/10/2011 19:52:24.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3326.2776 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\Downloads\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Allyc\Application Data\inst.exe
c:\documents and settings\Allyc\Application Data\msregsvv.dll
c:\documents and settings\Allyc\Application Data\vso_ts_preview.xml
c:\documents and settings\Allyc\Cookies\isindex.dat
c:\windows\help\tours\htmltour\unlock_playing.htm
c:\windows\system32\d3d9caps.dat
c:\windows\system32\drivers\etc\hosts.txt
c:\windows\system32\msvcsv60.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-09-21 to 2011-10-21 )))))))))))))))))))))))))))))))
.
.
2011-10-17 13:19 . 2011-10-17 13:19 ——– d—–w- C:\TDSSKiller_Quarantine
2011-10-17 04:29 . 2011-05-24 18:14 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-10-16 19:48 . 2011-10-16 19:48 ——– d—–w- c:\program files\ESET
2011-10-14 11:50 . 2010-12-22 10:33 9078960 —-a-w- c:\windows\system32\mkl_p4p.dll
2011-10-14 11:50 . 2010-12-22 10:33 9033904 —-a-w- c:\windows\system32\mkl_p4m3.dll
2011-10-14 11:50 . 2010-12-22 10:33 9410736 —-a-w- c:\windows\system32\mkl_p4m.dll
2011-10-14 11:50 . 2010-12-22 10:33 9210032 —-a-w- c:\windows\system32\mkl_p4.dll
2011-10-14 11:50 . 2010-12-22 10:33 3868848 —-a-w- c:\windows\system32\mkl_intel_thread.dll
2011-10-14 11:50 . 2010-12-22 10:33 6944944 —-a-w- c:\windows\system32\mkl_core.dll
2011-10-14 11:50 . 2010-12-22 10:33 530608 —-a-w- c:\windows\system32\libiomp5md.dll
2011-10-14 11:49 . 2011-10-14 11:49 ——– d—–w- c:\program files\Steinberg
2011-10-14 11:49 . 2009-10-14 15:15 499712 —-a-w- c:\windows\msvcp71.dll
2011-10-14 11:49 . 2009-10-14 15:15 348160 —-a-w- c:\windows\msvcr71.dll
2011-10-14 11:49 . 2011-10-14 11:51 ——– d—–w- c:\program files\IK Multimedia
2011-10-14 11:49 . 2011-10-14 11:49 ——– d—–w- c:\program files\VstPlugIns
2011-10-14 10:40 . 2011-10-14 11:12 ——– d—–w- c:\documents and settings\Allyc\Application Data\IK Multimedia
2011-10-14 10:32 . 2011-10-14 10:32 ——– d—–w- c:\program files\QuickTime
2011-10-14 10:32 . 2011-10-14 10:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2011-10-14 10:32 . 2011-10-14 10:32 ——– d—–w- c:\program files\Common Files\Apple
2011-10-14 10:32 . 2011-10-14 10:32 ——– d—–w- c:\program files\Apple Software Update
2011-10-14 10:32 . 2011-10-14 10:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2011-10-14 08:30 . 2011-10-14 08:30 ——– d—–w- c:\program files\WinPcap
2011-10-14 08:24 . 2009-09-02 12:44 65602 —-a-w- c:\windows\system32\cook3260.dll
2011-10-14 08:24 . 2009-09-02 12:44 626688 —-a-w- c:\windows\system32\vp7vfw.dll
2011-10-14 08:24 . 2009-09-02 12:44 217127 —-a-w- c:\windows\system32\drv43260.dll
2011-10-14 08:24 . 2009-09-02 12:44 208935 —-a-w- c:\windows\system32\drv33260.dll
2011-10-14 08:24 . 2009-09-02 12:44 176165 —-a-w- c:\windows\system32\drv23260.dll
2011-10-14 08:24 . 2009-09-02 12:44 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll
2011-10-14 08:24 . 2009-09-02 12:44 102439 —-a-w- c:\windows\system32\sipr3260.dll
2011-10-06 02:36 . 2011-10-06 02:36 ——– d—–w- c:\program files\CCleaner
2011-10-04 01:51 . 2011-10-04 01:53 ——– d—–w- c:\program files\TweakNow RegCleaner 2011
2011-10-04 01:51 . 2011-10-04 01:51 ——– d—–w- c:\documents and settings\Allyc\Application Data\TweakNow RegCleaner 2011
2011-10-03 09:12 . 2009-07-06 09:48 11448 —-a-w- c:\windows\system32\drivers\AsUpIO.sys
2011-10-03 09:12 . 2009-09-30 10:33 24576 —-a-w- c:\windows\system32\AsIO.dll
2011-10-03 09:12 . 2009-08-04 09:28 11296 —-a-w- c:\windows\system32\drivers\AsIO.sys
2011-10-03 09:12 . 2011-10-03 09:12 ——– d—–w- c:\program files\ASUS
2011-09-30 03:37 . 2011-10-17 05:15 ——– d—–w- c:\documents and settings\Allyc\Application Data\vlc
2011-09-30 03:37 . 2011-09-30 03:37 ——– d—–w- c:\program files\VideoLAN
2011-09-30 03:24 . 2011-09-30 03:35 ——– d—–w- c:\documents and settings\Allyc\Application Data\Media Player Classic
2011-09-30 03:16 . 2011-09-30 03:16 ——– d–h–w- c:\windows\msdownld.tmp
2011-09-30 03:15 . 2011-09-30 16:39 ——– d—–w- c:\program files\Essentials Codec Pack
2011-09-30 03:14 . 2011-09-30 03:14 ——– d—–w- c:\documents and settings\Allyc\Application Data\Nullsoft
2011-09-24 10:50 . 2011-09-24 10:50 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-24 10:41 . 2011-09-24 10:50 ——– d—–w- c:\documents and settings\Allyc\Local Settings\Application Data\Solid State Networks
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-14 08:24 . 2011-06-03 07:19 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2011-10-14 08:24 . 2011-06-03 07:19 47360 —-a-w- c:\documents and settings\Allyc\Application Data\pcouffin.sys
2011-09-26 10:41 . 2009-10-08 13:57 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 2004-08-04 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 10:41 . 2004-08-04 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-18 15:46 . 2011-09-18 15:47 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-18 15:46 . 2011-06-02 18:59 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-09-09 09:12 . 2004-08-04 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2004-08-04 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-31 16:00 . 2011-06-03 06:55 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 23:48 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2004-08-04 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2004-08-04 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-04 12:00 385024 ——w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2004-08-04 12:00 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2011-07-28 19:54 . 2011-02-28 17:01 947472 —-a-w- c:\windows\system32\msjava.dll
2011-07-26 20:57 . 2011-07-26 20:57 1060864 —-a-w- c:\windows\system32\mfc71.dll
2011-07-26 20:57 . 2011-07-26 20:57 1700352 —-a-w- c:\windows\system32\gdiplus.dll
2011-09-30 18:00 . 2011-06-02 16:48 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostsMan"="c:\program files\HostsMan\hm.exe" [2010-02-06 3043840]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 16844800]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 202296]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-05 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\VSO\\VSO Downloader\\1\\VsoDownloader.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [03/10/2011 10:12 11448]
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [04/03/2011 13:23 11352]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [17/02/2010 19:25 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [04/05/2011 18:54 116608]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [02/06/2011 21:42 328536]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [16/07/2010 01:45 35088]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [10/03/2011 18:34 34608]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/11/2009 20:27 19472]
R3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [03/06/2011 10:46 580480]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [03/06/2011 08:19 47360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13:16 130384]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 13:37 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [04/08/2004 13:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13:16 753504]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ASWMBR
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2011-10-21 c:\windows\Tasks\ASC4_AutoCare.job
- c:\program files\IObit\Advanced SystemCare 4\AutoCare.exe [2011-06-02 15:38]
.
2011-10-19 c:\windows\Tasks\ASC4_AutoConverter.job
- c:\program files\IObit\Advanced SystemCare 4\LicenseConverter.exe [2011-10-19 16:45]
.
.
——- Supplementary Scan ——-
.
mStart Page = about:blank
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Allyc\Application Data\Mozilla\Firefox\Profiles\kesbenv4.default\
FF - prefs.js: browser.startup.homepage - hxxp://uk.yahoo.com/
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-21 19:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1156)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
.
Completion time: 2011-10-21 19:55:25
ComboFix-quarantined-files.txt 2011-10-21 18:55
.
Pre-Run: 304,943,263,744 bytes free
Post-Run: 304,967,569,408 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - E0CC6C4663E512FA76860FC5AE3D5C76
That'd be the oneis this the correct log?
It's time to sweep for leftovers…
Scan For Malware:
Download and save to your desktop Malwarebytes Anti-Malware
Double Click mbam-setup.exe to install the application.
- Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy&Paste the entire report in your next reply.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
Do An Online Scan For Viruses:
Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.
- Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan
- Click the [external image: Posted Image] button.
- For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
- Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
- Double click on the [external image: Posted Image] icon on your desktop.
- Check [external image: Posted Image]
- Click the Start button.
- Accept any security warnings from your browser.
- Check [external image: Posted Image]
- Make sure that the option "Remove found threats" is Unchecked
- Push the Start button.
- ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
- When the scan completes, push [external image: Posted Image]
- Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Include the contents of this report in your next reply.
- Push the Back button.
- Push Finish
How is your system is running now?
For your icon refresh problem, bring up the following page and download number 121 on the list, "iconcache.vbs".
Once on your machine, simply double click the file, press "OK" on the dialog that comes up, then reboot your machine:
http://www.kellys-korner-xp.com/xp_tweaks.htm
Next,
Please run another DDS scan:
- Double click DDS.scr to run it and wait for the scan to finish
- When finished DDS.txt will open
- A small while later, a prompt will open. Answer Yes
- DDS will continue scanning
- When done, Attach.txt will open
- Post DDS.txt and attach Attach.txt
P2P - I see you have P2P software ( µTorrent ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Add or Remove Programs.
Ally, please tell me how your machine is running now. Are there any further issues?
You are most welcomeMy PC is running great now thanks.
Now we need to clean up our tools…
From your desktop, please delete
- logs that we created
- MBR.dat
- MBR.zip
- aswMBR.exe
I recommend you keep Malwarebyte's Anti-Malware, update it regularly and run it often.
Follow these steps to uninstall Combofix
- Make sure your security programs are totally disabled.
- Click START then RUN
- Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
The above procedure will:
- Implement some cleanup procedures.
- Reset System Restore.
Next, Please re-enable any security that was disabled.
Here are a few recomendations to help keep you malware-free:
Make your Internet Explorer more secure - This can be done by following these simple instructions:
- From within Internet Explorer click on the Tools menu and then click on Options.
- Click once on the Security tab
- Click once on the Internet icon so it becomes highlighted.
- Click once on the Custom Level button.
- Change the Download signed ActiveX controls to Prompt
- Change the Download unsigned ActiveX controls to Disable
- Change the Initialize and script ActiveX controls not marked as safe to Disable
- Change the Installation of desktop items to Prompt
- Change the Launching programs and files in an IFRAME to Prompt
- Change the Navigate sub-frames across different domains to Prompt
- When all these settings have been made, click on the OK button.
- If it prompts you as to whether or not you want to save the settings, press the Yes button.
- Next press the Apply button and then the OK to exit the Internet Properties page.
Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.
WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for both Firefox and IE.
Only run one Anti-Virus and Firewall program.
I would suggest you read:
PC Safety and Security–What Do I Need?
How to Prevent Malware
Please acknowledge with one more post so that we may close this thread.
Take care and safe computing
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI