This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] browser corrupted ?

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK , I went ahead on my own and put the leftover combofix folder in another C: folder and reran the program from link 2 . This time it worked and I have the two logs , first the combofix and thn the HJT

ComboFix 08-11-02.03 - vp^ 2008-11-02 18:57:36.6 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.432 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-10-02 to 2008-11-02 )))))))))))))))))))))))))))))))
.

2008-11-02 18:56 . 2008-11-02 18:56 d——– C:\extrafile
2008-11-01 15:38 . 2008-11-01 15:38 d——– C:\Program Files\ERUNT
2008-11-01 15:30 . 2008-11-01 15:30 d——– C:\Program Files\Trend Micro
2008-11-01 13:31 . 2008-11-01 13:34 1,374 –a—— C:\WINDOWS\imsins.BAK
2008-10-16 10:36 . 2008-10-31 18:53 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-10-16 10:36 . 2008-10-16 10:36 1,409 –a—— C:\WINDOWS\QTFont.for
2008-10-11 19:35 . 2008-10-11 19:35 d——– C:\Documents and Settings\vp^\Application Data\Ulead Systems
2008-10-11 19:33 . 2008-10-11 19:33 d——– C:\Program Files\Ulead Systems
2008-10-11 19:33 . 2008-10-11 19:33 d——– C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-10-11 19:32 . 2008-10-11 19:32 d——– C:\WINDOWS\Noslip
2008-10-11 19:29 . 2008-10-11 19:29 11,014,144 –a—— C:\Program Files\UGA5TBYB_E_USG.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-02 01:49 5,527 —-a-w C:\Program Files\hijackthis11-1.log
2008-11-02 01:48 5,527 —-a-w C:\Program Files\hijackthis.log
2008-10-30 02:54 27,991 —-a-w C:\Program Files\081029_2140.caf
2008-10-28 10:06 75,492 —-a-w C:\Program Files\081028_0451.caf
2008-10-26 09:14 64,725 —-a-w C:\Program Files\081026_0346.caf
2008-10-25 15:17 3,096 —-a-w C:\Program Files\081025_1005.caf
2008-10-23 13:21 74,174 —-a-w C:\Program Files\081023_0758.caf
2008-10-22 19:26 2,225 —-a-w C:\Program Files\081022_1338.caf
2008-10-20 23:35 9,496 —-a-w C:\Program Files\081020_1751.caf
2008-10-19 20:40 2,484 —-a-w C:\Program Files\081019_1528.caf
2008-10-17 22:29 31,313 —-a-w C:\Program Files\081017_1716.caf
2008-10-16 04:22 27,679 —-a-w C:\Program Files\081015_2305.caf
2008-10-14 19:02 928 —-a-w C:\Program Files\081014_1347.caf
2008-10-14 03:00 1,085 —-a-w C:\Program Files\081013_2137.caf
2008-10-13 11:07 3,627 —-a-w C:\Program Files\081013_0521.caf
2008-10-12 18:43 3,878 —-a-w C:\Program Files\081012_1322.caf
2008-10-10 16:59 5,361 —-a-w C:\Program Files\081010_1142.caf
2008-10-09 13:22 3,469 —-a-w C:\Program Files\081009_0810.caf
2008-10-08 16:51 2,434 —-a-w C:\Program Files\081008_1138.caf
2008-10-07 11:44 14,949 —-a-w C:\Program Files\081007_0632.caf
2008-10-04 18:25 22,698 —-a-w C:\Program Files\081004_1252.caf
2008-10-04 04:21 8,071 —-a-w C:\Program Files\081003_2310.caf
2008-10-04 02:15 7,574 —-a-w C:\Program Files\081002_0811.caf
2008-10-02 20:46 1,167 —-a-w C:\Program Files\081002_1535.caf
2008-09-30 03:53 4,975 —-a-w C:\Program Files\080929_2227.caf
2008-09-28 21:15 35,592 —-a-w C:\Program Files\080928_1558.caf
2008-09-28 06:15 9,895 —-a-w C:\Program Files\080928_0103.caf
2008-09-27 12:42 1,611 —-a-w C:\Program Files\080927_0728.caf
2008-09-27 05:18 5,582 —-a-w C:\Program Files\080927_0002.caf
2008-09-25 13:59 2,076 —-a-w C:\Program Files\080925_0826.caf
2008-09-24 18:15 1,048 —-a-w C:\Program Files\080924_1252.caf
2008-09-24 04:03 7,437 —-a-w C:\Program Files\080923_2251.caf
2008-09-23 10:36 4,083 —-a-w C:\Program Files\080923_0510.caf
2008-09-22 05:16 5,721 —-a-w C:\Program Files\080921_2356.caf
2008-09-21 00:02 36,226 —-a-w C:\Program Files\080920_1841.caf
2008-09-19 03:44 46,650 —-a-w C:\Program Files\080918_2226.caf
2008-09-17 22:20 15,678 —-a-w C:\Program Files\080917_1704.caf
2008-09-16 05:15 3,071 —-a-w C:\Program Files\080916_0002.caf
2008-09-14 15:25 968 —-a-w C:\Program Files\080914_1012.caf
2008-09-13 18:11 4,247 —-a-w C:\Program Files\080913_1259.caf
2008-09-12 23:17 8,993 —-a-w C:\Program Files\080912_1649.caf
2008-09-08 22:59 1,947 —-a-w C:\Program Files\080908_1708.caf
2008-09-07 12:26 3,808 —-a-w C:\Program Files\080907_0715.caf
2008-09-07 04:37 11,778 —-a-w C:\Program Files\080906_2326.caf
2008-09-06 12:42 2,549 —-a-w C:\Program Files\080906_0729.caf
2008-09-05 22:39 13,118 —-a-w C:\Program Files\080905_1724.caf
2008-09-03 22:21 2,221 —-a-w C:\Program Files\080903_1710.caf
2008-09-03 04:29 75,660 —-a-w C:\Program Files\080902_2312.caf
2008-08-31 18:58 11,310 —-a-w C:\Program Files\080831_1343.caf
2008-08-30 16:41 1,068 —-a-w C:\Program Files\080830_1127.caf
2008-08-30 03:58 130,474 —-a-w C:\Program Files\080829_2216.caf
2008-08-29 20:58 3,297,268 —-a-w C:\WINDOWS\system32\via_chipset_AC_97_sound_driver.ZIP
2008-08-29 19:50 12,848 —-a-w C:\Program Files\080829_1427.caf
2008-08-28 15:07 15,201 —-a-w C:\Program Files\080828_0953.caf
2008-08-26 15:06 1,516 —-a-w C:\WINDOWS\system32\tmp.reg
2008-08-25 03:34 10,235 —-a-w C:\Program Files\080824_2218.caf
2008-08-25 02:06 10,744 —-a-w C:\Program Files\080824_2027.caf
2008-08-20 17:46 6,188 —-a-w C:\Program Files\080820_1226.caf
2008-08-19 13:47 5,620 —-a-w C:\Program Files\080819_0824.caf
2008-08-17 03:37 68,738 —-a-w C:\Program Files\080816_2218.caf
2008-08-16 14:25 5,092 —-a-w C:\Program Files\080816_0900.caf
2008-08-15 02:35 3,672 —-a-w C:\Program Files\080814_1352.caf
2008-08-14 00:28 12,665 —-a-w C:\Program Files\080813_1914.caf
2008-08-12 15:12 9,474 —-a-w C:\Program Files\080812_0957.caf
2008-08-10 04:16 12,688 —-a-w C:\Program Files\080809_2303.caf
2008-08-09 12:54 9,029 —-a-w C:\Program Files\080809_0738.caf
2008-08-07 11:58 3,390 —-a-w C:\Program Files\080807_0644.caf
2008-08-05 11:15 975 —-a-w C:\Program Files\080805_0600.caf
2008-08-03 02:05 76,146 —-a-w C:\Program Files\080802_2007.caf
2008-08-01 14:54 28,640 —-a-w C:\Program Files\080801_0848.caf
2008-07-31 05:21 4,511 —-a-w C:\Program Files\080731_0009.caf
2008-07-30 21:21 9,175 —-a-w C:\Program Files\080727_0642.caf
2008-07-30 05:46 18,389 —-a-w C:\Program Files\080730_0024.caf
2008-07-26 18:11 2,847 —-a-w C:\Program Files\080726_1127.caf
2008-07-26 06:11 3,917 —-a-w C:\Program Files\080719_1631.caf
2008-07-24 18:37 1,791 —-a-w C:\Program Files\080724_1320.caf
2008-07-24 04:11 2,466 —-a-w C:\Program Files\080723_2258.caf
2008-07-22 18:41 1,200 —-a-w C:\Program Files\080722_1310.caf
2008-07-21 04:31 8,727 —-a-w C:\Program Files\080720_2313.caf
2008-07-19 22:11 31,339 —-a-w C:\Program Files\080718_1202.caf
2008-07-19 10:53 35,368 —-a-w C:\Program Files\080719_0029.caf
2008-07-18 00:15 3,623 —-a-w C:\Program Files\080717_1703.caf
2008-07-17 00:42 3,401 —-a-w C:\Program Files\080716_1917.caf
2008-07-15 05:21 3,671 —-a-w C:\Program Files\080715_0000.caf
2008-07-15 03:50 5,421 —-a-w C:\Program Files\080713_1149.caf
2008-07-12 18:44 93,996 —-a-w C:\Program Files\080712_1330.caf
2008-07-09 18:13 62,250 —-a-w C:\Program Files\080709_1255.caf
2008-07-09 17:29 46,390 —-a-w C:\Program Files\080709_09541.caf
2008-07-07 22:41 512,000 —-a-w C:\Program Files\arcn147b.exe
2008-07-07 21:44 15,206 —-a-w C:\Program Files\080707_1628.caf
2008-07-05 15:25 25,670 —-a-w C:\Program Files\080705_1011.caf
2008-07-05 14:08 20,451 —-a-w C:\Program Files\080705_0829.caf
2008-07-04 19:24 3,850 —-a-w C:\Program Files\080704_1411.caf
2008-07-03 00:34 54,526 —-a-w C:\Program Files\080702_1917.caf
2008-07-02 12:03 2,333 —-a-w C:\Program Files\080702_0615.caf
2008-06-30 20:51 3,249 —-a-w C:\Program Files\080630_1524.caf
2008-06-29 14:16 4,027 —-a-w C:\Program Files\080629_00281.caf
2008-06-27 18:14 5,450 —-a-w C:\Program Files\080627_1300.caf
2008-06-26 01:52 3,399 —-a-w C:\Program Files\080625_2034.caf
2008-06-24 03:17 5,871 —-a-w C:\Program Files\080623_2200.caf
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eRecoveryService"="C:\Program Files\Acer\eRecovery\Monitor.exe" [2005-06-20 352256]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-09-28 177416]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-04-30 230928]
"SoundMan"="SOUNDMAN.EXE" [2005-06-08 C:\WINDOWS\SOUNDMAN.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner Help.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner Help.lnk
backup=C:\WINDOWS\pss\Easy Video Joiner Help.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner on the Web.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner on the Web.lnk
backup=C:\WINDOWS\pss\Easy Video Joiner on the Web.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner.lnk
backup=C:\WINDOWS\pss\Easy Video Joiner.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Uninstall Easy Video Joiner.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Uninstall Easy Video Joiner.lnk
backup=C:\WINDOWS\pss\Uninstall Easy Video Joiner.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Online Help & Support.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Verizon Online Help & Support.lnk
backup=C:\WINDOWS\pss\Verizon Online Help & Support.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Support Service.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Verizon Support Service.lnk
backup=C:\WINDOWS\pss\Verizon Support Service.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^vp^^Start Menu^Programs^Startup^Kremlin Sentry.lnk]
path=C:\Documents and Settings\vp^\Start Menu\Programs\Startup\Kremlin Sentry.lnk
backup=C:\WINDOWS\pss\Kremlin Sentry.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AspireService]
–a—— 2005-06-04 12:40 110592 C:\Program Files\acer\Acer eMode Management\AspireService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
–a—— 2005-02-07 15:00 98304 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIACA.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaSync]
–a—— 2005-06-01 14:25 421888 C:\Program Files\acer\Acer eConsole\MediaSync.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 09:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
——— 2005-09-16 16:41 1961984 C:\Program Files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2004-07-15 01:07 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"VTTimer"=VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Free Download Manager\\fdmwi.exe"=
"C:\\Program Files\\Westell\\Diagnostic Icon\\DGNIcon.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=

R2 int15.sys;int15.sys;C:\Program Files\acer\eRecovery\int15.sys [2005-01-13 69632]
S3 {DEF85C80-216A-43ab-AF70-1665EDBE2780};{DEF85C80-216A-43ab-AF70-1665EDBE2780};C:\WINDOWS\TEMP\11B.tmp [ ]
.
Contents of the 'Scheduled Tasks' folder

2008-11-02 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Cmaudio - cmicnfg.cpl
HKLM-Explorer_Run-services - C:\WINDOWS\services.exe
MSConfigStartUp-SunJavaUpdateSched - C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = about:blank
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=2.0&bm=bz_welcome
O8 -: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 -: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 -: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 -: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm

O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd

O16 -: vzTCPConfig
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-02 18:58:21
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}]
"ImagePath"="\??\C:\WINDOWS\TEMP\11B.tmp"
.
Completion time: 2008-11-02 18:58:52
ComboFix-quarantined-files.txt 2008-11-02 23:58:52

Pre-Run: 5,094,604,800 bytes free
Post-Run: 5,079,040,000 bytes free

229 — E O F — 2008-08-20 06:20:25





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:01, on 2008-11-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://cgi.verizon.net/bookmarks/bmredir.a…p;bm=bz_welcome
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158766737609
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1163900908375
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} -
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 5192 bytes
Gee , I have no idea what a .caf file extension actually is . I went to the infected desktop and opened one of those caf files as a text . I found many familiar file names amid all the programming gibberish . The caf files seem to be related to some sites (or maye a single site) that I have visited and downloaded files from , files which I burn to disk to save and then delete from hard drive . Or they may be related to my download manager . Anyway , my guess is they can all be deleted , or maybe cut and copied to the thumbdrive if they need to be reinstalled . What do you think , and if I cut them out , what would be the next step after that ?
Lets have a look at one.

Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:

C:\Program Files\081029_2140.caf

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.


If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html


http://www.virustotal.com/en/indexf.html
I don't think I have any Apple style insallation that use audio on my desktop , I download songs as mp3 and listen to them with Nero Media Player , none of the file names I saw in the caf file are music titles . You also asked how is the computer running now , , I shut down and restarted , it still takes about 2 or 3 minutes for My Computer to show me the icons , I don't dare try to connect to the Internet since all my Protective Programs are still off , I have some web pages complete that I have saved to folders on my drive , when I try to open one of those , the window freezes , just like it did on the first day of the infection , and just like it does when I try to go to a web address onthe Internt , so I think all of my problems are still there . Something has corrupted either my OS or browser , I don't have a Windows XP disk to replace files from , and I cant do any reinstalls by simple download from the Intenet , maybe from my thumbdrive , I have an exterior CD/DVD burner that I planned to use with this laptop , I may be able to make a disk for the desktop from there if I have to reinstall something . I have never tried any recovery programs and I hope I will not have to reformat my entire drive and lose my data (yeah , no backup) .
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\Program Files\081029_2140.caf
C:\Program Files\081028_0451.caf
C:\Program Files\081026_0346.caf
C:\Program Files\081025_1005.caf
C:\Program Files\081023_0758.caf
C:\Program Files\081022_1338.caf
C:\Program Files\081020_1751.caf
C:\Program Files\081019_1528.caf
C:\Program Files\081017_1716.caf
C:\Program Files\081015_2305.caf
C:\Program Files\081014_1347.caf
C:\Program Files\081013_2137.caf
C:\Program Files\081013_0521.caf
C:\Program Files\081012_1322.caf
C:\Program Files\081010_1142.caf
C:\Program Files\081009_0810.caf
C:\Program Files\081008_1138.caf
C:\Program Files\081007_0632.caf
C:\Program Files\081004_1252.caf
C:\Program Files\081003_2310.caf
C:\Program Files\081002_0811.caf
C:\Program Files\081002_1535.caf
C:\Program Files\080929_2227.caf
C:\Program Files\080928_1558.caf
C:\Program Files\080928_0103.caf
C:\Program Files\080927_0728.caf
C:\Program Files\080927_0002.caf
C:\Program Files\080925_0826.caf
C:\Program Files\080924_1252.caf
C:\Program Files\080923_2251.caf
C:\Program Files\080923_0510.caf
C:\Program Files\080921_2356.caf
C:\Program Files\080920_1841.caf
C:\Program Files\080918_2226.caf
C:\Program Files\080917_1704.caf
C:\Program Files\080916_0002.caf
C:\Program Files\080914_1012.caf
C:\Program Files\080913_1259.caf
C:\Program Files\080912_1649.caf
C:\Program Files\080908_1708.caf
C:\Program Files\080907_0715.caf
C:\Program Files\080906_2326.caf
C:\Program Files\080906_0729.caf
C:\Program Files\080905_1724.caf
C:\Program Files\080903_1710.caf
C:\Program Files\080902_2312.caf
C:\Program Files\080831_1343.caf
C:\Program Files\080830_1127.caf
C:\Program Files\080829_2216.caf
C:\Program Files\080829_1427.caf
C:\Program Files\080828_0953.caf
C:\WINDOWS\system32\tmp.reg
C:\Program Files\080824_2218.caf
C:\Program Files\080824_2027.caf
C:\Program Files\080820_1226.caf
C:\Program Files\080819_0824.caf
C:\Program Files\080816_2218.caf
C:\Program Files\080816_0900.caf
C:\Program Files\080814_1352.caf
C:\Program Files\080813_1914.caf
C:\Program Files\080812_0957.caf
C:\Program Files\080809_2303.caf
C:\Program Files\080809_0738.caf
C:\Program Files\080807_0644.caf
C:\Program Files\080805_0600.caf
C:\Program Files\080802_2007.caf
C:\Program Files\080801_0848.caf
C:\Program Files\080731_0009.caf
C:\Program Files\080727_0642.caf
C:\Program Files\080730_0024.caf
C:\Program Files\080726_1127.caf
C:\Program Files\080719_1631.caf
C:\Program Files\080724_1320.caf
C:\Program Files\080723_2258.caf
C:\Program Files\080722_1310.caf
C:\Program Files\080720_2313.caf
C:\Program Files\080718_1202.caf
C:\Program Files\080719_0029.caf
C:\Program Files\080717_1703.caf
C:\Program Files\080716_1917.caf
C:\Program Files\080715_0000.caf
C:\Program Files\080713_1149.caf
C:\Program Files\080712_1330.caf
C:\Program Files\080709_1255.caf
C:\Program Files\080709_09541.caf
C:\Program Files\arcn147b.exe
C:\Program Files\080707_1628.caf
C:\Program Files\080705_1011.caf
C:\Program Files\080705_0829.caf
C:\Program Files\080704_1411.caf
C:\Program Files\080702_1917.caf
C:\Program Files\080702_0615.caf
C:\Program Files\080630_1524.caf
C:\Program Files\080629_00281.caf
C:\Program Files\080627_1300.caf
C:\Program Files\080625_2034.caf
C:\Program Files\080623_2200.caf
C:\WINDOWS\TEMP\11B.tmp

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
OK , I know what these caf files are . I told you I down load and burn files to disk , I have HUNDREDS of files saved this way , and I downloaded a free file catalog program called CATHY which some guy in a scandinavian country wrote . I think these caf files are CAthy Files for the program to store as an index of titles (thats how I can tell if I already downloaded and saved a file a year ago , and I won't make a duplicate) . Anyway , I did copy the file you asked for from the desktop to the laptop and uploaded it to Jotti and I will inclde the results . By the way the file copied to the thumb drive as a caf.txt file , I think that with all the fixes I have done , my desktop is back to hiding "known file extensions" . Remind me how to change it to show file settings , we may have to scan again if files were hidden . The scan is taking a long time on Jotti so I sent it to VirusTotal , here's what it found File 081029_2140.caf.txt received on 11.03.2008 02:23:24 (CET) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/36 (0%) Loading server information… Your file is queued in position: ___. Estimated start time is between ___ and ___ . Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2008.11.1.0 2008.11.02 - AntiVir 7.9.0.10 2008.11.02 - Authentium 5.1.0.4 2008.11.02 - Avast 4.8.1248.0 2008.11.02 - AVG 8.0.0.161 2008.11.02 - BitDefender 7.2 2008.11.03 - CAT-QuickHeal 9.50 2008.11.01 - ClamAV 0.94.1 2008.11.03 - DrWeb 4.44.0.09170 2008.11.03 - eSafe 7.0.17.0 2008.11.02 - eTrust-Vet 31.6.6185 2008.11.01 - Ewido 4.0 2008.11.02 - F-Prot 4.4.4.56 2008.11.02 - F-Secure 8.0.14332.0 2008.11.03 - Fortinet 3.117.0.0 2008.11.02 - GData 19 2008.11.03 - Ikarus T3.1.1.45.0 2008.11.02 - K7AntiVirus 7.10.514 2008.11.01 - Kaspersky 7.0.0.125 2008.11.02 - McAfee 5422 2008.11.02 - Microsoft 1.4005 2008.11.03 - NOD32 3576 2008.11.03 - Norman 5.80.02 2008.10.31 - Panda 9.0.0.4 2008.11.02 - PCTools 4.4.2.0 2008.11.02 - Prevx1 V2 2008.11.03 - Rising 21.01.62.00 2008.11.02 - SecureWeb-Gateway 6.7.6 2008.11.02 - Sophos 4.35.0 2008.11.03 - Sunbelt 3.1.1767.2 2008.10.31 - Symantec 10 2008.11.03 - TheHacker [removed].135 2008.10.31 - TrendMicro 8.700.0.1004 2008.10.31 - VBA32 3.12.8.9 2008.11.02 - ViRobot 2008.10.31.1446 2008.10.31 - VirusBuster 4.5.11.0 2008.11.02 - Additional information File size: 27991 bytes MD5…: 893cbc0200bfa03a70674c100e6dcb6c SHA1..: 6b7be78a7439464e52cadefbac184c749c0f17a8 SHA256: c42e613d5cb51b3f9e76bb82af7dd3c6cd2ed8799235400d2c4540b9e29c1392 SHA512: c171ef99d151a90c08746d55b03ab7720d345805ba437e19dda018b3c560f1cf 928f56dbf9cca3554d455dcc87ae243fc08142d83a3e6f50226834c953045ae6 PEiD..: - TrID..: File type identification Unknown! PEInfo: - I renamed it back to .caf only and rescanned it , and I got nearly the same results File 081029_2140.caf received on 11.03.2008 02:31:38 (CET) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/35 (0%)
Your logs look good to me.

Be sure to do this now:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]

    You can remove these leftover files and folders if listed:
    C:\ComboFix
    C:\QooBox
    C:\combofix.txt
    C:\combofix-quarantine-files.txt

    Maybe this will help:

    http://www.malwareremoval.com/tutorials/runningslowly.php
OK , I did what you said about making that CFScript.txt file , but youdidn't tell me to put it on the infected DESKTOP computer , so it ended up scaning the LAPTOP , because I am reading and sending all my messages from the laptop . Anyway , here is the log produced from the laptop scan . Now should I transfer the CFScript file from the laptop to the desktop and rescan again ? I will delete the two files you mentioned , one is supposed to be an installation of an old DOS program called arachne , but I will wait to confirm that you want me to uninstall ComboFix from the infected computer , or make a final scan. Also should I re-enable all of the protection programs on the infected machine ?
(by the way , I am not named Barry Baram , he is the guy I bought the used laptop from)

ComboFix 08-11-02.04 - Barry Baram 11/02/2008 20:48:22.1 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.52 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Barry Baram\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Program Files\080623_2200.caf
C:\Program Files\080625_2034.caf
C:\Program Files\080627_1300.caf
C:\Program Files\080629_00281.caf
C:\Program Files\080630_1524.caf
C:\Program Files\080702_0615.caf
C:\Program Files\080702_1917.caf
C:\Program Files\080704_1411.caf
C:\Program Files\080705_0829.caf
C:\Program Files\080705_1011.caf
C:\Program Files\080707_1628.caf
C:\Program Files\080709_09541.caf
C:\Program Files\080709_1255.caf
C:\Program Files\080712_1330.caf
C:\Program Files\080713_1149.caf
C:\Program Files\080715_0000.caf
C:\Program Files\080716_1917.caf
C:\Program Files\080717_1703.caf
C:\Program Files\080718_1202.caf
C:\Program Files\080719_0029.caf
C:\Program Files\080719_1631.caf
C:\Program Files\080720_2313.caf
C:\Program Files\080722_1310.caf
C:\Program Files\080723_2258.caf
C:\Program Files\080724_1320.caf
C:\Program Files\080726_1127.caf
C:\Program Files\080727_0642.caf
C:\Program Files\080730_0024.caf
C:\Program Files\080731_0009.caf
C:\Program Files\080801_0848.caf
C:\Program Files\080802_2007.caf
C:\Program Files\080805_0600.caf
C:\Program Files\080807_0644.caf
C:\Program Files\080809_0738.caf
C:\Program Files\080809_2303.caf
C:\Program Files\080812_0957.caf
C:\Program Files\080813_1914.caf
C:\Program Files\080814_1352.caf
C:\Program Files\080816_0900.caf
C:\Program Files\080816_2218.caf
C:\Program Files\080819_0824.caf
C:\Program Files\080820_1226.caf
C:\Program Files\080824_2027.caf
C:\Program Files\080824_2218.caf
C:\Program Files\080828_0953.caf
C:\Program Files\080829_1427.caf
C:\Program Files\080829_2216.caf
C:\Program Files\080830_1127.caf
C:\Program Files\080831_1343.caf
C:\Program Files\080902_2312.caf
C:\Program Files\080903_1710.caf
C:\Program Files\080905_1724.caf
C:\Program Files\080906_0729.caf
C:\Program Files\080906_2326.caf
C:\Program Files\080907_0715.caf
C:\Program Files\080908_1708.caf
C:\Program Files\080912_1649.caf
C:\Program Files\080913_1259.caf
C:\Program Files\080914_1012.caf
C:\Program Files\080916_0002.caf
C:\Program Files\080917_1704.caf
C:\Program Files\080918_2226.caf
C:\Program Files\080920_1841.caf
C:\Program Files\080921_2356.caf
C:\Program Files\080923_0510.caf
C:\Program Files\080923_2251.caf
C:\Program Files\080924_1252.caf
C:\Program Files\080925_0826.caf
C:\Program Files\080927_0002.caf
C:\Program Files\080927_0728.caf
C:\Program Files\080928_0103.caf
C:\Program Files\080928_1558.caf
C:\Program Files\080929_2227.caf
C:\Program Files\081002_0811.caf
C:\Program Files\081002_1535.caf
C:\Program Files\081003_2310.caf
C:\Program Files\081004_1252.caf
C:\Program Files\081007_0632.caf
C:\Program Files\081008_1138.caf
C:\Program Files\081009_0810.caf
C:\Program Files\081010_1142.caf
C:\Program Files\081012_1322.caf
C:\Program Files\081013_0521.caf
C:\Program Files\081013_2137.caf
C:\Program Files\081014_1347.caf
C:\Program Files\081015_2305.caf
C:\Program Files\081017_1716.caf
C:\Program Files\081019_1528.caf
C:\Program Files\081020_1751.caf
C:\Program Files\081022_1338.caf
C:\Program Files\081023_0758.caf
C:\Program Files\081025_1005.caf
C:\Program Files\081026_0346.caf
C:\Program Files\081028_0451.caf
C:\Program Files\081029_2140.caf
C:\Program Files\arcn147b.exe
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\TEMP\11B.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\Web\default.htt

.
((((((((((((((((((((((((( Files Created from 2008-10-03 to 2008-11-03 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-01 15:43 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-11-01 15:43 ——— d—–w C:\Program Files\SanDisk
2008-11-01 14:55 ——— d—–w C:\Program Files\Snapshot Viewer
2008-11-01 14:52 ——— d—–w C:\Program Files\TZEdit
2008-09-15 05:13 1,644,432 —-a-w C:\WINNT\system32\WIN32K.SYS
2008-08-20 15:51 575,488 —-a-w C:\WINNT\system32\WININET.DLL
2006-03-21 18:03 784 —-a-w C:\Documents and Settings\Barry Baram\Application Data\mpauth.dat
2006-03-21 04:13 5,834,344 —-a-w C:\Program Files\winzip100.exe
2002-12-14 10:31 271 —h–w C:\Program Files\desktop.ini
2002-12-14 10:31 21,952 —h–w C:\Program Files\folder.htt
1999-12-07 12:00 32,528 —-a-w C:\WINNT\inf\wbfirdma.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [05/31/05 12:04a 1415824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Motive SmartBridge"="C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe" [12/10/03 04:21a 380928]
"Synchronization Manager"="mobsync.exe" [06/19/03 02:05p 111376 C:\WINNT\system32\mobsync.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [06/19/03 02:05p 186640]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
Monitor.lnk - C:\Program Files\SanDisk\SanDisk TransferMate\SD Monitor.exe [2008-11-01 114688]
Verizon Online Help & Support.lnk - C:\Program Files\Verizon Online\Help Support\bin\matcli.exe [2006-03-20 217088]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\WINNT\warnhp.html
FriendlyName= Desktop Uninstall

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=C:\WINNT\pss\Billminder.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
backup=C:\WINNT\pss\Exif Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=C:\WINNT\pss\Quicken Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINNT\pss\WinZip Quick Pick.lnkCommon Startup

R3 ati2mpab;ati2mpab;C:\WINNT\system32\DRIVERS\ati2mpab.sys [02/07/00 06:09a 249120]
R3 maestro;ESS Maestro Audio Driver (WDM);C:\WINNT\system32\drivers\maestro.sys [11/22/99 11:01a 48368]
R3 pc100;Linksys EtherFast 10/100 PC Card NT Driver;C:\WINNT\system32\DRIVERS\pc100nd5.sys [11/15/01 12:44p 32589]
R3 USB_RNDIS_2K;Westell WireSpeed Dual Connect Modem;C:\WINNT\system32\DRIVERS\usb8023k.sys [08/12/02 02:20a 11136]

*Newly Created Service* - PROCEXP90
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-02 20:53:40
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 11/02/2008 20:56:15
ComboFix-quarantined-files.txt 2008-11-03 01:56:10

Pre-Run: 12,197,822,464 bytes free
Post-Run: 12,357,312,512 bytes free

181
If you know what this file is, no need to remove it unless you don't use it.
C:\Program Files\arcn147b.exe

I know what these caf files are

I wouldn't worry about those then either.

Yes, re-enable all your protection programs.
I went back to the infected computer and re-enabled all of the protection progams . Then I restarted it . Then I tried to uninstall Combofix . It wouldn't uninstall says it cant find CF14771.exe . Combofix folder is still on C: , as well as QooBox folder and the text files .
I tried to uninstall Combofix again this morning and apparently it worked although I had to delete a couple items manually . I looked at the running slowly page at the link you gave above . I don't think any of those things would help,at this point . The computer probably could use a good defrag but it was still running OK up to the day the adobe opened by itself and froze the computer . I hope that the recovery console that ComboFix installed will help to fix the browser or OS , although I have been using computers since 1998 , I have not done a recovery , although years ago my computer engineer friend reformatted my first computer because of a virus and I lost much work ( I moved away from his town early this year and that is why I don't have anyone nearby to help or let me make a good copy of any corrupt file from their XP system ) . I am going to be away from my computer all day today , Monday , I will be back on Tuesday , if you can leave any messages about how to fix the OS or browser , please do so .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI