This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

sirefef.AO/AB/AN/AG and blacoleref.BV infections [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is the combofix.txt that was done on 7/21: ( Also in that folder was Combofix-quarantined-files.txt ( I copied that file at the end ))

ComboFix 12-07-21.01 - Kevin 07/22/2012 7:12.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.538 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
c:\program files\FunWebProducts
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\_000019_.tmp.dll
c:\windows\system32\_000020_.tmp.dll
c:\windows\system32\_000021_.tmp.dll
c:\windows\system32\_000022_.tmp.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 )))))))))))))))))))))))))))))))
.
.
2012-07-22 05:38 . 2012-07-22 05:38 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\offreg.dll
2012-07-22 05:38 . 2012-07-22 05:38 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\MpKsladdc328d.sys
2012-07-22 05:37 . 2012-06-29 08:44 6891424 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\mpengine.dll
2012-07-22 02:26 . 2012-07-22 02:26 ——– d—–w- C:\_OTL
2012-07-22 02:23 . 2012-07-22 02:23 ——– d—–w- c:\program files\ERUNT
2012-07-21 19:49 . 2012-06-29 08:44 6891424 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-08 22:07 . 2012-07-08 22:08 ——– d—–w- c:\program files\Microsoft Security Client
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-11 22:53 . 2012-04-17 10:20 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-11 22:53 . 2011-05-16 11:34 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:19 . 2005-08-16 10:18 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2010-10-01 22:16 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2005-08-16 10:18 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2005-08-16 10:18 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2009-08-07 00:24 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2009-08-07 00:24 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2005-08-16 10:40 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2005-08-16 10:40 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2005-08-16 10:40 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2009-08-07 00:24 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2009-08-07 00:24 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2005-08-16 10:40 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2005-08-16 10:40 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2005-08-16 10:18 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2009-08-07 00:24 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2005-08-16 10:40 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2005-08-16 10:40 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2010-10-02 02:57 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18 . 2010-10-02 02:57 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 19:18 . 2010-10-02 02:57 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2005-08-16 10:18 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2005-08-16 10:18 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2005-08-16 10:18 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2005-08-16 10:18 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2005-08-16 10:18 385024 —-a-w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2005-08-16 10:18 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-04 04:59 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2005-08-16 10:37 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2010-03-11 04:01 . 2010-03-11 04:01 124272 —-a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2010-03-11 04:40 . 2010-03-11 04:40 13168 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2010-03-11 04:02 . 2010-03-11 04:02 70512 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2010-03-11 04:01 . 2010-03-11 04:01 91504 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2010-03-11 04:01 . 2010-03-11 04:01 22384 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2010-03-11 04:00 . 2010-03-11 04:00 255344 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2010-03-11 04:01 . 2010-03-11 04:01 31088 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2010-03-11 04:01 . 2010-03-11 04:01 40304 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2009-10-05 17:49 . 2009-10-05 17:49 652640 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2010-03-11 04:02 . 2010-03-11 04:02 23920 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2012-07-20 10:44 . 2011-05-02 21:54 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-12-19 26112]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-13 1117184]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-03-11 300400]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
c:\documents and settings\Kevin\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Content Manager Assistant for PlayStation®.lnk - c:\program files\Sony\Content Manager Assistant\CMA.exe [2012-1-26 2520504]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-12-19 24576]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [10/5/2009 10:08 AM 65584]
R1 MpKsladdc328d;MpKsladdc328d;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\MpKsladdc328d.sys [7/22/2012 1:38 AM 29904]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/17/2012 6:20 AM 250056]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [4/25/2012 7:46 AM 113120]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2/13/2009 3:02 PM 11520]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLADDC328D
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 22:53]
.
2012-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-07-22 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dell4me.com/myway
Trusted Zone: musicmatch.com\online
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Kevin\Application Data\Mozilla\Firefox\Profiles\mvuvldgi.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yankees.com/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Apple - c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
HKU-Default-Run-Apple - c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-22 07:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-07-22 07:19:29
ComboFix-quarantined-files.txt 2012-07-22 11:19
.
Pre-Run: 42,415,812,608 bytes free
Post-Run: 42,381,115,392 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 38382EB380F25AFCAD75D503E831D4B4


2012-07-22 11:18:35 . 2012-07-22 11:18:35 230 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKU-Default-Run-Apple.reg.dat
2012-07-22 11:18:33 . 2012-07-22 11:18:33 228 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-Apple.reg.dat
2012-07-22 11:15:19 . 2012-07-22 11:15:19 6,241 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2012-07-22 11:08:04 . 2012-07-22 11:08:05 51 —-a-w- C:\Qoobox\Quarantine\catchme.log
2012-07-15 04:39:29 . 2012-07-15 04:39:30 566,784 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll.vir
2005-08-16 10:18:45 . 2008-04-14 09:42:10 132,096 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000008_.tmp.dll.vir
2005-08-16 10:18:43 . 2008-04-14 05:00:12 1,845,632 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000010_.tmp.dll.vir
2005-08-16 10:18:36 . 2008-04-14 09:42:36 108,544 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000019_.tmp.dll.vir
2005-08-16 10:18:29 . 2008-04-14 09:41:26 706,048 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000020_.tmp.dll.vir
2005-08-16 10:18:22 . 2008-04-14 09:41:58 728,064 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000021_.tmp.dll.vir
2005-08-16 10:18:22 . 2008-04-14 09:41:58 343,040 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000006_.tmp.dll.vir
2005-08-16 10:18:21 . 2008-04-14 09:41:58 989,696 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000007_.tmp.dll.vir
2005-08-16 10:18:07 . 2008-04-14 09:41:52 32,256 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000009_.tmp.dll.vir
2005-08-16 10:18:03 . 2008-04-14 09:41:50 617,472 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000022_.tmp.dll.vir
Hi,

Great job getting those for me.
————

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats is NOT selected and the option Scan unwanted applications is selected.
  • Click Scan (This scan can take several hours, so please be patient)
  • If there are threats that are found, please press List of found threats and then in the next window that opens press Export to text file…
  • Copy and paste/or attach that log as a reply to this topic
**Note** If not threats are found there will not be a log created.
———-

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt
  • Please post the contents of that document.
———-

In your next reply please post the logs made by Malwarebytes, ESET and Security Check. :)
Ok, here you go:

MALWAREBYTES

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.07.24.12

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Kevin :: D9MDH191 [administrator]

7/24/2012 6:43:48 PM
mbam-log-2012-07-24 (18-43-48).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 240763
Time elapsed: 6 minute(s), 36 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4D25F926-B9FE-4682-BF72-8AB8210D6D75} (PUP.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks|{4D25F926-B9FE-4682-BF72-8AB8210D6D75} (PUP.MyWebSearch) -> Data: -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Documents and Settings\Missy\My Documents\Downloads\Webfetti.exe (PUP.FunWebProducts) -> Quarantined and deleted successfully.

(end)

ESET

C:\Documents and Settings\Missy\My Documents\Downloads\PageRageSetup.exe probably a variant of Win32/Adware.LRYETGT application

SECURITY CHECK

Results of screen317's Security Check version 0.99.43
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.62.0.1300
Java™ 6 Update 31
Java 2 Runtime Environment, SE v1.4.2_03
Java version out of Date!
Adobe Flash Player 11.3.300.265
Adobe Reader X (10.1.3)
Mozilla Firefox (14.0.1)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 9%
````````````````````End of Log``````````````````````
Hi,

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-

First go to Start >> Run >> type CMD and the Command Prompt will open.
Copy the contents of the code box > right click in the command window and select paste >> Press Enter (do one line at a time if there are more than one)
del "C:\Documents and Settings\Missy\My Documents\Downloads\PageRageSetup.exe"
Close the Command Prompt box.

In your next reply let me know how your system is running. :)
Ok…..not sure which Java to download on the oracle.com website??? I know it's JRE, but when you select it, which one?? I deleted that file and my computer seems to be running fine…..( I really haven't had any issues with running it normally. )
Ok, I tried this but it tells me that: Installation failed The wizard was interrupted before Java ™ Update 5 could be completely installed. To complete this installation at another time, please run setup again. I ran it a couple of times and it didn't work. It asked me to download some McAfee Security Plus or something during the installation and I unchecked the box each time…..
When you ran JavaRa you were taken to a site where you could choose which version of Java (JRE) that you wanted to install. Go back there and use the x86 Offline version. See if you are able to get it installed.
Ok, I had to remove previous versions of Java before installing it… Now I was able to install it…. I also removed the file PageRageSetup.exe as you asked in a previous post…. No problems with computer running at all…..
Providing there are no other malware related problems…

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

7.Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Ok, I ran MBAM again and no detection of malware found….. I am currently using Microsoft Security Essentials. In your opinion is this anti-virus software okay? Is there any "free" options that are better? I also use Firefox instead of Internet Explorer. Which is better to avoid viruses in the future?? Thanks for all your help!
Hi,

In your opinion is this anti-virus software okay? Is there any "free" options that are better?

The one you are using if ok….I prefer Avast though myself.

You are more than welcome. I am glad that I could help. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI