[Resolved] Antivirus 2009
41 min read
I haven't noticed any files but I will see if I can find any.
Here is the latest combofix report
ComboFix 08-11-12.02 - Kim Eyler 2008-11-14 9:46:32.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.124 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kim Eyler\Desktop\CFScript.txt
FILE ::
c:\documents and settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\AD Balster.zip
c:\documents and settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\Cool System Tools.zip
c:\documents and settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\Easy JAVA Pop Up.zip
c:\windows\SYSTEM32\cinstaller_xp.msi
E:\SH-S182M(TS-H652M).exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\AD Balster.zip
c:\documents and settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\Cool System Tools.zip
c:\documents and settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\Easy JAVA Pop Up.zip
c:\windows\SYSTEM32\cinstaller_xp.msi
.
((((((((((((((((((((((((( Files Created from 2008-10-14 to 2008-11-14 )))))))))))))))))))))))))))))))
.
2008-11-13 19:40 . 2008-06-10 02:32 73,728 –a—— c:\windows\SYSTEM32\javacpl.cpl
2008-11-13 19:39 . 2008-11-13 19:39 d——– c:\program files\Common Files\Java
2008-11-13 13:13 . 2005-09-20 09:36 114,688 –a—— c:\windows\SYSTEM32\igfxpers.exe
2008-11-13 13:13 . 2005-09-20 09:35 94,208 –a—— c:\windows\SYSTEM32\igfxtray.exe
2008-11-13 13:13 . 2005-09-20 09:32 77,824 –a—— c:\windows\SYSTEM32\hkcmd.exe
2008-11-13 10:59 . 2008-11-13 10:59 578,560 –a—— c:\windows\SYSTEM32\DLLCACHE\user32.dll
2008-11-13 10:54 . 2008-11-13 10:54 d——– c:\windows\ERUNT
2008-11-13 10:52 . 2008-11-13 11:36 d—-c— C:\SDFix
2008-11-13 00:07 . 2008-11-13 00:07 d——– c:\documents and settings\LocalService\Application Data\McAfee
2008-11-12 23:30 . 2008-11-14 09:33 d——– c:\documents and settings\Kim Eyler\SmitfraudFix
2008-11-12 23:13 . 2008-11-12 23:13 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-12 23:13 . 2008-11-12 23:13 d——– c:\documents and settings\Kim Eyler\Application Data\Malwarebytes
2008-11-12 23:13 . 2008-11-12 23:13 d—-c— c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-12 23:13 . 2008-10-22 16:10 38,496 –a—— c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-11-12 23:13 . 2008-10-22 16:10 15,504 –a—— c:\windows\SYSTEM32\DRIVERS\mbam.sys
2008-11-12 06:26 . 2008-11-12 06:26 1,393 –a—— c:\windows\imsins.BAK
2008-11-12 06:16 . 2008-10-24 06:21 455,296 ——— c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-11-12 06:15 . 2008-09-04 12:15 1,106,944 ——— c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
2008-11-11 17:33 . 2008-11-11 18:41 d—-c— C:\SDAT
2008-11-11 17:30 . 2008-11-11 17:25 95,253,636 –a–c— C:\sdat5430.exe
2008-11-10 18:07 . 2008-11-12 23:32 2,568 –a—— c:\windows\SYSTEM32\tmp.reg
2008-11-10 16:41 . 2005-03-16 14:21 0 –ah-c— c:\documents and settings\Administrator\hpothb07.dat
2008-11-10 16:40 . 2005-03-02 00:57 d—-c— c:\documents and settings\Administrator\Application Data\Jasc Software Inc
2008-11-10 16:40 . 2005-03-02 00:57 d–h-c— c:\documents and settings\Administrator\Application Data\Gtek
2008-11-10 16:40 . 2008-11-10 16:41 d—-c— c:\documents and settings\Administrator
2008-11-10 16:33 . 2008-11-10 16:33 d——– c:\program files\Trend Micro
2008-11-10 16:28 . 2008-11-10 16:28 d——– c:\program files\CCleaner
2008-11-10 13:53 . 2008-11-10 16:48 d—-c— c:\documents and settings\All Users\Application Data\avg8
2008-11-09 09:50 . 2008-11-09 09:50 9,662 –a—— c:\windows\SYSTEM32\ZoneAlarmIconUS.ico
2008-11-09 09:50 . 2008-11-09 09:50 4,286 –a—— c:\windows\SYSTEM32\Jamster.ico
2008-11-09 09:34 . 2008-11-10 13:39 d–hs—- c:\windows\RXJpYyBFeWxlcg
2008-11-08 09:03 . 2008-11-08 11:36 58 –a—— c:\windows\SYSTEM32\winwp.bmp
2008-11-08 08:58 . 2004-08-04 06:00 4,224 –a—— c:\windows\SYSTEM32\DRIVERS\beep.sys
2008-11-08 08:58 . 2004-08-04 06:00 4,224 –a—— c:\windows\SYSTEM32\DLLCACHE\beep.sys
2008-11-08 08:58 . 2004-08-04 06:00 2,944 –a—— c:\windows\SYSTEM32\DRIVERS\null.sys
2008-11-08 08:58 . 2004-08-04 06:00 2,944 –a—— c:\windows\SYSTEM32\DLLCACHE\null.sys
2008-11-08 08:57 . 2008-11-08 08:57 d——– c:\windows\SYSTEM32\sX3i19
2008-11-08 08:57 . 2008-11-08 08:57 d——– c:\temp\PRE45
2008-11-06 06:29 . 2008-11-06 06:29 6,144 –ahsc— C:\Thumbs.db
2008-11-04 07:11 . 2008-11-04 07:11 d——– C:\MSI
2008-11-04 07:11 . 2008-11-04 07:11 52 –a—— c:\windows\FPRINCE.INI
2008-11-03 19:46 . 2008-11-03 19:46 d——– c:\windows\Reader Rabbit Creative Studio
2008-11-03 19:46 . 2000-12-21 07:43 194,048 –a—— c:\windows\RRPW.pol
2008-11-03 19:35 . 2008-11-03 19:35 d——– c:\program files\Disney Interactive
2008-11-03 19:33 . 2008-11-03 19:35 1,259 –a—— c:\windows\disney.ini
2008-11-03 19:22 . 2008-11-03 19:22 d——– c:\windows\WNBackup
2008-11-03 19:22 . 2008-11-11 17:31 d——– C:\KA
2008-11-03 19:22 . 1998-09-24 18:31 270,848 –a—— c:\windows\unwise.exe
2008-11-03 19:22 . 2008-11-03 19:22 218 –a—— c:\windows\KA.INI
2008-11-03 19:22 . 2008-11-03 19:22 60 –a—— c:\windows\SIERRA.INI
2008-11-03 19:12 . 2008-11-06 06:36 d——– c:\program files\The Learning Company
2008-10-31 15:50 . 2008-10-31 15:50 0 –a—— c:\windows\SETUP32.INI
2008-10-26 08:55 . 2008-10-15 11:34 337,408 ——— c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-15 02:11 . 2008-09-08 05:41 333,824 ——— c:\windows\SYSTEM32\DLLCACHE\srv.sys
2008-10-15 02:10 . 2008-08-14 05:11 2,189,184 ——— c:\windows\SYSTEM32\DLLCACHE\ntoskrnl.exe
2008-10-15 02:10 . 2008-08-14 05:09 2,145,280 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2008-10-15 02:10 . 2008-08-14 04:33 2,066,048 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2008-10-15 02:10 . 2008-08-14 04:33 2,023,936 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrpamp.exe
2008-10-15 02:10 . 2008-09-15 07:12 1,846,400 ——— c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2008-10-14 09:42 . 2008-10-14 09:42 d–hs—- c:\windows\ftpcache
2008-10-14 09:41 . 2004-03-29 15:23 90,112 –a—— c:\windows\unvise32.exe
2008-10-14 09:38 . 2008-10-14 09:38 d——– c:\program files\Hooked on Phonics Learning
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-14 03:48 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-14 00:40 ——— d—–w c:\program files\Java
2008-11-13 20:18 ——— d—–w c:\program files\QuickTime
2008-11-13 20:18 ——— d—–w c:\program files\Lexmark Fax Solutions
2008-11-13 20:18 ——— d—–w c:\program files\Lexmark 2300 Series
2008-11-13 20:18 ——— d—–w c:\program files\Dell Support
2008-11-11 21:51 ——— d—–w c:\documents and settings\Kim Eyler\Application Data\McAfee
2008-11-11 15:20 ——— dc—-w c:\documents and settings\All Users\Application Data\McAfee
2008-11-10 23:25 ——— d—–w c:\program files\Audible
2008-11-08 12:17 ——— d—–w c:\program files\Lx_cats
2008-11-06 13:04 ——— d—–w c:\program files\GamingSquared
2008-11-06 12:50 ——— d—–w c:\program files\Broderbund
2008-11-06 11:40 ——— d—–w c:\program files\Real
2008-11-06 11:39 ——— d—–w c:\program files\Kids Cam Show and Share Creativity Center
2008-11-06 11:38 ——— d—–w c:\program files\Dell Games
2008-11-06 11:33 ——— d—–w c:\program files\_uninstallation_info
2008-11-06 11:32 ——— d—–w c:\program files\Windows Media Connect 2
2008-11-06 11:32 ——— d—–w c:\program files\PopCap Games
2008-11-06 11:31 ——— d—–w c:\program files\GameFiesta
2008-11-06 11:31 ——— d—–w c:\program files\Free Offers from Freeze.com
2008-11-04 00:35 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-09-18 10:58 ——— d—–w c:\program files\Blubster
2008-09-07 02:09 0 -c–a-w c:\program files\temp01
2006-02-02 14:59 322 -c-ha-w c:\documents and settings\Kim Eyler\hpothb07.dat
2006-02-02 14:56 169 -c-ha-w c:\documents and settings\NetworkService\hpothb07.dat
2005-08-14 15:55 0 -c-ha-w c:\documents and settings\LocalService\hpothb07.dat
2005-07-16 12:04 70,076 -c–a-w c:\documents and settings\Eric Eyler\Winsock2.reg
2005-03-16 19:21 368 -c-ha-w c:\documents and settings\Kim Eyler\Application Data\hpothb07.dat
2005-03-16 19:21 164 -c-ha-w c:\documents and settings\All Users\hpothb07.dat
2005-03-16 19:21 0 -c-ha-w c:\documents and settings\Default User\hpothb07.dat
.
((((((((((((((((((((((((((((( snapshot@2008-11-13_ 1.33.47.75 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 20:27:04 163,328 —-a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2008-11-13 15:54:37 6,643,712 —-a-w c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-11-13 15:54:37 114,688 —-a-w c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 —-a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-11-13 15:54:21 6,643,712 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-11-13 15:54:21 114,688 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-11-13 01:45:17 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2008-11-14 14:05:27 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
- 2008-11-13 01:45:17 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-14 14:05:27 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-11-10 16:27:06 49,248 -c–a-w c:\windows\SYSTEM32\java.exe
+ 2008-06-10 06:21:01 135,168 —-a-w c:\windows\SYSTEM32\java.exe
- 2005-11-10 16:27:16 49,250 -c–a-w c:\windows\SYSTEM32\javaw.exe
+ 2008-06-10 06:21:04 135,168 —-a-w c:\windows\SYSTEM32\javaw.exe
- 2005-11-10 18:03:54 127,078 -c–a-w c:\windows\SYSTEM32\javaws.exe
+ 2008-06-10 07:32:34 139,264 —-a-w c:\windows\SYSTEM32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Name of App"="c:\program files\SAMSUNG\FW LiveUpdate\Liveupdate.exe" [2006-03-10 667735]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-03-02 98304]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3IV2"= 3ivxVfWCodec.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.CDVC"= cdvccodc.dll
"VIDC.NTN1"= NUVision.ax
[HKLM\~\startupfolder\c:^documents and settings^all users^start menu^programs^startup^kodak easyshare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aim6]
–a—— 2008-08-06 10:21 50472 c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aim6.exe"=
"c:\\WINDOWS\\SYSTEM32\\lxcgcoms.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxcgpswx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Blubster\\Blubster.exe"=
"c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\system32\DRIVERS\mr97310v.sys [2006-07-18 99840]
.
Contents of the 'Scheduled Tasks' folder
2008-11-08 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\RUNDLL32.EXE [2008-04-13 19:12]
2008-11-07 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (MAIN-Kim Eyler).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []
2008-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-11-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-14 10:25:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Name of App = c:\program files\SAMSUNG\FW LiveUpdate\Liveupdate.exe??|P???????P??????? ?B?????Kim Eyler?y?l?e?r???(??????|@??|????=??|Y??|????????x???x?????C?x???P??????? ?B?????????????????????061210122311500?2?3?1?1?5?0?0???????????????????????????????????????0???(?????G
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\CTSVCCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\McAfee\MBK\MBackMonitor.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Logitech\MouseWare\system\EM_EXEC.EXE
c:\program files\AIM6\aolsoftware.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-11-14 10:36:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-14 15:36:50
ComboFix2.txt 2008-11-14 04:20:05
ComboFix3.txt 2008-11-13 22:44:22
ComboFix4.txt 2008-11-13 06:37:05
Pre-Run: 22,173,302,784 bytes free
Post-Run: 22,212,583,424 bytes free
256 — E O F — 2008-11-12 11:28:56
Because they like you and want to stay with you forever.Why do some programs not allow me to remove them in the add/remove list?
Actually, there are multiple reasons. They could be a bad install so they won't uninstall. In cases like that you can re-install and then uninstall.
They could have had malware associated with them and the uninstall program was damaged when the adware was removed.
They could just be garbage and the programmer never made a good uninstall program in the first place.
Here is how I handle uninstalls.
- Add/remove panel. This is the best. Always try first.
- Uninstall program. Sometimes if you click on Start->All programs you will find a "folder" for your program that has multiple options that run the program, checks for updates, adjusts settings, or maybe even uninstall. If it has this uninstall option, this is my second choice.
- If I can't get rid of it using either of those options, I just delete the folder associated with it.
Log looks good
Time for some housekeeping
- Click START then RUN
- Now type Combofix /u in the runbox and click OK
- Note the space between the X and the U, it needs to be there.
- [external image: Posted Image]
- Delete the following:
- ComboFix and its associated files and folders.
- VundoFix backups, if present
- The C:\Deckard folder, if present
- The C:_OtMoveIt folder, if present
- Reset the clock settings.
- Hide file extensions, if required.
- Hide System/Hidden files, if required.
- Reset System Restore.
Please re-enable any security that was disabled.
Delete any tools we used with the exception of Mbam. I suggest you keep it and run it once and awhile (after updating first)
Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.
For a tutorial on Firewalls and a listing of some available ones see the link below:
Understanding and Using Firewalls
Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
- From your desktop, right-click on My Computer,
- click on Properties
- Select the Automatic Updates tab
- Click on Automatic
- Click on Apply button
- Click on OK to exit.
Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware
Download and install the free version of WinPatrol - This program protects your computer in a variety of ways and will work well with your existing security software.
Winpatrol
Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.
Only run one Anti-Virus and Firewall program.
I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Also: "How to prevent malware"
by miekiemoes
Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved.
Delete any tools we used with the exception of Mbam. I suggest you keep it and run it once and awhile (after updating first)
Try this on your time.
If you want your clock in 12 hr vs. 24 hour format:
- Click on Start
- Click on Control Panel
- Click on Regional and language options
- Click on customize
- Click on Time tab
- Click on arrow to the right of time format
- Select h:mm:ss tt
- OK your way out
Let me know if you need to clean the other computer.
I'm not usually friendly. I'm just a sucker for a damsel in distress. Those tears got to me in post #1.You were so friendly
Let me know about the other computer and the clock before I close this thread please.
Delete any tools we used with the exception of Mbam. I suggest you keep it and run it once and awhile (after updating first)
OK so it's always safe to delete whatever it finds correct?
Try this on your time.
If you want your clock in 12 hr vs. 24 hour format:
- Click on Start
- Click on Control Panel
- Click on Regional and language options
- Click on customize
- Click on Time tab
- Click on arrow to the right of time format
- Select h:mm:ss tt
- OK your way out
YAY it worked!!!!!!!!! YOU SO ROCK!
I'm not usually friendly. I'm just a sucker for a damsel in distress. Those tears got to me in post #1.
![]()
Let me know about the other computer and the clock before I close this thread please.
I find that hard to believe
Ok I will scan the other computer and let you know ASAP!
Thanks again
Technically no. But it is so close to true that I would just go with it.OK so it's always safe to delete whatever it finds correct?
Every scanner can make mistakes. What we call a false positive. However, it happens so rarely that I would always assume that Mbam is correct. Also, always check for updates. It gets updated regularly. Maybe even more than once in a day. When false positives are found, the database is corrected almost immediately.
Scan saved at 3:13:34 PM, on 11/14/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Windows\System32\wpcumi.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\sttray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\vghd\VirtuaGirl_downloader.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cm.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\PhotoDownloader.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [trioService] "C:\PROGRA~1\Freeze.com\3D Falling Leaves\\trioService.exe "
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: DesktopVideoPlayer.LNK = C:\Program Files\vghd\vghd.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Odds Maker - b3cab7b9-eb43-46a2-8e15-02cc298dec71 - C:\Users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Odds Maker\Odds Maker.lnk (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FreezeScreenSaver - Unknown owner - C:\Windows\system32\FreezeScreenSaver.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxcg_device - - C:\Windows\system32\lxcgcoms.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 12159 bytes
I still have the same opinion of Viewpoint as I had on your other machine. If it was mine, I'd uninstall it.
FREEZESCREENSAVER.EXE_is_Adware (click for info)
- Please open HijackThis and run Do a system scan only
- Check the boxes next to ONLY the entries listed below(if present):
- O23 - Service: FreezeScreenSaver - Unknown owner - C:\Windows\system32\FreezeScreenSaver.exe
- Close all programs except for HijackThis.
- Click on Fix checked
- A box will pop up asking you if you wish to fix the selected items. Please choose YES.
- Once it has fixed them, please exit/close HijackThis.
We Now Need To Boot Into Safemode
Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.
Using Windows Explorer (Windows Key + E), locate the following file, and DELETE it (if still present):
C:\Windows\system32\FreezeScreenSaver.exe <–This file
Don't be concerned if you don't find it. It just means that it was already removed in a previous step.
Restart your computer normally.
Unless you know of some other problem, I'd say you are good to go.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI