This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] W32.Trats!inf

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got this virus January 19, 2008. Not only am I a newbie/novice, but I failed to keep my virus software up-to-date. I did put down the sledgehammer, please help before I pick up a gun.

Here is my recollection of events. I was online when I got a popup from McAfee stating it had detected a Trojan Horse. I naively thought everything was cool. I began to get internet popups. I restarted my computer. Upon restart, some weird stuff started to happen. HP Product Assistant tried to load 5 or 6 times in row from the CD drive. (I have since performed a Windows Install Cleanup and removed the HP Product Assistant for now) I also got a message that Windows could not find C:\WINDOWS|system32\geedb.exe.

The most distressing thing is that I have a third party software program named ACT that I use in my business. This program will not load.

Here is what I have done to date: First, I stupidly attempted to do a System Restore. When that did not work I attempted a ASystem Recovery. Next, I downloaded Norton 360 and installed it on my computer. This has located the virus in question and deleted it more than once, along with some adware and other stuff it did not like. I have run quick scans, comprehensive scans both with Restore on and off. As I mentioned I did the Windows Install Cleanup to stop the HP Product Assistant annoyance. I have run Spybot S&D.

I am at my wits end and this has really affected my ability to perform my work since the ACT program has all of my customer contact information. I would really appreciate some help. Hopefully I have not screwed up too badly.

Thanks

Update….

While waiting for a response I decided to follow the advice in the "Self Help" area. I did the ATF Cleaner, SpyBot, AVG, and HijackThis. I have attached the AVG report and the HijackThis for your review.

Continuing problems: random IE popups/redirects, W32.Tratsinf continues to be found by Norton 360, Norton did not startup after a reboot and I had to manually start it up (the shortcut on the desktop did not work either), some weird window appears as the machine is shutting down-says something about referenced memory-can't read it in time before the machine cuts off, one time the whole desktop went blank for a few seconds and then came back, desktop icons do not stay where I put them and some other weird stuff that I can't remember.

Anyway, here are the reports and logs:

AVG Report

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 6:12:07 PM 1/24/2008

+ Scan result:



HKLM\SOFTWARE\Classes\WR -> Adware.Generic : Cleaned with backup (quarantined).
C:\Program Files\Temporary\kernInst.exe -> Trojan.Agent.dwb : Cleaned with backup (quarantined).


::Report end

HijackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:11:37 PM, on 1/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\BigFix\bigfix.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch…TB&M=MX6920
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssttq.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [089e76d7] rundll32.exe "C:\WINDOWS\system32\egdlfuuk.dll",b
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1181877720343
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 9022 bytes
Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net


2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
OK, I need for you to tell me how bad I screwed up. Somehow I managed to run Combofix direct from your link rather than saving to my desktop as instructed. It ran and generated a log which I saved in Notepad to my desktop. Should I post the log for you or should I run Combofix again, this time per your instructions?? Sorry about this, I know you are trying to help me and I'm not helping myself….
Here is the ComboFix log:

ComboFix 08-01-28.2 - Owner 2008-01-28 13:10:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.457 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\GCT543FI\ComboFix[1].exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\pmnomki.dll
C:\WINDOWS\system32\ssttq.dll
D:\Autorun.inf
C:\Documents and Settings\Owner.Reggie\Application Data\macromedia\Flash Player\#SharedObjects\KRLHQFP8\www.broadcaster.com
C:\Documents and Settings\Owner.Reggie\Application Data\macromedia\Flash Player\#SharedObjects\KRLHQFP8\www.broadcaster.com\played_list.sol
C:\Documents and Settings\Owner.Reggie\Application Data\macromedia\Flash Player\#SharedObjects\KRLHQFP8\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\Owner.Reggie\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Owner.Reggie\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Program Files\Temporary
C:\WINDOWS\system32\bdeeg.ini
C:\WINDOWS\system32\bdeeg.ini2
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\ddvwkvfk.ini
C:\WINDOWS\system32\egjlm.ini
C:\WINDOWS\system32\egjlm.ini2
C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini2
C:\WINDOWS\system32\hqyyoluy.dll
C:\WINDOWS\system32\jufqlnto.ini
C:\WINDOWS\system32\kuufldge.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\otnlqfuj.dll
C:\WINDOWS\system32\ousmeltq.ini
C:\WINDOWS\system32\pmnomki.dll
C:\WINDOWS\system32\qtlemsuo.dll
C:\WINDOWS\system32\qttss.ini
C:\WINDOWS\system32\qttss.ini2
C:\WINDOWS\system32\ssttq.dll
C:\WINDOWS\system32\usxhghvp.ini
C:\WINDOWS\system32\wvmvbsaj.ini
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_NTNDIS


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-28 )))))))))))))))))))))))))))))))
.

2008-01-24 21:11 . 2008-01-24 21:11 d——– C:\Program Files\Trend Micro
2008-01-24 17:34 . 2008-01-24 17:34 d——– C:\Documents and Settings\Owner.Reggie\Application Data\Grisoft
2008-01-24 17:33 . 2008-01-24 17:33 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-22 17:07 . 2008-01-22 17:07 8 -r-hs—- C:\WINDOWS\system32\2FEDDBE7A9.sys
2008-01-22 00:03 . 2008-01-22 17:19 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-21 21:24 . 2008-01-21 21:24 d——– C:\Program Files\Windows Installer Clean Up
2008-01-21 21:23 . 2008-01-21 21:23 d——– C:\Program Files\MSECACHE
2008-01-21 10:15 . 2008-01-24 17:28 308 –a—— C:\WINDOWS\wininit.ini
2008-01-21 09:32 . 2008-01-21 09:53 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-21 09:03 . 2008-01-21 09:03 d——– C:\Documents and Settings\Owner.Reggie\Application Data\Symantec
2008-01-21 08:00 . 2008-01-21 08:50 d——– C:\Program Files\Norton 360
2008-01-21 07:59 . 2008-01-21 08:38 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-21 07:59 . 2008-01-21 08:38 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-21 07:59 . 2008-01-21 08:38 10,740 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-21 07:59 . 2008-01-21 08:38 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-21 07:57 . 2008-01-21 08:38 d——– C:\Program Files\Symantec
2008-01-21 07:57 . 2008-01-28 11:27 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-21 07:54 . 2008-01-21 07:54 d——– C:\Documents and Settings\All Users\Symantec Temporary Files
2008-01-20 21:25 . 2008-01-20 21:25 2 –a—— C:\WINDOWS\msoffice.ini
2008-01-20 19:19 . 2008-01-20 21:33 118,784 –a—— C:\WINDOWS\system32\igfxpers .exe
2008-01-20 19:19 . 2008-01-20 21:33 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2008-01-20 19:19 . 2008-01-20 21:33 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2008-01-20 14:03 . 2008-01-21 15:38 d——– C:\Program Files\Dot1XCfg
2008-01-09 19:07 . 2008-01-21 15:53 d——– C:\Program Files\PartyGaming
2007-12-29 23:32 . 2007-12-29 23:32 d——– C:\Documents and Settings\Owner.Reggie\Application Data\CyberLink
2007-12-29 23:32 . 2007-12-29 23:32 d——– C:\Documents and Settings\All Users\Application Data\CyberLink

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-28 17:56 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-28 17:50 ——— d—–w C:\Program Files\Norton Security Scan
2008-01-22 12:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-01-22 12:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-01-22 04:04 ——— d—–w C:\Program Files\ACT
2008-01-21 15:33 ——— d—–w C:\Program Files\iTunes
2008-01-21 14:15 ——— d—–w C:\Program Files\QuickTime
2008-01-21 02:32 ——— d—–w C:\Program Files\Pure Networks
2008-01-21 02:29 ——— d—–w C:\Program Files\Napster
2008-01-21 02:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Napster
2008-01-21 02:25 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-21 02:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-22 19:19 ——— d—–w C:\Program Files\Master of Defense
2007-12-22 18:08 ——— d—–w C:\Program Files\KingdomElemental_at
2007-12-22 17:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-01 04:57 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-30 23:39 ——— d—–w C:\Program Files\Mario Forever
2007-01-04 00:12 0 —-a-w C:\Documents and Settings\Owner.Reggie\Application Data\wklnhst.dat
2007-02-02 15:56 88 –sh–r C:\WINDOWS\system32\2854082939.sys
.
—-a-w			 9,728 2008-01-21 02:33:51  C:\Program Files\ACT\Act for Windows\Act.Outlook.Service .exe
—-a-w		 1,015,808 2008-01-21 12:26:39  C:\Program Files\ACT\Act for Windows\ActSage .exe
—-a-w		   313,472 2008-01-21 02:34:20  C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
—-a-w		   329,008 2008-01-21 02:19:06  C:\Program Files\Boingo\GoBoingo\GoBoingo .exe
—-a-w		   622,592 2008-01-21 02:34:02  C:\Program Files\Brother\Brmfcmon\BrMfcWnd .exe
—-a-w			49,152 2008-01-21 02:34:03  C:\Program Files\Brother\Brmfl06b\BrStDvPt .exe
—-a-w			77,824 2008-01-21 02:34:04  C:\Program Files\Brother\ControlCenter3\brctrcen .exe
—-a-w		   125,528 2008-01-21 02:25:30  C:\Program Files\Common Files\AOL\1152074312\EE\AOLHostManager .exe
—-a-w		   125,528 2008-01-21 02:18:39  C:\Program Files\Common Files\AOL\1152074312\EE\AOLHOS~1 .EXE
—-a-w		   185,896 2008-01-21 02:33:49  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w		   155,648 2008-01-21 02:33:57  C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdupdate .exe
—-a-w		   116,072 2008-01-22 22:19:28  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			68,856 2008-01-21 02:34:12  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w			49,152 2008-01-21 02:33:53  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   139,264 2008-01-21 02:33:31  C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe
—-a-w		   602,182 2008-01-21 02:33:43  C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
—-a-w		   667,718 2008-01-21 02:33:40  C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe
—-a-w		   271,672 2008-01-21 02:34:06  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		 1,694,208 2008-01-21 13:51:31  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   286,720 2008-01-21 02:34:05  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   286,720 2008-01-21 20:42:52  C:\Program Files\QuickTime\qttask  .exe
—-a-w			40,960 2008-01-21 02:34:01  C:\Program Files\ScanSoft\PaperPort\IndexSearch .exe
—-a-w			57,393 2008-01-21 02:33:59  C:\Program Files\ScanSoft\PaperPort\pptd40nt .exe
—-a-w		   688,218 2008-01-21 02:33:30  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
—-a-w			98,394 2008-01-21 02:33:27  C:\Program Files\Synaptics\SynTP\SynTPLpr .exe
—-a-w		 4,670,968 2008-01-21 02:34:36  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
—-a-w			64,512 2008-01-21 02:33:29  C:\WINDOWS\ehome\ehtray .exe
—-a-w			15,360 2008-01-22 22:19:29  C:\WINDOWS\system32\ctfmon .exe
—-a-w			77,824 2008-01-21 02:33:33  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   118,784 2008-01-21 02:33:35  C:\WINDOWS\system32\igfxpers .exe
—-a-w			94,208 2008-01-21 02:33:32  C:\WINDOWS\system32\igfxtray .exe


– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4



Here is the latest HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:49:47 PM, on 1/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\BigFix\bigfix.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch…TB&M=MX6920
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13AC3E3F-209A-42C1-99F9-C59ABA9C883A} - C:\WINDOWS\system32\geedb.dll (file missing)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: (no name) - {2878595C-C6E2-4A89-A642-41A2E382C790} - C:\WINDOWS\system32\mljgf.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O2 - BHO: (no name) - {E90C406B-4E7F-4869-A55D-B00515B79A10} - C:\WINDOWS\system32\mljge.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1181877720343
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 9929 bytes
I cannot stress how important this is!!
So as a first step, please read the instructions again how to install the Recovery Console:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix
I am being very careful. First I saved ComboFix to my desktop which I downloaded from bleepingcomputer. Next, I went to the Microsoft site by clicking the bleepingcomputer link to get the recovery console installed. I verified which operating system I have and it shows Windows XP Media Center Edition Version 2002 Service Pack 2. I selected the Windows XP Home Edition SP2 download from Microsoft and saved it to my desktop. The next step tells me to drag the Microsoft file on to the ComboFix icon and release. Combo fix is supposed to automatically install the Windows Recovery Console. That's where I have a question. Mine does not automatically install, instead, I get the Windows Open File Security Warning. I have not proceeded from here because I am unsure as to whether ComboFix is going to run immediately or if Windows Recovery Console is going to install. Is Windows XP Media Center SP2 the same as Windows XP Home Edition SP2? Do I have the correct Windows file to drag on ComboFix to install the Windows Recovery Console? The icon reads "Windows XP-KB310994-SP2-Home-BootDisk-ENU" The file description reads "Win32 Cabinet Self-Extractor" Lastly, I have not had the same issues that I described in my earlier posts since I mistakenly ran ComboFix. My computer seems to be operating normally. I'm not suggesting that it is fixed yet but I did want you to be aware that so far, I have not had the IE popups/redirects and Norton has not picked up the W32.Trats!inf virus again. Thanks for your patience. I am not going to proceed further until you direct me to do so.
This is a quick update regarding my infection…I still have not yet installed the Recovery Console (see previous message). I am, however, using the computer in my business and so far everything seems to be normal. Since I am using the computer and the internet, I remain concerned that I may still be infected. I have run complete scans with Spybot, AVG and Norton 360. All have returned nothing of concern so far. I will await further instructions regarding the Recovery Console. Thanks for your efforts.
Little Eagle, Did I explain my dilemma regarding the ComboFix auto startup clearly? Please read my January 29, 2008 post and let me know how to proceed. By the way, everything still seems to be normal on my computer. Thanks

By the way, everything still seems to be normal on my computer.

I would like to see the recovery console installed. :thumbup:
There are still infected files on your PC.
I do not want to use combo fix untill you have a recovery console installed.

Lets see what this finds.
Run this online scan from ESET

You will need to use Internet explorer for this scan!
  • First, accept the Terms of Use
  • Click: Start
  • When asked, allow the ActiveX control to install
  • Click: Start
  • Make sure the options:
    Remove found threats, and Scan unwanted applications
    are both checked!
  • Click: Scan

When the scan finishes, use Notepad to open the ESET report.
It will be located here C:\Program Files\EsetOnlineScanner\log.txt
little eagle, I ran ESET and here is a copy of the log: # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=2867 (20080212) # vers_arch_module=1.063 (20080117) # vers_adv_heur_module=1.060 (20070601) # EOSSerial=1fe4400d8942d24fa1b3f090254bcf10 # end=finished # remove_checked=true # unwanted_checked=true # utc_time=2008-02-12 01:11:28 # local_time=2008-02-12 08:11:28 (-0500, Eastern Standard Time) # country="United States" # osver=5.1.2600 NT Service Pack 2 # scanned=325384 # found=6 # scan_time=3753 C:\Downloads\PraetoriansSetup-dm[1].exe Win32/Adware.Trymedia application (unable to clean - deleted) 00000000000000000000000000000000 C:\Program Files\PartyGaming\vvqq.exe Win32/Adware.ISM application (deleted) 00000000000000000000000000000000 C:\Program Files\PartyGaming\vvqq.exe »NSIS »QdrDrive9.dll Win32/Adware.ISM application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\QooBox\Quarantine\catchme2008-01-28_131606.59.zip Win32/Adware.Virtumonde application (deleted) 00000000000000000000000000000000 C:\QooBox\Quarantine\catchme2008-01-28_131606.59.zip »ZIP »pmnomki.dll Win32/Adware.Virtumonde application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\QooBox\Quarantine\C\WINDOWS\system32\hqyyoluy.dll.vir Win32/BHO.G trojan (unable to clean - deleted) 00000000000000000000000000000000 Also, while ESET was running, my Norton 360 kicked in and located Trojan.Vundo. I delayed running th Norton fix until ESET had completed. After ESET ran complete, I did run the Norton fix and rebooted. I will wait for further instructions. Thanks
Open notepad and copy/paste the text in the codebox below into it:

[b]RenV::[/b]
C:\Program Files\ACT\Act for Windows\Act.Outlook.Service .exe
C:\Program Files\ACT\Act for Windows\ActSage .exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
C:\Program Files\Boingo\GoBoingo\GoBoingo .exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd .exe
C:\Program Files\Brother\Brmfl06b\BrStDvPt .exe
C:\Program Files\Brother\ControlCenter3\brctrcen .exe
C:\Program Files\Common Files\AOL\1152074312\EE\AOLHostManager .exe
C:\Program Files\Common Files\AOL\1152074312\EE\AOLHOS~1 .EXE
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdupdate .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\Messenger\msmsgs .exe
C:\Program Files\QuickTime\qttask   .exe
C:\Program Files\QuickTime\qttask  .exe
C:\Program Files\ScanSoft\PaperPort\IndexSearch .exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt .exe
C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
C:\Program Files\Synaptics\SynTP\SynTPLpr .exe
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\WINDOWS\ehome\ehtray .exe
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\igfxpers .exe
C:\WINDOWS\system32\igfxtray .exe

Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
little eagle,

The ComboFix program that I previously downloaded per your link has now expired. I know that I can get it from bleepingcomputer but my question is should I run it based on your previous instructions from January 28 as follows:

Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.


1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
Remember to re enable the protection again afterwards before connecting to the net



2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.

IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.


3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.


Just to refresh your memory - I ran ComboFix once before but did not follow your instructions correctly. I also do not have the Recovery Console installed on my computer yet as well. Just want to make sure before I proceed.

Thanks

I ran ComboFix once before but did not follow your instructions correctly. I also do not have the Recovery Console installed on my computer yet as well. Just want to make sure before I proceed.

Download then install the recovery console. Run combofix and post the log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI