This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Green Dot, FBI Malware [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
c:\windows\vfgbelkj.exe

Folder::
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

================================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.
Logs to include with the next post:

ComboFix.txt
Mbam.txt
checkup.txt


Can you tell me if there are any outstanding problems.

Satchfan
Hi Satchfan.

Here is CF log:

ComboFix 12-11-06.03 - nurse 11/15/2012 19:31:29.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2012.1136 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\nurse\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\windows\vfgbelkj.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\arr-next.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\b-sep.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\btn-sq.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\btn.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\card.jpg
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\green-l.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\green-r.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\ie7.css
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\larr.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\lock.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\locked-text-en.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\logo-img.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\logo-text.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\main.html
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\mainbg.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\mcafee-lock.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\money.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\moneypak.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\payments-en.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\side-block.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\step.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\step.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\style.css
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\wait.html
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\webcam.swf
c:\documents and settings\nurse\Local Settings\Application Data\assembly\tmp
.
c:\windows\system32\drivers\i8042prt.sys . . . is missing!!
.
.
((((((((((((((((((((((((( Files Created from 2012-10-16 to 2012-11-16 )))))))))))))))))))))))))))))))
.
.
2012-11-16 01:29 . 2012-11-16 01:29 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FE5F6D23-9541-426E-B6CA-5538135EB061}\MpKslef224626.sys
2012-11-15 09:40 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FE5F6D23-9541-426E-B6CA-5538135EB061}\mpengine.dll
2012-11-14 13:23 . 2012-11-14 13:23 ——– d—–w- c:\documents and settings\nurse\Local Settings\Application Data\PCHealth
2012-11-14 04:09 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-06 03:06 . 2012-11-06 03:06 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-11-05 00:27 . 2012-11-05 00:27 ——– d—–w- c:\documents and settings\administrator.AFC\Application Data\Malwarebytes
2012-11-05 00:20 . 2012-11-05 00:20 ——– d—–w- c:\windows\system32\Wave Systems Corp
2012-11-04 23:45 . 2012-11-04 23:45 ——– d—–w- c:\documents and settings\nurse\Application Data\Malwarebytes
2012-11-04 23:44 . 2012-11-04 23:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-11-04 23:44 . 2012-11-04 23:46 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-11-04 23:44 . 2012-09-30 01:54 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-11-04 22:38 . 2012-11-04 22:38 ——– d-sh–w- c:\documents and settings\administrator.AFC\IECompatCache
2012-11-04 22:37 . 2012-11-04 22:37 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-04 22:37 . 2012-11-04 22:37 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-04 22:34 . 2012-11-04 22:34 ——– d—–w- c:\documents and settings\administrator.AFC\Application Data\ScanSoft
2012-11-04 22:25 . 2012-11-04 22:25 388096 —-a-r- c:\documents and settings\administrator.AFC\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-11-04 22:12 . 2012-11-04 22:12 ——– d—–w- c:\program files\Trend Micro
2012-11-04 22:05 . 2012-11-05 00:31 ——– d—–w- c:\documents and settings\administrator.AFC\Application Data\Nico Mak Computing
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-14 13:19 . 2010-03-02 20:29 0 —-a-w- c:\documents and settings\nurse\Local Settings\Application Data\WavXMapDrive.bat
2012-11-06 23:53 . 2010-03-01 23:26 0 —-a-w- c:\documents and settings\administrator.AFC\Local Settings\Application Data\WavXMapDrive.bat
2012-10-29 19:33 . 2011-07-20 20:38 52648 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2012-10-29 19:33 . 2011-07-20 20:38 83912 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-10-29 19:33 . 2011-07-20 20:38 31144 —-a-w- c:\windows\system32\LMIport.dll
2012-10-29 19:33 . 2011-07-20 20:38 92072 —-a-w- c:\windows\system32\LMIinit.dll
2012-10-22 08:43 . 2008-04-25 16:16 1875328 —-a-w- c:\windows\system32\win32k.sys
2012-10-02 18:04 . 2008-04-25 16:16 58368 —-a-w- c:\windows\system32\synceng.dll
2012-08-31 03:03 . 2011-04-18 18:18 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:14 . 2008-04-25 16:16 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2008-04-25 16:16 43520 ——w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2008-04-25 16:16 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2008-04-25 16:16 385024 ——w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2008-04-25 16:16 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:52 . 2008-04-25 16:16 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 13:05 . 2008-04-14 00:01 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}"
[HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}]
2009-06-12 00:41 49152 —-a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2009-06-12 00:41 49152 —-a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTDCPL.EXE" [2009-08-26 2691072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-28 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-28 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-28 142872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-02-24 149280]
"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2009-06-03 184320]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2009-05-18 145920]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2009-06-12 656384]
"USCService"="c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe" [2009-07-05 15872]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"DBRMTray"="c:\dell\DBRM\Reminder\DbrmTrayIcon.exe" [2009-11-12 203776]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-01-12 63048]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-18 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-18 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DBRMTray"="c:\dell\DBRM\Reminder\TrayApp.exe" [2009-10-18 7168]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-14 596584]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-10-29 19:33 92072 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 MpKslef224626;MpKslef224626;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FE5F6D23-9541-426E-B6CA-5538135EB061}\MpKslef224626.sys [11/15/2012 7:29 PM 29904]
R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [10/13/2011 5:21 PM 249648]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [7/6/2011 3:32 PM 374704]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/11/2011 6:04 PM 12856]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [11/4/2012 5:46 PM 399432]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/4/2012 5:44 PM 676936]
R3 k57w2k;Broadcom NetLink ™ Gigabit Ethernet;c:\windows\system32\drivers\k57xp32.sys [2/23/2010 10:54 PM 209960]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11/4/2012 5:44 PM 22856]
S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [10/21/2011 3:23 PM 196176]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [11/5/2012 9:06 PM 40776]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLEF224626
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-14 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-09-12 22:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?ilc=5
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: myonlinereports.com
TCP: Interfaces\{F368150C-E683-42C5-A7EF-03B2654F1DC3}: NameServer = 192.168.77.10
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-15 19:37
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(740)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'lsass.exe'(796)
c:\windows\system32\wvauth.dll
c:\windows\system32\WININET.dll
.
Completion time: 2012-11-15 19:38:44
ComboFix-quarantined-files.txt 2012-11-16 01:38
ComboFix2.txt 2012-11-08 01:02
.
Pre-Run: 225,271,693,312 bytes free
Post-Run: 225,377,800,192 bytes free
.
- - End Of File - - B52D18088B047CEDEE8323D45818703F
Here is MB and Security Check logs:

Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.16.01

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
nurse :: RECEPTION1 [administrator]

Protection: Enabled

11/15/2012 7:40:25 PM
mbam-log-2012-11-15 (19-40-25).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 267963
Time elapsed: 4 minute(s), 44 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


Results of screen317's Security Check version 0.99.54
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Disabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Out of date HijackThis installed!
Malwarebytes Anti-Malware version 1.65.1.1000
HijackThis 2.0.2
Java™ 6 Update 17
Java version out of Date!
Adobe Reader 9 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 20% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
Excellent.

We'll run an online scan and if that is clear we can tidy up.

Run ESET Online Scan

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - if ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Satchfan
Hi hecrodfnp It has been several days since I replied and asked you to run a scans to make sure your computer was clean. Please let me know if you are having problems and still need help. Thanks Satchfan

Thanks for being patient

No problem - we all have busy lives.


Your computer appears to be clean.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

Make sure that you have re-enabled Microsoft Security Essentials.
  • click on Start, Programs, Microsoft Security Essentials
  • click on the “Settings” tab
  • on the left, click on Real-time protection
  • place a check mark next to Turn on real-time protection (recommended)
===================================================

Uninstall Combofix

Follow these steps to uninstall Combofix
  • click Start then Run
  • now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
🖼Click to load external image (Posted Image)
  • please follow the prompts to uninstall Combofix.
  • once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.
===================================================

Uninstall AdwCleaner
  • double click on adwcleaner.exe to run the tool
  • click on Uninstall
  • confirm with Yes.
You can delete all other logs and programs we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Windows updates

I notice that Windows updates are waiting to be installed. Click here for information on how to get the latest Windows updates:

==================================================

Firewall

I see no evidence of a firewall. I suggest you get one in place now. I can’t stress how important it is that you use a firewall on your computer. This is one of the ways computers are open to Malware. Without a firewall, your computer is susceptible to being attacked again. Windows XP firewall is not adequate protection.

If you have a router with firewall features that’s fine – if not, I suggest you do the following:

Download one of the following firewalls:

ZoneAlarm
Sunbelt Personal Firewall

NOTE only install one firewall. Having more than one could cause many programs to stop working altogether. Also, the firewalls may get in each others' way and cause some security holes that would not be there with just one firewall.

For a tutorial on Firewalls and a listing of some other available ones see Understanding and Using Firewalls

==================================================

Update installed programs

Some of your programs are out-of-date:

[external image: Posted Image]
Your Java and Reader are out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components, Adobe Reader and update both.
  • from the Start menu, select Control Panel.
  • in Large or Small icon view, click Programs and Features. If you're using Category view, under "Programs", click Uninstall a program.
  • look for all versions of Java or Java Rintime Environment, and click Uninstall. Alternatively, right-click the program and select Uninstall
  • do the same to remove any version of Adobe Reader
Install the latest version of Java from here

NEXT

Visit Adobe and download the latest version of Acrobat Reader.

Having the latest updates ensures there are no security vulnerabilities on your system.

==================================================

Recommended programs

SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.

===================================================

Install Spybot - Search and Destroy - Download and install Spybot Search and Destroy which provides real time spyware and hijacker protection .

You should scan your computer with the program on a regular basis as you would with your anti-virus software.

A tutorial on installing and using SS&D can be found here

===================================================

Update and run Malwarebytes. This really is an excellent program that you should also update and run on a regular basis, probably weekly.

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

==================================================

Finally:

Defragment your hard drive

SecurityCheck showed that you need to defragment your hard drive.
  • open My Computer.
  • right-click on C:\, then click Properties.
  • on the Tools tab > click Defragment Now.
  • click Defragment
  • give it time to run (it can take a while).

I will keep this open for 24 hours in case you have any problems, after which I’ll close the topic.

Safe computing

Satchfan
Thanks Satchfan! You're help and expertise are greatly appreciated. I will use all your advice for the future. I'll attempt a donation with another card as PayPal is not letting the Visa run through. Don't know if it's an international issue or what. Again, many thanks, my friend.
You're welcome for the help. Thanks for the donation offer but don't worry as we don't do this for profit. I hope you have no further problems but if you do, you know where we are. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI