This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with win32.downloader.gen [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.21.2 Run by [removed] at 0:08:00 on 2013-08-18 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.139 [GMT -6:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: avast! Antivirus *Disabled* . ============== Running Processes ================ . C:\WINDOWS\system32\ibmpmsvc.exe C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\tp4mon.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\AVAST Software\Avast\avastUI.exe C:\Program Files\Ask.com\Updater\Updater.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre7\bin\jqs.exe C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\Zoom\TpScrex.exe C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\WINDOWS\explorer.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe C:\Program Files\Application Updater\ApplicationUpdater.exe C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe C:\Documents and Settings\Owner\Application Data\Slick Savings\CouponsHelper.exe C:\Program Files\Vuze\Azureus.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k bthsvcs C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\svchost.exe -k HTTPFilter . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.yahoo.com?type=994519&fr=spigot-yhp-ie uURLSearchHooks: Vuze Remote Toolbar: {05478A66-EDB6-4A22-A870-A5987F80A7DA} - c:\program files\vuze remote toolbar\ie\7.4\vuzeToolbarIE.dll uURLSearchHooks: TrustWorthy Toolbar: {8480b7b1-a45c-4feb-8653-60f834f7ca4b} - c:\program files\trustworthy\prxtbTrus.dll BHO: Vuze Remote Toolbar: {05478A66-EDB6-4A22-A870-A5987F80A7DA} - c:\program files\vuze remote toolbar\ie\7.4\vuzeToolbarIE.dll BHO: Slick Savings: {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - c:\documents and settings\owner\application data\slick savings\Coupons.dll BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: TrustWorthy Toolbar: {8480b7b1-a45c-4feb-8653-60f834f7ca4b} - c:\program files\trustworthy\prxtbTrus.dll BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - TB: TrustWorthy Toolbar: {8480b7b1-a45c-4feb-8653-60f834f7ca4b} - c:\program files\trustworthy\prxtbTrus.dll TB: Vuze Remote Toolbar: {05478A66-EDB6-4A22-A870-A5987F80A7DA} - c:\program files\vuze remote toolbar\ie\7.4\vuzeToolbarIE.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [ConduitFloatingPlugin_dkjaldeegndmngnahlmdbfnejdobkmil] "c:\windows\system32\rundll32.exe" "c:\program files\conduit\ct3309758\plugins\TBVerifier.dll",RunConduitFloatingPlugin dkjaldeegndmngnahlmdbfnejdobkmil uRun: [Slick Savings] "c:\documents and settings\owner\application data\slick savings\CouponsHelper.exe" mRun: [TrackPointSrv] tp4mon.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [LenovoAutoScrollUtility] c:\program files\lenovo\virtscrl\virtscrl.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe" mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe" mRunOnce: [SpUninstallCleanUp] REG delete HKEY_CURRENT_USER\Software\SearchProtect /f StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1301095190906 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab TCP: NameServer = 8.8.8.8 8.8.4.4 66.62.161.193 TCP: Interfaces\{A2775735-E1D5-4F8B-B582-2CE294A0DA14} : DHCPNameServer = 8.8.8.8 8.8.4.4 [removed] Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\28.0.1500.95\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\6o41ph79.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3309758&CUI=UN14806301332351523&UM=2&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxp://search.yahoo.com?type=994519&fr=spigot-yhp-ff FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=994519&p= FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_202.dll FF - plugin: c:\windows\system32\npdeployJava1.dll FF - plugin: c:\windows\system32\npptools.dll FF - ExtSQL: 2013-08-17 23:52; [removed]; c:\documents and settings\owner\application data\mozilla\firefox\profiles\6o41ph79.default\extensions\[removed] . ============= SERVICES / DRIVERS =============== . R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-4-16 49376] R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-4-16 175176] R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2013-7-4 21576] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-6-5 770344] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-6-5 369584] R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [2011-3-25 13680] R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2013-8-8 807800] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-6-5 29816] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-4-16 66336] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-6-5 46808] R2 Motorola Device Manager;Motorola Device Manager Service;c:\program files\motorola mobility\motorola device manager\MotoHelperService.exe [2013-3-25 121144] R2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\lenovo\hotkey\tphkload.exe [2011-3-25 99328] R2 TPHKSVC;On Screen Display;c:\program files\lenovo\hotkey\TPHKSVC.exe [2011-3-25 64440] S0 cerc6;cerc6; [x] S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\lenovo\hotkey\micmute.exe [2011-3-25 45496] S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [2013-5-11 6016] S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2013-5-11 20864] S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2013-5-11 8448] S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [2013-5-11 23808] S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [2013-5-11 11008] . =============== Created Last 30 ================ . 2013-08-18 06:03:34 ——– d—–w- c:\documents and settings\owner\.swt 2013-08-18 05:52:58 ——– d—–w- c:\documents and settings\owner\local settings\application data\Slick Savings 2013-08-18 05:52:53 ——– d—–w- c:\documents and settings\owner\application data\Slick Savings 2013-08-18 05:52:53 ——– d—–w- c:\documents and settings\owner\application data\Search Settings 2013-08-18 05:52:31 ——– d—–w- c:\program files\Application Updater 2013-08-18 05:52:14 ——– d—–w- c:\program files\Vuze Remote Toolbar 2013-08-18 05:52:14 ——– d—–w- c:\program files\common files\Spigot 2013-08-18 05:49:11 ——– d—–w- c:\documents and settings\owner\application data\Azureus 2013-08-18 05:49:04 ——– d—–w- c:\program files\Vuze 2013-08-18 05:05:49 ——– d—–w- c:\documents and settings\owner\.frostwire5 2013-08-18 05:04:21 ——– d—–w- c:\program files\FrostWire 5 2013-08-18 05:00:32 ——– d—–w- c:\documents and settings\owner\local settings\application data\TrustWorthy 2013-08-18 05:00:28 ——– d—–w- c:\program files\TrustWorthy 2013-08-18 04:59:47 ——– d—–w- c:\program files\Conduit 2013-08-18 04:59:47 ——– d—–w- c:\documents and settings\owner\local settings\application data\CRE 2013-08-18 04:59:47 ——– d—–w- c:\documents and settings\owner\local settings\application data\Conduit 2013-08-18 04:59:01 770384 —-a-w- c:\windows\system32\msvcr100.dll 2013-08-18 04:59:01 421200 —-a-w- c:\windows\system32\msvcp100.dll 2013-08-18 04:57:24 ——– d—–w- c:\documents and settings\owner\application data\OpenCandy 2013-08-18 04:57:20 ——– d—–w- c:\program files\GetPrivate . ==================== Find3M ==================== . 2013-06-30 00:09:05 770344 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-06-30 00:09:05 175176 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-06-14 01:00:17 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-06-14 01:00:17 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe . ============= FINISH: 0:09:00.40 =============== . DDS (Ver_2012-11-20.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 3/25/2011 5:04:29 PM System Uptime: 8/13/2013 6:20:24 PM (102 hours ago) . Motherboard: LENOVO | | 1707W9L Processor: Intel® Core™ Duo CPU T2400 @ 1.83GHz | None | 1828/167mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 75 GiB total, 58.947 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP104: 7/13/2013 2:55:21 PM - System Checkpoint RP105: 7/14/2013 3:25:15 PM - System Checkpoint RP106: 7/15/2013 4:19:45 PM - System Checkpoint RP107: 7/16/2013 5:14:10 PM - System Checkpoint RP108: 7/17/2013 6:08:35 PM - System Checkpoint RP109: 7/18/2013 7:03:02 PM - System Checkpoint RP110: 7/19/2013 7:12:32 PM - System Checkpoint RP111: 7/20/2013 7:53:01 PM - System Checkpoint RP112: 7/21/2013 8:47:30 PM - System Checkpoint RP113: 7/22/2013 9:41:58 PM - System Checkpoint RP114: 7/23/2013 10:36:27 PM - System Checkpoint RP115: 7/24/2013 11:30:55 PM - System Checkpoint RP116: 7/26/2013 12:25:26 AM - System Checkpoint RP117: 7/27/2013 1:19:57 AM - System Checkpoint RP118: 7/28/2013 2:14:25 AM - System Checkpoint RP119: 7/29/2013 3:08:54 AM - System Checkpoint RP120: 7/30/2013 4:03:27 AM - System Checkpoint RP121: 7/31/2013 11:32:09 AM - System Checkpoint RP122: 8/1/2013 12:40:56 PM - System Checkpoint RP123: 8/2/2013 1:10:34 PM - System Checkpoint RP124: 8/3/2013 2:00:02 PM - System Checkpoint RP125: 8/4/2013 2:26:24 PM - System Checkpoint RP126: 8/5/2013 2:57:39 PM - System Checkpoint RP127: 8/6/2013 4:06:49 PM - System Checkpoint RP128: 8/7/2013 4:51:05 PM - System Checkpoint RP129: 8/8/2013 5:49:55 PM - System Checkpoint RP130: 8/9/2013 6:41:09 PM - System Checkpoint RP131: 8/10/2013 7:37:50 PM - System Checkpoint RP132: 8/13/2013 7:18:28 PM - System Checkpoint RP133: 8/14/2013 7:40:12 PM - System Checkpoint RP134: 8/15/2013 8:34:41 PM - System Checkpoint RP135: 8/16/2013 9:30:16 PM - System Checkpoint RP136: 8/17/2013 9:43:52 PM - System Checkpoint RP137: 8/17/2013 11:56:42 PM - OTL Restore Point - 8/17/2013 11:56:26 PM . ==== Installed Programs ====================== . Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X (10.1.7) Apple Application Support Apple Mobile Device Support Apple Software Update Ask Toolbar Ask Toolbar Updater avast! Free Antivirus Bonjour FrostWire 5.6.2 Google Chrome Google Drive Google Update Helper HDAUDIO Soft Data Fax Modem with SmartCP Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB952287) Intel® PRO Network Connections Drivers iTunes Java 7 Update 21 Java Auto Updater Lenovo Auto Scroll Utility Lenovo System Interface Driver Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Motorola Device Manager Motorola Device Software Update Motorola Mobile Drivers Installation 6.0.0 Mozilla Firefox 20.0.1 (x86 en-US) Mozilla Maintenance Service MSXML 4.0 SP3 Parser On Screen Display OpenOffice.org 3.3 Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB2675157) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2621440) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2695962) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Slick Savings Spybot - Search & Destroy ThinkPad FullScreen Magnifier ThinkPad Modem ThinkPad Power Management Driver TrustWorthy Toolbar Update for Windows Internet Explorer 8 (KB976662) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2541763) Update for Windows XP (KB2616676-v2) Update for Windows XP (KB2641690) Update for Windows XP (KB2718704) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VLC media player 2.0.1 Vuze Vuze Remote Toolbar v7.4 WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 . ==== Event Viewer Messages From Past Week ======== . 8/16/2013 10:10:00 AM, error: W32Time [34] - The time service has detected that the system time needs to be changed by -172966 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com (ntp.m|0x1|192.168.1.118:123->[removed]:123) is working properly. . ==== End Of File ===========================
Hi and Welcome!!

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.


Having said that…. [external image: Posted Image] Let's get going!!
———-

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
———-

[external image: Posted Image] AdwCleaner

Please download AdwCleaner by Xplode onto your desktop.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[R1].txt as well.
———-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI