This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]A Friend Is Complaining Of Lots Of Popups

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a friend in the office we work in that is complaining of lots of popups in internet explorer like (drivecleaner.com, errorsafe.com, & secure-cash.net) and I have removed a couple different spyware this week. Today I removed a "webassist.dll" I was wandering if someone could take a look at the log that was created from her computer to see what else if anything could be done to help.

Logfile of HijackThis v1.99.1
Scan saved at 9:47:06 AM, on 8/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\avgagent.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\RealPopup\RealPopup.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Intuit\QuickBooks Enterprise Solutions 6.0\qbw32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\axlbridge.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
F:\Shared Programs\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.americanairworks.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7113255a-7fe9-4665-a70e-2d88483c7767} - (no file)
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\tmpA7.tmp.dll
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\vtrpmk.dll",forkonce
O4 - HKCU\..\Run: [RealPopup] "C:\Program Files\RealPopup\RealPopup.exe" BOOT
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = airworks.local
O17 - HKLM\Software\..\Telephony: DomainName = airworks.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{D152B029-278D-4B88-80C1-1D3B22546EFF}: NameServer = 71.252.0.12,71.242.0.12
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = airworks.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = airworks.local
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O20 - Winlogon Notify: dllare - dllare.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Remote Support Service (AvgAgent) (avgagent) - Unknown owner - avgagent.exe (file missing)
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
Hi! Welcome to the Tom Coyote forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Sorry for the late reply, I have been out due to illness.
Here's my HijackThis Uninstall Log:

Acronis True Image Home
Ad-Aware 2007
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0.8
AVG 7.5
CCleaner (remove only)
Gadwin PrintScreen Professional
HijackThis 1.99.1
Intel® Extreme Graphics Driver
Intel® PRO Network Adapters and Drivers
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft Office 2000 Premium
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 Parser and SDK
Outlook Express Backup Genie v1.8
PDFCreator
QODBC Driver
QuickBooks Enterprise Solutions: Mfg and Whsle Edition 7.0
QuickBooks Product Listing Service
RealPopup
Security Update for Windows XP (KB928843)
Soft Data Fax Modem with SmartCP
Spybot - Search & Destroy 1.3
SupportSoft Assisted Service
Update for Windows XP (KB898461)
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime

Here's my ComboFix log:

ComboFix 07-08-10.8 - "Tina" 2007-08-10 16:20:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1192 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Tina\APPLIC~1\tmp58.tmp.exe
C:\DOCUME~1\Tina\APPLIC~1\tmp5A.tmp.exe
C:\DOCUME~1\Tina\APPLIC~1\tmp8B.tmp.exe
C:\DOCUME~1\Tina\APPLIC~1\tmp8D.tmp.exe
C:\DOCUME~1\Tina\APPLIC~1\tmp98.tmp.exe
C:\DOCUME~1\Tina\APPLIC~1\tmpA7.tmp.exe
C:\DOCUME~1\Tina\APPLIC~1\tmpED.tmp.exe
C:\WINDOWS\kmprtv.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\dn4cdb4750.dat
C:\WINDOWS\system32\k6mG78t0.exe
C:\WINDOWS\system32\tmp5A.tmp.dll
C:\WINDOWS\system32\tmp8D.tmp.dll
C:\WINDOWS\Tasks.\At1.job
C:\WINDOWS\Tasks.\At10.job
C:\WINDOWS\Tasks.\At11.job
C:\WINDOWS\Tasks.\At12.job
C:\WINDOWS\Tasks.\At13.job
C:\WINDOWS\Tasks.\At14.job
C:\WINDOWS\Tasks.\At15.job
C:\WINDOWS\Tasks.\At16.job
C:\WINDOWS\Tasks.\At17.job
C:\WINDOWS\Tasks.\At18.job
C:\WINDOWS\Tasks.\At19.job
C:\WINDOWS\Tasks.\At2.job
C:\WINDOWS\Tasks.\At20.job
C:\WINDOWS\Tasks.\At21.job
C:\WINDOWS\Tasks.\At22.job
C:\WINDOWS\Tasks.\At23.job
C:\WINDOWS\Tasks.\At24.job
C:\WINDOWS\Tasks.\At3.job
C:\WINDOWS\Tasks.\At4.job
C:\WINDOWS\Tasks.\At5.job
C:\WINDOWS\Tasks.\At6.job
C:\WINDOWS\Tasks.\At7.job
C:\WINDOWS\Tasks.\At8.job
C:\WINDOWS\Tasks.\At9.job
C:\WINDOWS\vtrpmk.dll
C:\WINDOWS\xhelper.dll


((((((((((((((((((((((((( Files Created from 2007-07-10 to 2007-08-10 )))))))))))))))))))))))))))))))


2007-08-10 16:18 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-24 14:34 d——– C:\Program Files\NetworkStreaming
2007-07-24 13:41 d——– C:\Program Files\Gadwin Systems


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-20 13:31 ——— d——– C:\Program Files\Lavasoft
2007-06-20 13:31 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-06-13 10:55 397312 –a—— C:\WINDOWS\avgagent.exe
1998-12-08 22:53 99840 –a—— C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-08 22:53 70144 –a—— C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-08 22:53 48640 –a—— C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-08 22:53 31744 –a—— C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-08 22:53 186368 –a—— C:\Program Files\Common Files\IRAREG.DLL
1998-12-08 22:53 17920 –a—— C:\Program Files\Common Files\IRASRIAL.DLL


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7113255a-7fe9-4665-a70e-2d88483c7767}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-04-07 18:29]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-04-07 18:37]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-04-07 18:30]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealPopup"="C:\Program Files\RealPopup\RealPopup.exe" [2005-02-24 00:50]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:06]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-12-26 14:31:06]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dllare]
dllare.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap

R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys


Contents of the 'Scheduled Tasks' folder
2007-08-09 04:00:00 C:\WINDOWS\Tasks\At25.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 05:00:00 C:\WINDOWS\Tasks\At26.job
2007-08-09 06:00:00 C:\WINDOWS\Tasks\At27.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 07:00:00 C:\WINDOWS\Tasks\At28.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 08:00:00 C:\WINDOWS\Tasks\At29.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 09:00:00 C:\WINDOWS\Tasks\At30.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 10:00:00 C:\WINDOWS\Tasks\At31.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 11:00:00 C:\WINDOWS\Tasks\At32.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 12:00:00 C:\WINDOWS\Tasks\At33.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-10 13:00:00 C:\WINDOWS\Tasks\At34.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-10 14:00:00 C:\WINDOWS\Tasks\At35.job
2007-08-10 15:00:00 C:\WINDOWS\Tasks\At36.job
2007-08-10 16:00:00 C:\WINDOWS\Tasks\At37.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-10 17:00:00 C:\WINDOWS\Tasks\At38.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-10 18:00:00 C:\WINDOWS\Tasks\At39.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-10 19:00:00 C:\WINDOWS\Tasks\At40.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-10 20:00:00 C:\WINDOWS\Tasks\At41.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-08 21:00:00 C:\WINDOWS\Tasks\At42.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-08 22:00:00 C:\WINDOWS\Tasks\At43.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-08 23:00:00 C:\WINDOWS\Tasks\At44.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 00:00:00 C:\WINDOWS\Tasks\At45.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 01:00:00 C:\WINDOWS\Tasks\At46.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 02:00:00 C:\WINDOWS\Tasks\At47.job - C:\WINDOWS\system32\A3Nn6C05.exe
2007-08-09 03:00:00 C:\WINDOWS\Tasks\At48.job - C:\WINDOWS\system32\A3Nn6C05.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-10 16:23:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-10 16:24:10 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-10 16:23

— E O F —


I have one question though, apparently the ComboFix changed the time on the machine and said not to change the time manually that it fix that. It didn't when the computer restarted, will it at another point or did I do something wrong?
Hi

Ive left a question for the developer of Combofix about the clock, though I dont think it will mean much. In the meantime, could you search for a file for me?
  • Click Start.
  • Click Search.
  • Click All files and folders.
  • Expand More advanced optionsand then check Search system folders, Search hidden files and folders and Search Subfolders.
  • Paste this into the All or part of the file name box:

    dllare.dll
If any of this file is found please write down it's full path, ie C:\Windows\etc.
When I searched this file it found it here: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde15.zip C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde8.zip
Hi

Im still awaiting an answer on the clock issue. Are you able to change it back manually?

That file must be contained within Spybot's Recovery, which we will empty out later.

Upload a File to Virustotal
Please visit Virustotal
  • Click the Browse… button
  • Navigate to the file C:\WINDOWS\system32\A3Nn6C05.exe
  • Click the Open button
  • Click the Send button
  • Copy and paste the results back here please.
That file does not appear to exist anymore. I did notice that when ComboFix finished apparently it created a "ComboFix-quarantined-files" log, not sure if you needed this or not. 2000-10-27 17:23 50688 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\BSZIP.DLL.vir 2007-07-13 15:26 19520 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\k6mG78t0.exe.vir 2007-07-19 11:10 126976 –a—— C:\Qoobox\Quarantine\C\WINDOWS\xhelper.dll.vir 2007-08-07 08:12 124743 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\Tina\APPLIC~1\tmp58.tmp.exe.vir 2007-08-07 08:12 63532 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\tmp5A.tmp.dll.vir 2007-08-07 08:12 78517 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\Tina\APPLIC~1\tmp5A.tmp.exe.vir 2007-08-07 08:55 124743 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\Tina\APPLIC~1\tmp8B.tmp.exe.vir 2007-08-07 08:56 63532 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\tmp8D.tmp.dll.vir 2007-08-07 08:56 78517 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\Tina\APPLIC~1\tmp8D.tmp.exe.vir 2007-08-07 09:03 124743 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\Tina\APPLIC~1\tmp98.tmp.exe.vir 2007-08-07 09:06 78517 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\Tina\APPLIC~1\tmpA7.tmp.exe.vir 2007-08-07 11:21 124743 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\Tina\APPLIC~1\tmpED.tmp.exe.vir 2007-08-07 11:21 131419 –a—— C:\Qoobox\Quarantine\C\WINDOWS\vtrpmk.dll.vir 2007-08-07 13:15 218395 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\dn4cdb4750.dat.vir 2007-08-08 17:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At18.job.vir 2007-08-08 18:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At19.job.vir 2007-08-08 19:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At20.job.vir 2007-08-08 20:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At21.job.vir 2007-08-08 21:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At22.job.vir 2007-08-08 22:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At23.job.vir 2007-08-08 23:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At24.job.vir 2007-08-09 00:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At1.job.vir 2007-08-09 01:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At2.job.vir 2007-08-09 02:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At3.job.vir 2007-08-09 03:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At4.job.vir 2007-08-09 04:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At5.job.vir 2007-08-09 05:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At6.job.vir 2007-08-09 06:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At7.job.vir 2007-08-09 07:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At8.job.vir 2007-08-09 08:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At9.job.vir 2007-08-10 09:01 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At10.job.vir 2007-08-10 10:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At11.job.vir 2007-08-10 11:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At12.job.vir 2007-08-10 12:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At13.job.vir 2007-08-10 13:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At14.job.vir 2007-08-10 14:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At15.job.vir 2007-08-10 15:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At16.job.vir 2007-08-10 16:00 350 –a—— C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At17.job.vir 2007-08-10 16:19 1067523 –a—— C:\Qoobox\Quarantine\C\WINDOWS\kmprtv.ini.vir Folder PATH listing Volume serial number is 4CDB-4750 C:\QOOBOX \—Quarantine +—C | +—DOCUME~1 | | \—Tina | | \—APPLIC~1 | | tmp58.tmp.exe.vir | | tmp5A.tmp.exe.vir | | tmp8B.tmp.exe.vir | | tmp8D.tmp.exe.vir | | tmp98.tmp.exe.vir | | tmpA7.tmp.exe.vir | | tmpED.tmp.exe.vir | | | \—WINDOWS | | kmprtv.ini.vir | | vtrpmk.dll.vir | | xhelper.dll.vir | | | +—system32 | | BSZIP.DLL.vir | | dn4cdb4750.dat.vir | | k6mG78t0.exe.vir | | tmp5A.tmp.dll.vir | | tmp8D.tmp.dll.vir | | | \—Tasks | At1.job.vir | At10.job.vir | At11.job.vir | At12.job.vir | At13.job.vir | At14.job.vir | At15.job.vir | At16.job.vir | At17.job.vir | At18.job.vir | At19.job.vir | At2.job.vir | At20.job.vir | At21.job.vir | At22.job.vir | At23.job.vir | At24.job.vir | At3.job.vir | At4.job.vir | At5.job.vir | At6.job.vir | At7.job.vir | At8.job.vir | At9.job.vir | \—Registry_backups
Hi

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
C:\WINDOWS\system32\A3Nn6C05.exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7113255a-7fe9-4665-a70e-2d88483c7767}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dllare]

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
I think I did this correctly.

Here's the ComboFix log:

ComboFix 07-08-10.8 - "Tina" 2007-08-14 10:29:50.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.971 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Tina\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
C:\WINDOWS\system32\A3Nn6C05.exe


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job


((((((((((((((((((((((((( Files Created from 2007-07-14 to 2007-08-14 )))))))))))))))))))))))))))))))


2007-08-13 09:46 3,932,160 –a—— C:\DOCUME~1\Tina\ntuser.dat
2007-08-10 16:32 9,216 –a—— C:\WINDOWS\system32\avgwlntf.dll
2007-08-10 16:18 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-24 14:34 d——– C:\Program Files\NetworkStreaming
2007-07-24 13:41 d——– C:\Program Files\Gadwin Systems


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-20 13:31 ——— d——– C:\Program Files\Lavasoft
2007-06-20 13:31 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-06-13 10:55 397312 –a—— C:\WINDOWS\avgagent.exe
1998-12-08 22:53 99840 –a—— C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-08 22:53 70144 –a—— C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-08 22:53 48640 –a—— C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-08 22:53 31744 –a—— C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-08 22:53 186368 –a—— C:\Program Files\Common Files\IRAREG.DLL
1998-12-08 22:53 17920 –a—— C:\Program Files\Common Files\IRASRIAL.DLL


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-04-07 18:29]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-04-07 18:37]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-04-07 18:30]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-10 16:32]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealPopup"="C:\Program Files\RealPopup\RealPopup.exe" [2005-02-24 00:50]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:06]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-12-26 14:31:06]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-08-10 16:32 9216 C:\WINDOWS\system32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap

R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R1 AvgMfx86;AVG Minifilter x86 Resident Driver;C:\WINDOWS\system32\Drivers\avgmfx86.sys
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-14 10:30:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Tour]
"RunCount"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer]
"CleanShutdown"=dword:00000001
"Shutdown Setting"=dword:00000004

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000002
"ListviewAlphaSelect"=dword:00000000
"ListviewShadow"=dword:00000000
"TaskbarAnimations"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData"="C:\Documents and Settings\Tina.TINARANDOLPH01\Application Data"
"Cookies"="C:\Documents and Settings\Tina.TINARANDOLPH01\Cookies"
"Desktop"="C:\Documents and Settings\Tina.TINARANDOLPH01\Desktop"
"Favorites"="C:\Documents and Settings\Tina.TINARANDOLPH01\Favorites"
"NetHood"="C:\Documents and Settings\Tina.TINARANDOLPH01\NetHood"
"Personal"="C:\Documents and Settings\Tina.TINARANDOLPH01\My Documents"
"PrintHood"="C:\Documents and Settings\Tina.TINARANDOLPH01\PrintHood"
"Recent"="C:\Documents and Settings\Tina.TINARANDOLPH01\Recent"
"SendTo"="C:\Documents and Settings\Tina.TINARANDOLPH01\SendTo"
"Start Menu"="C:\Documents and Settings\Tina.TINARANDOLPH01\Start Menu"
"Templates"="C:\Documents and Settings\Tina.TINARANDOLPH01\Templates"
"Programs"="C:\Documents and Settings\Tina.TINARANDOLPH01\Start Menu\Programs"
"Startup"="C:\Documents and Settings\Tina.TINARANDOLPH01\Start Menu\Programs\Startup"
"Local Settings"="C:\Documents and Settings\Tina.TINARANDOLPH01\Local Settings"
"Local AppData"="C:\Documents and Settings\Tina.TINARANDOLPH01\Local Settings\Application Data"
"Cache"="C:\Documents and Settings\Tina.TINARANDOLPH01\Local Settings\Temporary Internet Files"
"History"="C:\Documents and Settings\Tina.TINARANDOLPH01\Local Settings\History"
"My Pictures"="C:\Documents and Settings\Tina.TINARANDOLPH01\My Documents\My Pictures"
"My Music"="C:\Documents and Settings\Tina.TINARANDOLPH01\My Documents\My Music"
"CD Burning"="C:\Documents and Settings\Tina.TINARANDOLPH01\Local Settings\Application Data\Microsoft\CD Burning"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders]
"Recent"=str(2):"USERPROFILE\Recent"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DropShadow]
"DefaultValue"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing]
"DefaultValue"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewAlphaSelect]
"DefaultValue"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewShadow]
"DefaultValue"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation]
"DefaultValue"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade]
"DefaultValue"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TaskbarAnimations]
"DefaultValue"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation]
"DefaultValue"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\iexplore]
"Count"=dword:00000002
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7113255A-7FE9-4665-A70E-2D88483C7767}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7113255A-7FE9-4665-A70E-2D88483C7767}\iexplore]
"Type"=dword:00000003
"Count"=dword:00000002
"Time"=hex:d7,07,08,00,05,00,0a,00,14,00,0d,00,36,00,0f,00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C6039E6C-BDE9-4DE5-BB40-768CAA584FDC}\iexplore]
"Count"=dword:00000002
[HKEY_CURRscanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-14 10:31:52
C:\ComboFix-quarantined-files.txt … 2007-08-14 10:31

— E O F —


And here's the HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 10:34, on 2007-08-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\avgagent.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\RealPopup\RealPopup.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Intuit\QuickBooks Enterprise Solutions 6.0\qbw32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\axlbridge.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\explorer.exe
F:\Shared Programs\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.americanairworks.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [RealPopup] "C:\Program Files\RealPopup\RealPopup.exe" BOOT
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = airworks.local
O17 - HKLM\Software\..\Telephony: DomainName = airworks.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{D152B029-278D-4B88-80C1-1D3B22546EFF}: NameServer = 71.252.0.12,71.242.0.12
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = airworks.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = airworks.local
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Remote Support Service (AvgAgent) (avgagent) - Unknown owner - avgagent.exe (file missing)
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
Hi

Delete the Combofix icon from your Desktop.

Navigate to and delete the following files and/or folders (if they are present):

Folders:
C:\Combofix
C:\Qoobox

Download ATF (Atribune Temp File) Cleaner� by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.

*Note* If you do not have Firefox or Opera, those options will be greyed out.

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI