Funny, but the IE changes I had made before and were still there. The View Folder Options changes I had made before to see all those things were already changed back to the (default?) settings you recommended.
Do the IE changes apply to Mozilla Firefox, too?
I'll keep an eye on things and let you know how it's running.
Well,….i just walked into the room and that calculator was pulled up again. Also, my wife said that while logged onto AOL and playing a game, aol log-on screen came up by itself. I guess we're not out of the woods yet.
* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Doubleclick the drweb-cureit.exe file and Allow to run the express scan
This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
Once the short scan has finished, mark the drives that you want to scan.
Select all drives. A red dot shows which drives have been chosen.
Click the green arrow at the right, and the scan will start.
Click 'Yes to all' if it asks if you want to cure/move the file.
When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
If so, click it and then click the next icon right below and select Move incurable as you'll see in next image: [external image: Posted Image]
This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.
Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
I ran AimFix and it found and disabled and deleted NPKCSVC Service and quarantined c:\WINDOWS\system32\NPKCSVC.exe.
Then I rebooted. It said a reboot was needed to finish doing it's job.
Any other ideas on things to do?
I haven't even tried to access any AOL products. Do you think it would be worth uninstalling all of it (saving the user data) and reloading from a CD or a fresh download?
Also, should i dump the restore files by turning off the feature and then turn it on again after a reboot?
Any need for a new HJT log or start-up list?
Here is the AIMFix Note:
AIMFix version: 1.6.1220.935 (Dec 20 2007 09:35:55)
SeDebug Privilege set successfully
***ANY VIRUS FILES REMOVED WILL BE LISTED BELOW***
BlockRemove(): Now checking for Block-Checker: .5
BlockRemove(): Block-Checker not found
IMNamesRemove(): Now checking for IMNames: .2
IMNamesRemove(): IM Names not found
ServiceExists(): Found service npkcsvc
StopService(): failed on call to ControlService() for "npkcsvc": The service has not been started.
KillService(): Unable to stop service, trying kill
Service npkcsvc successfully disabled
Service npkcsvc successfully deleted
Now attempting quarantine of "npkcsvc" executable: C:\WINDOWS\system32\npkcsvc.exe
File::Quarantine(): attempting to quarantine C:\WINDOWS\system32\npkcsvc.exe
quarantine(): C:\WINDOWS\system32\npkcsvc.exe quarantined
CleanMstc(): mstc not found
***RUN COMPLETED. ANY FILES REMOVED LISTED ABOVE***
———————————————————-
I ran Dr.Web CureIt again. Here is the file:
A0001470.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0001471.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0001472.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0001473.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0001474.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0001475.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0001476.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0001477.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0001478.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0001479.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0001480.dll;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably DLOADER.Trojan;Incurable.Moved.;
A0001481.ocx;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Adware.Gdown;Incurable.Moved.;
A0001482.dll;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably DLOADER.Trojan;Incurable.Moved.;
Looks like they were all in that restore file, so I turned off system restore - no sense keeping what I don't want to go back to.
I suggest you now create a new clean System Restore.
You need to create a new Clean restore point.
Note: This will remove all previous Restore Points
Click Start Menu > Run > copy and paste
%SystemRoot%\System32\restore\rstrui.exe
Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab. Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders." Check "Hide protected operating system files."
Click Apply, and then click OK.