This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Antivirus 2008..and more?

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here's some suggestions to repair your Internet connection.

Near the clock, there will be dual or single monitor icon. Right click on it and select Repair.
Image for reference
If this icon isn't present, do the following:
1. Click on Start > Control Panel and double click on Network Connections.
2. Under LAN or High-Speed Internet, right click on your connection and click on Repair.

Alternatively

Copy & paste the contents of the Code box below into Notepad:
ipconfig.exe /renew
pause
Click on File > Save As…. & save the file to your desktop
In the File Name box, copy & paste in FixConnections.bat
In the Save As Type box, select All Files from the drop-down list
Click Save.
Double click on FixConnections.bat to run it. A Command Prompt will open and run. In a short while, you will see this message if everything goes fine:

Press any key to continue . . .

Just press any key to exit.

If there are any errors, please let me know.
Well thanks for the suggestions but I tried out both alternatives and still no luck :( . it's kind of hard to believe too..since everything looks perfectly fine when it comes to settings, and i've made sure no security programs were interfering. I doubt it's combofix either, but maybe it's possible? when I was searching around for answers to the problem, in most cases it was a deletion from some type of anti-spyware program. I'm not saying it's you but with the program itself.

anyways when it comes to the virus, I'm pretty sure nothing really changed, but heres another log just incase:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:35:15 PM, on 9/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…DTP&M=W3622
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 4441 bytes
Hello MikeJones
We'll come back to the Internet connection issue shortly but first I need you to check some files.
Your last HijackThis log was clean, however there are a couple of files that Combofix flagged that need to be verified. So please do this:
View Hidden Files & Folders Windows XP
To view Hidden Files & Folders do the following:
Click Start
Open My Computer
Select the Tools menu and click Folder Options
Select the View Tab
Under the Hidden files and folders heading select Show hidden files and folders
Uncheck the Hide protected operating system files (recommended) option
Click Yes to confirm
Click OK

  • Create a new folder on your desktop by right-clicking anywhere, scroll down to New then click Folder
  • Name it something like Upload
  • Navigate to C:\WINDOWS\explorer.exe, right click on explorer.exe then click Copy
  • Go back to the Upload folder you created on your desktop, open it then right-click & select Paste
  • Following the instructions above do the same for:
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\userinit.exe
  • When finished you should have copies of the three files in the desktop folder.
The following instructions will require an Internet connection, so you may need to copy the folder to a computer with a working Internet connection.

Upload Files for Scanning
Go to VirusTotal or Jotti
(Just use one or the other. No need to use both.)

If you use VirusTotal click Browse
In the Choose File box that opens navigate to your Upload folder, open it & double click Explorer.exe
Then click Send File
Wait for scans to finish then copy & paste the results into your next reply
Following the instructions above do the same for:
ctfmon.exe
userinit.exe

If you use Jotti click Browse
In the Choose File box that opens navigate to your Upload folder, open it & double click Explorer.exe
Then click Submit
Wait for scans to finish then copy & paste the results into your next reply
Following the instructions above do the same for:
ctfmon.exe
userinit.exe
Here's the results:



Log for explorer:

Antivirus/Version/Result

AhnLab-V3 / 2008.9.23.1 / Win32/Virut.Gen

AntiVir / 7.8.1.34 / W32/Virut.BL

Authentium / 5.1.0.4 / -

Avast / .8.1195.0 / Win32:Virtob

AVG / 8.0.0.161 / -

BitDefender / 7.2 / Win32.Virut.K

CAT-QuickHeal / 9.50 / -

ClamAV / 0.93.1 / W32.Virut-27

DrWeb / 4.44.0.09170 / Win32.Virut.40

eSafe / 7.0.17.0 / -

eTrust-Vet / 1.6.6101 / -

Ewido / 4.0 / -

F-Prot / 4.4.4.56 / W32/Patched.E.gen!Eldorado

F-Secure / 8.0.14332.0 / Virus.Win32.Virut.bq

Fortinet / 3.113.0.0 / W32/Virut.BQ

GData / 19 / Win32.Virut.K

Ikarus / T3.1.1.34.0 / Trojan.Win32.Patched.ai

K7AntiVirus / 7.10.469 / Trojan.Win32.Patched.ai

Kaspersky / 7.0.0.125 / Virus.Win32.Virut.bq

McAfee / 5390 / W32/Virut.j

Microsoft / 1.3903 / Virus:Win32/Virut.AI

NOD32v2 / 3466 / Win32/Virut.NBF

Norman / 5.80.02 / W32/Virut.BN

Panda / 9.0.0.4 / -

PCTools / 4.4.2.0 / -

Prevx1 / V2 / -

Rising / 20.63.12.00 / -

Sophos / 4.33.0 / W32/Virut-Gen

Sunbelt / 3.1.1662.1 / -

Symantec / 10 / W32.Virut.W

TheHacker / 6.3.0.9.091 / -

TrendMicro / 8.700.0.1004 / PE_VIRUT.LJ

VBA32 / 3.12.8.5 / -

ViRobot / 2008.9.23.1389 / -

VirusBuster / [removed] / Win32.Virut.Gen.4

Webwasher-Gateway / 6.6.2 / Win32.Virut.BL



Additional information
File size: 1039872 bytes
MD5…: 6beed988649566e49c3fb63dec564c3c
SHA1..: db70e8e405d87bcd384ed528e2b05e5728d379a0
SHA256: d232edca26b63c529198cbdae6fa932e6a02dd4954db3e99cae233da4b35a540
SHA512: 4859507177c4d66d7b446f8bf57798a4907a77b8e4b61f98d9c99f96c5201cc8
db88ea713f11005448262269a5201797a4dafa1d9a434f72af1ee2ed6b1ec8a2
PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x10fe800
timedatestamp…..: 0x41107ece (Wed Aug 04 06:14:38 2004)
machinetype…….: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x44689 0x44800 6.38 b257b3cd7102cece46cd7366aff0f34b
.data 0x46000 0x1d90 0x1800 1.29 d0b87d8ce5a34731be197efb73b5d7bf
.rsrc 0x48000 0xb2278 0xb2400 6.63 abf6dc1befe1a4a4c7f6ef51d1a6f907
.reloc 0xfb000 0xa800 0x5600 7.29 e248d45890a81ebc9cc28d5af0848def

( 13 imports )
> msvcrt.dll: _itow, free, memmove, realloc, _except_handler3, malloc, _ftol, _vsnwprintf
> ADVAPI32.dll: RegSetValueW, RegEnumKeyExW, GetUserNameW, RegNotifyChangeKeyValue, RegEnumValueW, RegQueryValueExA, RegOpenKeyExA, RegEnumKeyW, RegCloseKey, RegCreateKeyW, RegQueryInfoKeyW, RegOpenKeyExW, RegQueryValueExW, RegCreateKeyExW, RegSetValueExW, RegDeleteValueW, RegQueryValueW
> KERNEL32.dll: GetSystemDirectoryW, CreateThread, CreateJobObjectW, ExitProcess, SetProcessShutdownParameters, ReleaseMutex, CreateMutexW, SetPriorityClass, GetCurrentProcess, GetStartupInfoW, GetCommandLineW, SetErrorMode, LeaveCriticalSection, EnterCriticalSection, ResetEvent, LoadLibraryExA, CompareFileTime, GetSystemTimeAsFileTime, SetThreadPriority, GetCurrentThreadId, GetThreadPriority, GetCurrentThread, GetUserDefaultLangID, Sleep, GetBinaryTypeW, GetModuleHandleExW, SystemTimeToFileTime, GetLocalTime, GetCurrentProcessId, GetEnvironmentVariableW, UnregisterWait, GlobalGetAtomNameW, GetFileAttributesW, MoveFileW, lstrcmpW, LoadLibraryExW, FindClose, FindNextFileW, FindFirstFileW, lstrcmpiA, SetEvent, AssignProcessToJobObject, GetDateFormatW, GetTimeFormatW, FlushInstructionCache, lstrcpynW, GetSystemWindowsDirectoryW, SetLastError, GetProcessHeap, HeapFree, HeapReAlloc, HeapSize, HeapAlloc, GetUserDefaultLCID, ReadProcessMemory, OpenProcess, InterlockedCompareExchange, LoadLibraryA, QueryPerformanceCounter, UnhandledExceptionFilter, SetUnhandledExceptionFilter, VirtualFree, VirtualAlloc, ResumeThread, TerminateProcess, TerminateThread, GetSystemDefaultLCID, GetLocaleInfoW, CreateEventW, GetLastError, RegisterWaitForSingleObject, OpenEventW, WaitForSingleObject, GetTickCount, ExpandEnvironmentStringsW, GetModuleFileNameW, GetPrivateProfileStringW, lstrcmpiW, CreateProcessW, FreeLibrary, GetWindowsDirectoryW, LocalAlloc, CreateFileW, DeviceIoControl, LocalFree, GetQueuedCompletionStatus, CreateIoCompletionPort, SetInformationJobObject, CloseHandle, LoadLibraryW, GetModuleHandleW, ActivateActCtx, DeactivateActCtx, DelayLoadFailureHook, GetProcAddress, DeleteCriticalSection, CreateEventA, HeapDestroy, InitializeCriticalSection, GetFileAttributesExW, MulDiv, lstrlenW, InterlockedDecrement, InterlockedIncrement, GlobalAlloc, InterlockedExchange, GetModuleHandleA, GetVersionExA, GlobalFree, GetProcessTimes, lstrcpyW, GetLongPathNameW, InitializeCriticalSectionAndSpinCount
> GDI32.dll: GetStockObject, CreatePatternBrush, OffsetViewportOrgEx, GetLayout, CombineRgn, CreateDIBSection, GetTextExtentPoint32W, StretchBlt, SetTextColor, CreateRectRgn, GetClipRgn, IntersectClipRect, GetViewportOrgEx, SetViewportOrgEx, SelectClipRgn, PatBlt, GetBkColor, CreateCompatibleDC, CreateCompatibleBitmap, OffsetWindowOrgEx, DeleteDC, SetBkColor, BitBlt, ExtTextOutW, GetTextExtentPointW, GetClipBox, GetObjectW, CreateRectRgnIndirect, SetBkMode, CreateFontIndirectW, DeleteObject, GetTextMetricsW, SelectObject, GetDeviceCaps, TranslateCharsetInfo, SetStretchBltMode
> USER32.dll: TileWindows, GetDoubleClickTime, GetSystemMetrics, GetSysColorBrush, AllowSetForegroundWindow, LoadMenuW, GetSubMenu, RemoveMenu, SetParent, GetMessagePos, CheckDlgButton, EnableWindow, GetDlgItemInt, SetDlgItemInt, CopyIcon, AdjustWindowRectEx, DrawFocusRect, DrawEdge, ExitWindowsEx, WindowFromPoint, SetRect, AppendMenuW, LoadAcceleratorsW, LoadBitmapW, SendNotifyMessageW, SetWindowPlacement, CheckMenuItem, EndDialog, SendDlgItemMessageW, MessageBeep, GetActiveWindow, PostQuitMessage, MoveWindow, GetDlgItem, RemovePropW, GetClassNameW, GetDCEx, SetCursorPos, ChildWindowFromPoint, ChangeDisplaySettingsW, RegisterHotKey, UnregisterHotKey, SetCursor, SendMessageTimeoutW, GetWindowPlacement, LoadImageW, SetWindowRgn, IntersectRect, OffsetRect, EnumDisplayMonitors, RedrawWindow, SubtractRect, TranslateAcceleratorW, WaitMessage, InflateRect, CallWindowProcW, GetDlgCtrlID, SetCapture, LockSetForegroundWindow, CopyRect, SystemParametersInfoW, FindWindowW, CreatePopupMenu, GetMenuDefaultItem, DestroyMenu, GetShellWindow, EnumChildWindows, GetWindowLongW, SendMessageW, RegisterWindowMessageW, GetKeyState, MonitorFromRect, MonitorFromPoint, RegisterClassW, SetPropW, GetWindowLongA, SetWindowLongW, FillRect, GetCursorPos, PtInRect, MessageBoxW, LoadStringW, ReleaseDC, GetDC, EnumDisplaySettingsExW, EnumDisplayDevicesW, PostMessageW, DispatchMessageW, TranslateMessage, GetMessageW, PeekMessageW, BeginPaint, EndPaint, SetWindowTextW, GetAsyncKeyState, InvalidateRect, GetWindow, ShowWindowAsync, TrackPopupMenuEx, UpdateWindow, DestroyIcon, IsRectEmpty, SetActiveWindow, GetSysColor, DrawTextW, IsHungAppWindow, SetTimer, GetMenuItemID, TrackPopupMenu, EndTask, SendMessageCallbackW, GetClassLongW, LoadIconW, OpenInputDesktop, CloseDesktop, SetScrollPos, ShowWindow, BringWindowToTop, GetDesktopWindow, CascadeWindows, CharUpperBuffW, SwitchToThisWindow, InternalGetWindowText, GetScrollInfo, GetMenuItemCount, ModifyMenuW, CreateWindowExW, DialogBoxParamW, MsgWaitForMultipleObjects, CharNextA, RegisterClipboardFormatW, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, PrintWindow, SetClassLongW, GetPropW, GetNextDlgGroupItem, GetNextDlgTabItem, ChildWindowFromPointEx, IsChild, NotifyWinEvent, TrackMouseEvent, GetCapture, GetAncestor, CharUpperW, SetWindowLongA, DrawCaption, InsertMenuW, IsWindowEnabled, GetMenuState, LoadCursorW, GetParent, IsDlgButtonChecked, DestroyWindow, EnumWindows, IsWindowVisible, GetClientRect, UnionRect, EqualRect, GetWindowThreadProcessId, GetForegroundWindow, KillTimer, GetClassInfoExW, DefWindowProcW, RegisterClassExW, GetIconInfo, SetScrollInfo, GetLastActivePopup, SetForegroundWindow, IsWindow, GetSystemMenu, IsIconic, IsZoomed, EnableMenuItem, SetMenuDefaultItem, MonitorFromWindow, GetMonitorInfoW, GetWindowInfo, GetFocus, SetFocus, MapWindowPoints, ScreenToClient, ClientToScreen, GetWindowRect, SetWindowPos, DeleteMenu, GetMenuItemInfoW, SetMenuItemInfoW, CharNextW
> ntdll.dll: RtlNtStatusToDosError, NtQueryInformationProcess
> SHLWAPI.dll: StrCpyNW, -, -, -, -, StrRetToBufW, StrRetToStrW, -, -, -, -, SHQueryValueExW, PathIsNetworkPathW, -, AssocCreate, -, -, -, -, -, StrCatW, StrCpyW, -, -, -, -, -, -, -, SHGetValueW, -, StrCmpNIW, PathRemoveBlanksW, PathRemoveArgsW, PathFindFileNameW, StrStrIW, PathGetArgsW, -, StrToIntW, SHRegGetBoolUSValueW, SHRegWriteUSValueW, SHRegCloseUSKey, SHRegCreateUSKeyW, SHRegGetUSValueW, SHSetValueW, -, PathAppendW, PathUnquoteSpacesW, -, -, PathQuoteSpacesW, -, SHSetThreadRef, SHCreateThreadRef, -, -, -, PathCombineW, -, -, -, SHStrDupW, PathIsPrefixW, PathParseIconLocationW, AssocQueryKeyW, -, AssocQueryStringW, StrCmpW, -, -, -, -, -, -, -, -, SHRegQueryUSValueW, SHRegOpenUSKeyW, SHRegSetUSValueW, PathIsDirectoryW, PathFileExistsW, PathGetDriveNumberW, -, StrChrW, PathFindExtensionW, -, -, PathRemoveFileSpecW, PathStripToRootW, -, -, -, SHOpenRegStream2W, -, -, -, StrDupW, SHDeleteValueW, StrCatBuffW, SHDeleteKeyW, StrCmpIW, -, -, wnsprintfW, -, StrCmpNW, -, -
> SHELL32.dll: -, SHGetFolderPathW, -, -, -, -, -, ExtractIconExW, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, ShellExecuteExW, -, -, -, -, -, -, -, SHBindToParent, -, -, -, SHParseDisplayName, -, -, -, -, -, -, SHGetSpecialFolderLocation, -, -, -, -, SHGetSpecialFolderPathW, -, -, -, -, -, SHChangeNotify, SHGetDesktopFolder, SHAddToRecentDocs, -, -, -, DuplicateIcon, -, -, -, -, -, -, -, -, SHUpdateRecycleBinIcon, SHGetFolderLocation, SHGetPathFromIDListA, -, -, -, -, -, -, -, SHGetPathFromIDListW, -, -, -
> ole32.dll: CoFreeUnusedLibraries, RegisterDragDrop, CreateBindCtx, RevokeDragDrop, CoInitializeEx, CoUninitialize, OleInitialize, CoRevokeClassObject, CoRegisterClassObject, CoMarshalInterThreadInterfaceInStream, CoCreateInstance, OleUninitialize, DoDragDrop
> OLEAUT32.dll: -, -
> BROWSEUI.dll: -, -, -, -
> SHDOCVW.dll: -, -, -
> UxTheme.dll: GetThemeBackgroundContentRect, GetThemeBool, GetThemePartSize, DrawThemeParentBackground, OpenThemeData, DrawThemeBackground, GetThemeTextExtent, DrawThemeText, CloseThemeData, SetWindowTheme, GetThemeBackgroundRegion, -, GetThemeMargins, GetThemeColor, GetThemeFont, GetThemeRect, IsAppThemed

( 0 exports )





Log For Ctfmon:

AhnLab-V3 / 2008.9.23.1 / Win32/Virut.Gen

AntiVir / 7.8.1.34 / W32/Virut.BL

Authentium / 5.1.0.4 / -

Avast / .8.1195.0 / Win32:Virtob

AVG / 8.0.0.161 / -

BitDefender / 7.2 / Win32.Virut.K

CAT-QuickHeal / 9.50 / -

ClamAV / 0.93.1 / W32.Virut-27

DrWeb / 4.44.0.09170 / Win32.Virut.40

eSafe / 7.0.17.0 / -

eTrust-Vet / 1.6.6101 / -

Ewido / 4.0 / -

F-Prot / 4.4.4.56 / -

F-Secure / 8.0.14332.0 / Virus.Win32.Virut.bq

Fortinet / 3.113.0.0 / W32/Virut.BQ

GData / 19 / Win32.Virut.K

Ikarus / T3.1.1.34.0 / Trojan.Win32.Anomaly.D

K7AntiVirus / 7.10.469 / Virus.Win32.Virut.LJ

Kaspersky / 7.0.0.125 / Virus.Win32.Virut.bq

McAfee / 5390 / W32/Virut.j

Microsoft / 1.3903 / Virus:Win32/Virut.AI

NOD32v2 / 3466 / Win32/Virut.NBF

Norman / 5.80.02 / W32/Virut.BN

Panda / 9.0.0.4 / -

PCTools / 4.4.2.0 / -

Prevx1 / V2 / -

Rising / 20.63.12.00 / -

Sophos / 4.33.0 / W32/Virut-Gen

Sunbelt / 3.1.1662.1 / -

Symantec / 10 / W32.Virut.W

TheHacker / 6.3.0.9.091 / -

TrendMicro / 8.700.0.1004 / PE_VIRUT.LJ

VBA32 / 3.12.8.5 / -

ViRobot / 2008.9.23.1389 / -

VirusBuster / [removed] / Win32.Virut.Gen.4

Webwasher-Gateway / 6.6.2 / Win32.Virut.BL


Additional information
File size: 23040 bytes
MD5…: 8f95a0995a14394008f0415fa5aceaac
SHA1..: b73e814f6ededf6a6d94fb601e25e7b374ade0dc
SHA256: d308974d2e8b0e2382366ff3a636569a9e9c3f9e2729930ab076eea16d60218a
SHA512: 9df16a0b9c5a2d791c3e3985f7a155421592a9fdb7e6c20fd795b35901651d8f
e8a63786234481235828b25624faa398752aeae129665c94cfa60997a31a653d
PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x405a00
timedatestamp…..: 0x41107bfa (Wed Aug 04 06:02:34 2004)
machinetype…….: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x2ab8 0x2c00 6.75 e75af9431e119ddb814611dfdeca25c1
.data 0x4000 0x210 0x200 1.07 bd8c5cd346a9f53dc0dbc69260ab2240
.rsrc 0x5000 0x7a00 0x2800 7.17 e6da78549588a1cdd01f2142b86abf79

( 6 imports )
> msvcrt.dll: _controlfp, _except_handler3, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _cexit, _XcptFilter, _exit, _c_exit
> ADVAPI32.dll: RegDeleteValueA, RegOpenKeyExA, RegCloseKey, RegSetValueExA, RegCreateKeyA, RegCreateKeyExA
> KERNEL32.dll: lstrcpynA, lstrlenA, GetSystemDirectoryA, GetSystemWindowsDirectoryA, GetVersionExA, GetACP, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LocalFree, CloseHandle, ResetEvent, OpenEventA, CreateProcessA, lstrcatA, GetSystemInfo, lstrcmpiA, FreeLibrary, LoadLibraryA, CreateEventA, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetModuleHandleA, GetStartupInfoA, LocalAlloc, GetProcAddress
> USER32.dll: EnumWindows, GetClassNameA, FindWindowA, PostMessageA, SetTimer, KillTimer, MsgWaitForMultipleObjects, PeekMessageA, TranslateMessage, DispatchMessageA, GetMessageA, SetWindowPos, LoadCursorA, RegisterClassExA, DefWindowProcA, PostQuitMessage, CreateWindowExA, GetSystemMetrics
> MSCTF.dll: TF_InitSystem, TF_GetGlobalCompartment, TF_InvalidAssemblyListCacheIfExist, TF_InvalidAssemblyListCache, TF_PostAllThreadMsg, TF_CreateCicLoadMutex, TF_UninitSystem
> MSUTB.dll: ClosePopupTipbar, GetPopupTipbar

( 0 exports )


Log for userinit:

AhnLab-V3 / 2008.9.23.1 / Win32/Virut.Gen

AntiVir / 7.8.1.34 / W32/Virut.BL

Authentium / 5.1.0.4 / -

Avast / .8.1195.0 / Win32:Virtob

AVG / 8.0.0.161 / -

BitDefender / 7.2 / Win32.Virut.K

CAT-QuickHeal / 9.50 / -

ClamAV / 0.93.1 / W32.Virut-27

DrWeb / 4.44.0.09170 / Win32.Virut.40

eSafe / 7.0.17.0 / -

eTrust-Vet / 1.6.6101 / -

Ewido / 4.0 / -

F-Prot / 4.4.4.56 / W32/Patched.E.gen!Eldorado

F-Secure / 8.0.14332.0 / Virus.Win32.Virut.bq

Fortinet / 3.113.0.0 / W32/Virut.BQ

GData / 19 / Win32.Virut.K

Ikarus / T3.1.1.34.0 / Trojan.Win32.Anomaly.D

K7AntiVirus / 7.10.469 / Virus.Win32.Virut.LJ

Kaspersky / 7.0.0.125 / Virus.Win32.Virut.bq

McAfee / 5390 / W32/Virut.j

Microsoft / 1.3903 / Virus:Win32/Virut.AI

NOD32v2 / 3466 / Win32/Virut.NBF

Norman / 5.80.02 / W32/Virut.BN

Panda / 9.0.0.4 / Suspicious file

PCTools / 4.4.2.0 / -

Prevx1 / V2 / -

Rising / 20.63.12.00 / -

Sophos / 4.33.0 / W32/Virut-Gen

Sunbelt / 3.1.1662.1 / -

Symantec / 10 / W32.Virut.W W32.Virut.W

TheHacker / 6.3.0.9.091 / -

TrendMicro / 8.700.0.1004 / PE_VIRUT.LJ

VBA32 / 3.12.8.5 / -

ViRobot / 2008.9.23.1389 / -

VirusBuster / [removed] / Win32.Virut.Gen.4

Webwasher-Gateway / 6.6.2 / Win32.Virut.BL

Additional information
File size: 32256 bytes
MD5…: 72eadc55ba014923295f84aba5361d50
SHA1..: 48c547ce605c151bd497cfa6408d1155d1e6273b
SHA256: 800796e0b8ffda86c8cdce628522ba3e863769c953ff54c9f154278f74f75dc5
SHA512: 42de52b14a49cb4c28dba48296c53ec42a59116694bfcb54041b1ed83e0369f0
dbe7b7207f2afc00d37f33bbddd4f0e53eccdf650f177f335d1245baa4995b4b
PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1007c00
timedatestamp…..: 0x41107b78 (Wed Aug 04 06:00:24 2004)
machinetype…….: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x4db8 0x4e00 6.01 16aee663ed180007a0bf5bf24b845096
.data 0x6000 0x14c 0x200 1.86 cbb599f9267bf53209039d14a3574eb1
.rsrc 0x7000 0x7c00 0x2a00 6.93 1b8ceb8f0c2ec0470dc57b089554cd79

( 7 imports )
> USER32.dll: CreateWindowExW, DestroyWindow, RegisterClassExW, DefWindowProcW, LoadRemoteFonts, wsprintfW, GetSystemMetrics, GetKeyboardLayout, SystemParametersInfoW, GetDesktopWindow, LoadStringW, MessageBoxW, ExitWindowsEx, CharNextW
> ADVAPI32.dll: RegOpenKeyExA, ReportEventW, RegisterEventSourceW, DeregisterEventSource, OpenProcessToken, RegCreateKeyExW, RegSetValueExW, GetUserNameW, RegQueryValueExW, RegOpenKeyExW, RegQueryInfoKeyW, RegCloseKey, RegQueryValueExA
> CRYPT32.dll: CryptProtectData
> WINSPOOL.DRV: SpoolerInit
> ntdll.dll: RtlLengthSid, RtlCopySid, _itow, RtlFreeUnicodeString, DbgPrint, wcslen, wcscpy, wcscat, wcscmp, RtlInitUnicodeString, NtOpenKey, NtClose, _wcsicmp, memmove, NtQueryInformationToken, RtlConvertSidToUnicodeString
> msvcrt.dll: _controlfp, _except_handler3, __set_app_type, __p__fmode, __p__commode, __setusermatherr, __getmainargs, _acmdln, exit, _cexit, _XcptFilter, _exit, _c_exit, _initterm, _adjust_fdiv
> KERNEL32.dll: GetVersionExW, LocalFree, LocalAlloc, GetEnvironmentVariableW, SetEnvironmentVariableW, lstrlenW, lstrcpyW, FreeLibrary, GetProcAddress, LoadLibraryW, CompareFileTime, CloseHandle, lstrcatW, WaitForSingleObject, DelayLoadFailureHook, GetStartupInfoA, GetModuleHandleA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, LoadLibraryA, InterlockedCompareExchange, LocalReAlloc, GetSystemTime, lstrcmpW, GetCurrentThread, SetThreadPriority, CreateThread, GetFileAttributesExW, GetSystemDirectoryW, SetCurrentDirectoryW, FormatMessageW, lstrcmpiW, GetCurrentProcess, GetUserDefaultLangID, GetCurrentProcessId, ExpandEnvironmentStringsW, SetEvent, OpenEventW, Sleep, GetLastError, SearchPathW, CreateProcessW

( 0 exports )
Hello MikeJones23
Those files appear to be infected & will need to be replaced. There appears to be clean copies of two of the files in your System Restore, the other will need to be copied from a clean computer.

To replace ctfmon.exe,do this:
You'll need some sort of removable storage device such as flash/thumb drive.
  • Insert your flash drive into a known clean computer then navigate to C:\WINDOWS\system32\ctfmon.exe
  • Right-click ctfmon.exe & select Copy
  • Open your flash drive, select Paste
  • You should now have a copy of the file on your flash drive.
Remove your flash drive & go back to your computer.

Close all open browser windows.

End a Process using Task Manager
Open Task Manager by pressing crtl + alt + delete keys simultaneously or by right clicking the taskbar at the bottom of your screen & then clicking Task Manager
  • Click Processes
  • Click Image Name to alphabetize the list
  • Find the following process
ctfmon.exe
  • If present click on it
  • After clicking on the process, click End Process
  • Close Task Manager

Navigate to C:\WINDOWS\system32\ctfmon.exe & delete the file.
Insert your flash drive, open it & find the ctfmon.exe file you copied previously.
Either drag ctfmon.exe into the System32 folder or right-click on it & select copy then paste it into the System32 folder.

To replace explorer.exe & userinit.exe do this:
CFScript
Close any open browsers.
Open notepad and copy/paste the text in the code box below into it:

SCopy::
{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002186.exe|C:\WINDOWS\explorer.exe
{39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002185.exe|C:\WINDOWS\system32\userinit.exe
Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Post the contents of the Combofix log along with a new HijackThis log in your next reply.
when It rebooted, DEP was preventing the clean ctfmon from running, so I put it on the exceptions list, so hopefully it works after a reboot.

here's the logs:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:16:11 PM, on 9/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…DTP&M;=W3622
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 4346 bytes







ComboFix 08-09-19.13 - Owner 2008-09-24 18:54:47.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFscript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV


((((((((((((((((((((((((( Files Created from 2008-08-24 to 2008-09-24 )))))))))))))))))))))))))))))))
.

2008-09-24 18:51 . 2008-09-24 18:51 d——– C:\Documents and Settings\Owner\DoctorWeb
2008-09-19 09:23 . 2008-09-19 09:25 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-19 09:23 . 2008-09-19 10:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-19 08:23 . 2008-09-22 04:50 d–h—– C:\$AVG8.VAULT$
2008-09-19 08:13 . 2008-09-19 08:24 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\AVGTOOLBAR
2008-09-19 08:11 . 2008-09-20 04:06 d——– C:\WINDOWS\system32\drivers\Avg
2008-09-19 08:11 . 2008-09-19 08:11 d——– C:\Program Files\AVG
2008-09-19 08:11 . 2008-09-23 18:47 d——– C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-09-19 08:11 . 2008-09-19 11:13 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-09-19 08:11 . 2008-09-19 08:11 97,928 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-19 08:11 . 2008-09-19 08:11 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-19 08:11 . 2008-09-19 08:11 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-09-19 07:44 . 2008-09-19 07:44 0 –a—— C:\WINDOWS\nsreg.dat
2008-09-17 15:33 . 2008-09-17 15:33 d——– C:\Program Files\Microsoft Silverlight
2008-09-17 15:19 . 2008-09-17 15:19 d——– C:\Program Files\Windows Media Components
2008-09-17 15:14 . 2008-09-17 15:15 d——– C:\Documents and Settings\Owner\Application Data\Ventrilo
2008-09-17 15:14 . 2008-09-19 09:05 d——– C:\Documents and Settings\Owner\Application Data\Hamachi
2008-09-17 15:06 . 2008-09-17 15:06 d——– C:\Program Files\Xilisoft
2008-09-17 15:06 . 2008-09-17 15:06 d——– C:\Program Files\Trend Micro
2008-09-17 15:04 . 2008-09-17 15:05 d——– C:\Program Files\Warcraft III
2008-09-17 14:25 . 2008-09-17 15:35 d——– C:\Program Files\Beston
2008-09-17 14:20 . 2008-09-17 14:35 137,472 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-09-17 14:20 . 2008-09-17 14:35 111,928 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2008-09-17 14:19 . 2008-09-17 14:19 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Program Files\Lavasoft
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-17 08:56 . 2008-09-17 14:11 d——– C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-09-17 08:55 . 2008-04-17 13:12 107,368 –a—— C:\WINDOWS\system32\GEARAspi.dll
2008-09-17 08:55 . 2008-04-17 13:12 15,464 –a—— C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-09-17 08:54 . 2008-09-17 15:42 d——– C:\Program Files\iTunes
2008-09-17 08:54 . 2008-09-17 14:28 d——– C:\Program Files\iPod
2008-09-17 08:53 . 2008-09-17 08:53 d——– C:\Program Files\Bonjour
2008-09-17 08:51 . 2008-09-17 08:53 d——– C:\Program Files\QuickTime
2008-09-17 08:51 . 2008-09-17 08:54 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-17 08:50 . 2008-09-17 08:50 d——– C:\Program Files\Apple Software Update
2008-09-17 08:49 . 2008-09-17 08:52 d——– C:\Program Files\Common Files\Apple
2008-09-17 08:48 . 2008-09-17 08:48 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-09-17 08:38 . 2008-09-17 08:38 d——– C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-09-17 08:36 . 2008-09-17 08:36 d——– C:\Program Files\River Past
2008-09-17 08:36 . 2008-09-17 08:36 d——– C:\Program Files\Common Files\River Past
2008-09-17 08:36 . 2008-09-17 09:44 d——– C:\Documents and Settings\Owner\Application Data\River Past G5
2008-09-17 08:36 . 2008-09-17 09:44 d——– C:\Documents and Settings\All Users\Application Data\River Past G5
2008-09-17 08:36 . 2008-09-17 08:36 164,872 –a—— C:\WINDOWS\Crazi Video Uninstaller.exe
2008-09-17 08:29 . 2008-09-17 10:05 d——– C:\Documents and Settings\Owner\Incomplete
2008-09-17 03:00 . 2008-09-17 03:00 d——– C:\Program Files\MSXML 4.0
2008-09-16 01:30 . 2008-09-20 04:07 d——– C:\Documents and Settings\Owner\Shared
2008-09-16 01:27 . 2008-09-16 11:29 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-16 01:27 . 2008-06-13 09:10 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-09-16 01:27 . 2008-06-13 09:10 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-16 01:26 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-16 01:26 . 2008-06-23 12:57 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-09-16 01:23 . 2004-08-04 15:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-09-16 01:22 . 2006-07-01 01:30 d——– C:\WINDOWS\system32\config\systemprofile\WINDOWS
2008-09-16 01:22 . 2008-09-16 00:59 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\Spare Backup
2008-09-16 01:22 . 2008-09-16 00:56 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
2008-09-16 01:22 . 2006-07-01 01:30 d——– C:\Documents and Settings\Default User\WINDOWS
2008-09-16 01:03 . 2008-09-16 01:03 8,192 –a—— C:\WINDOWS\REGLOCS.OLD
2008-09-16 00:59 . 2008-09-16 00:59 333 –a—— C:\WINDOWS\system32\$ncsp$.inf
2008-09-16 00:59 . 2008-09-16 00:59 0 –a—— C:\WINDOWS\system32\Gateway_W3622_3.1_0000.MRK
2008-09-16 00:58 . 2008-09-16 00:58 940,794 –a—— C:\WINDOWS\system32\LoopyMusic.wav
2008-09-16 00:58 . 2008-09-16 00:58 146,650 –a—— C:\WINDOWS\system32\BuzzingBee.wav
2008-09-16 00:57 . 2006-10-06 00:09 155,648 –a—— C:\WINDOWS\system32\igfxres.dll
2008-09-16 00:56 . 2008-09-16 00:56 d——– C:\Documents and Settings\Owner\Application Data\SampleView
2008-09-16 00:54 . 2006-12-19 17:52 8,453,632 –a–c— C:\WINDOWS\system32\dllcache\shell32.dll
2008-09-16 00:54 . 2006-12-19 17:52 134,656 –a–c— C:\WINDOWS\system32\dllcache\shsvcs.dll
2008-09-16 00:52 . 2006-11-27 10:54 539,136 –a–c— C:\WINDOWS\system32\dllcache\msftedit.dll
2008-09-16 00:52 . 2006-11-27 10:54 433,152 –a–c— C:\WINDOWS\system32\dllcache\riched20.dll
2008-09-16 00:51 . 2006-08-21 05:14 128,896 –a–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-09-16 00:51 . 2006-08-21 05:14 30,720 –a–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-09-16 00:51 . 2006-08-21 08:21 16,896 –a–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-09-16 00:50 . 2006-06-22 01:06 1,435,648 –a–c— C:\WINDOWS\system32\dllcache\query.dll
2008-09-16 00:50 . 2008-05-08 08:28 202,752 –a–c— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-16 00:50 . 2006-06-22 01:06 69,120 –a–c— C:\WINDOWS\system32\dllcache\ciodm.dll
2008-09-16 00:49 . 2006-04-21 02:12 332,800 –a–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-09-16 00:49 . 2006-06-22 06:47 181,248 –a–c— C:\WINDOWS\system32\dllcache\rasmans.dll
2008-09-16 00:49 . 2008-06-20 13:41 148,992 –a–c— C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-09-16 00:49 . 2006-05-19 08:59 111,616 –a–c— C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
2008-09-16 00:49 . 2006-05-19 08:59 94,720 –a–c— C:\WINDOWS\system32\dllcache\iphlpapi.dll
2008-09-16 00:48 . 2004-09-03 19:07 28,672 –a—— C:\WINDOWS\system32\Marker32.exe
2008-09-16 00:47 . 2008-09-16 00:47 d——– C:\Program Files\Spare Backup
2008-09-16 00:47 . 2008-09-16 00:47 d——– C:\Program Files\Microsoft WSE
2008-09-16 00:47 . 2008-09-22 23:27 d——– C:\Documents and Settings\Owner\Application Data\Spare Backup
2008-09-16 00:46 . 2008-09-16 00:46 d——– C:\McAfee
2008-09-16 00:46 . 2007-04-23 06:14 364,160 –a–c— C:\WINDOWS\system32\dllcache\update.sys
2008-09-16 00:44 . 2007-02-28 05:55 2,182,144 –a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-09-16 00:44 . 2007-02-28 05:53 2,137,600 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-09-16 00:44 . 2007-02-28 05:15 2,017,280 –a–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-09-16 00:44 . 2007-03-17 09:43 292,864 –a–c— C:\WINDOWS\system32\dllcache\winsrv.dll
2008-09-16 00:44 . 2007-02-05 16:17 185,344 –a–c— C:\WINDOWS\system32\dllcache\upnphost.dll
2008-09-16 00:44 . 2007-03-09 09:58 57,344 –a–c— C:\WINDOWS\system32\dllcache\agentdpv.dll
2008-09-16 00:43 . 2008-09-16 01:34 d——– C:\Program Files\BigFix
2008-09-16 00:43 . 2007-03-08 09:47 1,843,584 –a–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-09-16 00:43 . 2007-03-08 11:36 577,536 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-09-16 00:43 . 2007-03-08 11:36 281,600 –a–c— C:\WINDOWS\system32\dllcache\gdi32.dll
2008-09-16 00:43 . 2007-03-08 11:36 40,960 –a–c— C:\WINDOWS\system32\dllcache\mf3216.dll
2008-09-16 00:43 . 2006-11-16 19:05 11,816 –a—— C:\WINDOWS\BigFixClientOverride.dll
2008-09-16 00:42 . 2008-09-16 11:18 d——– C:\Program Files\eMachines Games
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Program Files\NetZero
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\google
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Documents and Settings\All Users\Application Data\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2008-09-16 00:41 . 2006-02-01 06:54 94,208 –a—— C:\WINDOWS\system32\BAE.dll
2008-09-16 00:39 . 2008-09-16 11:19 d——– C:\Program Files\Java
2008-09-16 00:39 . 2008-09-16 11:44 d——– C:\Program Files\Google
2008-09-16 00:39 . 2008-09-16 00:39 d——– C:\Program Files\Common Files\Java
2008-09-16 00:39 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-16 00:39 . 2008-09-16 00:39 0 –a—— C:\WINDOWS\system32\drivers\Gateway_W3622_3.1_0000.MRK
2008-09-16 00:38 . 2008-09-16 00:38 d–h—– C:\WINDOWS\msdownld.tmp
2008-09-16 00:38 . 2006-10-26 22:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2008-09-16 00:37 . 2008-09-16 00:37 d——– C:\Program Files\Microsoft.NET
2008-09-16 00:37 . 2008-09-16 00:40 d——– C:\Program Files\Microsoft Works
2008-09-16 00:36 . 2008-09-16 00:36 d——– C:\WINDOWS\SHELLNEW
2008-09-16 00:35 . 2008-09-16 00:35 dr-h—– C:\MSOCache
2008-09-16 00:35 . 2008-09-16 00:38 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-16 00:34 . 2001-03-08 21:30 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2008-09-16 00:33 . 2008-09-16 00:34 d——– C:\Program Files\CyberLink
2008-09-16 00:33 . 2003-03-18 23:14 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-09-16 00:33 . 2003-02-21 07:42 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-09-16 00:32 . 2008-09-16 00:33 d——– C:\Program Files\Common Files\Adobe
2008-09-16 00:31 . 2008-09-17 15:19 d——– C:\Program Files\Windows Media Connect 2
2008-09-16 00:31 . 2006-10-04 10:06 1,197,294 –a–c— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-09-16 00:31 . 2006-10-04 10:06 764,868 –a–c— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-09-16 00:31 . 2006-10-04 10:06 217,118 –a–c— C:\WINDOWS\system32\dllcache\apphelp.sdb

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 07:54 ——— d—–w C:\Program Files\Diablo II
2008-09-17 19:15 ——— d—–w C:\Program Files\Ventrilo
2008-09-17 18:55 ——— d—–w C:\Program Files\Q3Ademo
2008-09-17 18:20 ——— d—–w C:\Program Files\Wolfenstein - Enemy Territory
2008-09-15 23:05 ——— d—–w C:\Program Files\Starcraft
2008-08-12 06:05 ——— d—–w C:\Program Files\Rockstar Games
2008-08-08 00:10 ——— d—–w C:\Program Files\EA GAMES
.

——- Sigcheck ——-

2004-08-04 15:00 1039872 6beed988649566e49c3fb63dec564c3c C:\WINDOWS\explorer.exe
2008-04-13 20:12 1041408 6ce19208891e9dc85b46ec32ea3fa3e9 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\explorer.exe

2008-04-13 20:12 23040 7994d694ec2fb339baff2e50925e62cf C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ctfmon.exe
2004-08-04 08:00 15360 57ef99f9200df3e4d718fd3c60fcbe2e C:\WINDOWS\system32\ctfmon.exe

2008-04-13 20:12 33792 66f69cf680ee53f7751ab7bd8490c797 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 15:00 32256 72eadc55ba014923295f84aba5361d50 C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((( snapshot@2008-09-20_ 4.40.07.89 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 00:02:28 174,592 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2008-09-20 08:33:53 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-24 23:23:45 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-20 08:33:53 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-24 23:23:45 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-20 08:33:53 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-24 23:23:45 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 1675264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 106496]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-06 102400]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 221184]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 65120]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-11-29 58928]
"Spare Backup"="C:\Program Files\Spare Backup\SpareBackup.exe" [2007-07-13 5252936]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 421888]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-19 1235736]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 C:\WINDOWS\RTHDCPL.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\River Past\\Crazi Video\\CraziVideo.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\Xilisoft\\AVI to DVD Converter\\AVI to DVD Converter.exe"=
"C:\\Program Files\\Lavasoft\\Ad-Aware\\Ad-Aware.exe"=
"C:\\Program Files\\Microsoft Works\\wksdb.exe"=
"C:\\Program Files\\Lavasoft\\Ad-Aware\\Ad-Watch.exe"=
"C:\\Program Files\\Lavasoft\\Ad-Aware\\threatwork.exe"=
"C:\\Documents and Settings\\Owner\\Desktop\\ComboFix.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;C:\WINDOWS\system32\DRIVERS\el575nd5.sys [2001-08-17 22:10]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-09-19 08:11]
S2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-19 08:11]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-19 08:11]
S2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-09-19 08:11]

.
Contents of the 'Scheduled Tasks' folder
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-24 19:56:49
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


C:\WINDOWS\TEMP\lxrtaex3.TMP 616448 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\ComboFix\pv.cfexe
C:\WINDOWS\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 2008-09-24 20:00:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-25 00:00:42
ComboFix2.txt 2008-09-20 16:41:10
ComboFix3.txt 2008-09-20 08:40:34

Pre-Run: 39,176,912,896 bytes free
Post-Run: 39,685,877,760 bytes free

250 — E O F — 2008-09-17 07:00:22
Hello MikeJones23

After further research of the logs you provided I must tell you that your computer is infected with a Backdoor Trojan. A backdoor gives intruders complete control of your computer, logs your keystrokes, steals personal information, etc.
The infection present is called Virut. This infection when executed becomes resident in memory. It then attempts to infect any executable file that is accessed by any process running on the system.
It also attempts to connect to an IRC channel and serves as a backdoor with which a remote attacker may compromise the system.

I would strongly advise you to do the following:
  • Disconnect the computer from the Internet and from any networked computers until it is cleaned.
  • Back up all your important data except programs. The programs can be reinstalled back from the original disc or from the Net.
  • Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft and put a watch on your accounts. If you don't mind the hassle, change all your account numbers.
  • From a clean computer, change all your passwords (ISP login password, your email address(es) passwords, financial accounts, PayPal, eBay, Amazon, online groups and forums and any other online activities you carry out which require a username and password).
Do NOT change your passwords from this computer as the attacker will be able to get all the new passwords and transaction records.

Due to its backdoor functionality, your computer is very likely to have been compromised and there is no way that it can be trusted again. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be to do a reformat and reinstallation of the operating system (OS).
To help you understand more, please take some time to read the following articles:
What are Remote Access Trojans and why are they dangerous
How do I respond to a possible identity theft and how do I prevent it
When should I re-format and reinstall my OS
Where to backup your files
How to backup your files in Windows XP
Restoring your backups

Under the circumstances, the safest course of action would be to format your hard drive & re-install Windows. However if you are unable to do that, then there are a couple of tools we could use to clean the infection but the computer will still not be 100% safe.

It's your call. Let me know what you decide.
well I plugged in my usb (since it kept redirecting me) into this computer to give you some of the hijackthis logs, etc. before the the flash disinf., so I scanned with that online website and it detected it on here too..so I decided to format and re-install on the computer you've been helping me deal with maybe use the tools you mentioned on here to help cleanout virut. depending on how complicated it would be and how efficient it is, but going from what you're saying it sounds like that would probably be a waste of mine and your time to even try them, is that true? because I might just decide to format them both.

depending on how complicated it would be and how efficient it is, but going from what you're saying it sounds like that would probably be a waste of mine and your time to even try them, is that true? because I might just decide to format them both.

I think under the circumstances this would be the best course of action.
When Virut is activated it injects code into the executable files on the compromised system. The main problem with the Virut infection is a bug in the viral code, which can leave legitimate .exe files corrupted & unable to be cleaned. Most good quality Anti-virus & Spyware scanners can disinfect the infected files, however the files that may have been injected with the buggy code are unable to be cleaned because the scanners won't detect them. You are then left with corrupted files on the system which would need to be replaced. This, along with it's backdoor capability, is the main reason why a format & re-install is recommended when this infection is present.
Ok, I'll go ahead and format + re-install both of them then, but one last question about the backup files first. Would virut be able to transfer to my computer if I transferred the files onto this computer (even though its infected too) and transferred them back? I'm not an expert on computers, but my guess is that it can't spread itself any further if none of the backed-up files are .exe's , but i'm probably wrong. btw thanks for the help/advice so far.

Would virut be able to transfer to my computer if I transferred the files onto this computer (even though its infected too) and transferred them back? I'm not an expert on computers, but my guess is that it can't spread itself any further if none of the backed-up files are .exe's , but i'm probably wrong.

As far as I am aware this infection only affects .exe (executables) & .scr (script or screen saver) files. So all your personal data such as documents, spreadsheets, photos, music etc. should be OK. Maybe transferring all those type of files to a portable external hard drive would be the best bet. Once transferred to the external drive I would recommend scanning it to make sure your files are clean.
hey sorry I never got back to you, but I did end up reformatting both of the computers and took your advice on using an external drive. All seems to be running fine and no viruses are being detected by the online scanners after the file transfer. you can go ahead and close the topic now. I appreciate the help
Hello MikeJones23

Good to hear all is well. Here's a few tips to help keep your computer safe & free of malware.

Microsoft Windows Update
Microsoft releases patches for Windows and Office products regularly to patch up Windows and Office products loopholes and fix any bugs found. Install the updates immediately if they are found.
To update Windows
Go to Start > All Programs > Windows Update
To update Office
Open up any Office program.
Go to Help > Check for Updates

Malwarebytes' Anti-Malware
Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is totally free but for real-time protection you will have to pay a small one-time fee.
You can download it here & find a tutorial here.

SpywareBlaster
Download and install Javacools SpywareBlaster from here
SpywareBlaster adds a list of ActiveX controls, tracking cookies and sites which will be blocked in either Internet Explorer or Firefox browsers. You need to manually check for updates regularly.

Download and Install a HOSTS File
A HOSTS file is a big list of bad web sites. The list has a specific format, a specific name, (name is just HOSTS with no file extension), and a specific location. Your machine always looks at that file in that location before connecting to a web site to verify the address. So the HOSTS listing can be used to "short circuit" a request to a bad website by giving it the address of your own machine.

Download BlueTack's HOSTS Manager here, using Internet Explorer (Firefox won't work):
  • A short distance down the page in the centre, click on the Download button
  • Agree to the license
  • On the next page, to the right side of where it says Download Estimates, right click on the underlined word Hosts Manager choose Save Target As and download the installer Hosts20setup.exe to your desktop
  • Double click the Installer on your desktop and let it Install the Hosts Manager
  • After the installation is complete, click on the Hosts Manager icon on your desktop. (You can delete the other Hosts Switch icon from your desktop)
  • When the Hosts Manager comes up, click the small down arrows on the right side of the bar labeled Options and Tools,
  • Click Disable DNS Service. This is important
  • In the Left Pane, click Download
  • It will load 80,000 lines or more. When it finishes, also in the left pane, click Replace, and then click Save
You can use this manager to handle your HOSTS file download, edits, and most any other HOSTS issue.
If you have a separate party firewall or Winpatrol, you may have to give permissions at various times to Unlock the present default HOSTS file and install the new one.

Install WinPatrol
Download it here
You can find information about how WinPatrol works here

Read some information here on how to prevent Malware.

Hopefully these steps will help keep your computer clean.

Stand Up and Be Counted —> Malware Complaints <— where you can make difference!
The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Good luck & surf safe
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI