This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

infected with trojan or rootkit - maybe mdefender [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I ran Malwarebytes antimalware because my computer was popping up with all sorts of error messages that I knew were not actual errors. It said it discovered 4 files and 1 registry file and it said it removed them. I am still having problems with my computer. Like the internet will close automatically.. both internet explorer and firefox. I also put the Malwarebytes logs at the bottom in-case that is helpful at all.



Here is my DDS Log

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_23
Run by [removed] at 16:11:23 on 2011-11-27
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.446 [GMT -6:00]
.
AV: AVG Internet Security 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Antivirus AntiSpyware 2011 *Enabled/Updated* {7A7C62D5-3E0E-428A-B99E-F88986F30D6E}
AV: Personal Internet Security 2011 *Enabled/Updated* {2C8F87C8-9D0A-4311-8244-A061B30F2EB3}
FW: Personal Internet Security 2011 *Enabled*
FW: AVG Firewall *Disabled*
FW: Antivirus AntiSpyware 2011 *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\System32\svchost.exe -k eapsvcs
svchost.exe
C:\WINDOWS\System32\svchost.exe -k dot3svc
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
mStart Page = hxxp://www.yahoo.com
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Jkeqix] rundll32.exe "c:\windows\acepiguyor.dll",Startup
StartupFolder: c:\docume~1\jenna\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgetEngine.exe
uPolicies-explorer: DisallowRun = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: microsoft.com\support
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{814214B4-E12D-4F12-83F4-2665E97E1542} : DhcpNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: itlntfy - itlnfw32.dll
IFEO: image file execution options - svchost.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\jenna\application data\mozilla\firefox\profiles\eqiypswi.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://blink.bethel.edu/
FF - prefs.js: keyword.URL - hxxp://myclearsearch.com/?prt=Guppymcs02ff&Keywords=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 56667
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\jenna\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: XULRunner: {8FC8D1C6-133D-4A17-8A1C-816C1C52A68C} - c:\documents and settings\jenna\local settings\application data\{8FC8D1C6-133D-4A17-8A1C-816C1C52A68C}
.
—- FIREFOX POLICIES —-
FF - user.js: keyword.URL - hxxp://myclearsearch.com/?prt=Guppymcs02ff&Keywords=
FF - user.js: keyword.enabled - 1
.
============= SERVICES / DRIVERS ===============
.
S0 mdfhvgg;mdfhvgg;c:\windows\system32\drivers\dksgket.sys –> c:\windows\system32\drivers\dksgket.sys [?]
S0 npqitlg;npqitlg;c:\windows\system32\drivers\vdse.sys –> c:\windows\system32\drivers\vdse.sys [?]
S2 itlperf;Intel CPU Perfermons;c:\windows\system32\svchost.exe -k itlsvc [2004-8-10 14336]
S2 srvAA8;srvAA8;c:\windows\system32\svchost.exe -k netsvcs [2004-8-10 14336]
.
=============== Created Last 30 ================
.
2011-11-27 22:06:28 607260 ——r- C:\dds(1).scr
2011-11-27 21:38:56 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2011-11-27 21:38:56 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-11-27 21:38:55 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll
2011-11-27 21:38:54 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll
2011-11-27 21:38:54 478168 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-11-27 21:38:54 1989592 —-a-w- c:\program files\mozilla firefox\mozjs.dll
2011-11-27 21:38:54 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-11-27 21:38:53 801752 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-11-27 20:41:18 ——– d—–w- c:\documents and settings\jenna\application data\MSNInstaller
.
==================== Find3M ====================
.
2011-11-27 20:02:40 0 —-a-w- c:\windows\Vwusoh.bin
2011-08-31 23:00:50 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: FUJITSU_MHV2100BH rev.00850028 -> Harddisk0\DR0 -> \Device\Ide\IdePort0 P0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x87143439]<< >>UNKNOWN [0x87051929]<<
_asm { INT 3 ; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x871497d0]; MOV EAX, [0x8714984c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8717FAB8]
3 CLASSPNP[0xF757DFD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x87119A78]
\Driver\atapi[0x87176C98] -> IRP_MJ_CREATE -> 0x87143439
kernel: MBR read successfully
_asm { MOV AX, 0x0; MOV SS, AX; MOV SP, 0x7c00; MOV DS, AX; CLD ; MOV CX, 0x100; MOV SI, SP; MOV DI, 0x600; MOV ES, AX; REP MOVSW ; JMP FAR 0x0:0x62c; }
detected disk devices:
\Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskFUJITSU_MHV2100BH_______________________00850028#5&19c84639&2&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x8714327F
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 16:14:17.64 ===============




The Second log from DDS

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 7/29/2006 1:33:24 AM
System Uptime: 11/27/2011 3:43:30 PM (1 hours ago)
.
Motherboard: Dell Inc. | | 0KD882
Processor: Genuine Intel® CPU T2300 @ 1.66GHz | Microprocessor | 1664/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 88 GiB total, 29.596 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Broadcom 440x 10/100 Integrated Controller
Device ID: PCI\VEN_14E4&DEV_170C&SUBSYS_01AF1028&REV_02\4&2FE911E8&0&00F0
Manufacturer: Broadcom
Name: Broadcom 440x 10/100 Integrated Controller
PNP Device ID: PCI\VEN_14E4&DEV_170C&SUBSYS_01AF1028&REV_02\4&2FE911E8&0&00F0
Service: bcm4sbxp
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\32A10141374FC000
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\32A10141374FC000
Service: NIC1394
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
32 Bit HP CIO Components Installer
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.0.1)
Adobe Shockwave Player
Alarm 2.0.4
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Bonjour
Broadcom Management Programs
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
Dell Digital Jukebox Driver
Dell Driver Download Manager
Dell Media Experience
Dell Support Center (Support Software)
Dell Wireless WLAN Card
DellSupport
Digital Content Portal
Digital Line Detect
DivX
DivX Player
DivX Web Player
Facebook Plug-In
Form Fill (Windows Live Toolbar)
High Definition Audio Driver Package - KB835221
Hotfix 2050 for SQL Server 2000 ENU (KB948110)
Hotfix 2055 for SQL Server 2000 ENU (KB960082)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Intel® Graphics Media Accelerator Driver
iTunes
Java Auto Updater
Java™ 6 Update 23
Logitech QuickCam
Logitech QuickCam Driver Package
Macromedia Flash Player
Malwarebytes' Anti-Malware version 1.51.2.1300
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Small Business Accounting 2006
Microsoft Office Small Business Edition 2003
Microsoft Plus! Photo Story 2 LE
Microsoft Search Enhancement Pack
Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Modem Helper
Mozilla Firefox 8.0 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NetWaiting
PowerDVD 5.7
QuickBooks Simple Start Special Edition
QuickSet
QuickTime
Rhapsody Player Engine
SBA
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB2183461)
Security Update for Windows Internet Explorer 7 (KB2360131)
Security Update for Windows Internet Explorer 7 (KB2416400)
Security Update for Windows Internet Explorer 7 (KB2482017)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Encoder (KB2447961)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Encoder (KB979332)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Segoe UI
Skype™ 4.2
Smart Menus (Windows Live Toolbar)
SmartSound Quicktracks Plugin
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Synaptics Pointing Device Driver
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar Feed Detector (Windows Live Toolbar)
Windows Live Upload Tool
Windows Media Encoder 9 Series
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
Yahoo! Widgets
.
==== Event Viewer Messages From Past Week ========
.
11/27/2011 6:22:36 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: APPDRV Fips intelppm
11/27/2011 2:44:55 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
11/27/2011 12:47:27 PM, error: Service Control Manager [7023] - The srvAA8 service terminated with the following error: Invalid access to memory location.
11/27/2011 12:47:27 PM, error: Service Control Manager [7023] - The SAP Agent service terminated with the following error: The specified module could not be found.
11/27/2011 12:47:27 PM, error: Service Control Manager [7023] - The Network Security service terminated with the following error: The specified module could not be found.
11/27/2011 12:47:27 PM, error: Service Control Manager [7023] - The Intel CPU Perfermons service terminated with the following error: The specified module could not be found.
11/27/2011 12:46:09 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
11/27/2011 12:45:46 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
11/26/2011 11:17:43 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
11/26/2011 11:16:28 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD APPDRV Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
11/26/2011 11:16:28 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
11/26/2011 11:16:28 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
11/26/2011 11:16:28 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
11/26/2011 11:16:28 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
11/26/2011 11:16:28 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
11/26/2011 11:16:28 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
11/26/2011 11:12:06 PM, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).
11/23/2011 1:21:22 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
11/21/2011 11:38:23 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
11/21/2011 11:38:15 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
.
==== End Of File ===========================



Here are the MBAM Logs

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8252

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 7.0.5730.11

11/27/2011 12:45:24 PM
mbam-log-2011-11-27 (12-45-24).txt

Scan type: Full scan (C:\|)
Objects scanned: 312532
Time elapsed: 59 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\all users\application data\privacy.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\Jenna\local settings\temp\0.10619912742670645fdrgs.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jenna\local settings\temp\B6.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jenna\local settings\temp\B7.tmp (Trojan.Agent) -> Quarantined and deleted successfully.





Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8252

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

11/27/2011 1:58:50 PM
mbam-log-2011-11-27 (13-58-50).txt

Scan type: Full scan (C:\|)
Objects scanned: 293269
Time elapsed: 1 hour(s), 5 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Privacy Protection (Rogue.PrvacyProtect) -> Value: Privacy Protection -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hello D_Piddy89

You have a serious infection on your computer.

However, you have requested help at another forum as well as here at WTT.

Please read this and close either the topic at the other forum or request that we close this.

If the other forum has not been informed and/or we don’t hear from you within 24 hours, this will be closed.

Satchfan
Hello again D Piddy89

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

aswMBR log

Thanks

Satchfan
Alright, here is my log aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-28 16:57:16 —————————– 16:57:16.453 OS Version: Windows 5.1.2600 Service Pack 3 16:57:16.453 Number of processors: 2 586 0xE08 16:57:16.453 ComputerName: BAHJEN UserName: Jenna 16:57:17.593 Initialize success 16:57:59.421 AVAST engine defs: 11112802 16:58:58.343 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0 16:58:58.343 Disk 0 Vendor: FUJITSU_MHV2100BH 00850028 Size: 93958MB BusType: 3 16:58:58.359 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskFUJITSU_MHV2100BH_______________________00850028#5&19c84639&2&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found 16:58:58.359 Device \Driver\atapi -> DriverStartIo 8713a27f 16:59:00.359 Disk 0 MBR read successfully 16:59:00.359 Disk 0 MBR scan 16:59:00.437 Disk 0 MBR:Alureon-G [Rtk] 16:59:00.437 Disk 0 TDL4@MBR code has been found 16:59:00.437 Disk 0 MBR hidden 16:59:00.437 Disk 0 MBR [TDL4] **ROOTKIT** 16:59:00.453 Disk 0 trace - called modules: 16:59:00.453 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8713a439]<<>>UNKNOWN [0x86f83379]<< 16:59:00.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87154ab8] 16:59:00.453 3 CLASSPNP.SYS[f757dfd7] -> nt!IofCallDriver -> [0x870b3580] 16:59:00.468 \Driver\atapi[0x8717a270] -> IRP_MJ_CREATE -> 0x8713a439 16:59:01.031 AVAST engine scan C:\WINDOWS 16:59:07.109 File: C:\WINDOWS\acepiguyor.dll **INFECTED** Win32:MalOb-EG [Cryp] 16:59:21.093 AVAST engine scan C:\WINDOWS\system32 17:01:08.609 AVAST engine scan C:\WINDOWS\system32\drivers 17:01:11.875 File: C:\WINDOWS\system32\drivers\acpi.sys **INFECTED** Win32:RLoader-B 17:01:25.593 AVAST engine scan C:\Documents and Settings\Jenna 17:11:58.234 File: C:\Documents and Settings\Jenna\Local Settings\temp\5557.sys **INFECTED** Win32:Rootkit-gen [Rtk] 17:12:15.937 File: C:\Documents and Settings\Jenna\Local Settings\temp\jar_cache4904684289884108571.tmp **INFECTED** Win32:Rootkit-gen [Rtk] 17:17:09.656 AVAST engine scan C:\Documents and Settings\All Users 17:18:30.343 Scan finished successfully 17:19:36.609 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Jenna\My Documents\MBR.dat" 17:19:36.625 The log file has been saved successfully to "C:\Documents and Settings\Jenna\My Documents\aswMBR.txt" Thanks
D_Piddy89
  • re-Run aswMBR
  • click Scan
  • on completion of the scan click the Fix button
🖼Click to load external image (Posted Image)

Save the log as before and post in your next reply

=================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Satchfan

Satchfan
Alright I did those. Here are my logs. Thanks

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-29 10:21:09
—————————–
10:21:09.359 OS Version: Windows 5.1.2600 Service Pack 3
10:21:09.359 Number of processors: 2 586 0xE08
10:21:09.359 ComputerName: BAHJEN UserName: Jenna
10:21:10.484 Initialize success
10:21:24.640 AVAST engine defs: 11112802
10:21:28.703 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0
10:21:28.703 Disk 0 Vendor: FUJITSU_MHV2100BH 00850028 Size: 93958MB BusType: 3
10:21:28.703 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskFUJITSU_MHV2100BH_______________________00850028#5&19c84639&2&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
10:21:28.718 Device \Driver\atapi -> DriverStartIo 8710427f
10:21:30.718 Disk 0 MBR read successfully
10:21:30.718 Disk 0 MBR scan
10:21:30.781 Disk 0 MBR:Alureon-G [Rtk]
10:21:30.781 Disk 0 TDL4@MBR code has been found
10:21:30.796 Disk 0 MBR hidden
10:21:30.796 Disk 0 MBR [TDL4] **ROOTKIT**
10:21:30.796 Disk 0 trace - called modules:
10:21:30.812 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x87104439]<<>>UNKNOWN [0x8704dc01]<<
10:21:30.812 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8717cab8]
10:21:30.812 3 CLASSPNP.SYS[f757dfd7] -> nt!IofCallDriver -> [0x870c8118]
10:21:30.843 \Driver\atapi[0x87116270] -> IRP_MJ_CREATE -> 0x87104439
10:21:31.531 AVAST engine scan C:\WINDOWS
10:21:37.375 File: C:\WINDOWS\acepiguyor.dll **INFECTED** Win32:MalOb-EG [Cryp]
10:21:50.875 AVAST engine scan C:\WINDOWS\system32
10:23:45.484 AVAST engine scan C:\WINDOWS\system32\drivers
10:23:48.750 File: C:\WINDOWS\system32\drivers\acpi.sys **INFECTED** Win32:RLoader-B
10:24:03.328 AVAST engine scan C:\Documents and Settings\Jenna
10:34:25.281 File: C:\Documents and Settings\Jenna\Local Settings\temp\5557.sys **INFECTED** Win32:Rootkit-gen [Rtk]
10:34:42.406 File: C:\Documents and Settings\Jenna\Local Settings\temp\jar_cache4904684289884108571.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
10:39:28.750 AVAST engine scan C:\Documents and Settings\All Users
10:40:50.656 Scan finished successfully
10:43:54.281 Disk 0 MBR read successfully
10:43:54.281 Disk 0 MBR:Alureon-G [Rtk]
10:43:54.281 Disk 0 TDL4@MBR code has been found
10:43:54.296 Disk 0 fixing MBR …
10:44:04.296 Disk 0 MBR restored successfully
10:44:04.296 Verifying disinfection
10:44:16.343 Infection fixed successfully - please reboot ASAP
10:45:21.000 Disk 0 MBR has been saved successfully to "E:\aviru\2\MBR.dat"
10:45:21.062 The log file has been saved successfully to "E:\aviru\2\aswMBR.txt"






ComboFix 11-11-29.04 - Jenna 11/29/2011 11:21:32.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.295 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Internet Security 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts
c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\Digital Line Detect.lnk
c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\Service Manager.lnk
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Jenna\Application Data\9A8A.6FE
c:\documents and settings\Jenna\Application Data\Adobe\plugs
c:\documents and settings\Jenna\Application Data\Adobe\shed
c:\documents and settings\Jenna\Application Data\OfferBox
c:\documents and settings\Jenna\Application Data\OfferBox\config.dat
c:\documents and settings\Jenna\Application Data\OfferBox\config.xml
c:\documents and settings\Jenna\Local Settings\Application Data\{8FC8D1C6-133D-4A17-8A1C-816C1C52A68C}
c:\documents and settings\Jenna\Local Settings\Application Data\{8FC8D1C6-133D-4A17-8A1C-816C1C52A68C}\chrome.manifest
c:\documents and settings\Jenna\Local Settings\Application Data\{8FC8D1C6-133D-4A17-8A1C-816C1C52A68C}\chrome\content\_cfg.js
c:\documents and settings\Jenna\Local Settings\Application Data\{8FC8D1C6-133D-4A17-8A1C-816C1C52A68C}\chrome\content\overlay.xul
c:\documents and settings\Jenna\Local Settings\Application Data\{8FC8D1C6-133D-4A17-8A1C-816C1C52A68C}\install.rdf
c:\documents and settings\Jenna\My Documents\~WRL0153.tmp
c:\documents and settings\Jenna\My Documents\~WRL0155.tmp
c:\documents and settings\Jenna\My Documents\~WRL0250.tmp
c:\documents and settings\Jenna\My Documents\~WRL0281.tmp
c:\documents and settings\Jenna\My Documents\~WRL0294.tmp
c:\documents and settings\Jenna\My Documents\~WRL0449.tmp
c:\documents and settings\Jenna\My Documents\~WRL0470.tmp
c:\documents and settings\Jenna\My Documents\~WRL0533.tmp
c:\documents and settings\Jenna\My Documents\~WRL0591.tmp
c:\documents and settings\Jenna\My Documents\~WRL0594.tmp
c:\documents and settings\Jenna\My Documents\~WRL0750.tmp
c:\documents and settings\Jenna\My Documents\~WRL0797.tmp
c:\documents and settings\Jenna\My Documents\~WRL0806.tmp
c:\documents and settings\Jenna\My Documents\~WRL0874.tmp
c:\documents and settings\Jenna\My Documents\~WRL0919.tmp
c:\documents and settings\Jenna\My Documents\~WRL0966.tmp
c:\documents and settings\Jenna\My Documents\~WRL1121.tmp
c:\documents and settings\Jenna\My Documents\~WRL1183.tmp
c:\documents and settings\Jenna\My Documents\~WRL1196.tmp
c:\documents and settings\Jenna\My Documents\~WRL1227.tmp
c:\documents and settings\Jenna\My Documents\~WRL1233.tmp
c:\documents and settings\Jenna\My Documents\~WRL1266.tmp
c:\documents and settings\Jenna\My Documents\~WRL1332.tmp
c:\documents and settings\Jenna\My Documents\~WRL1530.tmp
c:\documents and settings\Jenna\My Documents\~WRL1681.tmp
c:\documents and settings\Jenna\My Documents\~WRL1701.tmp
c:\documents and settings\Jenna\My Documents\~WRL1715.tmp
c:\documents and settings\Jenna\My Documents\~WRL1781.tmp
c:\documents and settings\Jenna\My Documents\~WRL1794.tmp
c:\documents and settings\Jenna\My Documents\~WRL2069.tmp
c:\documents and settings\Jenna\My Documents\~WRL2101.tmp
c:\documents and settings\Jenna\My Documents\~WRL2201.tmp
c:\documents and settings\Jenna\My Documents\~WRL2243.tmp
c:\documents and settings\Jenna\My Documents\~WRL2371.tmp
c:\documents and settings\Jenna\My Documents\~WRL2373.tmp
c:\documents and settings\Jenna\My Documents\~WRL2377.tmp
c:\documents and settings\Jenna\My Documents\~WRL2496.tmp
c:\documents and settings\Jenna\My Documents\~WRL2505.tmp
c:\documents and settings\Jenna\My Documents\~WRL2606.tmp
c:\documents and settings\Jenna\My Documents\~WRL2741.tmp
c:\documents and settings\Jenna\My Documents\~WRL2879.tmp
c:\documents and settings\Jenna\My Documents\~WRL2927.tmp
c:\documents and settings\Jenna\My Documents\~WRL3031.tmp
c:\documents and settings\Jenna\My Documents\~WRL3057.tmp
c:\documents and settings\Jenna\My Documents\~WRL3078.tmp
c:\documents and settings\Jenna\My Documents\~WRL3140.tmp
c:\documents and settings\Jenna\My Documents\~WRL3256.tmp
c:\documents and settings\Jenna\My Documents\~WRL3267.tmp
c:\documents and settings\Jenna\My Documents\~WRL3282.tmp
c:\documents and settings\Jenna\My Documents\~WRL3366.tmp
c:\documents and settings\Jenna\My Documents\~WRL3460.tmp
c:\documents and settings\Jenna\My Documents\~WRL3509.tmp
c:\documents and settings\Jenna\My Documents\~WRL3583.tmp
c:\documents and settings\Jenna\My Documents\~WRL3584.tmp
c:\documents and settings\Jenna\My Documents\~WRL3593.tmp
c:\documents and settings\Jenna\My Documents\~WRL3626.tmp
c:\documents and settings\Jenna\My Documents\~WRL3685.tmp
c:\documents and settings\Jenna\My Documents\~WRL3694.tmp
c:\documents and settings\Jenna\My Documents\~WRL3718.tmp
c:\documents and settings\Jenna\My Documents\~WRL3767.tmp
c:\documents and settings\Jenna\My Documents\~WRL3805.tmp
c:\documents and settings\Jenna\My Documents\~WRL3819.tmp
c:\documents and settings\Jenna\My Documents\~WRL3905.tmp
c:\documents and settings\Jenna\My Documents\~WRL3943.tmp
c:\documents and settings\Jenna\My Documents\~WRL3960.tmp
c:\documents and settings\Jenna\My Documents\~WRL4072.tmp
c:\documents and settings\Jenna\My Documents\~WRL4073.tmp
c:\documents and settings\Jenna\Recent\ANTIGEN.exe
c:\documents and settings\Jenna\Recent\ANTIGEN.tmp
c:\documents and settings\Jenna\Recent\CLSV.drv
c:\documents and settings\Jenna\Recent\CLSV.sys
c:\documents and settings\Jenna\Recent\eb.drv
c:\documents and settings\Jenna\Recent\eb.exe
c:\documents and settings\Jenna\Recent\eb.sys
c:\documents and settings\Jenna\Recent\energy.dll
c:\documents and settings\Jenna\Recent\energy.drv
c:\documents and settings\Jenna\Recent\energy.tmp
c:\documents and settings\Jenna\Recent\exec.tmp
c:\documents and settings\Jenna\Recent\FW.tmp
c:\documents and settings\Jenna\Recent\grid.dll
c:\documents and settings\Jenna\Recent\hymt.tmp
c:\documents and settings\Jenna\Recent\kernel32.tmp
c:\documents and settings\Jenna\Recent\pal.sys
c:\documents and settings\Jenna\Recent\PE.exe
c:\documents and settings\Jenna\Recent\PE.sys
c:\documents and settings\Jenna\Recent\ppal.sys
c:\documents and settings\Jenna\Recent\runddl.sys
c:\documents and settings\Jenna\Recent\tjd.dll
c:\documents and settings\Jenna\Recent\tjd.drv
c:\windows\system32\CF21634.exe
c:\windows\TEMP\logishrd\LVPrcInj02.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_6TO4
——-\Legacy_ITLPERF
——-\Legacy_NWSAPAGENT
——-\Legacy_SRVAA8
——-\Service_6to4
——-\Service_itlperf
——-\Service_Nwsapagent
——-\Service_srvAA8
.
.
((((((((((((((((((((((((( Files Created from 2011-10-28 to 2011-11-29 )))))))))))))))))))))))))))))))
.
.
2011-11-27 22:17 . 2011-11-27 22:07 302592 —-a-w- C:\hf8cxjbm.exe
2011-11-27 22:06 . 2011-11-27 22:02 607260 ——r- C:\dds(1).scr
2011-11-27 21:38 . 2011-11-27 21:38 2106216 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-11-27 21:38 . 2011-11-27 21:38 134104 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-11-27 21:38 . 2011-11-27 21:38 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-11-27 21:38 . 2011-11-27 21:38 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-11-27 21:38 . 2011-11-27 21:38 478168 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-11-27 21:38 . 2011-11-27 21:38 1989592 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-11-27 21:38 . 2011-11-27 21:38 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-11-27 21:38 . 2011-11-27 21:38 801752 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-11-27 20:41 . 2011-11-27 20:41 ——– d—–w- c:\documents and settings\Jenna\Application Data\MSNInstaller
2011-11-27 05:49 . 2011-11-27 05:49 ——– d—–w- c:\documents and settings\Administrator.BAHJEN\Application Data\iolo
2011-11-27 05:15 . 2011-11-27 05:15 ——– d—–w- c:\documents and settings\NetworkService\Application Data\iolo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-07 12:23 . 2011-10-07 12:23 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 12:21 . 2011-10-04 12:21 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-13 12:30 . 2011-09-13 12:30 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-08-31 23:00 . 2010-08-19 03:03 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-27 21:38 . 2011-11-27 21:38 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 282624]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"Jkeqix"="c:\windows\acepiguyor.dll" [2008-04-14 369152]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
.
c:\documents and settings\Jenna\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - c:\program files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-7-20 2913584]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^icwsetup.exe]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^QuickBooks Update Agent.lnk]
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^Service Manager.lnk]
path=c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShStatEXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
2006-04-06 19:58 1032192 —-a-w- c:\program files\Dell\QuickSet\quickset.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
2009-05-21 15:55 206064 —-a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-12-06 06:05 127035 —-a-w- c:\windows\system32\dla\tfswctrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2007-11-15 14:24 16384 —-a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-12-10 01:29 49152 ——w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-12-14 04:41 77824 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-12-14 04:45 118784 —-a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-12-14 04:44 98304 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 15:44 249856 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 15:44 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-06-05 18:39 292136 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jkeqix]
2008-04-14 00:12 369152 —-a-w- c:\windows\acepiguyor.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]
2003-09-10 07:24 20480 ——w- c:\program files\NetWaiting\netwaiting.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
2005-07-13 00:05 1117184 —-a-w- c:\program files\McAfee\SpamKiller\MSKDetct.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2004-04-12 01:15 290816 ——w- c:\program files\Dell\Media Experience\PCMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-03-08 23:48 761947 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 1:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/13/2011 6:30 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [10/7/2011 6:23 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 1:14 AM 295248]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [7/11/2011 1:14 AM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [7/11/2011 1:14 AM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [10/4/2011 6:21 AM 16720]
S0 mdfhvgg;mdfhvgg;c:\windows\system32\drivers\dksgket.sys –> c:\windows\system32\drivers\dksgket.sys [?]
S0 npqitlg;npqitlg;c:\windows\system32\drivers\vdse.sys –> c:\windows\system32\drivers\vdse.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WUAUSERV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
mStart Page = hxxp://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: microsoft.com\support
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Jenna\Application Data\Mozilla\Firefox\Profiles\eqiypswi.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://blink.bethel.edu/
FF - prefs.js: keyword.URL - hxxp://myclearsearch.com/?prt=Guppymcs02ff&Keywords=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 56667
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: keyword.URL - hxxp://myclearsearch.com/?prt=Guppymcs02ff&Keywords=
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-itlntfy - itlnfw32.dll
Notify-~ - (no file)
MSConfigStartUp-Corel Photo Downloader - c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe
MSConfigStartUp-McAfeeUpdaterUI - c:\program files\Network Associates\Common Framework\UpdaterUI.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-29 13:44
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(892)
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(4724)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\stsystra.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\AVG\AVG2012\avgmfapx.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\MsiExec.exe
c:\windows\system32\MsiExec.exe
.
**************************************************************************
.
Completion time: 2011-11-29 14:04:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-29 20:03
.
Pre-Run: 31,409,111,040 bytes free
Post-Run: 36,079,583,232 bytes free
.
- - End Of File - - C1801FE831705724D03987C46F5E4FD7
Hi D Piddy89

Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
C:\hf8cxjbm.exe
c:\windows\system32\drivers\dksgket.sys
c:\windows\system32\drivers\vdse.sys
c:\windows\acepiguyor.dll

Driver::
mdfhvgg
npqitlg

DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:56667
mRun: [Jkeqix] rundll32.exe "c:\windows\acepiguyor.dll",Startup

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Jkeqix"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" =dword:00000000
"FirewallOverride" = dword:00000000

Firefox:: 
FF - ProfilePath - c:\documents and settings\Jenna\Application Data\Mozilla\Firefox\Profiles\eqiypswi.default\
FF - prefs.js: network.proxy.http - 127.0.0.1 
FF - prefs.js: network.proxy.http_port - 56667 
FF - prefs.js: network.proxy.type - 4


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

Please also let me know how your computer is running now

Satchfan
Alright, here is my log



ComboFix 11-11-29.04 - Jenna 11/30/2011 10:30:47.6.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.524 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jenna\Desktop\CFScript.txt
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
FILE ::
"C:\hf8cxjbm.exe"
"c:\windows\acepiguyor.dll"
"c:\windows\system32\drivers\dksgket.sys"
"c:\windows\system32\drivers\vdse.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\acepiguyor.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_mdfhvgg
——-\Service_npqitlg
.
.
((((((((((((((((((((((((( Files Created from 2011-10-28 to 2011-11-30 )))))))))))))))))))))))))))))))
.
.
2011-11-30 16:24 . 2011-11-30 16:24 ——– d—–w- C:\cflogs
2011-11-29 20:13 . 2011-11-29 20:13 ——– d—–w- c:\documents and settings\Jenna\Local Settings\Application Data\{ECC5870A-1E65-4A92-BD38-F11005F8E18F}
2011-11-27 22:17 . 2011-11-27 22:07 302592 —-a-w- C:\hf8cxjbm.exe
2011-11-27 22:06 . 2011-11-27 22:02 607260 ——r- C:\dds(1).scr
2011-11-27 21:38 . 2011-11-27 21:38 2106216 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-11-27 21:38 . 2011-11-27 21:38 134104 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-11-27 21:38 . 2011-11-27 21:38 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-11-27 21:38 . 2011-11-27 21:38 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-11-27 21:38 . 2011-11-27 21:38 478168 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-11-27 21:38 . 2011-11-27 21:38 1989592 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-11-27 21:38 . 2011-11-27 21:38 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-11-27 21:38 . 2011-11-27 21:38 801752 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-11-27 20:41 . 2011-11-27 20:41 ——– d—–w- c:\documents and settings\Jenna\Application Data\MSNInstaller
2011-11-27 05:49 . 2011-11-27 05:49 ——– d—–w- c:\documents and settings\Administrator.BAHJEN\Application Data\iolo
2011-11-27 05:15 . 2011-11-27 05:15 ——– d—–w- c:\documents and settings\NetworkService\Application Data\iolo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-27 21:38 . 2011-11-27 21:38 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-29_19.44.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-30 16:48 . 2011-11-30 16:48 16384 c:\windows\Temp\Perflib_Perfdata_708.dat
+ 2011-11-30 16:48 . 2011-11-30 16:48 16384 c:\windows\Temp\Perflib_Perfdata_67c.dat
- 2010-09-23 20:55 . 2010-09-23 20:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-08 20:00 . 2011-07-08 20:00 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
- 2010-09-23 07:26 . 2010-09-23 07:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2011-07-07 18:04 . 2011-07-07 18:04 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2011-07-07 18:04 . 2011-07-07 18:04 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2010-09-23 07:26 . 2010-09-23 07:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-07-07 18:03 . 2011-07-07 18:03 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-09-23 07:26 . 2010-09-23 07:26 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-09-23 08:17 . 2010-09-23 08:17 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-07-07 19:09 . 2011-07-07 19:09 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-07-07 19:09 . 2011-07-07 19:09 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
- 2010-09-23 08:17 . 2010-09-23 08:17 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-11-30 16:26 . 2011-11-30 16:26 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_570188ac\System.Drawing.Design.dll
+ 2011-11-30 16:26 . 2011-11-30 16:26 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_2da08383\CustomMarshalers.dll
- 2010-10-08 08:02 . 2010-10-08 08:02 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-11-30 16:25 . 2011-11-30 16:25 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
- 2010-09-23 07:26 . 2010-09-23 07:26 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-07-07 18:04 . 2011-07-07 18:04 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-09-23 07:25 . 2010-09-23 07:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2011-07-07 18:01 . 2011-07-07 18:01 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2011-07-07 19:09 . 2011-07-07 19:09 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2010-09-23 08:17 . 2010-09-23 08:17 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-11-30 16:27 . 2011-11-30 16:27 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_72fc99ac\System.Drawing.dll
+ 2011-11-30 16:28 . 2011-11-30 16:28 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_b0701faf\System.Drawing.Design.dll
+ 2011-11-30 16:28 . 2011-11-30 16:28 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_3049bd24\CustomMarshalers.dll
+ 2011-07-08 19:59 . 2011-07-08 19:59 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2010-09-23 20:55 . 2010-09-23 20:55 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2011-07-08 19:59 . 2011-07-08 19:59 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2010-09-23 20:55 . 2010-09-23 20:55 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2010-09-23 07:26 . 2010-09-23 07:26 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 18:02 . 2011-07-07 18:02 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 18:02 . 2011-07-07 18:02 2527232 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2010-09-23 20:55 . 2010-09-23 20:55 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-07-08 19:59 . 2011-07-08 19:59 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-11-30 16:28 . 2011-11-30 16:28 4792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_fb04d074\System.dll
+ 2011-11-30 16:26 . 2011-11-30 16:26 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_ec66a052\System.dll
+ 2011-11-30 16:28 . 2011-11-30 16:28 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_acd4ad9a\System.Xml.dll
+ 2011-11-30 16:26 . 2011-11-30 16:26 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_6a40f96e\System.Xml.dll
+ 2011-11-30 16:28 . 2011-11-30 16:28 7884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_df88b11a\System.Windows.Forms.dll
+ 2011-11-30 16:26 . 2011-11-30 16:26 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_a5de22d3\System.Windows.Forms.dll
+ 2011-11-30 16:28 . 2011-11-30 16:28 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_672cfbb2\System.Drawing.dll
+ 2011-11-30 16:28 . 2011-11-30 16:28 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_e5269be3\System.Design.dll
+ 2011-11-30 16:27 . 2011-11-30 16:27 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_685de120\System.Design.dll
+ 2011-11-30 16:27 . 2011-11-30 16:27 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_edda6584\mscorlib.dll
+ 2011-11-30 16:29 . 2011-11-30 16:29 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_a53e3544\mscorlib.dll
+ 2011-11-30 16:25 . 2011-11-30 16:25 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2010-10-08 08:02 . 2010-10-08 08:02 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-11-30 16:25 . 2011-11-30 16:25 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-10-08 08:02 . 2010-10-08 08:02 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-07-13 04:49 . 2011-07-13 04:49 11459584 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2572067\M2572067Uninstall.msp
+ 2011-07-12 21:50 . 2011-07-12 21:50 17555968 c:\windows\Installer\455e543.msp
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 282624]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
.
c:\documents and settings\Jenna\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - c:\program files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-7-20 2913584]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^icwsetup.exe]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^QuickBooks Update Agent.lnk]
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Application Data^Microsoft^Shortcuts^Service Manager.lnk]
path=c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
2006-04-06 19:58 1032192 —-a-w- c:\program files\Dell\QuickSet\quickset.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
2009-05-21 15:55 206064 —-a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-12-06 06:05 127035 —-a-w- c:\windows\system32\dla\tfswctrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2007-11-15 14:24 16384 —-a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-12-10 01:29 49152 ——w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-12-14 04:41 77824 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-12-14 04:45 118784 —-a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-12-14 04:44 98304 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 15:44 249856 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 15:44 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-06-05 18:39 292136 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]
2003-09-10 07:24 20480 ——w- c:\program files\NetWaiting\netwaiting.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
2005-07-13 00:05 1117184 —-a-w- c:\program files\McAfee\SpamKiller\MSKDetct.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2004-04-12 01:15 290816 ——w- c:\program files\Dell\Media Experience\PCMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-03-08 23:48 761947 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
mStart Page = hxxp://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: microsoft.com\support
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Jenna\Application Data\Mozilla\Firefox\Profiles\eqiypswi.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://blink.bethel.edu/
FF - prefs.js: keyword.URL - hxxp://myclearsearch.com/?prt=Guppymcs02ff&Keywords=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: keyword.URL - hxxp://myclearsearch.com/?prt=Guppymcs02ff&Keywords=
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Jkeqix - c:\windows\acepiguyor.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-30 10:49
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(660)
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(7132)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\stsystra.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2011-11-30 10:55:01 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-30 16:54
.
Pre-Run: 36,304,822,272 bytes free
Post-Run: 36,214,255,616 bytes free
.
- - End Of File - - FB7DAE4F7E82AE26177980A8C22E7C54



Thanks, and at least upon my initial inspection the computer seems to be running really well.
Good news that all is running well and your log, at a quick glance looks OK but I’ll check it more thoroughly.

Meanwhile,

Run Malwarebytes’ Anti-Malware

MBAM was on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Satchfan
Alright, here is the log Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8281 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 11/30/2011 10:12:05 PM mbam-log-2011-11-30 (22-12-05).txt Scan type: Quick scan Objects scanned: 194355 Time elapsed: 4 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Thanks
Another good sign. Let’s make sure there is nothing left with an online scan.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Satchfan
Ok, here is my log from that. Thanks C:\Qoobox\Quarantine\C\WINDOWS\acepiguyor.dll.vir a variant of Win32/Kryptik.MHG trojan cleaned by deleting - quarantined C:\QUARANTINE\Av-test.txt.Vir Eicar test file cleaned by deleting - quarantined C:\QUARANTINE\Av-test.txt.Vir.0 Eicar test file cleaned by deleting - quarantined C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000058.dll a variant of Win32/Kryptik.MHG trojan cleaned by deleting - quarantined C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP3\A0000459.ini Win32/Adware.AntimalwareDoctor.AE.Gen application cleaned by deleting - quarantined

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI