This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

unknown!? (not sure how I should know name of virus?)

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

well I think this link is the same as one I used, and it is trial,, but I'll delete that one and try this one anyway,,,thank you for your help and patience–I had to leave for awhile (lest a hammer go thru my moniter lol) but I'm back now!!
here are the results of the mbam scan–it said nothing malicious was found! Malwarebytes Anti-Malware (Trial) 1.75.0.1300 www.malwarebytes.org Database version: v2013.06.26.07 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Najohodo :: LITTLELAPTOP [administrator] Protection: Enabled 6/26/2013 8:41:47 PM mbam-log-2013-06-26 (20-41-47).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 235962 Time elapsed: 7 minute(s), 59 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Finally! (please let me know what happens next? thanks!) C:\Documents and Settings\Najohodo\My Documents\MISC\some set up installer thingy\Setup(1).exe a variant of Win32/Adware.iBryte.G application C:\Documents and Settings\Najohodo\My Documents\MISC\some set up installer thingy\Setup.exe a variant of Win32/Adware.iBryte.G application C:\System Volume Information\_restore{C5865CF0-8F95-49F0-8B2D-414EBEF542AC}\RP793\A0095134.exe a variant of Win32/Soft32Downloader.D application C:\System Volume Information\_restore{C5865CF0-8F95-49F0-8B2D-414EBEF542AC}\RP797\A0095664.exe a variant of Win32/Soft32Downloader.D application
I just checked around, and am still seeing the yellow triangle with the little exclamation point in it at the bottom of the page, almost always says "done but with error on page"…also pages still loading very slow,,And facebook not loading images! Nothing has improved , is there anything else you can do?? thank you for trying! I'm so discouraged!!
Please run the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Press the WinKey + R to open a run box, type Notepad > click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
C:\Documents and Settings\Najohodo\My Documents\MISC\some set up installer thingy\Setup(1).exe 
C:\Documents and Settings\Najohodo\My Documents\MISC\some set up installer thingy\Setup.exe 
C:\System Volume Information\_restore{C5865CF0-8F95-49F0-8B2D-414EBEF542AC}\RP793\A0095134.exe 
C:\System Volume Information\_restore{C5865CF0-8F95-49F0-8B2D-414EBEF542AC}\RP797\A0095664.exe 

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT

Please download Windows Repair (all in one) from here

Install the program then run it

Go to step 2 and allow it to run Disk check


Once that is done then go to step 3 and allow it to run SFC

On the the Start Repairs tab => Click the Start


Click on the select all check box and then click on Start

DON'T use the computer while each scan is in progress.

Restart may be needed to finish the repair procedure.
I dont have a "Win" key on my keyboard…??? I dont know what that is..I'll just open up notepad the oldschool way… is this the last of this process???
here you go:

ComboFix 13-06-27.01 - Najohodo 06/27/2013 14:27:40.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.751.347 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Najohodo\Desktop\CFScript.txt
AV: AVG AntiVirus 2013 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\documents and settings\Najohodo\My Documents\MISC\some set up installer thingy\Setup(1).exe"
"c:\documents and settings\Najohodo\My Documents\MISC\some set up installer thingy\Setup.exe"
"c:\system volume information\_restore{C5865CF0-8F95-49F0-8B2D-414EBEF542AC}\RP793\A0095134.exe"
"c:\system volume information\_restore{C5865CF0-8F95-49F0-8B2D-414EBEF542AC}\RP797\A0095664.exe"
.
.
((((((((((((((((((((((((( Files Created from 2013-05-27 to 2013-06-27 )))))))))))))))))))))))))))))))
.
.
2013-06-27 01:18 . 2013-06-27 01:18 ——– d—–w- c:\program files\ESET
2013-06-26 21:13 . 2013-06-26 21:13 ——– d—–w- c:\documents and settings\Najohodo\Application Data\Malwarebytes
2013-06-26 21:13 . 2013-06-26 21:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-06-26 21:13 . 2013-06-27 00:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-06-26 21:13 . 2013-04-04 18:50 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-06-26 19:48 . 2013-06-26 19:48 ——– d—–w- c:\windows\ERUNT
2013-06-26 19:29 . 2013-06-26 19:29 ——– d—–w- C:\JRT
2013-06-26 05:17 . 2013-06-26 05:18 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG
2013-06-26 04:53 . 2013-06-26 04:53 ——– d-sh–w- c:\documents and settings\All Users\Application Data\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-06-26 04:16 . 2008-04-13 16:44 2560 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2013-06-26 02:37 . 2013-06-26 02:37 ——– d—–w- c:\documents and settings\Najohodo\Application Data\Foresight Software
2013-06-26 02:37 . 2013-06-26 02:37 ——– d—–w- c:\program files\Common Files\Foresight Software
2013-06-26 02:37 . 2013-06-26 02:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Foresight Software
2013-06-26 01:26 . 2013-06-26 01:26 ——– d—–w- C:\FRST
2013-06-26 00:33 . 2013-06-26 00:33 ——– d—–w- c:\documents and settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-06-26 00:33 . 2013-06-26 00:33 ——– d—–w- c:\documents and settings\Najohodo\AppData
2013-06-26 00:33 . 2013-06-26 00:35 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2013-06-26 00:33 . 2013-06-26 00:57 ——– d—–w- c:\documents and settings\Najohodo\Application Data\IObit
2013-06-26 00:32 . 2013-06-26 00:32 ——– d—–w- c:\program files\IObit
2013-06-24 23:01 . 2013-06-24 23:01 ——– d—–w- c:\program files\iPod
2013-06-24 23:01 . 2013-06-24 23:02 ——– d—–w- c:\program files\iTunes
2013-06-24 23:01 . 2013-06-24 23:02 ——– d—–w- c:\documents and settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-06-24 22:17 . 2013-06-24 22:17 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2013-06-24 22:17 . 2013-06-24 22:16 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2013-06-24 22:17 . 2013-06-24 22:16 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2013-06-24 22:17 . 2013-06-24 22:16 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2013-06-24 22:17 . 2013-06-24 22:16 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2013-06-24 22:16 . 2013-06-24 22:16 ——– d—–w- c:\program files\QuickTime
2013-06-24 20:43 . 2013-06-24 20:43 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Sun
2013-06-12 02:12 . 2013-06-12 02:12 9089416 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-05-31 01:13 . 2013-05-31 01:13 ——– d—–w- c:\documents and settings\All Users\Application Data\SSScanAppDataDir
2013-05-31 01:12 . 2013-05-31 01:12 ——– d—–w- c:\documents and settings\All Users\Application Data\MSScanAppDataDir
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-23 16:56 . 2012-07-04 02:55 12984 —-a-w- c:\windows\system32\drivers\SWDUMon.sys
2013-06-12 02:12 . 2012-04-14 14:47 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 02:12 . 2011-07-25 05:03 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-07 22:30 . 2006-06-23 19:33 920064 —-a-w- c:\windows\system32\wininet.dll
2013-05-07 22:30 . 2004-04-07 16:46 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-05-07 22:30 . 2004-04-07 16:46 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-05-07 21:53 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2013-05-03 01:26 . 2004-04-07 16:47 2193536 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-05-03 00:38 . 2002-08-29 01:04 2070144 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-01 07:59 . 2013-05-01 07:59 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2013-05-01 07:59 . 2013-05-01 07:59 69632 —-a-w- c:\windows\system32\QuickTime.qts
2013-04-10 01:31 . 2004-04-07 16:47 1876352 —-a-w- c:\windows\system32\win32k.sys
2013-04-04 09:36 . 2013-02-16 03:41 866720 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-04-04 09:35 . 2013-02-16 03:41 788896 —-a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2013-06-24 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-01-27 118784]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-26 118843]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2003-12-17 00:49 110592 —-a-w- c:\windows\system32\LgNotify.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2013\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk
backup=c:\windows\pss\RAMASST.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\000StTHK]
2001-06-24 03:28 24576 —-a-w- c:\windows\system32\000StTHK.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00THotkey]
2004-02-25 21:12 258048 —-a-w- c:\windows\system32\00THotkey.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2003-04-18 18:20 88363 —-a-w- c:\windows\agrsmmsg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2003-10-30 23:46 192512 —-a-w- c:\program files\Apoint2K\Apoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-11-02 13:51 59240 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_UI]
2013-04-29 04:58 4408368 —-a-w- c:\program files\AVG\AVG2013\avgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-15 02:17 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-01-27 02:03 155648 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2013-05-31 15:56 152392 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
2003-01-02 23:16 172032 —-a-w- c:\program files\ltmoh\ltmoh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Photobucket Backup]
2013-01-29 18:35 320000 —-a-w- c:\program files\Photobucket Backup\Photobucket.App.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinger]
2005-03-18 00:37 151552 —-a-w- c:\toshiba\Ivp\ISM\pinger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
2003-12-10 10:36 86016 —-a-w- c:\program files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2013-05-01 07:59 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reader Library Launcher]
2010-07-12 22:34 906648 —-a-w- c:\program files\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmaTel StacMon]
2003-08-03 23:01 86073 —-a-w- c:\program files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2013-06-24 02:27 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFNF5]
2003-12-02 21:15 73728 —-a-w- c:\windows\system32\TFNF5.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
2003-09-05 10:24 65536 —-a-w- c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TouchED]
2003-01-22 01:00 126976 —-a-w- c:\program files\TOSHIBA\TouchED\TouchED.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain]
2004-03-03 19:57 278528 —-a-w- c:\windows\system32\TPSMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\V0420Mon.exe]
2007-04-30 01:00 32768 —-a-w- c:\windows\V0420Mon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SightSpeed\\SightSpeed.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2013\\avgdiagex.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 4:50 AM 60216]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [9/21/2012 4:46 AM 245048]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/13/2011 7:30 AM 39224]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 1:32 PM 208184]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 1:32 PM 22328]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [10/7/2011 7:23 AM 170808]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 2:14 AM 182072]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [5/14/2013 12:54 AM 4937264]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [4/18/2013 4:34 AM 283136]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [6/26/2013 5:13 PM 418376]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/26/2013 5:13 PM 701512]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service;c:\program files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [8/23/2012 11:31 AM 1532280]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/26/2013 5:13 PM 22856]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [7/4/2012 3:26 PM 10088]
S2 mrtRate;mrtRate; [x]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [12/18/2009 12:58 PM 11336]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [5/13/2011 3:21 AM 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [5/13/2011 3:21 AM 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [5/13/2011 3:21 AM 136808]
S3 SWDUMon;SWDUMon;c:\windows\system32\drivers\SWDUMon.sys [7/3/2012 10:55 PM 12984]
S3 V0420VID;Live! Cam Vista IM (VF0420);c:\windows\system32\drivers\V0420Vid.sys [6/13/2010 8:45 AM 99648]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-14 02:12]
.
2013-06-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 23:57]
.
2013-06-26 c:\windows\Tasks\Foresight Software Registration3.job
- c:\program files\Common Files\Foresight Software\UUS3\UUS3.dll [2013-01-15 21:40]
.
2013-06-26 c:\windows\Tasks\Foresight Software Update3.job
- c:\program files\Common Files\Foresight Software\UUS3\Update3.exe [2013-01-15 21:40]
.
2013-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-06-24 02:26]
.
2013-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-06-24 02:26]
.
2013-06-26 c:\windows\Tasks\SpeedyPC Pro.job
- c:\documents and settings\Najohodo\My Documents\SpeedyPC\SpeedyPC.exe [2013-05-03 19:38]
.
2013-06-27 c:\windows\Tasks\User_Feed_Synchronization-{1D98A4D2-7DB1-48FB-B7AE-8B55CE506E04}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: advancedmd.com
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Najohodo\Application Data\Mozilla\Firefox\Profiles\dqw0abg4.default\
FF - prefs.js: browser.search.selectedEngine - Amazon.com
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-06-27 14:35
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(2000)
c:\windows\System32\LgNotify.dll
.
- - - - - - - > 'explorer.exe'(2812)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\program files\Common Files\Microsoft Shared\INK\PENUSA.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2013-06-27 14:39:19
ComboFix-quarantined-files.txt 2013-06-27 18:39
ComboFix2.txt 2013-06-26 18:13
.
Pre-Run: 42,750,533,632 bytes free
Post-Run: 42,767,298,560 bytes free
.
- - End Of File - - 9ADBB707FB7BAF1459EB728860DD709F
671B81004FDD1588FA9ED1331C9CECA9
had some problems cuz my pc is getting slower –anyway just downloading windows all in one now–so I have to close everything, but I'll be back, thanks!!
ok so I fudged my way thru, and I guess it worked cuz I got thru it—my computor is a little faster, It still has probs loading images, mostly on facebook—what should I delete from my desktop as it is scattered with a couple dozen icons? I think I should keep the malware programs, but delete the logs, is that right? anything I should keep for later, please let me know. Thanks for all your help, I do think my computor is faster!!
Keep the Malwarebytes program and run a scan every once in a while, we need to remove the rest

You can delete the FRST, JRT, and windows repair tool logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Press the WinKey +R to open a run box
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

  • Double click on adwcleaner.exe to run the tool.
  • Click on Uninstall.
  • Confirm with yes.


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    PC Safety and Security–What Do I Need?.
  • Simple and easy ways to keep your computer safe and secure on the Internet

Thank you for your patience, and performing all of the procedures requested.



As for the problems loading images, make sure your Java and Flash programs are totally up to date, if you still have problems loading images, start a new topic in our browsers forum
http://forums.whatthetech.com/index.php?showforum=123

link back to let them know what we have done here

hopefully the expert techs we have there will be able to resolve the issue
you still have not told me what a WinKey is..? I've looked all over my keyboard and do not see a key with Win on it.please advise

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI