This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help ! Can't seem to get rid of !

86 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

scotty, having trouble running combofix.exe, telling me today's date and copy is expired, please install updated copy? Would you know how I go about doing that?
Scotty, found a workable combofix download, here is resultant log with cfscript.txt, will post a new hijack log next. Renee6

ComboFix 07-11-08.3 - Renee Loiselle 2007-11-18 21:22:29.5 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Renee Loiselle\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Qekbrqbk
C:\Program Files\Qekbrqbk\bsxlgesz.dll
C:\Program Files\rizmxabe
C:\Program Files\rizmxabe\nixizuhe.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_UNPR
——-\UNPR


((((((((((((((((((((((((( Files Created from 2007-10-19 to 2007-11-19 )))))))))))))))))))))))))))))))
.

2007-11-16 09:52 58,368 –a—— C:\WINDOWS\NirCmd.exe
2007-11-16 09:26 81,984 –a—— C:\WINDOWS\system32\mcsvjxhj.dll
2007-11-16 09:23 85,056 –a—— C:\WINDOWS\system32\agxdvnma.dll
2007-11-16 08:54 d——– C:\WINDOWS\ERUNT
2007-11-15 19:31 3,094 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-15 09:12 79,936 –a—— C:\WINDOWS\system32\tjckgrif.dll
2007-11-15 09:09 85,056 –a—— C:\WINDOWS\system32\lthcwgnv.dll
2007-11-14 09:10 79,424 –a—— C:\WINDOWS\system32\jeoeoubq.dll
2007-11-14 09:07 85,056 –a—— C:\WINDOWS\system32\lxpnamqn.dll
2007-11-14 03:00 d——– C:\c57117a9cd66be78a498213d1341
2007-11-13 21:34 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-13 18:31 d——– C:\Documents and Settings\Renee Loiselle\Application Data\AdwareAlert
2007-11-13 18:25 20,480 ——— C:\Program Files\xloader10181.exe
2007-11-13 18:16 36,352 –a—— C:\WINDOWS\system32\jkkjjgh.dll
2007-11-13 11:24 d——– C:\Program Files\Comodo
2007-11-13 11:24 242,688 –a—— C:\WINDOWS\UNBOC.EXE
2007-11-13 11:24 208,896 –a—— C:\WINDOWS\CMDLIC.DLL
2007-11-13 09:16 80,448 –a—— C:\WINDOWS\system32\ptrrqqfs.dll
2007-11-13 09:13 88,128 –a—— C:\WINDOWS\system32\baqjfpcm.dll
2007-11-13 09:10 144,480 –a—— C:\WINDOWS\system32\vmdbpxrg.dll
2007-11-13 04:24 31,622 –a—— C:\WINDOWS\system32\ifvnptyk.exe
2007-11-12 22:48 d——– C:\Program Files\Virtual Earth 3D
2007-11-12 09:12 81,472 –a—— C:\WINDOWS\system32\tctisssh.dll
2007-11-11 20:26 d——– C:\e16f3d14460a32527faa
2007-11-11 09:06 79,936 –a—— C:\WINDOWS\system32\mwvhqyqr.dll
2007-11-11 04:10 2,432 –a—— C:\WINDOWS\system32\unpr.sys
2007-11-10 19:04 285,184 –a—— C:\WINDOWS\system32\LexBceS.exe
2007-11-10 19:04 201,728 –a—— C:\WINDOWS\system32\Lexp2p32.dll
2007-11-10 19:04 190,976 –a—— C:\WINDOWS\system32\lexlmpm.dll
2007-11-10 19:04 176,128 –a—— C:\WINDOWS\system32\Lexpps.exe
2007-11-10 19:04 175,104 –a—— C:\WINDOWS\system32\lex2kusb.dll
2007-11-10 19:04 135,168 –a—— C:\WINDOWS\system32\LexBce.dll
2007-11-10 19:04 79,872 –a—— C:\WINDOWS\system32\lex_psu.exe
2007-11-10 19:04 55,808 –a—— C:\WINDOWS\system32\Lexunst1.exe
2007-11-10 19:04 41,472 –a—— C:\WINDOWS\system32\ldeei.dll
2007-11-10 09:09 81,472 –a—— C:\WINDOWS\system32\ucvimryo.dll
2007-11-09 09:14 77,888 –a—— C:\WINDOWS\system32\mhynwqpc.dll
2007-11-09 09:11 88,128 –a—— C:\WINDOWS\system32\sxnonqay.dll
2007-11-08 09:08 86,080 –a—— C:\WINDOWS\system32\lodvpcac.dll
2007-11-07 09:11 79,936 –a—— C:\WINDOWS\system32\xqhcupsp.dll
2007-11-07 09:08 86,080 –a—— C:\WINDOWS\system32\fabmydeg.dll
2007-11-05 22:42 1,430,048 –a—— C:\WINDOWS\system32\AutoPartNt.exe
2007-11-05 22:36 d——– C:\Documents and Settings\All Users\Application Data\Seagate
2007-11-02 11:00 d——– C:\WINDOWS\SHELLNEW
2007-11-02 10:45 452,096 –a—— C:\WINDOWS\system32\fxsapi.dll
2007-11-02 10:45 452,096 –a–c— C:\WINDOWS\system32\dllcache\fxsapi.dll
2007-10-27 12:15 d——– C:\Program Files\Common Files\Wise Installation Wizard

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 20:31 ——— d—–w C:\Program Files\Linksys EasyLink Advisor
2007-11-10 22:04 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-11-07 04:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-10-07 01:54 392,320 —-a-w C:\WINDOWS\system32\drivers\timntr.sys
2007-10-07 01:54 32,768 —-a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
2007-10-07 01:54 120,992 —-a-w C:\WINDOWS\system32\drivers\snapman.sys
2007-10-07 01:54 ——— d—–w C:\Program Files\Common Files\Seagate
2007-10-07 01:53 ——— d—–w C:\Program Files\Seagate
2007-10-01 03:35 ——— d—–w C:\Program Files\BMCentral
2007-10-01 02:48 9,728 —-a-w C:\WINDOWS\_MSRSTRT.EXE
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2001-07-12 12:09 61,440 -c–a-w C:\WINDOWS\inf\i386\onetUSD.dll
2001-06-05 12:11 32,768 -c–a-w C:\WINDOWS\inf\i386\Wiamicro.dll
2001-05-14 14:19 51,984 -c–a-w C:\WINDOWS\inf\i386\Wiafbdrv.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\c57117a9cd66be78a498213d1341 —-

2007-11-14 03:00 788 –ah—– C:\c57117a9cd66be78a498213d1341\$shtdwn$.req
2007-11-02 00:19 801152 –a—— C:\c57117a9cd66be78a498213d1341\mrt.exe._p
2007-11-02 00:12 95864 –a—— C:\c57117a9cd66be78a498213d1341\mrtstub.exe

—- Directory of C:\e16f3d14460a32527faa —-

2007-09-27 22:19 95864 –a—— C:\e16f3d14460a32527faa\mrtstub.exe
2007-09-27 22:19 18089592 –a—— C:\e16f3d14460a32527faa\mrt.exe


((((((((((((((((((((((((((((( snapshot@2007-11-18_21.03.35.84 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 15:57:10 174,080 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2007-11-17 02:37:48 16,384 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-19 02:26:29 16,384 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-11-17 02:37:48 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-19 02:26:29 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-11-17 02:37:48 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-19 02:26:29 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50]
"HostManager"="C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe" [2007-04-12 16:23]
"Motive SmartBridge"="C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe" [2006-07-08 23:13]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-08 22:30]
"OneTouch Monitor"="C:\PROGRA~1\VISION~1\ONETOU~2.EXE" [2001-07-12 07:08]
"DiscWizardMonitor.exe"="C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2007-04-19 21:24]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [2007-04-19 21:38]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 21:29]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe" [2000-03-08 12:09]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPWebCap"="C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe" [2000-09-06 11:14]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 17:16]
"AdwareAlert"="C:\Program Files\AdwareAlert\AdwareAlert.exe" []
"AOL Fast Start"="C:\Program Files\AOL 9.0\AOL.exe" [2007-04-18 01:49]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-12-13 14:28:04]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-08-03 11:10:00]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 nwprovau relog_ap

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Broadband Support Center.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Broadband Support Center.lnk
backup=C:\WINDOWS\pss\Broadband Support Center.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailScan]
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
C:\Program Files\mcafee.com\antivirus\oasclnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sscRun]
C:\Program Files\Common Files\AOL\1152415670\ee\services\sscFirewallPlugin\ver1_205_1_1\SSCRun.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aolavupd"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"SCardSvr"=3 (0x3)
"SCardDrv"=3 (0x3)

R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R2 elagopro;GoProto Protocol Driver for LELA;C:\WINDOWS\system32\DRIVERS\elagopro.sys
R2 elaunidr;UniDriver for LELA;C:\WINDOWS\system32\DRIVERS\elaunidr.sys
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
S3 BOCDRIVE;BOClean Kernel Monitor.;\??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-18 08:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-18 21:27:43
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-18 21:29:47 - machine was rebooted
C:\ComboFix2.txt … 2007-11-18 21:04
C:\ComboFix3.txt … 2007-11-16 21:32
.
— E O F —
Logfile of HijackThis v1.99.1
Scan saved at 10:11:23 PM, on 11/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\VISION~1\ONETOU~2.EXE
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\AOL\1152415670\EE\aolsoftware.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Documents and Settings\Renee Loiselle\Desktop\Hijackthis\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~1\ONETOU~2.EXE
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - Startup: Check for OneTouch Updates.lnk = C:\Program Files\Visioneer OneTouch\WiseUpdt.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLaunc…iveLauncher.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1154124762625
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{C505CB0A-29F6-4582-8058-8E08509316EC}: NameServer = 71.243.0.12 71.250.0.12
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Program Files\Norman\Nvc\BIN\nipsvc.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
Hi

Renee6 Im afraid I may have bad news coming your way. I need you to follow the next instruction. If it begins to take hours and is finding hundreds of infected files, stop the scan and post the report it gives.

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select C:\Windows
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete.
Let me know your thoughts, Thank You Scotty, Sincerely Renee6 ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Monday, November 19, 2007 10:27:13 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 19/11/2007 Kaspersky Anti-Virus database records: 461543 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 42177 Number of viruses found: 11 Number of infected objects: 1943 Number of suspicious objects: 0 Duration of the scan process: 01:01:09 Infected Object Name / Virus Name / Last Action C:\aolextras\sm\sm3.exe Infected: Virus.Win32.Virut.av skipped C:\directx\dxsetup.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\AOL Explorer Screensaver\aexplore.scr Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\All Users\Application Data\AOL\AOLCoach\en_en\AdpTemp\BldLctn.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0\idb\Jpelc1998\mydb.idx Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0\idb\Jpelc1998\toolbar.lst Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0\idb\SNMaster.idx Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0\OptScan.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0\organize\CACHE\jpelc1901 Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0\organize\jpelc1998 Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0\organize\jpelc1998.abi Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0\organize\jpelc1998.aby Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstderr.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstdout.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aoltsmon.lock Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\cache.db Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\server.lock Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\3.0\aolstderr.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\3.0\aolstdout.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\3.0\cache.db Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\3.0\ncoc Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\3.0\server.lock Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\BFTS\BFTSDatabase.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL Downloads\aolcom_setupSTUS\comps\flash\flashax.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\All Users\Application Data\AOL Downloads\waol.4327.165.1\comps\vwpt\VPPrePop.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_3d001c_c53cb4d\Setup.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f1428131db5a7927a440928f4e11f49_01899df6-13d9-4c27-9961-82720d56058c Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\My Documents\New Folder\New Folder\crack.exe~ Infected: Trojan-Downloader.Win32.Agent.ejh skipped C:\Documents and Settings\LocalService\My Documents\New Folder\New Folder\install.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Renee Loiselle\Application Data\AOL\C_AOL 9.0\IDB\Apps.Lst Object is locked skipped C:\Documents and Settings\Renee Loiselle\Application Data\AOL\C_AOL 9.0\IDB\art.idx Object is locked skipped C:\Documents and Settings\Renee Loiselle\Application Data\AOL\C_AOL 9.0\IDB\sap.dat Object is locked skipped C:\Documents and Settings\Renee Loiselle\Application Data\AOL\C_AOL 9.0\IDB\spool.lst Object is locked skipped C:\Documents and Settings\Renee Loiselle\Application Data\AOL\C_AOL 9.0\IDB\sysnews.lst Object is locked skipped C:\Documents and Settings\Renee Loiselle\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\gdql_lsa_LinksysAgent.log Object is locked skipped C:\Documents and Settings\Renee Loiselle\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\glog.log Object is locked skipped C:\Documents and Settings\Renee Loiselle\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\LinksysAgent.log Object is locked skipped C:\Documents and Settings\Renee Loiselle\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\LinksysAgent_GTActions.log Object is locked skipped C:\Documents and Settings\Renee Loiselle\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Renee Loiselle\Desktop\Hijackthis\HijackThis.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Application Data\Wildtangent\CdacacheA03746C-E165-4493-ADF8-DACB1749355C\Racing.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Application Data\Wildtangent\CdacacheA03746C-E165-4493-ADF8-DACB1749355C\start.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Application Data\Wildtangent\Cdacache\D3B5D7A2-C079-4AED-9ACD-9576D2A05854\CutToTheBeat.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Temp\me_FevOxbJ6fZlRKFl Object is locked skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Temp\me_JoT53cYqpEFJ2N4 Object is locked skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Temp\me_W6UVQJbI487giYi Object is locked skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Temp\me_yXPPYRIEcDRi9LO Object is locked skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Temporary Internet Files\Content.IE5PUVGXQZ\blank[1].htm Infected: Worm.Win32.Mefir.p skipped C:\Documents and Settings\Renee Loiselle\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Renee Loiselle\My Documents\code for winzip 11.1.exe/data.rar/keygen.exe Infected: Trojan-Downloader.Win32.Small.gmx skipped C:\Documents and Settings\Renee Loiselle\My Documents\code for winzip 11.1.exe/data.rar/crack.exe Infected: Trojan-Downloader.Win32.Agent.dlu skipped C:\Documents and Settings\Renee Loiselle\My Documents\code for winzip 11.1.exe/data.rar/serial.exe Infected: Trojan.Win32.Dialer.qn skipped C:\Documents and Settings\Renee Loiselle\My Documents\code for winzip 11.1.exe/data.rar/install.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\code for winzip 11.1.exe/data.rar Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\code for winzip 11.1.exe RarSFX: infected - 5 skipped C:\Documents and Settings\Renee Loiselle\My Documents\desktop\crack.exe Infected: Trojan-Downloader.Win32.Agent.ejh skipped C:\Documents and Settings\Renee Loiselle\My Documents\desktop\install.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\desktop\keygen.exe Infected: Trojan-Downloader.Win32.Agent.dlu skipped C:\Documents and Settings\Renee Loiselle\My Documents\desktop\patch.exe~ Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\install.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\install.exe~ Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\dumphive.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\exit.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\GenericRenosFix.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\HostsChk.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\Process.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\Reboot.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\restart.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\SmiUpdate.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\swreg.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\swsc.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\swxcacls.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\unzip.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\My WinZip Files\SmitfraudFix\WS2Fix.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\Unzipped\keyfinder.2.0.beta.2.5[1]\keyfinder.exe Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\My Documents\winzip 11.1 code\install.exe~ Infected: Virus.Win32.Virut.av skipped C:\Documents and Settings\Renee Loiselle\ntuser.dat Object is locked skipped C:\Documents and Settings\Renee Loiselle\NTUSER.DAT.LOG Object is locked skipped C:\HASBRO\TONKA_RACEWAY\Uninstall_Tonka_Raceway.EXE Infected: Virus.Win32.Virut.av skipped C:\Program Files\Acer Inc\Acer GridVista\GridVistaU.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Acer Inc\Acer GridVista\GridVistaU64.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Adobe\Adobe Help Viewer\1.0\ahv.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Adobe\Reader 8.0\Reader\HowTo\ENU\version.html Infected: Worm.Win32.Mefir.p skipped C:\Program Files\AOL\Installers\ASP 2.0\postproc.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\AOL 9.0\AFLookup.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\AOL Deskbar\UNWISE.EXE Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Adobe\Help\en_US\Adobe Reader\8.0\version.html Infected: Worm.Win32.Mefir.p skipped C:\Program Files\Common Files\AOL\1152415670\EE\services\antiSpyware\ver2_4_6_1\resources\en-US\dat\PPClean.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AOL\1152415670\EE\services\browserapp\ver1_5001_7_1\resources\en-US\aexplore.scr Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AOL\ACS\InsHlp2k64.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AOL\CCU\anotify.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AOL\CCU\resetCCU.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AOL\uninstaller.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AOL\WinsockFix\en-US\WinsockFix.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\aolback\Comps\coach\aolcinst.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\aolback\Comps\flash\FlashAX.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\aolback\Comps\rp\realpl8.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\aolback\Comps\rp\real_upd.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\aolback\Comps\rp\rp9codec.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\aolback\Comps\vwpt\VPPrePop.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AolCoach\en_en\ab3.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AolCoach\en_en\AolCInUn.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AolCoach\en_en\player\tranplug.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AolCoach\en_en\SetSPath.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\AolCoach\en_en\upregcond.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\aolshare\aolreset.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05\launcher.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05\zipper.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_09.b03\launcher.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_09.b03\zipper.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_10.b03\launcher.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_10.b03\zipper.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Kodak\kodak_dr\inst_act.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Kodak\kodak_dr\KodakCCS.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Microsoft Shared\Speech\sapisvr.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Motive\InstallHelper.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Nullsoft\ActiveX\2.6\ProxyConfig.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Real\Update\rnuninst.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Real\Update\upgrdhlp.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\ScanSoft Shared\vizprint.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Seagate\CDRecord\cdrecord2.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Seagate\CDRecord\growisofs.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Seagate\CDRecord\readcd.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\InstallShield Installation Information\{25EF00BC-F17B-11D6-88EA-000476CD2443}\Setup.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\InstallShield Installation Information\{25EF00C5-F17B-11D6-88EA-000476CD2443}\Setup.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\InstallShield Installation Information\{25EF00C6-F17B-11D6-88EA-000476CD2443}\Setup.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\InstallShield Installation Information\{25EF00D1-F17B-11D6-88EA-000476CD2443}\Setup.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\InstallShield Installation Information\{25EF03DB-F17B-11D6-88EA-000476CD2443}\Setup.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\InstallShield Installation Information\{74C8BF56-6618-49AA-98BA-862223900CBF}\Setup.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Internet Explorer\Connection Wizard\icwconn2.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Internet Explorer\Connection Wizard\icwrmind.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Internet Explorer\Connection Wizard\icwtutor.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Internet Explorer\Connection Wizard\inetwiz.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Internet Explorer\Connection Wizard\isignup.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Internet Explorer\iedw.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Internet Explorer\iexplore.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Java\jre1.5.0_06\bin\java.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Java\jre1.5.0_06\bin\javacpl.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Java\jre1.5.0_06\bin\javaw.exe Infected: Virus.Win32.Virut.av skipped C:\Program Files\Java\jre1.5.0_06\bin\javaws.exe Infected: Virus.Win32.Virut.av skipped
Hi As I suspected, you have a Virut infection, which is a bad one. Virut infects the .exe files on the computer including the important Windows files. Normally the only way to clear this is by formatting your hard drive and reinstalling Windows. But I have been informed that F-Secures trial version has managed to clear this up once. It may depend on which files are infected. We can give that a go, but it may be best to have the Windows CD at hand in case you need to reinstall or repair the operating system. By the way, this infection is commonly picked up through websites where you download cracked and pirated software, and from what Ive seen of the KAV report, you have been doing just that. On the Internet, you really dont get something for nothing. Once you are up and running, I would strongly advise against visiting those sites, and instead look for freeware versions of the software you need. Let me know if you are ready to go.
Ready ! and a Great Big Thank You for your Expertise! I have my Windows CD ready just in case, and is anything salvagable in case I have to reinstall? like my photo's on kodak software, I have an external hard drive I can transfer them too, unless it will transfer a virus as well? please advise and Let's proceed! Renee6
Hi

You can transfer photos, music, just nothing that ends in .exe, which is an executable file. (what runs a program).

Try the F-Secure Anti-Virus evaluation. Click Here

Remember to uninstall your current anti-virus before installing F-Secure.

Run a full system scan.

Then run the Kaspersky Online Scan again. Use these instructions to scan the whole computer this time.

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete.


If you cannot boot the computer after running F-Secure, or have other problems and need to reinstall Windows, let me know you know how to first.
Will Do and Wish Me Luck! quick question in regards to reinstalling windows if I have too, do I need to reformat hard drive first ? or will it just reinstall over existing operating system? Renee6
Oh My! It just dawned on me, I am running two pc's on a network, if one is infected as it obviously is, does that mean the other one is as well? Renee6
Hi

I cant say for sure, but it could be possible. Run the first Kaspersky instruction, to scan the Windows folder on the other pc, and post the log.

Or if you see signs of Virut during scanning stop and let me know.
Hi scotty. ran the new kaspersky scan and 88 infected objects and 8 virus'es found I am trying to copy and paste now, but having a tough time. Renee6
It is telling me I don't have persmission to access file? "Windows cannot access the specified device, path or file. You may not have the appropiate permission to access the item" ? Saved the file to desktop like instructed? please advise. Renee
Scotty, just for clarification, I am still working on my main pc, I inquired about the other on a network, I will worry about that one, after I straitghten this one out first, so I ran a kaspersky scan and saved it to my desktop but I am unable to open it or paste and copy it to show you?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI