This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Horse

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I recently seemed to have installed a Trojan Horse (backdoor??) on my computer. I've run AVG and found it on there and then emptied the AVG's virus vault but this seems ineffective? It now won't let me access Google Chrome or Spybot- Search and Destroy. When turning on my computer today the vista bar the top of my screen containing my desktop shortcuts is now not showing up. There have also been pop ups claiming to be Microsoft that wanted you to accept it, in the style of the User Account Control pop ups. It didn't allow you to cancel it and so when I accepted it it turned to User Account Control off. I turned it on again straight away but I don't know if this is of any imporatance. I'm sorry if my description here isn't that great, I'm really have no knowledge of computuers and how to deal with these things. :unsure: Any help would be great or if any extra infomation is needed (: . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 18:39:16.54 on 06/07/2012 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_22 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2006.661 [GMT 1:00] . AV: AVG Anti-Virus Free *Enabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82} SP: AVG Anti-Virus Free *Enabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\Pen_Tablet.exe C:\Windows\system32\Wacom_Tablet.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Pen_Tablet.exe C:\Windows\Explorer.EXE C:\Windows\system32\Dwm.exe C:\Program Files\Dell\DellDock\DellDock.exe C:\Windows\system32\Wacom_Tablet.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\System32\igfxpers.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\iTunesHelper.exe C:\Program Files\IDT\WDM\sttray.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Users\Cazzimodo\Documents\Chikeeto's\Data\SpotifyWebHelper.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Windows\system32\svchost.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Windows\System32\rundll32.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Cazzimodo\Downloads\dds.scr C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uWindow Title = Internet Explorer provided by Dell uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client;=dell-usuk&channel;=uk&ibd;=3081119 uInternet Settings,ProxyOverride = *.local mURLSearchHooks: H - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.0.0.7\AVG Secure Search_toolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\10.0.0.7\AVG Secure Search_toolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File {e7df6bff-55a5-4eb7-a673-4ed3e9456d39} uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [Google Update] "c:\users\cazzimodo\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [Exetender] "c:\program files\free ride games\GPlayer.exe" /runonstartup uRun: [Facebook Update] "c:\users\cazzimodo\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver uRun: [Spotify Web Helper] "c:\users\cazzimodo\documents\chikeeto's\data\SpotifyWebHelper.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [QrjEjeex] c:\users\cazzimodo\appdata\local\ilrryeuh\qrjejeex.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Dell Webcam Central] "c:\program files\dell webcam\dell webcam central\WebcamDell.exe" /mode2 mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [vProt] "c:\program files\avg secure search\vprot.exe" mRun: [ROC_roc_dec12] "c:\program files\avg secure search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\iTunesHelper.exe" mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe StartupFolder: c:\users\cazzim~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe StartupFolder: c:\users\cazzim~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.0.207\SSScheduler.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} - hxxp://www.bebo.com/files/BeboUploader.5.8.05.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUplden-gb.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\10.0.6\ViProtocol.dll Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: avgrsstx.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\cazzim~1\appdata\roaming\mozilla\firefox\profiles\mujlpshm.default\ FF - prefs.js: browser.startup.homepage - hxxp://uk.msn.com/ FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B3ed1ed09-536e-4385-a872-ae321c84fb7f%7D∣=55e481a82585f07cebe73cfb4df89ed7-3c586feca70c5e74c334782c57fba0110f1190c3&ds;=AVG&v;=10.0.0.7⟨=us≺=fr&d;=2011-12-10%2014%3A33%3A45&sap;=ku&q;= FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla plugins\npitunes.dll FF - plugin: c:\program files\tabletplugins\npwacom.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\cazzimodo\appdata\local\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_262.dll . —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== . R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-25 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-12-25 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-7 108552] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-11-19 112128] R3 itecir;ITECIR Infrared Receiver;c:\windows\system32\drivers\itecir.sys [2008-11-19 54784] R3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60x.sys [2008-11-19 203264] R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2008-11-19 144672] R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2008-11-19 277632] . =============== Created Last 30 ================ . 2012-07-06 16:10:49 6762896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{6ee4cc8d-4183-43fc-916a-860561ad2213}\mpengine.dll 2012-07-04 20:48:18 421200 —-a-w- c:\program files\mozilla firefox\msvcp100.dll 2012-07-04 20:48:17 770384 —-a-w- c:\program files\mozilla firefox\msvcr100.dll 2012-07-01 11:50:03 ——– d—–w- c:\users\cazzim~1\appdata\local\Macromedia 2012-07-01 11:47:34 ——– d—–w- c:\progra~2\McAfee Security Scan 2012-07-01 11:47:15 ——– d—–w- c:\program files\McAfee Security Scan 2012-07-01 11:47:05 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-07-01 11:47:05 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-07-01 01:33:43 56200 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{f87a2154-cd98-47bb-8e98-596c59967ac4}\offreg.dll 2012-06-29 16:59:41 6762896 ——w- c:\progra~2\microsoft\windows defender\definition updates\{f87a2154-cd98-47bb-8e98-596c59967ac4}\mpengine.dll 2012-06-22 18:44:14 16864 —-a-w- c:\program files\mozilla firefox\plugin-container.exe 2012-06-22 08:49:52 876032 —-a-w- c:\windows\system32\XpsPrint.dll 2012-06-22 08:49:49 683008 —-a-w- c:\windows\system32\d2d1.dll 2012-06-22 08:49:49 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-06-22 08:49:49 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2012-06-22 08:49:49 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2012-06-22 08:49:49 1069056 —-a-w- c:\windows\system32\DWrite.dll 2012-06-22 03:39:25 ——– d—–w- c:\program files\Windows Portable Devices 2012-06-22 03:07:49 92672 —-a-w- c:\windows\system32\UIAnimation.dll 2012-06-22 03:07:48 3023360 —-a-w- c:\windows\system32\UIRibbon.dll 2012-06-22 03:07:48 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll 2012-06-22 02:56:16 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-22 02:55:31 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-22 02:54:52 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-22 02:54:52 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-22 02:51:50 5120 —-a-w- c:\windows\system32\wmi.dll 2012-06-22 02:51:50 172032 —-a-w- c:\windows\system32\wintrust.dll 2012-06-22 02:51:49 157696 —-a-w- c:\windows\system32\imagehlp.dll 2012-06-22 02:51:49 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-06-22 02:38:00 307200 —-a-w- c:\program files\internet explorer\iediagcmd.exe 2012-06-22 02:38:00 161792 —-a-w- c:\windows\system32\msls31.dll 2012-06-22 02:38:00 140920 —-a-w- c:\program files\internet explorer\sqmapi.dll 2012-06-22 02:38:00 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-06-22 02:38:00 107008 —-a-w- c:\program files\internet explorer\iecleanup.exe 2012-06-22 02:36:01 979456 —-a-w- c:\windows\system32\MFH264Dec.dll 2012-06-22 02:36:01 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll 2012-06-22 02:36:01 302592 —-a-w- c:\windows\system32\mfmp4src.dll 2012-06-22 02:36:01 261632 —-a-w- c:\windows\system32\mfreadwrite.dll 2012-06-22 02:36:00 98816 —-a-w- c:\windows\system32\mfps.dll 2012-06-22 02:36:00 2873344 —-a-w- c:\windows\system32\mf.dll 2012-06-22 02:34:45 369664 —-a-w- c:\windows\system32\WMPhoto.dll 2012-06-22 02:34:45 252928 —-a-w- c:\windows\system32\dxdiag.exe 2012-06-22 02:34:45 195584 —-a-w- c:\windows\system32\dxdiagn.dll 2012-06-22 02:34:44 519680 —-a-w- c:\windows\system32\d3d11.dll 2012-06-22 02:34:43 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll 2012-06-22 02:34:43 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll 2012-06-22 02:34:43 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll 2012-06-21 07:58:09 984064 —-a-w- c:\windows\system32\crypt32.dll 2012-06-21 07:58:09 98304 —-a-w- c:\windows\system32\cryptnet.dll 2012-06-21 07:58:09 133120 —-a-w- c:\windows\system32\cryptsvc.dll 2012-06-21 07:58:01 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax 2012-06-21 07:58:01 57856 —-a-w- c:\windows\system32\MSDvbNP.ax 2012-06-21 07:58:01 293376 —-a-w- c:\windows\system32\psisdecd.dll 2012-06-21 07:58:01 217088 —-a-w- c:\windows\system32\psisrndr.ax 2012-06-21 07:58:00 23552 —-a-w- c:\windows\system32\mciseq.dll 2012-06-21 07:58:00 189952 —-a-w- c:\windows\system32\winmm.dll 2012-06-21 07:57:33 429056 —-a-w- c:\windows\system32\EncDec.dll 2012-06-21 07:57:21 964608 —-a-w- c:\program files\windows journal\JNWDRV.dll 2012-06-21 07:57:21 1404928 —-a-w- c:\program files\common files\microsoft shared\ink\InkObj.dll 2012-06-21 07:57:21 1218048 —-a-w- c:\program files\windows journal\NBDoc.DLL 2012-06-21 07:57:20 983040 —-a-w- c:\program files\windows journal\JNTFiltr.dll 2012-06-21 07:57:20 936960 —-a-w- c:\program files\common files\microsoft shared\ink\journal.dll 2012-06-21 07:57:20 47104 —-a-w- c:\program files\windows journal\PDIALOG.exe 2012-06-21 07:57:18 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-06-21 07:57:17 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys 2012-06-21 07:57:16 66560 —-a-w- c:\windows\system32\packager.dll 2012-06-21 07:57:13 376320 —-a-w- c:\windows\system32\winsrv.dll 2012-06-21 07:55:51 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2012-06-21 07:55:46 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll 2012-06-21 07:55:46 4096 —-a-w- c:\windows\system32\oleaccrc.dll 2012-06-21 07:55:46 238080 —-a-w- c:\windows\system32\oleacc.dll 2012-06-21 07:55:45 563712 —-a-w- c:\windows\system32\oleaut32.dll 2012-06-21 07:55:15 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-06-21 07:55:14 2045440 —-a-w- c:\windows\system32\win32k.sys 2012-06-21 07:55:10 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-06-21 07:55:09 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-06-21 07:55:06 707584 —-a-w- c:\program files\common files\system\wab32.dll 2012-06-21 07:41:15 231424 —-a-w- c:\windows\system32\msshsq.dll 2012-06-21 07:32:56 613376 —-a-w- c:\windows\system32\rdpencom.dll 2012-06-21 02:24:23 ——– d—–w- c:\windows\system32\eu-ES 2012-06-21 02:24:23 ——– d—–w- c:\windows\system32\ca-ES 2012-06-21 02:24:17 ——– d—–w- c:\windows\system32\vi-VN 2012-06-20 10:18:02 ——– d—–w- c:\users\cazzim~1\appdata\local\ilrryeuh . ==================== Find3M ==================== . 2012-06-22 02:35:59 586240 —-a-w- c:\windows\system32\stobject.dll 2012-06-22 02:35:59 209920 —-a-w- c:\windows\system32\mfplat.dll 2012-06-22 02:35:56 135680 —-a-w- c:\windows\system32\XpsRasterService.dll 2012-06-22 02:35:55 486400 —-a-w- c:\windows\system32\d3d10level9.dll 2012-06-22 02:35:54 478720 —-a-w- c:\windows\system32\dxgi.dll 2012-06-22 02:35:54 37376 —-a-w- c:\windows\system32\cdd.dll 2012-06-22 02:35:54 258048 —-a-w- c:\windows\system32\winspool.drv 2012-06-22 02:35:54 189952 —-a-w- c:\windows\system32\d3d10core.dll 2012-06-22 02:35:54 1029120 —-a-w- c:\windows\system32\d3d10.dll 2012-06-22 02:35:53 847360 —-a-w- c:\windows\system32\OpcServices.dll 2012-06-22 02:35:53 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe 2012-06-22 02:35:53 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll 2012-06-22 02:35:52 1554432 —-a-w- c:\windows\system32\xpsservices.dll 2012-04-15 15:46:59 472808 —-a-w- c:\windows\system32\deployJava1.dll 2012-03-27 04:09:30 293736 —-a-w- c:\program files\iTunesOutlookAddIn.dll 2012-03-27 04:09:24 421736 —-a-w- c:\program files\iTunesHelper.exe 2012-03-27 04:09:24 124776 —-a-w- c:\program files\iTunesMiniPlayer.dll 2012-03-27 04:09:22 156520 —-a-w- c:\program files\iTunesHelper.dll 2012-03-27 04:09:20 402792 —-a-w- c:\program files\iTunesAdmin.dll 2012-03-27 04:09:16 9777000 —-a-w- c:\program files\iTunes.exe 2012-03-27 04:09:06 21006696 —-a-w- c:\program files\iTunes.dll 2012-03-27 04:09:02 797208 —-a-w- c:\program files\gnsdk_sdkmanager.dll 2012-03-27 04:09:02 649576 —-a-w- c:\program files\iPodUpdaterExt.dll 2012-03-27 04:09:02 3029528 —-a-w- c:\program files\gnsdk_dsp.dll 2012-03-27 04:09:02 281112 —-a-w- c:\program files\gnsdk_submit.dll 2012-03-27 04:09:02 240152 —-a-w- c:\program files\gnsdk_musicid.dll 2012-03-06 19:44:32 112488 —-a-w- c:\program files\ITDetector.ocx . ============= FINISH: 18:41:02.73 ===============
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)










Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
When I click on this link it comes up with a 'Problem Loading Page': The connection was reset The connection to the server was reset while the page was loading. he site could be temporarily unavailable or too busy. Try again in a few moments. If you are unable to load any pages, check your computer's network connection. If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the Web. I quit AVG in the system tray also. My internet is working and will load other sites. :unsure:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI