This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected By Adware.agent.bn - Please Help

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:57:11 AM, on 05/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Portrait Displays\forteManager\DTHtml.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: BhoApp Class - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\WINDOWS\system32\append.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DT LGE] C:\Program Files\Portrait Displays\forteManager\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.grab.com/media/d3d944/games/files/222.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/24aa4c5b0975d1…ip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8DA664DC-123E-4836-B7B3-6653A8B082AB} (ChatOCX Control) - http://www.igl.net/clo/dev/ChatOCX/grab/ChatOCXProj.cab
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://www.winkflash.com/photo/loaders/ImageUploader3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BD04C9C-5BDF-4E8F-9424-2CC0AFC3A9CF}: NameServer = 142.161.2.155 142.161.130.155
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8996 bytes
Okay when you first ran the Smitfraud tool did you ever run option #3 on it? If not or if you can't remember then please do so.

Looks like you may have may some progress. I would like to see if you can run Combofix now. Please remove the version I had you download earlier if you still have it and download it again.

Download and Run ComboFix
  • Download this file from below:
    Here
  • Disconnect from the Internet, than disable your Anti-virus and any real-time Anti-spyware monitors that are running.
  • Then double click Combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your Anti-virus and Anti-spyware before reconnecting to the Internet.
Panda Scan log Incident Status Location Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\ComboFix\nircmd.exe Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Ian Magarrell\Application Data\Mozilla\Profiles\default\p5cr0cn2.slt\cookies.txt[winantivirus.com/] Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Ian Magarrell\Desktop\ComboFix.exe[nircmd.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Ian Magarrell\Desktop\SmitfraudFix\Process.exe Potentially unwanted tool:Application/SuperFast Not disinfected C:\Documents and Settings\Ian Magarrell\Desktop\SmitfraudFix\restart.exe Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Kathryn Magarrell\Cookies\kathryn magarrell@64.62.232[1].txt Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Kathryn Magarrell\Cookies\kathryn magarrell@888[2].txt Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Kathryn Magarrell\Cookies\kathryn magarrell@go[2].txt Adware:adware/azesearch Not disinfected C:\myvbs.vbs Potentially unwanted tool:Application/Processor Not disinfected C:\SDFix\apps\Process.exe Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old1\backups.zip[backups/findfast.exe] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old2\backups.zip[backups/findfast.exe] Adware:Adware/TTC Not disinfected C:\SDFix\backups_old2\backups.zip[backups/spoolsvc.dll] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old3\backups.zip[backups/autorun.exe] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old3\backups.zip[backups/findfast.exe] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old3\backups.zip[backups/printer.exe] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old3\backups.zip[backups/shell.exe] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old3\backups.zip[backups/spoolvs.exe] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old4\backups.zip[backups/autorun.exe] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old4\backups.zip[backups/findfast.exe] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old4\backups.zip[backups/printer.exe] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old4\backups.zip[backups/shell.exe] Adware:Adware/WinAntiVirus2007 Not disinfected C:\SDFix\backups_old4\backups.zip[backups/spoolvs.exe] Adware:Adware/TTC Not disinfected C:\WINDOWS\system32\append.dll Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
ComboFix 07-09-06 - "XXXX XXXXXX" 2007-09-05 14:38:03.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.198 [GMT -5:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\IANMAG~1\APPLIC~1\PrivacyProtector
C:\DOCUME~1\TEMP\APPLIC~1\SystemDoctor 2006
C:\Program Files\Common Files\Companion Wizard
C:\Program Files\Common Files\companion wizard\compwiz.exe
C:\Program Files\Common Files\companion wizard\CompWiz.xml
C:\Program Files\Common Files\PrivacyProtector
C:\UWA7P
C:\WA7P
C:\WA7P\Quar\Index.dat
C:\WINDOWS\system32\append.dll
C:\WINDOWS\system32\stera.log


((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 )))))))))))))))))))))))))))))))


2007-09-05 14:21 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-04 22:42 d——– C:\WINDOWS\system32\ActiveScan
2007-09-04 17:12 d——– C:\WINDOWS\ERUNT
2007-09-03 19:59 d–h—– C:\WINDOWS\PIF
2007-09-03 19:21 d——– C:\DOCUME~1\BARBMA~1\APPLIC~1\RegistrySmart
2007-08-31 22:59 d——– C:\DOCUME~1\TEMP\APPLIC~1\RegistrySmart
2007-08-31 22:10 d——– C:\DOCUME~1\IANMAG~1\APPLIC~1\RegistrySmart
2007-08-31 22:09 d——– C:\Program Files\RegistrySmart
2007-08-31 19:32 d——– C:\Program Files\FindVudon
2007-08-31 17:41 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-31 17:34 3,308 –a—— C:\WINDOWS\system32\tmp.reg
2007-08-31 17:32 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-08-31 17:32 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-08-31 17:32 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-08-31 14:15 82,248 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-31 14:15 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-08-31 14:15 57,672 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-31 14:15 40,264 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-31 14:15 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-08-31 14:15 d——– C:\Program Files\Spyware Doctor
2007-08-31 14:15 d——– C:\DOCUME~1\IANMAG~1\APPLIC~1\PC Tools
2007-08-31 14:03 d——– C:\DOCUME~1\IANMAG~1\APPLIC~1\IPSearchToolbarCorp
2007-08-31 13:12 6,144 –a—— C:\WINDOWS\system32\daila.exe
2007-08-31 01:10 9,216 –a—— C:\WINDOWS\system32\drivers\tdird.sys
2007-08-30 22:10 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-08-30 18:48 1,617 –a—— C:\DOCUME~1\IANMAG~1\was0069.exe
2007-08-22 03:23 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-08-21 19:03 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
2007-08-21 19:02 d——– C:\Program Files\Common Files\HP
2007-08-21 18:45 21,124 ——— C:\WINDOWS\hpomdl07.dat
2007-08-21 18:45 112,898 –a—— C:\WINDOWS\hpoins07.dat
2007-08-21 18:44 d——– C:\DOCUME~1\TEMP\APPLIC~1\HP
2007-08-20 21:35 d——– C:\Program Files\Hp
2007-08-20 21:12 d——– C:\Program Files\CyberLink DVD Solution
2007-08-20 20:17 d——– C:\DOCUME~1\TEMP\APPLIC~1\Hewlett-Packard
2007-08-20 20:09 d——– C:\temp\HP All-in-One Series Web Release
2007-08-20 19:57 d——– C:\temp\FixEngine
2007-08-06 14:21 d——– C:\DOCUME~1\BARBMA~1\APPLIC~1\U3


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-06 14:51 ——— d——– C:\Program Files\lg_fwupdate
2007-09-05 12:47 ——— d——– C:\Program Files\FinePixViewer
2007-09-03 19:43 ——— d——– C:\Program Files\Trend Micro
2007-08-30 16:50 21840 –a–c-t- C:\WINDOWS\system32\SIntfNT.dll
2007-08-30 16:50 17212 –a–c-t- C:\WINDOWS\system32\SIntf32.dll
2007-08-30 16:50 12067 –a–c-t- C:\WINDOWS\system32\SIntf16.dll
2007-08-30 16:50 ——— d——– C:\Program Files\Diablo II
2007-08-21 19:01 ——— d——– C:\Program Files\Hewlett-Packard
2007-08-20 21:12 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-20 21:12 ——— d——– C:\Program Files\CyberLink
2007-07-31 20:13 ——— d——– C:\DOCUME~1\TEMP\APPLIC~1\DisplayTune
2007-07-31 19:22 ——— d——– C:\DOCUME~1\BARBMA~1\APPLIC~1\DisplayTune
2007-07-31 17:48 ——— d——– C:\DOCUME~1\IANMAG~1\APPLIC~1\DisplayTune
2007-07-31 17:44 ——— d——– C:\Program Files\Common Files\Portrait Displays
2007-07-31 17:43 ——— d——– C:\Program Files\Portrait Displays
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-06-26 01:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-19 08:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 05:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-04-29 21:30 63728072 –a–c— C:\Program Files\Power2Go4_VCD_setup.exe
2007-04-13 16:36 15505200 –a–c— C:\Program Files\IE7-WindowsXP-x86-enu.exe
2007-01-24 14:36 630784 –a–c— C:\DOCUME~1\TEMP\GoToAssist_chat2way__317_en.exe
2006-03-22 17:04 630784 –a–c— C:\DOCUME~1\TEMP\chatlnk.exe
2005-04-23 13:55 160520312 –a–c— C:\Program Files\WordPerfectOffice12TBYB.exe
2005-01-17 12:59 25915327 –a–c— C:\Program Files\pfwnu.exe
2004-10-01 15:00 40960 –a—— C:\Program Files\Uninstall_CDS.exe
2004-09-03 06:50 1408135 –a–c— C:\Program Files\aup_5713.exe
2004-09-01 20:48 10135688 –a–c— C:\Program Files\MPSetupXP.exe
2004-08-29 15:59 11510936 –a–c— C:\Program Files\EZArmorLE.exe
2004-06-30 11:02 19208239 –a–c— C:\Program Files\ecdc_v5.3.5.10_plt_enu.exe
2004-06-21 21:17 19631008 –a–c— C:\Program Files\nero551056.exe
2004-06-21 21:00 282066 –a–c— C:\Program Files\cddae_04.zip
2004-06-21 21:00 223594 –a–c— C:\Program Files\NeroInfoTool_221.zip
2004-06-21 21:00 212221 –a–c— C:\Program Files\NeroDriveSpeed_200.zip
2004-06-21 21:00 183209 –a–c— C:\Program Files\cdgcreator_01.zip
2004-06-21 20:59 510842 –a–c— C:\Program Files\NeroCDSpeed_300.zip
2004-06-21 20:59 48122 –a–c— C:\Program Files\NeroDVDSpeed_053.zip
2004-06-21 20:59 286564 –a–c— C:\Program Files\CDSpeed_eng.chm
2004-06-21 20:59 24194 –a–c— C:\Program Files\cdspeed_076.zip
2004-06-21 20:58 160016 –a–c— C:\Program Files\wnaspi32.dll
2005-05-19 19:00:54 152 -csh–r C:\WINDOWS\system32\9563240B09.sys
2005-06-04 03:28:16 4,184 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 11:29]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-11 21:37]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 23:32]
"nwiz"="nwiz.exe" [2006-04-11 21:37 C:\WINDOWS\system32\nwiz.exe]
"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-07-01 10:50]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"LGODDFU"="C:\Program Files\lg_fwupdate\fwupdate.exe" [2007-04-11 15:31]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2005-07-08 09:25]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-11 21:37]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"DT LGE"="C:\Program Files\Portrait Displays\forteManager\DTHtml.exe" [2007-02-01 15:07]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 17:02]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="\Program\BackWeb-8876480.exe" []
"PowerBar"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26]
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickDCF.exe [2003-12-25 16:56:09]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2003-12-23 11:10:09]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, xlibgfl254.dll, append.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

R1 tdird.sys;tdird.sys;\??\C:\WINDOWS\system32\drivers\tdird.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINDOWS\system32\drivers\UdfReadr_xp.sys
R3 pdiddcci;DDC/CI monitor;C:\WINDOWS\system32\DRIVERS\pdiddcci.sys
R3 PdiPorts;Portrait Displays low level device driver;C:\WINDOWS\system32\Drivers\PdiPorts.sys
S1 cdudf_xp;cdudf_xp;C:\WINDOWS\system32\drivers\cdudf_xp.sys
S3 NetMate2;CATC USB/Ethernet Link II device driver;C:\WINDOWS\system32\DRIVERS\netmate2.sys
S3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys


Contents of the 'Scheduled Tasks' folder
"2007-09-05 08:30:55 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.exe
"2005-02-22 20:38:05 C:\WINDOWS\Tasks\WTR.job"
- C:\Program Files\bulletproofsoft.com\WinTrace Remover\BC6FB8D5
"2006-07-21 03:00:26 C:\WINDOWS\Tasks\XoftSpy.job"

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-06 14:51:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PowerBar = ????
scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-06 14:54:31 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-06 14:54

— E O F —
Hi Jaot,

First, we need to backup your registry:
Please go to Start > Run
Paste in the following line:regedit /e c:\registrybackup.reg
Click OK.
It won't appear to be doing anything, that's normal.
Your mouse pointer may turn to an hour glass for a minute.
Please continue when it no longer has the hour glass.

Open Notepad (press Start->Run, enter notepad and press OK)
Copy everything inside the code box below (Starting with REGEDIT4) and paste it into a new notepad file.
Change the Save As Type to All Files and save it as fix.reg to your Desktop.

Note: Please copy and paste all the text at once, and check that there is NO blank line above REGEDIT4 and one blank line at the bottom.
REGEDIT4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Then double-click on the fix.reg file, and when it prompts to merge say yes.

————————————————————————–

Delete files with Killbox:

1) Please download the Killbox.
Save it to the desktop and run it.

2) Select Delete on Reboot, and then click the All Files button. That button should now flash on and off with a green color.

3) Copy the file names below to the clipboard by highlighting them and pressing Control-C (or, after highlighting, right-click and choose copy)::

C:\WINDOWS\system32\daila.exe
C:\myvbs.vbs
C:\Documents and Settings\Kathryn Magarrell\Cookies\kathryn magarrell@888[2].txt
C:\Documents and Settings\Kathryn Magarrell\Cookies\kathryn magarrell@go[2].txt
C:\Documents and Settings\Kathryn Magarrell\Cookies\kathryn magarrell@64.62.232[1].txt
C:\Documents and Settings\Ian Magarrell\Application Data\Mozilla\Profiles\default\p5cr0cn2.slt\cookies.txt[winantivirus.com/]

4) Return to Killbox, go to the File menu, and choose Paste from Clipboard.

5) Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

If your computer does not restart automatically, please restart it manually.After rebooting, open up Killbox again. Click File -> Logs -> Actions History Log
Post this log in your next reply.
Please also post a fresh HJT log and let me know how it's going.
Pocket Killbox version Running on Windows XP as Ian Magarrell(Administrator) was started @ Thursday, September 06, 2007, 3:50 PM Killbox Closed(Exit) @ 3:50:51 PM __________________________________________________ Pocket Killbox version 2.0.0.881 Running on Windows XP as Ian Magarrell(Administrator) was started @ Thursday, September 06, 2007, 3:51 PM # 1 [Delete on Reboot] Path = C:\WINDOWS\system32\daila.exe # 2 [Delete on Reboot] Path = C:\myvbs.vbs I Rebooted @ 3:54:25 PM Killbox Closed(Exit) @ 3:54:32 PM __________________________________________________ Pocket Killbox version 2.0.0.881 Running on Windows XP as Ian Magarrell(Administrator) was started @ Thursday, September 06, 2007, 4:01 PM Killbox Closed(Exit) @ 4:02:29 PM __________________________________________________ Pocket Killbox version 2.0.0.881 Running on Windows XP as Ian Magarrell(Administrator) was started @ Thursday, September 06, 2007, 4:02 PM
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:05:13 PM, on 06/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Portrait Displays\forteManager\DTHtml.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DT LGE] C:\Program Files\Portrait Displays\forteManager\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.grab.com/media/d3d944/games/files/222.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/24aa4c5b0975d1…ip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8DA664DC-123E-4836-B7B3-6653A8B082AB} (ChatOCX Control) - http://www.igl.net/clo/dev/ChatOCX/grab/ChatOCXProj.cab
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://www.winkflash.com/photo/loaders/ImageUploader3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BD04C9C-5BDF-4E8F-9424-2CC0AFC3A9CF}: NameServer = 142.161.2.155 142.161.130.155
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8810 bytes
How are things running now Jaot? And did everything go OK with the last part of the fix? I have to go out for the evening but will check in later before bed time… Dave
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which may be infected anyway).

Click Start>Help and Support>Undo changes to your computer with System Restore
Select Create A Restore Point then click Next. Give it a name it and then click Create

Click Start>Run and type Cleanmgr
Click the More Options Tab.
Click Clean Up in the System Restore section.

In addition to updating and using what you currently have you may want to consider the following:

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install SpywareGuard - SpywareGuard provides a real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.
A tutorial on installing & using this product can be found here:
Using SpywareGuard to protect your computer from Spyware and Malware

Use IESpy-Ad
IESpy-Ad will block access to malicious websites so you cannot be redirected to them from an infected site or email. Instructions for set up and use can be found at the website.

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

Here is a great link to a post here on securing your PC after an attack.
http://forums.tomcoyote.org/index.php?show…mp;#entry257163

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI