This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan i just can't remove!

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Awesome! VS Add-in SEEMS to have been destroyed! Thank you! Tell me though, as i'm interested, what had i been infected with exactly? Was it a root-kit or just very sneaky trojans?
The only visible problem now is that on boot it trys to find the bcgxzgn.dll file and gives me an error since it doesn't exist anymore.


Hijackthis Log:
Logfile of HijackThis v1.99.1
Scan saved at 12:44:58 PM, on 22/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\Documents and Settings\scottrichmond\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = melbourne.cache.telstra.net:3128
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [bcgxzgn.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\bcgxzgn.dll,kzenukf
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1098175036125
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
ComboFix Log
scottrichmond - 06-11-22 12:50:14.82 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\scottrichmond\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-10-22 to 2006-11-22 ))))))))))))))))))))))))))))))))))


2006-11-20 15:24 81,920 –a—— C:\WINDOWS\system32\OpenAL32.dll
2006-11-20 15:24 420,240 –a—— C:\WINDOWS\system32\mpg4c32.dll
2006-11-20 15:24 309,616 –a—— C:\WINDOWS\system32\wmv8dmod.dll
2006-11-20 15:24 221,184 –a—— C:\WINDOWS\system32\wrap_oal.dll
2006-11-16 15:13 121,856 ——— C:\WINDOWS\system32\xmllite.dll
2006-11-16 14:35 53,248 –a—— C:\WINDOWS\system32\Process.exe
2006-11-16 14:35 40,960 –a—— C:\WINDOWS\system32\swsc.exe
2006-11-16 14:35 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2006-11-16 14:35 2,172 –a—— C:\WINDOWS\system32\tmp.reg
2006-11-16 14:35 135,168 –a—— C:\WINDOWS\system32\swreg.exe
2006-11-08 20:50 2,560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2006-11-07 20:23 68,888 –a—— C:\WINDOWS\system32\xinput1_3.dll
2006-11-07 20:23 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2006-11-07 20:23 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2006-11-07 20:23 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2006-11-07 20:23 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2006-11-07 20:23 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2006-11-07 20:23 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2006-10-27 15:09 6,049,280 ——— C:\WINDOWS\system32\ieframe.dll
2006-10-27 15:09 50,688 ——— C:\WINDOWS\system32\msfeedsbs.dll
2006-10-27 15:09 458,752 ——— C:\WINDOWS\system32\msfeeds.dll
2006-10-27 15:09 180,736 ——— C:\WINDOWS\system32\ieui.dll
2006-10-27 02:44 13,312 –a—— C:\WINDOWS\system32\ieudinit.exe
2006-10-27 00:08 40,960 –a—— C:\WINDOWS\system32\frapsvid.dll
2006-10-26 21:49 1,038,848 –a—— C:\WINDOWS\system32\dbghelp-xfw.dll
2006-10-26 19:09 15,440 –a—— C:\WINDOWS\system32\drivers\hamachi.sys
2006-10-24 20:22 89,673 C:\WINDOWSThumbplug TGA Uninstaller.exe
2006-10-24 15:13 102,400 –a—— C:\WINDOWS\system32\tsccvid.dll
2006-10-23 15:27 73,728 –a—— C:\WINDOWS\system32\drivers\SENTINEL.SYS
2006-10-23 15:27 685,056 –a—— C:\WINDOWS\system32\drivers\hardlock.sys
2006-10-23 15:27 6,656 –a—— C:\WINDOWS\system32\haspvdd.dll
2006-10-23 15:27 49,664 –a—— C:\WINDOWS\system32\SNTI386.DLL
2006-10-23 15:27 47,616 –a—— C:\WINDOWS\system32\drivers\Haspnt.sys
2006-10-23 15:27 383 –a—— C:\WINDOWS\system32\haspdos.sys
2006-10-23 15:27 305,152 –a—— C:\WINDOWS\IsUninst.exe
2006-10-23 15:27 20,032 -ra—— C:\WINDOWS\system32\drivers\SNTNLUSB.SYS
2006-10-23 15:27 18,432 –a—— C:\WINDOWS\system32\RNBOVDD.DLL
2006-10-22 12:22 888,832 –a—— C:\WINDOWS\system32\nvmobls.dll
2006-10-22 12:22 86,016 –a—— C:\WINDOWS\system32\nvmctray.dll
2006-10-22 12:22 81,920 –a—— C:\WINDOWS\system32\nvwddi.dll
2006-10-22 12:22 794,624 –a—— C:\WINDOWS\system32\nvcplui.exe
2006-10-22 12:22 7,700,480 –a—— C:\WINDOWS\system32\nvcpl.dll
2006-10-22 12:22 581,632 –a—— C:\WINDOWS\system32\nvhwvid.dll
2006-10-22 12:22 5,644,288 –a—— C:\WINDOWS\system32\nvoglnt.dll
2006-10-22 12:22 5,619,712 –a—— C:\WINDOWS\system32\nvdisps.dll
2006-10-22 12:22 5,255,168 –a—— C:\WINDOWS\system32\nvdispsr.dll
2006-10-22 12:22 466,944 –a—— C:\WINDOWS\system32\nvshell.dll
2006-10-22 12:22 458,752 –a—— C:\WINDOWS\system32\nvmccssr.dll
2006-10-22 12:22 45,056 –a—— C:\WINDOWS\system32\nvmccsrs.dll
2006-10-22 12:22 442,368 –a—— C:\WINDOWS\system32\nvappbar.exe
2006-10-22 12:22 425,984 –a—— C:\WINDOWS\system32\keystone.exe
2006-10-22 12:22 35,840 –a—— C:\WINDOWS\system32\nvcodins.dll
2006-10-22 12:22 35,840 –a—— C:\WINDOWS\system32\nvcod.dll
2006-10-22 12:22 311,296 –a—— C:\WINDOWS\system32\nvexpbar.dll
2006-10-22 12:22 3,203,072 –a—— C:\WINDOWS\system32\nvgamesr.dll
2006-10-22 12:22 3,047,424 –a—— C:\WINDOWS\system32\nvgames.dll
2006-10-22 12:22 286,720 –a—— C:\WINDOWS\system32\nvnt4cpl.dll
2006-10-22 12:22 229,376 –a—— C:\WINDOWS\system32\nvmccs.dll
2006-10-22 12:22 212,992 –a—— C:\WINDOWS\system32\nvapi.dll
2006-10-22 12:22 2,973,696 –a—— C:\WINDOWS\system32\nvvitvsr.dll
2006-10-22 12:22 2,924,544 –a—— C:\WINDOWS\system32\nvvitvs.dll
2006-10-22 12:22 2,859,008 –a—— C:\WINDOWS\system32\nvmoblsr.dll
2006-10-22 12:22 188,416 –a—— C:\WINDOWS\system32\nvmccss.dll
2006-10-22 12:22 159,810 –a—— C:\WINDOWS\system32\nvsvc32.exe
2006-10-22 12:22 147,456 –a—— C:\WINDOWS\system32\nvcolor.exe
2006-10-22 12:22 1,732,608 –a—— C:\WINDOWS\system32\nvwssr.dll
2006-10-22 12:22 1,662,976 –a—— C:\WINDOWS\system32\nvwdmcpl.dll
2006-10-22 12:22 1,622,016 –a—— C:\WINDOWS\system32\nwiz.exe
2006-10-22 12:22 1,470,464 –a—— C:\WINDOWS\system32\nview.dll
2006-10-22 12:22 1,339,392 –a—— C:\WINDOWS\system32\nvdspsch.exe
2006-10-22 12:22 1,236,992 –a—— C:\WINDOWS\system32\nvwss.dll
2006-10-22 12:22 1,019,904 –a—— C:\WINDOWS\system32\nvwimg.dll
2006-10-22 12:22 1,011,712 –a—— C:\WINDOWS\system32\nvcpluir.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-22 12:44 ——– d——– C:\Program Files\Mozilla Firefox
2006-11-21 21:03 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Azureus
2006-11-17 15:48 ——– d——– C:\Program Files\Winamp
2006-11-17 11:17 ——– d——– C:\Program Files\Common Files
2006-11-17 03:06 ——– d——– C:\Program Files\Internet Explorer
2006-11-16 15:18 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\OfficeUpdate12
2006-11-14 19:09 ——– d——– C:\Program Files\Steam
2006-11-13 15:49 ——– d——– C:\Program Files\GetRight
2006-11-13 10:32 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Hamachi
2006-11-12 17:45 ——– d——– C:\Program Files\Trillian Pro
2006-11-12 01:55 ——– d——– C:\Program Files\NetMeeting
2006-11-12 01:15 ——– d——– C:\Program Files\Far Cry
2006-11-12 00:02 ——– d——– C:\Program Files\GFI
2006-11-11 22:58 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-11-11 22:58 ——– d——– C:\Program Files\Atari
2006-11-11 22:20 ——– d——– C:\Program Files\NovaLogic
2006-11-11 21:37 ——– d——– C:\Program Files\FEAR
2006-11-10 12:28 163644 –a—— C:\WINDOWS\system32\drivers\secdrv.sys
2006-11-09 22:24 ——– d——– C:\Program Files\Electronic Arts
2006-11-09 21:57 ——– d——– C:\Program Files\WinRAR
2006-11-08 20:51 ——– d——– C:\Program Files\FlashGet
2006-11-08 20:50 2560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2006-11-05 16:34 218624 –a—— C:\WINDOWS\system32\uxtheme.dll
2006-11-04 21:06 ——– d——– C:\Program Files\BPFTP Server
2006-11-03 13:01 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Real
2006-11-03 13:00 ——– d——– C:\Program Files\Real
2006-11-03 13:00 ——– d——– C:\Program Files\Common Files\xing shared
2006-11-03 13:00 ——– d——– C:\Program Files\Common Files\Real
2006-11-02 17:09 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\SearchToolbarCorp
2006-10-31 16:44 ——– d——– C:\Program Files\QuickTime Alternative
2006-10-31 16:44 ——– d——– C:\Program Files\Media Player Classic
2006-10-31 16:44 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Media Player Classic
2006-10-31 16:32 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Filter Forge
2006-10-29 22:49 ——– d——– C:\Program Files\Doom 3
2006-10-29 19:19 ——– d——– C:\Program Files\Filter Forge
2006-10-28 14:07 ——– d—s—- C:\Documents and Settings\scottrichmond\Application Data\Microsoft
2006-10-27 15:09 413696 –a—— C:\WINDOWS\system32\vbscript.dll
2006-10-27 15:09 231424 –a—— C:\WINDOWS\system32\webcheck.dll
2006-10-27 15:09 156160 –a—— C:\WINDOWS\system32\msls31.dll
2006-10-27 04:26 ——– d——– C:\Program Files\THQ
2006-10-27 02:44 71680 –a—— C:\WINDOWS\system32\admparse.dll
2006-10-27 02:44 55296 –a—— C:\WINDOWS\system32\iesetup.dll
2006-10-27 02:44 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe
2006-10-27 02:44 43008 –a—— C:\WINDOWS\system32\iernonce.dll
2006-10-27 02:44 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll
2006-10-27 02:44 229376 –a—— C:\WINDOWS\system32\ieaksie.dll
2006-10-27 02:44 152064 –a—— C:\WINDOWS\system32\ieakeng.dll
2006-10-27 02:44 123904 –a—— C:\WINDOWS\system32\advpack.dll
2006-10-27 02:42 161792 –a—— C:\WINDOWS\system32\ieakui.dll
2006-10-26 19:10 ——– d——– C:\Program Files\Hamachi
2006-10-24 21:04 ——– d——– C:\Program Files\NVIDIA Corporation
2006-10-24 20:22 89673 –a—— C:\WINDOWS\Thumbplug TGA Uninstaller.exe
2006-10-24 20:22 ——– d——– C:\Program Files\Thumbplug TGA
2006-10-23 15:26 ——– d——– C:\Program Files\Alias
2006-10-23 15:25 ——– d——– C:\Program Files\Common Files\Alias Shared
2006-10-23 15:24 ——– d——– C:\Program Files\Common Files\Autodesk Shared
2006-10-22 23:27 ——– d——– C:\Program Files\Microsoft Office
2006-10-22 23:27 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-10-22 12:42 ——– d——– C:\Program Files\TPG Usage Meter
2006-10-22 12:22 4527488 –a—— C:\WINDOWS\system32\nv4_disp.dll
2006-10-22 12:22 3994624 –a—— C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-10-20 17:12 ——– d——– C:\Program Files\EQ2MAP Updater
2006-10-20 15:44 ——– d——– C:\Program Files\ID3-TagIT 3
2006-10-20 14:19 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Canon
2006-10-20 14:07 ——– d——– C:\Program Files\Canon
2006-10-20 13:52 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Adobe
2006-10-20 13:39 ——– d——– C:\Program Files\BulletProof FTP Client v2.5
2006-10-20 13:38 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\BPFTP
2006-10-20 12:55 ——– d——– C:\Program Files\UltraVNC
2006-10-20 11:46 ——– d——– C:\Program Files\Common Files\InstallShield
2006-10-20 11:17 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\CyberLink
2006-10-20 11:14 ——– d——– C:\Program Files\CyberLink
2006-10-20 11:08 ——– d——– C:\Program Files\Common Files\Adobe
2006-10-20 11:08 ——– d——– C:\Program Files\Adobe
2006-10-20 11:06 ——– d——– C:\Program Files\Common Files\Adobe Systems Shared
2006-10-20 10:39 ——– d——– C:\Program Files\DAEMON Tools
2006-10-20 10:37 611064 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2006-10-20 01:07 ——– d——– C:\Program Files\Microsoft.NET
2006-10-20 01:06 ——– d——– C:\Program Files\Microsoft ActiveSync
2006-10-20 01:06 ——– d——– C:\Program Files\Common Files\DESIGNER
2006-10-20 00:15 98304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2006-10-20 00:15 ——– dr-h—– C:\Documents and Settings\scottrichmond\Application Data\SecuROM
2006-10-19 23:36 ——– d——– C:\Program Files\7-Zip
2006-10-19 23:08 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Macromedia
2006-10-19 21:29 ——– d——– C:\Program Files\Sony
2006-10-19 21:22 ——– d——– C:\Program Files\Trend Micro
2006-10-19 20:27 ——– d——– C:\Program Files\XviD
2006-10-19 20:21 ——– d——– C:\Program Files\Diskeeper Corporation
2006-10-19 20:21 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Leadertech
2006-10-19 19:59 ——– d——– C:\Program Files\Java
2006-10-19 19:59 ——– d——– C:\Program Files\Common Files\Java
2006-10-19 19:58 ——– d——– C:\Program Files\Windows Media Player
2006-10-19 19:58 ——– d——– C:\Program Files\Outlook Express
2006-10-19 19:58 ——– d——– C:\Program Files\Common Files\System
2006-10-19 19:56 ——– d——– C:\Program Files\Messenger
2006-10-19 19:52 ——– d——– C:\Program Files\Azureus
2006-10-19 19:52 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Mozilla
2006-10-19 19:14 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\InstallShield
2006-10-18 23:32 13312 –a—— C:\WINDOWS\system32\BASSMOD.dll
2006-10-18 23:18 ——– d——– C:\Program Files\IDM Computer Solutions
2006-10-18 23:18 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\IDMComp
2006-10-18 21:29 ——– d——– C:\Program Files\MSN Messenger
2006-10-18 20:32 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\Sun
2006-10-18 20:03 ——– d——– C:\Documents and Settings\scottrichmond\Application Data\ID3-TagIT 3
2006-10-18 19:35 ——– d——– C:\Program Files\Macromedia
2006-10-18 19:33 ——– d——– C:\Program Files\Common Files\Macromedia
2006-10-17 13:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll
2006-10-17 13:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll
2006-10-17 13:05 206336 ——— C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 13:05 105984 –a—— C:\WINDOWS\system32\url.dll
2006-10-17 13:04 101376 –a—— C:\WINDOWS\system32\occache.dll
2006-10-17 12:58 61952 ——— C:\WINDOWS\system32\icardie.dll
2006-10-17 12:58 12288 ——— C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 12:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll
2006-10-17 12:57 266752 ——— C:\WINDOWS\system32\iertutil.dll
2006-10-17 12:56 45568 –a—— C:\WINDOWS\system32\mshta.exe
2006-10-17 12:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll
2006-10-17 12:27 380928 ——— C:\WINDOWS\system32\ieapfltr.dll
2006-10-13 23:35 65536 –a—— C:\WINDOWS\system32\nwwks.dll
2006-10-13 23:35 64000 –a—— C:\WINDOWS\system32\nwapi32.dll
2006-10-13 23:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll
2006-10-13 21:23 163584 –a—— C:\WINDOWS\system32\drivers\nwrdr.sys
2006-09-30 09:18 524288 –a—— C:\WINDOWS\opuc.dll
2006-09-15 17:39 208896 –a—— C:\WINDOWS\system32\nvusmb.exe
2006-09-15 17:39 208896 –a—— C:\WINDOWS\system32\nvunrm.exe
2006-09-15 17:39 208896 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2006-09-13 16:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-09-06 17:43 22752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2006-08-26 02:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-25 14:47 129784 ——— C:\WINDOWS\system32\pxafs.dll
2006-08-25 14:47 115880 ——— C:\WINDOWS\system32\pxinsi64.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMan"="SOUNDMAN.EXE"
"pccguide.exe"="\"C:\\Program Files\\Trend Micro\\Internet Security 2006\\pccguide.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RunDLL32.exe NvMCTray.dll,NvTaskbarInit"
"bcgxzgn.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\bcgxzgn.dll,kzenukf"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{2B1B63E0-D818-4FB0-A504-DB8546149ABB}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^scottrichmond^Start Menu^Programs^Startup^Adobe Gamma.lnk]
"path"="C:\\Documents and Settings\\scottrichmond\\Start Menu\\Programs\\Startup\\Adobe Gamma.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="drvruv"
"hkey"="HKLM"
"command"="rundll32.exe C:\\WINDOWS\\system32\\drvruv.dll,startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskeeperSystray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DkIcon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Diskeeper Corporation\\Diskeeper\\DkIcon.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Language"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=dword:00000002
"ose"=dword:00000003
"Diskeeper"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-11-22 12:50:40.98
C:\ComboFix.txt … 06-11-22 12:50
C:\ComboFix2.txt … 06-11-21 21:52
C:\ComboFix3.txt … 06-11-17 13:54
I did not find any rootkits but some remnants of Vundo, etc. Let's also do a Kapersky scan just to double-check things.


Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 9.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-1_5_0_09-windowsi586-p.exe to install the newest version.
Scan with HijackThis. Place a check against each of the following:
O4 - HKLM\..\Run: [bcgxzgn.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\bcgxzgn.dll,kzenukf
Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information from Kapersky in your next post.

Post (reply) with a fresh HijackThis log and the Kapersky log.
First time i run the Kaspersky scanner i went away and let it do its thing and when i came back it must have finished because it wasn't there anymore. In any case i'm running it again right now.

Hijackthis Log:
Logfile of HijackThis v1.99.1
Scan saved at 5:23:18 PM, on 23/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPFW.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRAM FILES\TRILLIAN PRO\TRILLIAN.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPROXY.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Documents and Settings\scottrichmond\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = melbourne.cache.telstra.net:3128
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1098175036125
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Sorry, i haven't been able to obtain a log file of the search. But it has found some 'infected' files. But i believe it was only detecting some of the tools you had me download earlier.
Unless the above Hijackthis log contains any more problems, i think it'll be ok to shut this thread down.
Thanks very much for your help Susan. You've no idea how much grief you have prevented me from by removing the malware. :wavey:
Hi DJDD,

Glad your system is running better. I would have liked to check the Kapersky log. But here are some final recommendations.


STEP 1.

System Restore for Windows XP
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
  • Turn off System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Reboot.

Turn ON System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check *Turn off System Restore*.
  • Click Apply, and then click OK.

STEP 2.
======
DON’T BECOME OVERCONFIDENT WITH ANTIVIRUS APPLICATIONS INSTALLED!!!

http://forum.malwareremoval.com/viewtopic….39eba6ea0b5e8ee

Stay up to date on security patches and be extremely wary of clicking on links and attachments that arrive unbidden in instant messages and e-mail.

"The number one thing the majority of the malicious code we're seeing now does is disable or delete anti-virus and other security software," Dunham said. "In a lot of cases, once the user clicks on that attachment, it's already too late."


Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Visit Microsoft's Update Site Frequently - It is important that you visit Windows Updates regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
    A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
    A tutorial on installing & using this product can be found here:
    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
    A tutorial on installing & using this product can be found here:
    Using SpywareBlaster to protect your computer from Spyware and Malware

    Yes Java came out with another update!
  • Updating Java
    • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 10.
    • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
    • Click the "Download" button to the right.
    • Check the box that says: "Accept License Agreement".
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-1_5_0_10-windowsi586-p.exe to install the newest version.
  • More info on how to prevent malware you can also find here (By Tony Klein)
Follow this list and your potential for being infected again will reduce dramatically.

Thank you for allowing me to assist you.

Susan
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI