This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adknowledge Malware Removal?

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I seem to have picked up some malware called Adknowledge. It hijacks banner ads. I would like to get rid of it.

Here is the requested copy:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:45:17 PM, on 6/17/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\QUALCOMM\QDLService\QDLService.exe
C:\Program Files\Acer\Acer VCM\RS_Service.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Outlook Express\msimn.exe
C:\DOCUME~1\David\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\David\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…13&m=ao531h
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://homepage.acer.com/rdr.aspx?b=ACAW&a…13&m=ao531h
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE8701] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\ChromeModule.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingE3012] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\cltmng.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE287] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\ChromeModule.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE8583] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\CltMngSvc.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE7210] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\FirefoxModule.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE6378] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\InternetExplorerModule.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE7901] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\msvcp100.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE733] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\msvcr100.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE61] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\rep.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingE2434] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\SPHook32.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE148] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\SPRunner.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE2470] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\uninstall.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE7897] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\ChromeModule.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE508] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\CltMngSvc.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE7122] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\FirefoxModule.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE5642] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\InternetExplorerModule.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE9493] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\msvcp100.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE703] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\msvcr100.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE9459] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\rep.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingE2923] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\SPHook32.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingE4178] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\SPRunner.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE9306] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\uninstall.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE213] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Local Settings\Application Data\Updater26278\Updater26278.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingE5251] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\WINDOWS\SchedLgU.Txt"
O4 - HKLM\..\RunOnce: [SpybotDeletingE792] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\WINDOWS\SchedLgU.Txt"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingF9277] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\ChromeModule.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingF1235] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\cltmng.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingF662] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\ChromeModule.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF4282] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\CltMngSvc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingF447] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\FirefoxModule.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF6213] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\InternetExplorerModule.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF2813] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\msvcp100.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF6440] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\msvcr100.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF4847] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\rep.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingF1605] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\SPHook32.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF3798] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\SPRunner.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingF8199] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Application Data\SearchProtect\bin\uninstall.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingF5533] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\ChromeModule.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF2593] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\CltMngSvc.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingF6501] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\FirefoxModule.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF8859] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\InternetExplorerModule.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF9564] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\msvcp100.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF6892] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\msvcr100.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF2986] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\rep.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingF3850] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\SPHook32.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingF5476] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\SPRunner.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingF6960] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SearchProtect\bin\uninstall.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingF1955] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Documents and Settings\David\Local Settings\Application Data\Updater26278\Updater26278.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingF6309] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\WINDOWS\SchedLgU.Txt"
O4 - HKCU\..\RunOnce: [SpybotDeletingF942] "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\WINDOWS\SchedLgU.Txt"
O4 - Global Startup: Acer VCM.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Unknown owner - C:\Program Files\SearchProtect\bin\CltMngSvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Qualcomm Gobi Download Service (QDLService) - QUALCOMM, Inc. - C:\QUALCOMM\QDLService\QDLService.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe

–
End of file - 16979 bytes
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.



Download DDS and save it to your desktop from here or here or
here.

Disable any script blocker, and then double click dds.scr to run the tool.

When done, DDS will open two (2) logs
DDS.txt
Attach.txt
Save both reports to your desktop.



Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-18 18:08:32
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD16 rev.11.0 149.05GB
Running: jgojrlpg.exe; Driver: C:\DOCUME~1\David\LOCALS~1\Temp\pgecraob.sys


—- Devices - GMER 2.1 —-

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 wdf01000.sys
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 wdf01000.sys

—- EOF - GMER 2.1 —-
Sorry. Your instructions just said to save it to my desktop. Here it is: DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 6:38:41 on 2013-06-18 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.422 [GMT -7:00] . . ============== Running Processes ================ . C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\QUALCOMM\QDLService\QDLService.exe C:\Program Files\Acer\Acer VCM\RS_Service.exe C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe C:\WINDOWS\system32\wdfmgr.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Launch Manager\LManager.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Acer\Acer VCM\AcerVCM.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\igfxext.exe C:\Program Files\Outlook Express\msimn.exe C:\DOCUME~1\David\LOCALS~1\Temp\RtkBtMnt.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uStart Page = about:blank uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=0313&m=ao531h uInternet Connection Wizard,ShellNext = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=0313&m=ao531h BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRunOnce: [SpybotDeletingF9277] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\ChromeModule.dll_old" uRunOnce: [SpybotDeletingF1235] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\cltmng.exe" uRunOnce: [SpybotDeletingF662] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\ChromeModule.dll" uRunOnce: [SpybotDeletingF4282] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\CltMngSvc.exe" uRunOnce: [SpybotDeletingF447] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\FirefoxModule.dll" uRunOnce: [SpybotDeletingF6213] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\InternetExplorerModule.dll" uRunOnce: [SpybotDeletingF2813] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\msvcp100.dll" uRunOnce: [SpybotDeletingF6440] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\msvcr100.dll" uRunOnce: [SpybotDeletingF4847] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\rep.dat" uRunOnce: [SpybotDeletingF1605] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\SPHook32.dll" uRunOnce: [SpybotDeletingF3798] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\SPRunner.exe" uRunOnce: [SpybotDeletingF8199] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\uninstall.exe" uRunOnce: [SpybotDeletingF5533] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\ChromeModule.dll" uRunOnce: [SpybotDeletingF2593] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\CltMngSvc.exe" uRunOnce: [SpybotDeletingF6501] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\FirefoxModule.dll" uRunOnce: [SpybotDeletingF8859] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\InternetExplorerModule.dll" uRunOnce: [SpybotDeletingF9564] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\msvcp100.dll" uRunOnce: [SpybotDeletingF6892] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\msvcr100.dll" uRunOnce: [SpybotDeletingF2986] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\rep.dat" uRunOnce: [SpybotDeletingF3850] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\SPHook32.dll" uRunOnce: [SpybotDeletingF5476] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\SPRunner.exe" uRunOnce: [SpybotDeletingF6960] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\uninstall.exe" uRunOnce: [SpybotDeletingF1955] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\local settings\application data\updater26278\Updater26278.exe" uRunOnce: [SpybotDeletingF6309] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\windows\SchedLgU.Txt" uRunOnce: [SpybotDeletingF942] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\windows\SchedLgU.Txt" mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [AzMixerSel] c:\program files\realtek\audio\drivers\AzMixerSel.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [LManager] c:\program files\launch manager\LManager.exe mRun: [CarboniteSetupLite] "c:\program files\carbonite\CarbonitePreinstaller.exe" /preinstalled mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRunOnce: [SpybotDeletingE8701] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\ChromeModule.dll_old" mRunOnce: [SpybotDeletingE3012] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\cltmng.exe" mRunOnce: [SpybotDeletingE287] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\ChromeModule.dll" mRunOnce: [SpybotDeletingE8583] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\CltMngSvc.exe" mRunOnce: [SpybotDeletingE7210] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\FirefoxModule.dll" mRunOnce: [SpybotDeletingE6378] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\InternetExplorerModule.dll" mRunOnce: [SpybotDeletingE7901] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\msvcp100.dll" mRunOnce: [SpybotDeletingE733] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\msvcr100.dll" mRunOnce: [SpybotDeletingE61] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\rep.dat" mRunOnce: [SpybotDeletingE2434] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\SPHook32.dll" mRunOnce: [SpybotDeletingE148] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\SPRunner.exe" mRunOnce: [SpybotDeletingE2470] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\application data\searchprotect\bin\uninstall.exe" mRunOnce: [SpybotDeletingE7897] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\ChromeModule.dll" mRunOnce: [SpybotDeletingE508] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\CltMngSvc.exe" mRunOnce: [SpybotDeletingE7122] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\FirefoxModule.dll" mRunOnce: [SpybotDeletingE5642] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\InternetExplorerModule.dll" mRunOnce: [SpybotDeletingE9493] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\msvcp100.dll" mRunOnce: [SpybotDeletingE703] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\msvcr100.dll" mRunOnce: [SpybotDeletingE9459] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\rep.dat" mRunOnce: [SpybotDeletingE2923] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\SPHook32.dll" mRunOnce: [SpybotDeletingE4178] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\SPRunner.exe" mRunOnce: [SpybotDeletingE9306] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\searchprotect\bin\uninstall.exe" mRunOnce: [SpybotDeletingE213] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\documents and settings\david\local settings\application data\updater26278\Updater26278.exe" mRunOnce: [SpybotDeletingE5251] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\windows\SchedLgU.Txt" mRunOnce: [SpybotDeletingE792] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\windows\SchedLgU.Txt" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acervc~1.lnk - c:\program files\acer\acer vcm\AcerVCM.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . TCP: NameServer = 192.168.2.1 TCP: Interfaces\{6FF42509-5EF7-4B0D-8576-1233DBB74867} : DHCPNameServer = 192.168.2.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\acer\acer vcm\Skype4COM.dll Notify: igfxcui - igfxdev.dll Notify: SDWinLogon - SDWinLogon.dll mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\27.0.1453.110\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome Hosts: 127.0.0.1 www.spywareinfo.com . ============= SERVICES / DRIVERS =============== . R2 QDLService;Qualcomm Gobi Download Service;c:\qualcomm\qdlservice\QDLService.exe [2008-11-10 345336] R2 RS_Service;Raw Socket Service;c:\program files\acer\acer vcm\RS_Service.exe [2009-2-26 237568] R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2013-3-12 1103392] R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2013-3-12 1369624] S2 CltMngSvc;Search Protect by Conduit Updater;c:\program files\searchprotect\bin\cltmngsvc.exe –> c:\program files\searchprotect\bin\CltMngSvc.exe [?] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2013-3-12 168384] S3 QCFilterGAD;Gobi AD USB Composite Device Filter Driver;c:\windows\system32\drivers\qcfilterGAD.sys [2013-3-6 5248] S3 qcusbnetGAD;Gobi AD USB-NDIS miniport;c:\windows\system32\drivers\qcusbnetGAD.sys [2013-3-6 115200] S3 qcusbserGAD;Gobi AD USB Device for Legacy Serial Communication;c:\windows\system32\drivers\qcusbserGAD.sys [2009-2-26 103680] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-2-26 162816] S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\drivers\rts516xir.sys –> c:\windows\system32\drivers\Rts516xIR.sys [?] . =============== Created Last 30 ================ . . ==================== Find3M ==================== . 2013-05-07 22:30:06 920064 —-a-w- c:\windows\system32\wininet.dll 2013-05-07 22:30:05 43520 ——w- c:\windows\system32\licmgr10.dll 2013-05-07 22:30:05 1469440 ——w- c:\windows\system32\inetcpl.cpl 2013-05-07 21:53:29 385024 ——w- c:\windows\system32\html.iec 2013-05-03 01:30:20 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-05-03 00:38:17 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe 2013-04-10 01:31:19 1876352 —-a-w- c:\windows\system32\win32k.sys . ============= FINISH: 6:39:17.56 ===============
The other log named "attach.txt" had this warning: "UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT" What should I do?
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 3/5/2013 11:51:18 PM System Uptime: 6/13/2013 6:32:03 PM (108 hours ago) . Motherboard: Acer | | Processor: Intel® Atom™ CPU N270 @ 1.60GHz | CPU | 1595/533mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 142 GiB total, 128.91 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP18: 3/24/2013 6:00:11 PM - System Checkpoint RP19: 3/26/2013 7:52:43 PM - System Checkpoint RP20: 4/3/2013 7:37:30 PM - System Checkpoint RP21: 4/5/2013 7:59:03 PM - System Checkpoint RP22: 4/10/2013 8:29:47 PM - System Checkpoint RP23: 4/11/2013 6:22:23 AM - Software Distribution Service 3.0 RP24: 4/13/2013 1:10:12 PM - System Checkpoint RP25: 4/15/2013 11:07:57 PM - System Checkpoint RP26: 4/17/2013 9:22:19 PM - System Checkpoint RP27: 4/19/2013 6:59:56 AM - System Checkpoint RP28: 4/20/2013 5:30:15 PM - System Checkpoint RP29: 4/21/2013 11:25:14 PM - System Checkpoint RP30: 5/4/2013 12:25:22 AM - System Checkpoint RP31: 5/15/2013 6:28:03 AM - Software Distribution Service 3.0 RP32: 5/18/2013 2:26:23 PM - System Checkpoint RP33: 6/2/2013 7:16:10 AM - System Checkpoint RP34: 6/3/2013 9:35:40 AM - System Checkpoint RP35: 6/13/2013 6:12:50 AM - Software Distribution Service 3.0 RP36: 6/15/2013 11:25:16 PM - System Checkpoint . ==== Installed Programs ====================== . 2007 Microsoft Office Suite Service Pack 1 (SP1) Acer 3G Connection Manager Acer eRecovery Management Acer ScreenSaver Acer VCM Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.2 Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver Atheros for Acer Driver v7.6.1.221_Foxconn Installation Program Carbonite Online Backup Setup Choice Guard Compatibility Pack for the 2007 Office system eSobi v2 Google Chrome Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB2779562) Hotfix for Windows XP (KB932716-v2) Hotfix for Windows XP (KB949764) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB954708) Hotfix for Windows XP (KB961118) Intel® Graphics Media Accelerator Driver Intel® Matrix Storage Manager JMicron Flash Media Controller Driver Junk Mail filter update Launch Manager Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft National Language Support Downlevel APIs Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Suite Activation Assistant Microsoft Office Word MUI (English) 2007 Microsoft Software Update for Web Folders (English) 12 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Works MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) PhotoScape Qualcomm Gobi Driver Package Qualcomm Gobi Images Realtek High Definition Audio Driver SDFormatter Search Protect by conduit Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 7 (KB2792100) Security Update for Windows Internet Explorer 7 (KB2797052) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2744842) Security Update for Windows Internet Explorer 8 (KB2792100) Security Update for Windows Internet Explorer 8 (KB2797052) Security Update for Windows Internet Explorer 8 (KB2809289) Security Update for Windows Internet Explorer 8 (KB2817183) Security Update for Windows Internet Explorer 8 (KB2829530) Security Update for Windows Internet Explorer 8 (KB2838727) Security Update for Windows Internet Explorer 8 (KB2847204) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2655992) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2691442) Security Update for Windows XP (KB2698365) Security Update for Windows XP (KB2705219-v2) Security Update for Windows XP (KB2712808) Security Update for Windows XP (KB2719985) Security Update for Windows XP (KB2723135-v2) Security Update for Windows XP (KB2727528) Security Update for Windows XP (KB2753842-v2) Security Update for Windows XP (KB2757638) Security Update for Windows XP (KB2758857) Security Update for Windows XP (KB2770660) Security Update for Windows XP (KB2778344) Security Update for Windows XP (KB2780091) Security Update for Windows XP (KB2799494) Security Update for Windows XP (KB2802968) Security Update for Windows XP (KB2807986) Security Update for Windows XP (KB2808735) Security Update for Windows XP (KB2813170) Security Update for Windows XP (KB2813345) Security Update for Windows XP (KB2820197) Security Update for Windows XP (KB2820917) Security Update for Windows XP (KB2829361) Security Update for Windows XP (KB2839229) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982665) Segoe UI Software Version Updater Spybot - Search & Destroy Synaptics Pointing Device Driver Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Office 2007 (KB946691) Update for Windows Internet Explorer 8 (KB2598845) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2661254-v2) Update for Windows XP (KB2736233) Update for Windows XP (KB2749655) Update for Windows XP (KB898461) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB973815) USB2.0 Card Reader Software WebFldrs XP Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Live Writer Windows Media Format Runtime Windows Media Player 10 . ==== Event Viewer Messages From Past Week ======== . 6/16/2013 7:10:09 AM, error: Service Control Manager [7034] - The Search Protect by Conduit Updater service terminated unexpectedly. It has done this 1 time(s). 6/13/2013 6:32:35 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Spybot-S&D 2 Security Center Service service to connect. 6/13/2013 6:32:35 PM, error: Service Control Manager [7000] - The Spybot-S&D 2 Security Center Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 6/13/2013 11:35:13 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service. . ==== End Of File ===========================
Scan with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.




Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications


====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
# AdwCleaner v2.303 - Logfile created 06/19/2013 at 06:25:27 # Updated 08/06/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : David - ACER-925BE1910B # Boot Mode : Normal # Running from : C:\Documents and Settings\David\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : CltMngSvc ***** [Files / Folders] ***** File Deleted : C:\WINDOWS\Tasks\AmiUpdXp.job Folder Deleted : C:\Documents and Settings\David\Application Data\SwvUpdater Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\SearchProtect ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\ConduitSearchScopes Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com Key Deleted : HKCU\Software\SearchProtect Key Deleted : HKCU\Software\SmartBar Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289847 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect Key Deleted : HKLM\Software\SearchProtect ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Google Chrome v27.0.1453.110 File : C:\Documents and Settings\David\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences Deleted [l.28] : icon_url = "hxxp://search.conduit.com/fav.ico", Deleted [l.31] : keyword = "search.conduit.com", Deleted [l.34] : search_url = "hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&cui=UN15[…] Deleted [l.1873] : homepage = "hxxp://search.conduit.com/?CUI=UN15454097507458227&ctid=CT3289847&SearchSource=48", Deleted [l.2059] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?CUI=UN15454097507458227&ctid=CT328[…] ************************* AdwCleaner[S1].txt - [3088 octets] - [19/06/2013 06:25:27] ########## EOF - C:\AdwCleaner[S1].txt - [3148 octets] ##########
ComboFix 13-06-18.02 - David 06/19/2013 6:41.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.273 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-05-19 to 2013-06-19 )))))))))))))))))))))))))))))))
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-07 22:30 . 2009-02-26 22:40 920064 —-a-w- c:\windows\system32\wininet.dll
2013-05-07 22:30 . 2009-02-26 22:40 43520 ——w- c:\windows\system32\licmgr10.dll
2013-05-07 22:30 . 2009-02-26 22:40 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-05-07 21:53 . 2009-02-26 22:40 385024 ——w- c:\windows\system32\html.iec
2013-05-03 01:30 . 2008-04-14 00:54 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-05-03 00:38 . 2008-04-14 00:01 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-04-10 01:31 . 2009-02-26 22:40 1876352 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"RTHDCPL"="RTHDCPL.EXE" [2009-01-13 18084864]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-17 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-02-20 817672]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2008-10-03 294544]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-01-22 1422632]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-2-26 565248]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDTray.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDFSSvc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdate.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"=
.
R2 QDLService;Qualcomm Gobi Download Service;c:\qualcomm\QDLService\QDLService.exe [11/10/2008 12:43 AM 345336]
R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2/26/2009 5:18 PM 237568]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [3/12/2013 8:04 PM 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [3/12/2013 8:04 PM 1369624]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [3/12/2013 8:04 PM 168384]
S3 QCFilterGAD;Gobi AD USB Composite Device Filter Driver;c:\windows\system32\drivers\qcfilterGAD.sys [3/6/2013 12:53 AM 5248]
S3 qcusbnetGAD;Gobi AD USB-NDIS miniport;c:\windows\system32\drivers\qcusbnetGAD.sys [3/6/2013 12:53 AM 115200]
S3 qcusbserGAD;Gobi AD USB Device for Legacy Serial Communication;c:\windows\system32\drivers\qcusbserGAD.sys [2/26/2009 5:27 PM 103680]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2/26/2009 4:47 PM 162816]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys –> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-06-08 16:34 1165776 —-a-w- c:\program files\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-19 c:\windows\Tasks\Check for updates (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDUpdate.exe [2013-03-13 21:08]
.
2013-06-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-03-06 08:24]
.
2013-06-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-03-06 08:24]
.
2013-03-13 c:\windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDImmunize.exe [2013-03-13 21:07]
.
2013-03-13 c:\windows\Tasks\Scan the system (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDScan.exe [2013-03-13 21:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=0313&m=ao531h
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
.
- - - - ORPHANS REMOVED - - - -
.
Notify-SDWinLogon - SDWinLogon.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-06-19 06:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(412)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2013-06-19 06:49:45
ComboFix-quarantined-files.txt 2013-06-19 13:49
.
Pre-Run: 138,477,764,608 bytes free
Post-Run: 138,662,100,992 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30
.
- - End Of File - - 14AD3C687F539E201EE139E3728FA85E
5C616939100B85E558DA92B899A0FC36
Looks good!

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Here it is: C:\Documents and Settings\David\My Documents\Downloads\Photoscape_Setup.exe a variant of Win32/Adware.iBryte.G application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP24\A0007470.dll Win32/Conduit.SearchProtect.A application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP24\A0007471.dll Win32/Conduit.SearchProtect.A application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP24\A0007472.dll Win32/Conduit.SearchProtect.A application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP24\A0007473.exe Win32/Conduit.SearchProtect.A application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP24\A0007474.dll Win32/Conduit.SearchProtect.A application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP24\A0007475.exe Win32/Conduit.SearchProtect.A application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017799.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017800.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017801.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017802.exe a variant of Win32/Conduit.SearchProtect.B application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017803.dll Win32/Conduit.SearchProtect.A application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017806.exe Win32/Conduit.SearchProtect.A application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017807.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017808.exe a variant of Win32/Conduit.SearchProtect.B application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017810.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017811.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP31\A0017814.dll probably a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019067.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019069.exe a variant of Win32/Conduit.SearchProtect.B application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019070.exe Win32/Conduit.SearchProtect.A application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019071.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019072.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019075.dll probably a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019078.exe a variant of Win32/Conduit.SearchProtect.B application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019080.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019081.exe Win32/Conduit.SearchProtect.A application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019082.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019083.dll a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019086.dll probably a variant of Win32/Conduit.SearchProtect.C application C:\System Volume Information\_restore{049D926D-4432-406D-A3E4-0C7BA036C319}\RP36\A0019089.exe a variant of Win32/Toolbar.CrossRider.C application

C:\Documents and Settings\David\My Documents\Downloads\Photoscape_Setup.exe


Delete this file.


Then we can do the cleanup - if you are facing any issues, report that immediately.

Scan with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI