This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Kid's Computer infected

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Scotty, Here is the new Hijack log you requested. I'll wait to hear from you before uninstalling anything from viewpoint. Thanks very much. GracesDad
Hi Scotty,

Hmm…dont know how I screwed that up. Here is the Combo log:
File::
C:\3A4.tmp
C:\3A5.tmp
C:\3A6.tmp
C:\77D.tmp
C:\77E.tmp
C:\77F.tmp

Folder::
C:\Documents and Settings\Owner\Desktop\SDFix

and here is the new Hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 9:50:09 PM, on 10/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\aim\aim.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
E:\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - HKCU\..\Run: [ISMPack7] "C:\Program Files\ISM2\ISMPack7.exe"
O4 - HKCU\..\Run: [ISMModule8] "C:\Program Files\ISM\ISMModule8.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1125335325997
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1125335881153
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Hope this is correct. Thanks very much,
Gracesdad
Hi That's not the latest Combo log. It's just a copy of the CFScript. I need the whole log. If you go to the C:\ drive in My Computer there will be files called combofix.txt. Look at the dates at the top for the latest and post the whole log. You can remove Viewpoint through Add/Remove Programs. Any problems let me know.
Hi Scotty,
sorry for the delay. Here is the latest combofix log.
ComboFix 07-10-29.1 - Owner 2007-10-31 21:26:37.10 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.115 [GMT -4:00]
Running from: E:\ComboFix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point

FILE::
C:\3A4.tmp
C:\3A5.tmp
C:\3A6.tmp
C:\77D.tmp
C:\77E.tmp
C:\77F.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\3A4.tmp
C:\3A5.tmp
C:\3A6.tmp
C:\77D.tmp
C:\77E.tmp
C:\77F.tmp
C:\Documents and Settings\Owner\Desktop\SDFix
C:\Documents and Settings\Owner\Desktop\SDFix\apps\assosfix.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\cliptext.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\download.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\dummy.sys
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Enable_Command_Prompt.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\ERDNT.E_E
C:\Documents and Settings\Owner\Desktop\SDFix\apps\ERDNTDOS.LOC
C:\Documents and Settings\Owner\Desktop\SDFix\apps\ERDNTWIN.LOC
C:\Documents and Settings\Owner\Desktop\SDFix\apps\ERUNT.EXE
C:\Documents and Settings\Owner\Desktop\SDFix\apps\ERUNT.LOC
C:\Documents and Settings\Owner\Desktop\SDFix\apps\fix.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FixBH.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FIXCU.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FIXLM.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FixPath.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FixRedir.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FixWebCheck.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\fixXP.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FixXPsp2.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\HPFix.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\HPFix2.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\HPFix3.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\isadmin.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\leg2.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\legacy.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\legacybk.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\locate.com
C:\Documents and Settings\Owner\Desktop\SDFix\apps\LS.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\MD5File.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\moveex.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\MyGcpvFix.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\MyGkFix2.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Process.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\procs.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\psservice.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\RegDACL.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\regedit.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Rem.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Rem2.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Replace\W2K.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Replace\w2k\null.sys
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Replace\XP.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Replace\xp\null.sys
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Reset_AppInit_DLLs.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\RestartIt!.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Restore_SecurityCenter.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Restore_SharedAccess.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\sc.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\SF.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\shutdown.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\srv2.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\svc.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\svcbk.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\swreg.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\swsc.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\unzip.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\WINMSG.EXE
C:\Documents and Settings\Owner\Desktop\SDFix\apps\zip.exe
C:\Documents and Settings\Owner\Desktop\SDFix\backups\attrib.exe
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backupreg.zip
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip
C:\Documents and Settings\Owner\Desktop\SDFix\backups\find.exe
C:\Documents and Settings\Owner\Desktop\SDFix\backups\findstr.exe
C:\Documents and Settings\Owner\Desktop\SDFix\backups\HOSTS
C:\Documents and Settings\Owner\Desktop\SDFix\backups\regedit.exe
C:\Documents and Settings\Owner\Desktop\SDFix\catchme.exe
C:\Documents and Settings\Owner\Desktop\SDFix\dummy.sys
C:\Documents and Settings\Owner\Desktop\SDFix\Report.txt
C:\Documents and Settings\Owner\Desktop\SDFix\RunThis.bat
C:\Documents and Settings\Owner\Desktop\SDFix\SDFIX_ReadMe_Online.url

.
((((((((((((((((((((((((( Files Created from 2007-10-01 to 2007-11-01 )))))))))))))))))))))))))))))))
.

2007-10-28 17:01 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-10-28 17:01 d——– C:\WINDOWS\LastGood
2007-10-28 17:01 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-27 19:14 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-27 18:46 d——– C:\WINDOWS\ERUNT
2007-10-27 11:46 218,112 –a—— C:\Program Files\HijackThis.exe
2007-10-22 21:39 d——– C:\UBCD4Win
2007-10-20 18:37 d——– C:\Program Files\iTunes
2007-10-20 17:48 d——– C:\Program Files\Apple Software Update
2007-10-20 13:12 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-20 12:57 d——– C:\WINDOWS\system32\DRVSTORE
2007-10-20 12:56 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-10-20 12:55 d——– C:\Program Files\The Learning Company
2007-10-07 08:34 d——– C:\Program Files\iTunes(2)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-20 22:38 ——— d—–w C:\Program Files\iPod
2007-10-20 16:57 ——— d—–w C:\Program Files\QuickTime
2007-10-20 16:57 ——— d—–w C:\Program Files\Arcavista
2007-10-20 16:56 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-10-20 16:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-20 16:54 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-20 15:49 ——— d—–w C:\Program Files\Common Files\Network Associates
2007-10-07 23:48 ——— d–h–w C:\Documents and Settings\Owner\Application Data\Move Networks
2007-09-21 19:41 ——— d—–w C:\Program Files\Common Files\Apple
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2006-10-30 02:49 59,728 —-a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 11:46]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 13:55]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-08-18 08:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 09:48]
"HostManager"="C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe" [2006-04-20 13:10]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2002-08-01 16:13]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 12:59]
"Alogserv"="C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe" [2002-01-04 06:02]
"McAfee Guardian"="C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" [2001-12-18 02:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-13 16:00]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 11:29]
"AIM"="C:\Program Files\aim\aim.exe" [2005-08-05 15:08]
"McAfee.InstantUpdate.Monitor"="C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" [2002-02-11 00:03]
"ISMPack7"="C:\Program Files\ISM2\ISMPack7.exe" []
"ISMModule8"="C:\Program Files\ISM\ISMModule8.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-09-28 22:28:40]

R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R2 AvSynMgr;AVSync Manager;"C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe"
R3 NETGEAR NETGEAR_MA101_USB_Adapter®;NETGEAR NETGEAR_MA101_USB_Adapter® Service for NETGEAR MA101 USB Adapter;C:\WINDOWS\system32\DRIVERS\ma1012kr.sys
S3 NaiFiltr;NaiFiltr;C:\WINDOWS\system32\DRIVERS\NaiFiltr.sys
S3 USBFVNETR;NETGEAR MA101 USB Adapter;C:\WINDOWS\system32\DRIVERS\ma101rndxp.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 19:23:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-31 21:29:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-31 21:30:30
C:\ComboFix2.txt … 2007-10-29 18:07
C:\ComboFix3.txt … 2007-10-29 17:56
.
— E O F —


thanks for all your help,
Gracesdad
Hi

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.

    [external image: Posted Image]
  • When shown the disclaimer, Select "2"
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.

I would advise updating Adobe Reader, as the latest version clears up any vulnerabilities of previous versions.
First uninstall the version you have on your computer then download and install Adobe Reader 8.1.


This is my usual speech for when you are clean, which you appear to be.

Here are some free programs I recommend, although you will not need them all.

Spybot Search and Destroy
Download it from here . Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here

Install Spyware Guard
Download it from here
Find here the tutorial on how to use Spyware Guard here

Install SpyWare Blaster
Download it from here
Find here the tutorial on how to use Spyware Blaster here

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here


Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"


Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI