This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Green Dot, FBI Malware [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi.

Unable to browse internet when green dot, FBI screen shows up; now on computer using administrator mode, through in office network, but if other users login, they are unable to use internet; attaching hijack this and dds logs

thanks,
-hecrodfnp

HIJACK THIS
DDS (Ver_2012-10-19.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 16:09:54 on 2012-11-04
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2012.1162 [GMT -6:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ================
.
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft\BingBar\BBSvc.EXE
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\BingBar\BingBar.exe
C:\Program Files\Microsoft\BingBar\BingApp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uWindow Title = Windows Internet Explorer provided by MSN & Bing
uSearch Page = http://www.bing.com
mSearchAssistant = hxxp://www.bing.com/sphome.aspx
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: CompTool0234 Toolbar: {37153479-1976-43c3-a1ee-557513977b64} - c:\program files\coupons.com\prxtbCou2.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} -
BHO: ShopAtHome.com Toolbar: {66516A07-F617-488A-90CF-4E690CFB3C5F} - c:\program files\shopathome\tbcore3U.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: CompTool0234 Toolbar: {37153479-1976-43C3-A1EE-557513977B64} - c:\program files\coupons.com\prxtbCou2.dll
TB: ShopAtHome.com Toolbar: {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - c:\program files\shopathome\tbcore3U.dll
TB: CompTool0234 Toolbar: {37153479-1976-43c3-a1ee-557513977b64} - c:\program files\coupons.com\prxtbCou2.dll
TB: ShopAtHome.com Toolbar: {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - c:\program files\shopathome\tbcore3U.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [WROReminder] c:\program files\winzip registry optimizer\Winzipro.exe -rem
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10h_ActiveX.exe -update activex
mRun: [RTHDCPL] RTDCPL.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [ChangeTPMAuth] c:\program files\wave systems corp\common\ChangeTPMAuth.exe /T:NTRU12
mRun: [WavXMgr] c:\program files\wave systems corp\services manager\docmgr\bin\WavXDocMgr.exe
mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe"
mRun: [USCService] c:\program files\dell\dell controlpoint\security manager\BcmDeviceAndTaskStatusService.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [DBRMTray] c:\dell\dbrm\reminder\DbrmTrayIcon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini
mRunOnce: [DBRMTray] c:\dell\dbrm\reminder\TrayApp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: myonlinereports.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: Interfaces\{F368150C-E683-42C5-A7EF-03B2654F1DC3} : NameServer = 192.168.77.10
Notify: igfxcui - igfxdev.dll
Notify: LMIinit - LMIinit.dll
SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Authentication Packages = msv1_0 wvauth
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 193552]
R2 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-10-21 196176]
R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-10-13 249648]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-7-6 374704]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2011-1-11 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-7-20 47640]
R3 k57w2k;Broadcom NetLink ™ Gigabit Ethernet;c:\windows\system32\drivers\k57xp32.sys [2010-2-23 209960]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys –> c:\windows\system32\drivers\SSPORT.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-25 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
=============== Created Last 30 ================
.
2012-11-04 22:05:10 ——– d—–w- c:\documents and settings\administrator.afc\application data\Nico Mak Computing
2012-11-04 22:05:06 17224 —-a-w- c:\windows\system32\roboot.exe
2012-11-04 22:05:03 ——– d—–w- c:\program files\WinZip Registry Optimizer
2012-11-04 19:04:51 6918632 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2a0f8be6-a218-4061-8359-8d3a480a32e7}\mpengine.dll
2012-11-04 06:39:26 6918632 ——w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-11-03 18:51:23 ——– d—–w- c:\documents and settings\all users\application data\kighwaojvcanqgq
2012-11-03 18:51:21 124928 —-a-w- c:\windows\vfgbelkj.exe
2012-11-03 18:51:20 124928 —-a-w- c:\documents and settings\all users\application data\vfgbelkj.exe
.
==================== Find3M ====================
.
2012-10-29 19:33:49 83912 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-10-29 19:33:49 52648 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2012-10-29 19:33:48 92072 —-a-w- c:\windows\system32\LMIinit.dll
2012-10-29 19:33:48 31144 —-a-w- c:\windows\system32\LMIport.dll
2012-08-31 03:03:50 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:14:53 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14:53 43520 ——w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14:52 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07:15 385024 ——w- c:\windows\system32\html.iec
2012-08-24 13:53:22 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:52:42 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 13:05:53 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
============= FINISH: 16:10:30.33 ===============
Hello again hecrodfnp

now on computer using administrator mode, through in office network

This time I am sorry to say that we are unable to help with the problem.

As this is an office computer, it is up to the company's IT department to resolve this as we generally only help with home computers.

Working on a corporate computer can sometimes change settings and potentially harm your system which your company might not be too pleased about and could leave us liable for a lawsuit.

Again, I'm sorry and hope that your IT department can resolve this problem.

Satchfan
Thank you Satchfan. Actually, I am the entire office. It's my personal business, my computer and I own 100%– I take full responsibility for any issues on the computer and will not in anyway hold you (What the Tech?)accountable for any issues/problems that may occur on the computer as a result of your help. let me know if this statement helps in anyway. I appreciate you. hecrodfnp
Thank you for the clear explanation. I think we’re OK to try and sort this out.

Run RogueKiller

Download RogueKiller to your desktop.
  • close all running programs
  • double-click on RogueKiller.exe
  • when the prescan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects.
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

Thanks

Satchfan
Thank you Satchfan.
-hecrodfnp
Ran in safe mode. Here is RogueKiller report:

RogueKiller V8.2.2 [11/03/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Safe mode with network support
User : nurse [Admin rights]
Mode : Scan – Date : 11/05/2012 21:14:16

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 3 ¤¤¤
[RUN][SUSP PATH] HKCU\[…]\Run : vfgbelkjvhtyjob (C:\WINDOWS\vfgbelkj.exe) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-3272544874-3166413241-1926064316-1106[…]\Run : vfgbelkjvhtyjob (C:\WINDOWS\vfgbelkj.exe) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: Hitachi HDT721025SLA380 +++++
— User —
[MBR] 5916a31665d12f8ada58cbb9e62d862c
[BSP] 57ebeff2313f991a6fe753b171cc7198 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 238377 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1]_S_11052012_02d2114.txt >>
RKreport[1]_S_11052012_02d2114.txt
Please run all scans in normal mode if you can.

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again
  • close all programs
  • double-click RogueKiller.exe - Windows 7: right-click the program and select Run as Administrator'
  • after it has completed it's prescan click on the “Registry” tab
  • uncheck the following false positive


    [HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

  • make sure the other entries there are checked, then click on Delete
Send a new RogueKiller report.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply
Logs to include with next post:

RKreport.txt
AdwCleaner log


Thanks

Satchfan
Thank you Satchfan.
A copy of AdwCleaner to follow

Copy of rk log
RogueKiller V8.2.2 [11/03/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : nurse [Admin rights]
Mode : Remove – Date : 11/06/2012 21:50:58

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 1 ¤¤¤
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NOT SELECTED

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: Hitachi HDT721025SLA380 +++++
— User —
[MBR] 5916a31665d12f8ada58cbb9e62d862c
[BSP] 57ebeff2313f991a6fe753b171cc7198 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 238377 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[3]_D_11062012_02d2150.txt >>
RKreport[1]_S_11052012_02d2114.txt ; RKreport[2]_S_11062012_02d2150.txt ; RKreport[3]_D_11062012_02d2150.txt
Satchfan, Prior post is rk report, here is the AdwCleaner report: # AdwCleaner v2.007 - Logfile created 11/06/2012 at 21:56:56 # Updated 06/11/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : nurse - RECEPTION1 # Boot Mode : Normal # Running from : C:\Documents and Settings\nurse\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Documents and Settings\administrator.AFC\Local Settings\Application Data\Conduit Folder Deleted : C:\Documents and Settings\administrator.AFC\Local Settings\Application Data\Coupons.com Folder Deleted : C:\Documents and Settings\nurse\Local Settings\Application Data\Conduit Folder Deleted : C:\Documents and Settings\nurse\Local Settings\Application Data\Coupons.com Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\Coupons.com ***** [Registry] ***** Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\ConduitSearchScopes Key Deleted : HKCU\Software\Coupons.com Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{37153479-1976-43C3-A1EE-557513977B64} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37153479-1976-43C3-A1EE-557513977B64} Key Deleted : HKCU\Software\SmartBar Key Deleted : HKCU\Toolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{37AE00AB-70CA-4E98-B1CE-DC138AE847FA} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B} Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1 Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6} Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1 Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1 Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1 Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1 Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1 Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2559647 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C} Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\Coupons.com Key Deleted : HKLM\Software\Description Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B6F618FA-9672-4E6C-9B4C-F5376AA6B6FD} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8416B42-97A5-4067-806E-D059E9526301} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Coupons.com Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{37AE00AB-70CA-4E98-B1CE-DC138AE847FA} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupons.com Toolbar Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{37153479-1976-43C3-A1EE-557513977B64}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. ************************* AdwCleaner[S1].txt - [5933 octets] - [06/11/2012 21:56:56] ########## EOF - C:\AdwCleaner[S1].txt - [5993 octets] ##########
Quite a bit has been removed but there were some entries that still need to be checked out.

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    🖼Click to load external image (Posted Image)


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    🖼Click to load external image (Posted Image)


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Can you also tell me how your computer is now.

Satchfan
Thank you, Satchfan.
The computer/Internet is running a lot smoother. Once rk was run it knocked out the initial infection (Green Dot/FBI)-which at the time didn't even allow me the use of the desktop.
A couple of questions:
1. Do I delete all quarantines,etc?
2. Is it safe to run software like AdwCleaner (delete mode) on any computer?

Great work. Appreciate it.


Here's the ComboFix log:
ComboFix 12-11-06.03 - nurse 11/07/2012 18:56:17.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2012.1220 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\administrator.AFC\Local Settings\Application Data\assembly\tmp
c:\documents and settings\All Users\Application Data\vfgbelkj.exe
c:\documents and settings\nurse\Local Settings\Application Data\assembly\tmp
c:\windows\system32\roboot.exe
c:\windows\system32\spool\prtprocs\w32x86\sdf1mpc.dll
c:\windows\system32\test
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
c:\windows\system32\drivers\i8042prt.sys . . . is missing!!
.
.
((((((((((((((((((((((((( Files Created from 2012-10-08 to 2012-11-08 )))))))))))))))))))))))))))))))
.
.
2012-11-08 00:50 . 2012-11-08 00:50 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{336A7764-3480-49D6-A283-ACF343A398E9}\MpKsl866bd5e7.sys
2012-11-07 03:58 . 2012-11-07 03:58 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{336A7764-3480-49D6-A283-ACF343A398E9}\offreg.dll
2012-11-06 04:50 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{336A7764-3480-49D6-A283-ACF343A398E9}\mpengine.dll
2012-11-06 03:06 . 2012-11-06 03:06 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-11-05 00:27 . 2012-11-05 00:27 ——– d—–w- c:\documents and settings\administrator.AFC\Application Data\Malwarebytes
2012-11-05 00:20 . 2012-11-05 00:20 ——– d—–w- c:\windows\system32\Wave Systems Corp
2012-11-04 23:45 . 2012-11-04 23:45 ——– d—–w- c:\documents and settings\nurse\Application Data\Malwarebytes
2012-11-04 23:44 . 2012-11-04 23:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-11-04 23:44 . 2012-11-04 23:46 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-11-04 23:44 . 2012-09-30 01:54 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-11-04 22:38 . 2012-11-04 22:38 ——– d-sh–w- c:\documents and settings\administrator.AFC\IECompatCache
2012-11-04 22:37 . 2012-11-04 22:37 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-04 22:37 . 2012-11-04 22:37 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-04 22:34 . 2012-11-04 22:34 ——– d—–w- c:\documents and settings\administrator.AFC\Application Data\ScanSoft
2012-11-04 22:25 . 2012-11-04 22:25 388096 —-a-r- c:\documents and settings\administrator.AFC\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-11-04 22:12 . 2012-11-04 22:12 ——– d—–w- c:\program files\Trend Micro
2012-11-04 22:05 . 2012-11-05 00:31 ——– d—–w- c:\documents and settings\administrator.AFC\Application Data\Nico Mak Computing
2012-11-04 19:04 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-03 18:51 . 2012-11-03 18:51 ——– d—–w- c:\documents and settings\All Users\Application Data\kighwaojvcanqgq
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-07 03:59 . 2010-03-02 20:29 0 —-a-w- c:\documents and settings\nurse\Local Settings\Application Data\WavXMapDrive.bat
2012-11-06 23:53 . 2010-03-01 23:26 0 —-a-w- c:\documents and settings\administrator.AFC\Local Settings\Application Data\WavXMapDrive.bat
2012-10-29 19:33 . 2011-07-20 20:38 52648 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2012-10-29 19:33 . 2011-07-20 20:38 83912 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-10-29 19:33 . 2011-07-20 20:38 31144 —-a-w- c:\windows\system32\LMIport.dll
2012-10-29 19:33 . 2011-07-20 20:38 92072 —-a-w- c:\windows\system32\LMIinit.dll
2012-08-31 03:03 . 2011-04-18 18:18 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:14 . 2008-04-25 16:16 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2008-04-25 16:16 43520 ——w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2008-04-25 16:16 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2008-04-25 16:16 385024 ——w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2008-04-25 16:16 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:52 . 2008-04-25 16:16 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 13:05 . 2008-04-14 00:01 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}"
[HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}]
2009-06-12 00:41 49152 —-a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2009-06-12 00:41 49152 —-a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTDCPL.EXE" [2009-08-26 2691072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-28 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-28 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-28 142872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-02-24 149280]
"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2009-06-03 184320]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2009-05-18 145920]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2009-06-12 656384]
"USCService"="c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe" [2009-07-05 15872]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"DBRMTray"="c:\dell\DBRM\Reminder\DbrmTrayIcon.exe" [2009-11-12 203776]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-01-12 63048]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-18 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-18 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DBRMTray"="c:\dell\DBRM\Reminder\TrayApp.exe" [2009-10-18 7168]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-14 596584]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-10-29 19:33 92072 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 MpKsl866bd5e7;MpKsl866bd5e7;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{336A7764-3480-49D6-A283-ACF343A398E9}\MpKsl866bd5e7.sys [11/7/2012 6:50 PM 29904]
R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [10/13/2011 5:21 PM 249648]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [7/6/2011 3:32 PM 374704]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/11/2011 6:04 PM 12856]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [11/4/2012 5:46 PM 399432]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/4/2012 5:44 PM 676936]
R3 k57w2k;Broadcom NetLink ™ Gigabit Ethernet;c:\windows\system32\drivers\k57xp32.sys [2/23/2010 10:54 PM 209960]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11/4/2012 5:44 PM 22856]
S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [10/21/2011 3:23 PM 196176]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [11/5/2012 9:06 PM 40776]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL866BD5E7
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-07 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-09-12 22:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?ilc=5
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: myonlinereports.com
TCP: Interfaces\{F368150C-E683-42C5-A7EF-03B2654F1DC3}: NameServer = 192.168.77.10
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{311B58DC-A4DC-4B04-B1B5-60299AD3D803} - c:\program files\ShopAtHome\tbcore3U.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-07 19:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(740)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'lsass.exe'(796)
c:\windows\system32\wvauth.dll
c:\windows\system32\WININET.dll
.
Completion time: 2012-11-07 19:02:52
ComboFix-quarantined-files.txt 2012-11-08 01:02
.
Pre-Run: 220,775,755,776 bytes free
Post-Run: 226,135,920,640 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 4FDD84BB615627A0EFDEA729ACB6DFA9

1. Do I delete all quarantines,etc?

No; that will be dealt with when we tidy up at the end

2. Is it safe to run software like AdwCleaner (delete mode) on any computer?

Any PC, yes. Not sure about Macs.

Things are looking much better but we need to look at a folder.

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2
  • double-click SystemLook.exe to run it.
  • copy the content of the following codebox into the main textfield - please make sure you include the colon, (:), at the beginning.:

    :dir /s
    c:\documents and settings\All Users\Application Data\kighwaojvcanqgq

  • click the Look button to start the scan.
  • when finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Satchfan
Hi hecrodfnp It has been several days since I sent my last set of instructions to help with your computer problem. Please let me know if you are having problems. Thanks Satchfan
Hi Satchfan, My sincere apologies about the delay-I was out of town-the computer continues to run well. Thanks for your concern and follow up. Here is the SystemLook report: SystemLook 30.07.11 by jpshortstuff Log created at 20:23 on 12/11/2012 by nurse Administrator - Elevation successful Invalid Context: dir /s No Context: c:\documents and settings\All Users\Application Data\kighwaojvcanqgq -= EOF =-
My turn for apology now. In my haste, I gave you the wrong instructions. :blush:

Please run SystrmLook again.
  • double-click SystemLook.exe to run it.
  • copy the content of the following codebox into the main textfield - please make sure you include the colon, (:), at the beginning.:

    :dir
    c:\documents and settings\All Users\Application Data\kighwaojvcanqgq /s

  • click the Look button to start the scan.
  • when finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Satchfan
Hi Satchfan, here's the SystemLook log: SystemLook 30.07.11 by jpshortstuff Log created at 22:28 on 13/11/2012 by nurse Administrator - Elevation successful ========== dir ========== c:\documents and settings\All Users\Application Data\kighwaojvcanqgq - Parameters: "/s" —Files— arr-next.gif –a—- 2490 bytes [18:51 03/11/2012] [18:51 03/11/2012] b-sep.gif –a—- 1245 bytes [18:51 03/11/2012] [18:51 03/11/2012] btn-sq.gif –a—- 1379 bytes [18:51 03/11/2012] [18:51 03/11/2012] btn.png –a—- 1329 bytes [18:51 03/11/2012] [18:51 03/11/2012] card.jpg –a—- 2992 bytes [18:51 03/11/2012] [18:51 03/11/2012] green-l.png –a—- 3309 bytes [18:51 03/11/2012] [18:51 03/11/2012] green-r.png –a—- 2761 bytes [18:51 03/11/2012] [18:51 03/11/2012] ie7.css –a—- 19 bytes [18:51 03/11/2012] [18:51 03/11/2012] larr.gif –a—- 1106 bytes [18:51 03/11/2012] [18:51 03/11/2012] lock.png –a—- 4277 bytes [18:51 03/11/2012] [18:51 03/11/2012] locked-text-en.png –a—- 4179 bytes [18:51 03/11/2012] [18:51 03/11/2012] logo-img.png –a—- 9192 bytes [18:51 03/11/2012] [18:51 03/11/2012] logo-text.gif –a—- 2283 bytes [18:51 03/11/2012] [18:51 03/11/2012] main.html –a—- 99685 bytes [18:51 03/11/2012] [18:51 03/11/2012] mainbg.gif –a—- 1103 bytes [18:51 03/11/2012] [18:51 03/11/2012] mcafee-lock.png –a—- 4839 bytes [18:51 03/11/2012] [18:51 03/11/2012] money.gif –a—- 3573 bytes [18:51 03/11/2012] [18:51 03/11/2012] moneypak.png –a—- 7094 bytes [18:51 03/11/2012] [18:51 03/11/2012] payments-en.png –a—- 5493 bytes [18:51 03/11/2012] [18:51 03/11/2012] side-block.png –a—- 1936 bytes [18:51 03/11/2012] [18:51 03/11/2012] step.gif –a—- 2650 bytes [18:51 03/11/2012] [18:51 03/11/2012] step.png –a—- 1719 bytes [18:51 03/11/2012] [18:51 03/11/2012] style.css –a—- 6265 bytes [18:51 03/11/2012] [18:51 03/11/2012] wait.html –a—- 292 bytes [18:51 03/11/2012] [18:51 03/11/2012] webcam.swf –a—- 605 bytes [18:51 03/11/2012] [18:51 03/11/2012] No folders found. -= EOF =-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI