This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

popup usually on restart [Solved]

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This has been plaguing me for a month or two. Can't remember what I did just previously that it might have come along with.

It's a very large popup, window titled "Sponsorship" or somesuch.

URL is:

http://m.bingoodthingshappen.com/t/?ilmernzkvt

azn=001D098C2B9125D4&pu=&s=D-iexplore&nm

=ilmernzkvtazn&t=


I think sometimes it is a different URL

I'm assuming this is malwarel; have run a couple of scans but nothing shows up.
There are some online references to this sort of thing, but no real help getting rid of it.
(Couldn't winkle it out of the forum by searching)

Thanks,
denno
Hello, Denno . Welcome to WTT Forums.

My name is fbfbfb.

I will gladly assist you with your malware concerns. Malware logs may require some time to analyze, and because there is no quick-fix solution, we may need to use various approaches to clean your system. Please be patient.

While working to resolve the issues with your machine, please note the following guidelines:
  • Read and follow my directions carefully, in the sequence they are posted.
  • If you are unsure about anything, please ask for clarification before continuing.
  • To avoid potential problems and setbacks, do not:

  • install or uninstall any applications while your system is being cleaned.
  • use any tools other than those recommended.
  • run any other scans without being directed to do so.

  • Copy and Paste the log files inside your posts. Do not send them as attachments unless otherwise instructed.
  • Stay with this thread until your machine has been deemed all clear. Absence of symptoms does not mean your system is clear.
  • Please reply within 3 days of each posting to avoid closing this topic. If you need more time to complete tasks, or if you will be away, please let me know in advance.
Please run the following scans

1. DDS

Please download DDS from HERE. Click Save File. The file will save to your default location.
  • Disable any script blocking protection. (How to Temporarily Disable Security Programs: Anti-virus/Anti-spyware/Firewall)
  • Double click dds.com > Click Run.
  • At the next prompt, ensure check marks appear next to dds.com and attach.txt > Click Start to begin the scan. When done, click OK to close the DDS window.
  • Two reports will automatically open: dds.txt and Attach.txt. These reports are also saved to your desktop.
Please copy and paste the scan results of DDS.txt.

Please attach the second file: Attach.txt.

To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on [external image: Posted Image] to insert the attachment into your post.
2. aswMBR

Please download aswMBR from HERE.
  • Double click aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions, please select Yes.
  • Click the Scan button to start the scan.
[external image: Posted Image]
  • On completion of the scan, click save log, save it to your desktop, and post in your next reply.
[external image: Posted Image]

3. Security Check

Please download Security Check from HERE or HERE.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt. This may take a few minutes.
Please copy and paste the contents of that document into your next reply.
That was fast! So this is not one of the known-specific-removal dealies, eh? OK, I will get on these scans sometime today or tonight, and thanks. denno
Hello, denno. No problem, I'll wait for your logs. When it comes to malware, we need to take an in depth look at your computer to locate the problem, see how infected your system is, and apply the best solutions to ensure your machine is in good working order. This can take some time, but we try to resolve issues as efficiently as possible.
OK, and understood. Here are the first results. If you don't mind, I am going to paste the Attach file in here, as the attachment process seems to be confusing me. DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.25.2 Run by [removed] at 12:45:47 on 2013-08-01 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.329 [GMT -4:00] . AV: Microsoft Security Essentials Prerelease *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes ================ . c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE C:\Program Files\Fighters\Tray\FightersTray.exe C:\Program Files\Fighters\SPAMfighter\sfagent.exe C:\Program Files\PDF24\pdf24.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Microsoft Office\Office\FINDFAST.EXE C:\Program Files\IDrive\IDriveE Service.exe C:\Program Files\Java\jre7\bin\jqs.exe C:\Program Files\Fighters\SPAMfighter\sfus.exe C:\Program Files\Fighters\FighterSuiteService.exe C:\WINDOWS\System32\alg.exe C:\Program Files\IDrive\IDriveETray.exe C:\Program Files\IDrive\IDriveEBackground.exe C:\Program Files\IDrive\IDrivePlugin.exe C:\Program Files\azzCardfile\azzCardfile.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\azzCardfile\azzCardfile.exe C:\Program Files\IDrive\IDriveEClsClient.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\WINDOWS\explorer.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Google\Chrome\Application\chrome.exe c:\Program Files\Microsoft Security Client\MpCmdRun.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\System32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\System32\svchost.exe -k LocalService C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\system32\svchost.exe -k netsvcs . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com mStart Page = hxxp://www.google.com uProxyOverride = BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [IDriveE Startup] "c:\program files\idrive\IDrvieEStartup.exe" Hide uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [EPSON Stylus Photo RX620 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9HA.EXE /P31 "EPSON Stylus Photo RX620 Series" /O6 "USB001" /M "Stylus Photo RX620" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [CommonToolkitTray] c:\program files\fighters\tray\FightersTray.exe mRun: [sfagent] c:\program files\fighters\spamfighter\sfagent.exe mRun: [PDFPrint] c:\program files\pdf24\pdf24.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_11_7_700_224_ActiveX.exe -update activex StartupFolder: c:\docume~1\denno\startm~1\programs\startup\idrive~1.lnk - c:\program files\idrive\IDriveEReg2ini.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office\FINDFAST.EXE uPolicies-Explorer: NoDriveTypeAutoRun = dword:323 uPolicies-Explorer: NoDriveAutoRun = dword:67108863 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 mPolicies-Explorer: NoDriveTypeAutoRun = dword:323 mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:323 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1361254869718 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: NameServer = 64.22.32.8 64.22.32.9 TCP: Interfaces\{6C210370-FF0F-404C-A510-43343D733ACB} : DHCPNameServer = [removed] [removed] Notify: igfxcui - igfxdev.dll mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\28.0.1500.95\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\denno\application data\mozilla\firefox\profiles\2q6v47jq.default-1369105918343\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll FF - plugin: c:\program files\foxit software\foxit reader\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_202.dll . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-11-7 211560] R2 IDriveE Service;IDriveE Service;c:\program files\idrive\IDriveE Service.exe [2013-2-26 157128] R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\fighters\spamfighter\sfus.exe [2013-4-29 216608] R2 Suite Service;Suite Service;c:\program files\fighters\FighterSuiteService.exe [2012-11-12 1270376] . =============== Created Last 30 ================ . 2013-07-31 21:39:19 7143960 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ad3424c1-7af1-45e6-b9fa-04c7ed420150}\mpengine.dll 2013-07-30 21:39:03 7143960 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2013-07-04 03:25:21 144896 —-a-w- c:\windows\system32\javacpl.cpl 2013-07-04 03:25:17 94632 —-a-w- c:\windows\system32\WindowsAccessBridge.dll . ==================== Find3M ==================== . 2013-07-04 03:25:02 867240 —-a-w- c:\windows\system32\npDeployJava1.dll 2013-07-04 03:25:02 789416 —-a-w- c:\windows\system32\deployJava1.dll 2013-06-19 01:50:08 211560 —-a-w- c:\windows\system32\drivers\MpFilter.sys 2013-06-12 09:50:08 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-06-12 09:50:08 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-06-08 03:55:44 385024 ——w- c:\windows\system32\html.iec 2013-06-07 21:56:06 920064 —-a-w- c:\windows\system32\wininet.dll 2013-06-07 21:56:06 43520 ——w- c:\windows\system32\licmgr10.dll 2013-06-07 21:56:05 1469440 ——w- c:\windows\system32\inetcpl.cpl 2013-06-04 07:23:02 562688 —-a-w- c:\windows\system32\qedit.dll 2013-06-04 01:40:45 1876736 —-a-w- c:\windows\system32\win32k.sys 2003-04-25 10:32:56 1562624 —-a-w- c:\program files\AZZ Cardfile.exe . ============= FINISH: 12:46:17.45 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 2/18/2013 6:13:22 PM System Uptime: 7/27/2013 5:27:16 PM (115 hours ago) . Motherboard: Dell Inc. | | 0CU409 Processor: Intel® Pentium® Dual CPU E2180 @ 2.00GHz | Socket 775 | 1994/200mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 298 GiB total, 238.198 GiB free. D: is FIXED (NTFS) - 233 GiB total, 195.91 GiB free. F: is CDROM () G: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP1: 7/1/2013 10:35:30 AM - System Checkpoint RP2: 7/1/2013 10:24:19 PM - Software Distribution Service 3.0 RP3: 7/2/2013 12:27:22 AM - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 RP4: 7/2/2013 10:24:31 PM - Software Distribution Service 3.0 RP5: 7/3/2013 10:23:54 PM - Software Distribution Service 3.0 RP6: 7/3/2013 11:24:37 PM - Removed Java 7 Update 17 RP7: 7/3/2013 11:24:58 PM - Installed Java 7 Update 25 RP8: 7/4/2013 11:27:15 PM - Software Distribution Service 3.0 RP9: 7/5/2013 11:26:54 PM - Software Distribution Service 3.0 RP10: 7/6/2013 11:54:09 PM - System Checkpoint RP11: 7/7/2013 2:22:13 AM - Software Distribution Service 3.0 RP12: 7/7/2013 8:01:19 AM - Software Distribution Service 3.0 RP13: 7/24/2013 11:41:41 PM - Software Distribution Service 3.0 RP14: 7/25/2013 11:42:45 PM - System Checkpoint RP15: 7/25/2013 11:50:47 PM - Software Distribution Service 3.0 RP16: 7/26/2013 11:50:50 PM - Software Distribution Service 3.0 RP17: 7/27/2013 4:53:10 PM - Software Distribution Service 3.0 RP18: 7/28/2013 2:27:34 AM - Software Distribution Service 3.0 RP19: 7/28/2013 5:39:09 PM - Software Distribution Service 3.0 RP20: 7/29/2013 5:38:38 PM - Software Distribution Service 3.0 RP21: 7/30/2013 5:38:59 PM - Software Distribution Service 3.0 RP22: 7/31/2013 5:39:14 PM - Software Distribution Service 3.0 . ==== Installed Programs ====================== . Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Photoshop 7.0 Adobe Reader XI (11.0.03) Akamai NetSession Interface Audacity 2.0.3 azzCardfile 4.1 BitLord 2.3 Core FTP LE Dell Resource CD DRIVERfighter EPSON Printer Software EPSON Scan FFmpeg v0.6.2 for Audacity Foxit Reader FreeRIP 4.1.1 Google Chrome Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB2779562) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) IDrive version 3.4.1 January 03, 2012 Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections 12.1.12.0 Java 7 Update 25 Java Auto Updater LAME v3.99.3 (for Windows) Malwarebytes Anti-Malware version 1.75.0.1300 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Office 97, Professional Edition Microsoft Security Client Microsoft Security Essentials Prerelease Microsoft Silverlight Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Microsoft Works 6-9 Converter Mozilla Firefox 21.0 (x86 en-US) Mozilla Maintenance Service OpenOffice.org 3.4.1 PDF24 Creator 5.5.1 Realtek High Definition Audio Driver Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2744842) Security Update for Windows Internet Explorer 8 (KB2792100) Security Update for Windows Internet Explorer 8 (KB2797052) Security Update for Windows Internet Explorer 8 (KB2809289) Security Update for Windows Internet Explorer 8 (KB2817183) Security Update for Windows Internet Explorer 8 (KB2829530) Security Update for Windows Internet Explorer 8 (KB2838727) Security Update for Windows Internet Explorer 8 (KB2846071) Security Update for Windows Internet Explorer 8 (KB2847204) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB2803821) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2655992) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2691442) Security Update for Windows XP (KB2698365) Security Update for Windows XP (KB2705219-v2) Security Update for Windows XP (KB2712808) Security Update for Windows XP (KB2719985) Security Update for Windows XP (KB2723135-v2) Security Update for Windows XP (KB2727528) Security Update for Windows XP (KB2753842-v2) Security Update for Windows XP (KB2757638) Security Update for Windows XP (KB2758857) Security Update for Windows XP (KB2770660) Security Update for Windows XP (KB2778344) Security Update for Windows XP (KB2780091) Security Update for Windows XP (KB2792100) Security Update for Windows XP (KB2797052) Security Update for Windows XP (KB2799494) Security Update for Windows XP (KB2802968) Security Update for Windows XP (KB2807986) Security Update for Windows XP (KB2808735) Security Update for Windows XP (KB2813170) Security Update for Windows XP (KB2813345) Security Update for Windows XP (KB2820197) Security Update for Windows XP (KB2820917) Security Update for Windows XP (KB2829361) Security Update for Windows XP (KB2834886) Security Update for Windows XP (KB2839229) Security Update for Windows XP (KB2845187) Security Update for Windows XP (KB2850851) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982665) SPAMfighter Update for Audio Converter Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB2598845) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2661254-v2) Update for Windows XP (KB2736233) Update for Windows XP (KB2749655) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB973815) WebFldrs XP Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows PowerShell™ 1.0 Windows XP Service Pack 3 . ==== Event Viewer Messages From Past Week ======== . 7/27/2013 4:29:45 PM, error: Dhcp [1002] - The IP address lease 192.168.172.52 for the Network Card with network address 001D098C2B91 has been denied by the DHCP server 192.168.172.1 (The DHCP Server sent a DHCPNACK message). . ==== End Of File ===========================
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-08-01 19:41:14 —————————– 19:41:14.250 OS Version: Windows 5.1.2600 Service Pack 3 19:41:14.250 Number of processors: 2 586 0xF0D 19:41:14.250 ComputerName: SHERIFFJOHN UserName: Denno 19:41:15.703 Initialize success 19:49:30.062 AVAST engine defs: 13080101 19:50:53.656 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 19:50:53.656 Disk 0 Vendor: WDC_WD3200AAKS-75L9A0 01.03E01 Size: 305245MB BusType: 3 19:50:53.656 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-1b 19:50:53.671 Disk 1 Vendor: WDC_WD2500AAJS-75VWA0 12.01B02 Size: 238418MB BusType: 3 19:50:53.875 Disk 0 MBR read successfully 19:50:53.875 Disk 0 MBR scan 19:50:53.953 Disk 0 Windows XP default MBR code 19:50:53.953 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 305234 MB offset 63 19:50:53.953 Disk 0 scanning sectors +625121280 19:50:54.125 Disk 0 scanning C:\WINDOWS\system32\drivers 19:51:01.375 Service scanning 19:51:15.765 Modules scanning 19:51:23.296 Disk 0 trace - called modules: 19:51:23.328 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys 19:51:23.328 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86519ab8] 19:51:23.328 3 CLASSPNP.SYS[f7633fd7] -> nt!IofCallDriver -> \Device\0000005c[0x8658df18] 19:51:23.328 5 ACPI.sys[f74ca620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x86522940] 19:51:25.750 AVAST engine scan C:\WINDOWS 19:51:41.500 AVAST engine scan C:\WINDOWS\system32 19:53:40.421 AVAST engine scan C:\WINDOWS\system32\drivers 19:53:54.921 AVAST engine scan C:\Documents and Settings\Denno 20:10:15.109 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Denno\Desktop\MBR.dat" 20:10:15.109 The log file has been saved successfully to "C:\Documents and Settings\Denno\Desktop\aswMBR.txt"
Results of screen317's Security Check version 0.99.71
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials Prerelease
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 25
Adobe Flash Player 11.7.700.224
Adobe Reader XI
Mozilla Firefox 21.0 Firefox out of Date!
Google Chrome 28.0.1500.72
Google Chrome 28.0.1500.95
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 30% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
Hello, denno.

Thank you for your logs. While I review the contents, please provide me with the following additional information which may assist me in resolving your issue:
  • When the pop-up occurs, which site(s) are you visiting?
  • Exactly when does the pop-up occur – during browsing? after closing your browser?
  • What is the main browser you use, and does the pop-up occur only with this browser or in all browsers?
  • Please look through the list of installed programs. Did you knowingly install Akamai NetSession Interface , or was this installed without your approval?
Hello fbfbfb, Pop-up shows up on my desktop. I don't associate it with any site. Several times it has been there when I have been away from my desk for quite some time. I am using Chrome exclusively at this time. Firefox kept crashing. If I have Akamai NetSession Interface, whatever it is, I didn't install it on purpose; possibly I missed an uncheck-box while I was installing something else.
Hello, denno.

Thank you for your logs. DDS does not show any entries related to the pop-up. We'll run a couple of other scans, but first, I would like to bring the following to your attention:

Akamai NetSession Interface

Apparently, this program is automatically installed when you update Adobe Flash Player. It would have been noted in the fine print of the agreement which you obviously missed. It's purpose is to improve the speed and efficiency for downloads and streams. It may or may not cause problems, but since you did not purposely install the program, let's remove it via your Control Panel.
  • To uninstall, click Start > Control Panel > Add or Remove Programs. A list of currently installed programs will be displayed.
  • Scroll down the list and locate Akamai NetSession Interface. Click on it once to highlight it. > Click on the Remove button.
  • If you are prompted to re-boot your computer to complete the uninstall, please do so.
P2P Program

I see you have P2P software (BitLord 2.3 ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation.

Please note: Even if you are using a safe P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

Please see this topic for more information: Perils of P2P File Sharing.

I would strongly recommend that you uninstall this now. You can do so via Control Panel > Add or Remove Programs.

Please run the following scans

1. Rogue Killer

Please download Rogue Killer from HERE.
  • Quit all running programs before continuing.
  • Double-click roguekiller.exe to run it.
  • Wait for the Prescan to finish.
  • Click Scan and wait for the scan to complete.
  • A report will be created and saved on your desktop.
  • Exit the program.
Copy and paste the RKreport.txt report into your next reply.

2. C omboFix

Note: Before you begin, please read through these instructions completely, noting all important messages and warnings.
  • Please download ComboFix from HERE or HERE.
Very Important! Save ComboFix.exe to to your Desktop.
  • Close all browsers.
  • Disable your AntiVirus and AntiSpyware applications as they can interfere with running ComboFix. To disable any security programs:

  • Right click on the System Tray icon, or
  • Refer to this link HERE for further assistance.

  • Double click on ComboFix.exe and follow the prompts. ComboFix will automatically check to see if the Microsoft Windows Recovery Console is installed.

Note:

  • If Combofix asks you to install the Microsoft Windows Recovery Console, please allow it.
  • If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • When prompted, agree to the End-User License Agreement to begin installation.
  • If ComboFix asks you to update the program, please do so.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, ComboFix will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Warnings:
  • Do not mouse-click on ComboFix's window while it is running. This may cause it to stall.
  • Do not re-run ComboFix. If problems occur with the installation or running of ComboFix, please reply back for further instructions.
  • Do not attempt to surf the internet while ComboFix is scanning.

Note: If there is no internet connection after running ComboFix, reboot your computer to restore the connection.

Very Important! Make sure you re-enable your security programs when ComboFix is finished.

CHECKLIST: In your next reply, please post the following:
  • RKreport.txt
  • C:\ComboFix.txt
OK, hello again fbfbfb,

I have removed Akamai, and taken your advice and removed the P2P program.
Other scans as follows:

RogueKiller V8.6.4 [Jul 29 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Denno [Admin rights]
Mode : Scan – Date : 08/02/2013 18:59:15
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 15 ¤¤¤
[HJ POL] HKCU\[…]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[EXT RUN][SUSP PATH] HKLM\ON_D:\[…]\Run : osvjiscs (C:\Documents and Settings\Miekro S. Dallalio\Local Settings\Application Data\lcmchkknb\ldkymvatssd.exe [x][x][x]) -> FOUND
[EXT RUN][Microsoft] HKLM\ON_D:\[…]\Run : conhost (C:\Documents and Settings\Miekro S. Dallalio\Application Data\Microsoft\conhost.exe [x][x][x]) -> FOUND
[EXT RUN][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\Run : osvjiscs (C:\Documents and Settings\Miekro S. Dallalio\Local Settings\Application Data\lcmchkknb\ldkymvatssd.exe [x][x][x]) -> FOUND
[EXT RUNONCE][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\RunOnce : SpybotDeletingB3989 (command /c del "C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll" [x][x]) -> FOUND
[EXT RUNONCE][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\RunOnce : SpybotDeletingD3132 (cmd /c del "C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll" [x]) -> FOUND
[EXT RUNONCE][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\RunOnce : SpybotDeletingB9677 (command /c del "C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll" [x][x]) -> FOUND
[EXT RUNONCE][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\RunOnce : SpybotDeletingD3229 (cmd /c del "C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll" [x]) -> FOUND
[EXT RUNONCE][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\RunOnce : SpybotDeletingB4540 (command /c del "C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat" [x][x]) -> FOUND
[EXT RUNONCE][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\RunOnce : SpybotDeletingD7927 (cmd /c del "C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat" [x]) -> FOUND
[EXT RUNONCE][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\RunOnce : SpybotDeletingB3959 (command /c del "C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe" [x][x]) -> FOUND
[EXT RUNONCE][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\RunOnce : SpybotDeletingD6349 (cmd /c del "C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe" [x]) -> FOUND
[EXT RUNONCE][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\RunOnce : SpybotDeletingB4964 (command /c del "C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico" [x][x]) -> FOUND
[EXT RUNONCE][SUSP PATH] HKCU\Miekro S. Dallalio_ON_D:\[…]\RunOnce : SpybotDeletingD7948 (cmd /c del "C:\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico" [x]) -> FOUND

¤¤¤ Scheduled tasks : 1 ¤¤¤
[V1][SUSP PATH] At1.job : C:\DOCUME~1\Denno\APPLIC~1\DSite\UPDATE~1\UPDATE~1.EXE - /Check [-] -> FOUND

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤
-> D:\windows\system32\config\SOFTWARE | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\windows\system32\config\SECURITY | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\windows\system32\config\SAM | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\windows\system32\config\DEFAULT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\Documents and Settings\Administrator\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\Documents and Settings\All Users\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
-> D:\Documents and Settings\Default User\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\Documents and Settings\LocalService\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\Documents and Settings\Miekro S. Dallalio\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]
-> D:\Documents and Settings\MIEKRO~1\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - NOT_FOUND]
-> D:\Documents and Settings\NetworkService\NTUSER.DAT | DRVINFO [Drv - D:] | SYSTEMINFO [Sys - C:] [Sys32 - FOUND] | USERINFO [Startup - FOUND]

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD3200AAKS-75L9A0 +++++
— User —
[MBR] accb30a41c33313d17a209cc74f8e0cf
[BSP] 40f6ad6c64f9c9cb6ff24dbfee9c02ff : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 305234 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive1: WDC WD3200AAKS-75L9A0 +++++
— User —
[MBR] fffdbaa954ea7a3c6e3f84050e6ed7dc
[BSP] ae203e84dcb456630d870d8f3155a2b5 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 47 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 96390 | Size: 238355 Mo
User = LL1 … OK!
User = LL2 … OK!

+++++ PhysicalDrive2: WDC WD3200AAKS-75L9A0 +++++
— User —
[MBR] 56f7fd06e486eb4d7b77162db1ba1249
[BSP] 7208b105e661849d4a48c279d3177d8d : Empty MBR Code
Partition table:
0 - [XXXXXX] FAT16 (0x06) [VISIBLE] Offset (sectors): 249 | Size: 1938 Mo
User = LL1 … OK!
Error reading LL2 MBR!

Finished : << RKreport[0]_S_08022013_185915.txt >>


——————————————————————————————————————————————————————-

ComboFix 13-08-02.01 - Denno 08/02/2013 19:11:44.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.500 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials Prerelease *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Denno\My Documents\~WRL0282.tmp
c:\documents and settings\Denno\My Documents\~WRL2621.tmp
c:\documents and settings\Denno\My Documents\~WRL3536.tmp
C:\Install.exe
c:\windows\offitems.log
c:\windows\system32\dllcache\wmpvis.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-07-02 to 2013-08-02 )))))))))))))))))))))))))))))))
.
.
2013-08-02 22:57 . 2013-08-02 22:57 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{24C709C0-5273-4ACA-80D7-B93CC991E433}\MpKsle75ba3d5.sys
2013-08-02 00:14 . 2013-07-02 06:54 7143960 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{24C709C0-5273-4ACA-80D7-B93CC991E433}\mpengine.dll
2013-08-01 16:52 . 2013-07-02 06:54 7143960 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-07-04 03:25 . 2013-07-04 03:25 144896 —-a-w- c:\windows\system32\javacpl.cpl
2013-07-04 03:25 . 2013-07-04 03:25 94632 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-07-04 03:24 . 2013-07-04 03:24 ——– d—–w- c:\program files\Java
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-04 03:25 . 2013-04-08 15:08 789416 —-a-w- c:\windows\system32\deployJava1.dll
2013-07-04 03:25 . 2013-04-08 15:08 867240 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-06-19 01:50 . 2012-11-07 18:53 211560 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2013-06-12 09:50 . 2013-02-20 05:17 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-12 09:50 . 2013-02-20 05:17 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-08 03:55 . 2013-02-19 05:59 385024 ——w- c:\windows\system32\html.iec
2013-06-07 21:56 . 2003-07-16 20:51 920064 —-a-w- c:\windows\system32\wininet.dll
2013-06-07 21:56 . 2003-07-16 20:32 43520 ——w- c:\windows\system32\licmgr10.dll
2013-06-07 21:56 . 2003-07-16 20:30 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-06-04 07:23 . 2003-07-16 20:42 562688 —-a-w- c:\windows\system32\qedit.dll
2013-06-04 01:40 . 2003-07-16 20:51 1876736 —-a-w- c:\windows\system32\win32k.sys
2003-04-25 10:32 . 2013-02-24 03:15 1562624 —-a-w- c:\program files\AZZ Cardfile.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDriveE Startup"="c:\program files\IDrive\IDrvieEStartup.exe" [2011-06-24 185800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 995176]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-17 138008]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-26 16132608]
"EPSON Stylus Photo RX620 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE" [2004-05-20 98304]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"CommonToolkitTray"="c:\program files\Fighters\Tray\FightersTray.exe" [2013-03-11 1425952]
"sfagent"="c:\program files\Fighters\SPAMfighter\sfagent.exe" [2013-04-29 1065504]
"PDFPrint"="c:\program files\PDF24\pdf24.exe" [2013-05-31 162856]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil32_11_7_700_224_ActiveX.exe" [2013-06-12 814472]
.
c:\documents and settings\Denno\Start Menu\Programs\Startup\
IDrive Tray.lnk - c:\program files\IDrive\IDriveEReg2ini.exe 2 [2013-2-26 311296]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2013-4-10 113664]
Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-7-11 111376]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Shortcut Bar.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office Shortcut Bar.lnk
backup=c:\windows\pss\Microsoft Office Shortcut Bar.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Office Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
backup=c:\windows\pss\Office Startup.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Denno^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk]
path=c:\documents and settings\Denno\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.4.1.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 10:42 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WS_FTP Pro\\ftp95pro.exe"=
.
R1 MpKsle75ba3d5;MpKsle75ba3d5;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{24C709C0-5273-4ACA-80D7-B93CC991E433}\MpKsle75ba3d5.sys [8/2/2013 6:57 PM 29904]
R2 IDriveE Service;IDriveE Service;c:\program files\IDrive\IDriveE Service.exe [2/26/2013 4:38 PM 157128]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\Fighters\SPAMfighter\sfus.exe [4/29/2013 10:48 AM 216608]
R2 Suite Service;Suite Service;c:\program files\Fighters\FighterSuiteService.exe [11/12/2012 1:47 PM 1270376]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6/3/2013 12:47 AM 116648]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [6/3/2013 12:47 AM 116648]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLE75BA3D5
*NewlyCreated* - TRUESIGHT
*Deregistered* - TrueSight
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-07-31 19:47 1173456 —-a-w- c:\program files\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-08-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-20 09:50]
.
2013-08-02 c:\windows\Tasks\DRIVERfighter Auto Start.job
- c:\program files\Fighters\DRIVERfighter\DRIVERfighter.exe [2012-12-11 19:32]
.
2013-08-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-06-03 04:46]
.
2013-08-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-06-03 04:46]
.
2013-08-02 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-06-20 22:05]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride =
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Denno\Application Data\Mozilla\Firefox\Profiles\2q6v47jq.default-1369105918343\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL -
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Akamai NetSession Interface - c:\documents and settings\Denno\Local Settings\Application Data\Akamai\netsession_win.exe
AddRemove-{501451DE-5808-4599-B544-8BD0915B6B24}_is1 - c:\program files\FreeRIP\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-08-02 19:20
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,5a,e9,e0,a8,59,46,f8,47,a5,ff,59,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,5a,e9,e0,a8,59,46,f8,47,a5,ff,59,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-08-02 19:21:58
ComboFix-quarantined-files.txt 2013-08-02 23:21
.
Pre-Run: 260,078,616,576 bytes free
Post-Run: 261,351,497,728 bytes free
.
- - End Of File - - E9D7AC98ED7ED189B996F08F1ECC62B8
8F558EB6672622401DA993E1E865C861
Hello, denno.

Sorry for the delay. Thank you for the RogueKiller log.

Please run the following scans

1. AdwCleaner

Please download AdwCleaner from HERE.
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on the Delete button.
  • A logfile will automatically open after the scan has finished.
  • You can also find the logfile at C:\AdwCleaner[S1].txt.
Copy and paste the adwcleaner.txt report into your next reply.

2. Junkware Removal Tool

Please download Junkware Removal Tool from HERE and save it to your desktop.
  • Shutdown your antivirus to avoid any potential conflicts.
  • Right-mouse click JRT.exe and select Run as Administrator.
  • JRTwill begin to backup your registry and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, the log JRT.txt is saved on your desktop and will automatically open.
Post the contents of JRT.txt into your next reply.

3. Malwarebytes Anti-Malware

I see you have Malwarebytes installed on your system. Please run a fresh scan and send me the log.

CHECKLIST: In your next reply, please post the following:
  • adwcleaner.txt
  • JRT.txt
  • MBAM log
  • Let me know how your computer is running and if the pop-up is still present.
Hello fbfbfb, No problem with any delays. I appreciate your time and help. Now, then, MBAM ran today for about 4-1/2 hours, must have been almost all the way through (detected 3 objects), and "encountered a problem and had to close" apparently without finishing or producing a log. Shall I run it again? I'll do it overnight this time. Haven't seen the pop-up, but hard to proove a negative, of course. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.3.2 (08.03.2013:1) OS: Microsoft Windows XP x86 Ran by [removed] on Sun 08/04/2013 at 10:15:27.56 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully stopped: [Service] spamfighter update service Successfully deleted: [Service] spamfighter update service Failed to stop: [Service] suite service ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\commontoolkittray ~~~ Registry Keys ~~~ Files Successfully deleted: [File] C:\eula.1028.txt Successfully deleted: [File] C:\eula.1031.txt Successfully deleted: [File] C:\eula.1033.txt Successfully deleted: [File] C:\eula.1036.txt Successfully deleted: [File] C:\eula.1040.txt Successfully deleted: [File] C:\eula.1041.txt Successfully deleted: [File] C:\eula.1042.txt Successfully deleted: [File] C:\eula.2052.txt Successfully deleted: [File] C:\install.res.1028.dll Successfully deleted: [File] C:\install.res.1031.dll Successfully deleted: [File] C:\install.res.1033.dll Successfully deleted: [File] C:\install.res.1036.dll Successfully deleted: [File] C:\install.res.1040.dll Successfully deleted: [File] C:\install.res.1041.dll Successfully deleted: [File] C:\install.res.1042.dll Successfully deleted: [File] C:\install.res.2052.dll Successfully deleted: [File] C:\install.res.3082.dll ~~~ Folders Failed to delete: [Folder] "C:\Documents and Settings\All Users\application data\fighters" Failed to delete: [Folder] "C:\Documents and Settings\Denno\Application Data\fighters" Failed to delete: [Folder] "C:\Program Files\fighters" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sun 08/04/2013 at 10:18:36.07 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ad-cleaner: # AdwCleaner v2.306 - Logfile created 08/04/2013 at 03:37:22 # Updated 19/07/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Denno - SHERIFFJOHN # Boot Mode : Normal # Running from : C:\Documents and Settings\Denno\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Documents and Settings\Denno\Application Data\DSite Folder Deleted : C:\Documents and Settings\Denno\Start Menu\Programs\FreeRIP ***** [Registry] ***** Key Deleted : HKCU\Software\InstallCore Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Mozilla Firefox v21.0 (en-US) File : C:\Documents and Settings\Denno\Application Data\Mozilla\Firefox\Profiles\2q6v47jq.default-1369105918343\prefs.js [OK] File is clean. -\\ Google Chrome v28.0.1500.95 File : C:\Documents and Settings\Denno\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [1423 octets] - [04/08/2013 03:37:22] ########## EOF - C:\AdwCleaner[S1].txt - [1483 octets] ##########
Hello, denno.

Thank you for the JRT and AdwCleaner logs.

Malwarebytes Issue
  • MBAM will automatically saves a copy of its log. Open Malwarebytes and click the log tab to see if anything is there.
  • If no log has been saved, please run MBAM in Safe Mode.
  • If MBAM is still problematic, please delete MBAM from your computer, download a fresh copy, and then try scanning your system again.
Safe Mode

Using the F8 Method as an option:
  • Restart your computer.
  • Gently tap the F8 key repeatedly until the Windows XP Advanced Options menu appears.

Note: If Windows launches before you can choose Safe Mode, restart your computer and try again.

  • Select the Safe Mode option using the up and down arrow keys.
  • Then, press the enter key on your keyboard to boot into Safe Mode.
[external image: Posted Image]

Note: When tasks have been completed, reboot your computer to normal mode.

Malwarebytes Anti-Malware

Please download Malwarebytes from Here or Here.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan
.[external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

Post the report please.
OK—here is an MBAM log. Dunno if it is the recent one, tho' dated today. Seems last I looked at the scan in progress, it was up to 350K objects scanned, and was reporting 3 objects found so far, and was already over 4 hours. After that is the log produced after removing MBAM and re-installing it and running the quick scan and removal of 3 objects. Couple questions: —first time around did you mean for me to do a full scan? —the D drive is pretty passive; a former HD that I've mined for some files; and I think there is maybe one program (Gold Wave, possibly?) that I couldn't transfer to the C drive so I have run it out of D. I could probably remove or wipe it by now. At any rate, is there much/any chance of its becoming infected, or would that be contained to the actively uses C drive? —I take it that when I downloaded the font Signature, something rode along with it? Why doesn't my realtime protection catch that sort of thing? How do I know if such downloads are safe? (I do have WOT now). Thanks, denno Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.07.03.05 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Denno :: SHERIFFJOHN [administrator] 7/4/2013 11:06:22 AM mbam-log-2013-07-04 (11-06-22).txt Scan type: Full scan (C:\|D:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 540823 Time elapsed: 4 hour(s), 1 minute(s), 13 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ================================================================================ ======== Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.08.05.01 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Denno :: SHERIFFJOHN [administrator] 8/4/2013 10:25:37 PM mbam-log-2013-08-04 (22-25-37).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 200447 Time elapsed: 3 minute(s), 47 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 3 C:\Documents and Settings\Denno\My Documents\Downloads\Signature_downloader_by_Fonts101(1).exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully. C:\Documents and Settings\Denno\My Documents\Downloads\Signature_downloader_by_Fonts101.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully. C:\Documents and Settings\Denno\My Documents\Downloads\7ZipSetup-drQlTjQ.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully. (end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI