This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] IE pop ups using Firefox

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I installed a bad file on the computer (stupid me) and got some bad stuff as a result. Lately it's been giving me a ton of IE pop ups and I'm using FireFox. Also I have been getting some redirects from yahoo and google searches. I ran AVG, CCleaner, and Spybot and each one gives me an error message during the scan, although I have been able to clean up a lot of stuff. I get the feeling I havn't fixed the root of the problem, and was hoping somebody on here would be able to help me out.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:35:03 PM, on 11/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\PROGRA~1\AVG\AVG8\avgtray.exe
E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
E:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
E:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
E:\PROGRA~1\Iomega\System32\AppServices.exe
E:\Program Files\Norton AntiVirus\navapsvc.exe
E:\EMTS\Launcher.Exe
E:\WINDOWS\system32\HPZipm12.exe
E:\Program Files\Norton AntiVirus\SAVScan.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
E:\Program Files\Iomega\AutoDisk\ADService.exe
E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
E:\PROGRA~1\AVG\AVG8\avgrsx.exe
E:\WINDOWS\System32\alg.exe
E:\Program Files\Microsoft Office\Office\WINWORD.EXE
E:\Program Files\Mozilla Firefox\firefox.exe
E:\Program Files\Trend Micro\HijackThis\HijackThis.exe
E:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {0431D889-7867-4943-88E3-00F67A166149} - (no file)
O2 - BHO: (no name) - {302D49CA-575B-4262-9B8C-2F26C2D9F83A} - (no file)
O2 - BHO: {42c8a275-aeb4-4cea-02c4-7a4915143cb4} - {4bc34151-94a7-4c20-aec4-4bea572a8c24} - E:\WINDOWS\system32\pelbot.dll
O2 - BHO: (no name) - {4CAB59B4-55A3-4737-9FD5-B93C6430BF76} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - E:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - E:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - E:\Program Files\MSN\Toolbar\3.0.0311.0\msneshellx.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - E:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [E:\WINDOWS\system32\kdjjq.exe] E:\WINDOWS\system32\kdjjq.exe
O4 - HKLM\..\Run: [AVG8_TRAY] E:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSConfig] E:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ccleaner] "E:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - Global Startup: ClubPRO 3000 Launcher.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/popzuma/…ploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{735CAA80-4962-4E18-AFC7-827D88FB4102}: NameServer = 85.255.112.108;85.255.112.167
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC765CAC-EF38-4264-AA8C-139657F7DCE5}: NameServer = 85.255.112.108;85.255.112.167
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: ,avgrsstx.dll pelbot.dll
O20 - Winlogon Notify: efcCrOfG - efcCrOfG.dll (file missing)
O20 - Winlogon Notify: winoyo32 - winoyo32.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - E:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iomega App Services - Iomega Corporation - E:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - E:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - E:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - E:\Program Files\Iomega\AutoDisk\ADService.exe

–
End of file - 7609 bytes
Hello

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
i closed the avg but it looks like the scan said it was on anyways so i hope this still works




X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 CPU 1.70GHz )
BIOS : Default System BIOS
USER : ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus Free 8.0 (Activated)
A:\ (USB)
C:\ (USB)
D:\ (CD or DVD)
E:\ (Local Disk) - NTFS - Total:37 Go (Free:24 Go)
G:\ (USB)

"E:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Mon 11/17/2008|19:23 )

——————–\\ Listing folders in APPLIC~1

[11/13/2008|02:38] E:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft

[10/23/2008|04:26] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[06/16/2008|10:54] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[10/23/2008|04:22] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[10/23/2008|04:26] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[11/13/2008|02:52] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ avg8
[02/19/2007|05:51] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[11/17/2008|12:30] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google Updater
[02/01/2007|06:56] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[09/19/2008|02:21] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[06/21/2003|08:22] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ MSN6
[06/09/2007|08:49] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ PopCap
[02/10/2003|04:55] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBT
[02/01/2007|06:53] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[07/08/2008|01:54] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[11/17/2008|07:18] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[01/10/2007|08:23] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[02/18/2008|04:26] E:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! Companion

[11/30/2007|07:05] E:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[02/24/2003|06:36] E:\DOCUME~1\KARATE~1\APPLIC~1\ Active Disk
[06/16/2008|10:54] E:\DOCUME~1\KARATE~1\APPLIC~1\ Adobe
[02/19/2007|05:54] E:\DOCUME~1\KARATE~1\APPLIC~1\ AdobeAUM
[09/19/2007|06:02] E:\DOCUME~1\KARATE~1\APPLIC~1\ AdobeUM
[10/27/2008|03:06] E:\DOCUME~1\KARATE~1\APPLIC~1\ Apple Computer
[11/13/2008|04:49] E:\DOCUME~1\KARATE~1\APPLIC~1\ AVGTOOLBAR
[04/22/2005|05:32] E:\DOCUME~1\KARATE~1\APPLIC~1\ Brother
[10/27/2008|02:53] E:\DOCUME~1\KARATE~1\APPLIC~1\ EurekaLog
[02/19/2007|07:44] E:\DOCUME~1\KARATE~1\APPLIC~1\ Google
[05/22/2008|03:09] E:\DOCUME~1\KARATE~1\APPLIC~1\ Help
[02/01/2007|07:03] E:\DOCUME~1\KARATE~1\APPLIC~1\ HP
[05/25/2005|04:22] E:\DOCUME~1\KARATE~1\APPLIC~1\ Identities
[07/18/2008|10:31] E:\DOCUME~1\KARATE~1\APPLIC~1\ InstallShield
[04/22/2005|04:43] E:\DOCUME~1\KARATE~1\APPLIC~1\ InterTrust
[10/27/2008|02:53] E:\DOCUME~1\KARATE~1\APPLIC~1\ iPod2PC3
[09/24/2007|05:03] E:\DOCUME~1\KARATE~1\APPLIC~1\ Leadertech
[11/12/2008|07:18] E:\DOCUME~1\KARATE~1\APPLIC~1\ LimeWire
[10/01/2003|06:10] E:\DOCUME~1\KARATE~1\APPLIC~1\ Macromedia
[02/02/2007|03:42] E:\DOCUME~1\KARATE~1\APPLIC~1\ Microsoft
[02/10/2003|04:42] E:\DOCUME~1\KARATE~1\APPLIC~1\ Microsoft Web Folders
[07/30/2008|12:52] E:\DOCUME~1\KARATE~1\APPLIC~1\ Mozilla
[10/31/2006|01:29] E:\DOCUME~1\KARATE~1\APPLIC~1\ MSN6
[07/18/2008|12:31] E:\DOCUME~1\KARATE~1\APPLIC~1\ Sony Corporation
[07/30/2008|01:03] E:\DOCUME~1\KARATE~1\APPLIC~1\ Sun
[11/24/2004|03:48] E:\DOCUME~1\KARATE~1\APPLIC~1\ Symantec
[07/30/2008|12:53] E:\DOCUME~1\KARATE~1\APPLIC~1\ Talkback
[02/18/2008|04:26] E:\DOCUME~1\KARATE~1\APPLIC~1\ Yahoo!

[01/28/2003|10:32] E:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[12/04/2007|06:40] E:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft
[10/10/2006|06:05] E:\DOCUME~1\NETWOR~1\APPLIC~1\ Symantec


——————–\\ Scheduled Tasks located in E:\WINDOWS\Tasks

[11/14/2008 04:34 PM][–a——] E:\WINDOWS\tasks\AppleSoftwareUpdate.job
[11/17/2008 04:21 PM][–a——] E:\WINDOWS\tasks\Symantec NetDetect.job
[11/17/2008 07:21 PM][–ah—–] E:\WINDOWS\tasks\SA.DAT
[08/29/2002 06:00 AM][———] E:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in E:\Program Files

[07/29/2008|06:07] E:\Program Files\ Adobe
[06/16/2008|10:53] E:\Program Files\ Adobe Media Player
[01/28/2003|01:31] E:\Program Files\ Analog Devices
[10/23/2008|04:24] E:\Program Files\ Apple Software Update
[11/13/2008|02:39] E:\Program Files\ AVG
[04/20/2004|12:52] E:\Program Files\ Black Belt Enterprises
[10/23/2008|04:25] E:\Program Files\ Bonjour
[04/22/2005|04:29] E:\Program Files\ Brother
[10/24/2005|05:14] E:\Program Files\ Brownie
[11/17/2008|07:19] E:\Program Files\ CCleaner
[10/23/2008|04:23] E:\Program Files\ Common Files
[01/28/2003|10:29] E:\Program Files\ ComPlus Applications
[11/17/2008|04:06] E:\Program Files\ ERUNT
[11/10/2008|02:54] E:\Program Files\ Free PDF to Word Doc Converter
[07/30/2008|12:50] E:\Program Files\ Google
[02/01/2007|06:48] E:\Program Files\ Hewlett-Packard
[11/17/2008|04:11] E:\Program Files\ Hijackthis
[02/01/2007|06:56] E:\Program Files\ HP
[09/19/2008|02:18] E:\Program Files\ InstallShield Installation Information
[01/28/2003|01:26] E:\Program Files\ Intel
[10/16/2008|02:00] E:\Program Files\ Internet Explorer
[01/28/2003|01:37] E:\Program Files\ Iomega
[10/23/2008|04:26] E:\Program Files\ iPod
[10/23/2008|04:26] E:\Program Files\ iTunes
[07/30/2008|01:02] E:\Program Files\ Java
[02/14/2008|02:30] E:\Program Files\ JavaSoft
[10/23/2008|03:15] E:\Program Files\ LimeWire
[09/20/2008|02:04] E:\Program Files\ Messenger
[02/10/2003|04:54] E:\Program Files\ microsoft frontpage
[02/03/2007|11:01] E:\Program Files\ Microsoft Office
[06/28/2008|12:35] E:\Program Files\ Microsoft Silverlight
[09/15/2004|02:57] E:\Program Files\ Movie Maker
[11/17/2008|07:23] E:\Program Files\ Mozilla Firefox
[06/28/2008|12:36] E:\Program Files\ MSN
[01/28/2003|10:28] E:\Program Files\ MSN Gaming Zone
[02/02/2007|07:54] E:\Program Files\ MSXML 4.0
[09/19/2008|02:18] E:\Program Files\ NETGEAR
[09/15/2004|02:55] E:\Program Files\ NetMeeting
[11/17/2008|07:18] E:\Program Files\ Norton AntiVirus
[01/28/2003|10:31] E:\Program Files\ Online Services
[06/13/2007|05:52] E:\Program Files\ Outlook Express
[10/23/2008|04:25] E:\Program Files\ QuickTime
[09/22/2006|10:18] E:\Program Files\ Seagate Software
[02/10/2003|04:55] E:\Program Files\ Snapshot Viewer
[07/18/2008|10:32] E:\Program Files\ Sony
[11/11/2006|11:33] E:\Program Files\ Spybot - Search & Destroy
[10/10/2006|06:07] E:\Program Files\ Symantec
[10/10/2006|06:07] E:\Program Files\ SymNetDrv
[06/25/2008|06:22] E:\Program Files\ The Weather Channel FW
[11/17/2008|05:17] E:\Program Files\ Trend Micro
[07/17/2004|10:51] E:\Program Files\ Uninstall Information
[11/06/2008|01:40] E:\Program Files\ WebEx
[03/08/2007|01:44] E:\Program Files\ Windows Media Connect 2
[03/08/2007|01:47] E:\Program Files\ Windows Media Player
[09/15/2004|02:55] E:\Program Files\ Windows NT
[08/11/2004|02:52] E:\Program Files\ WindowsUpdate
[01/28/2003|10:32] E:\Program Files\ xerox
[02/18/2008|04:21] E:\Program Files\ Yahoo!

——————–\\ Listing Folders in E:\Program Files\Common Files

[08/22/2007|02:01] E:\Program Files\Common Files\ Adobe
[06/16/2008|10:53] E:\Program Files\Common Files\ Adobe AIR
[10/23/2008|04:24] E:\Program Files\Common Files\ Apple
[02/24/2003|06:17] E:\Program Files\Common Files\ Designer
[02/01/2007|06:47] E:\Program Files\Common Files\ Hewlett-Packard
[02/01/2007|06:53] E:\Program Files\Common Files\ HP
[04/22/2005|04:26] E:\Program Files\Common Files\ InstallShield
[07/30/2008|12:57] E:\Program Files\Common Files\ Java
[02/03/2007|11:01] E:\Program Files\Common Files\ Microsoft Shared
[01/28/2003|10:30] E:\Program Files\Common Files\ MSSoap
[01/28/2003|04:19] E:\Program Files\Common Files\ ODBC
[01/28/2003|10:30] E:\Program Files\Common Files\ Services
[02/01/2007|06:53] E:\Program Files\Common Files\ Sonic Shared
[01/28/2003|04:19] E:\Program Files\Common Files\ SpeechEngines
[11/17/2008|07:20] E:\Program Files\Common Files\ Symantec Shared
[06/13/2007|05:52] E:\Program Files\Common Files\ System

——————–\\ Process

( 29 Processes )

iexplore.exe ~ [PID:2908]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-17 19:33:02
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwQueryDirectoryFile
scanning hidden processes …
scanning hidden files …
E:\WINDOWS\System32\kdjjq.exe 69120 bytes executable
scan completed successfully
hidden processes: 0
hidden files: 1

——————–\\ Searching for other infections

E:\WINDOWS\system32\JRYbLTwa.ini
E:\WINDOWS\system32\JRYbLTwa.ini2
==> VUNDO <==

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{735CAA80-4962-4E18-AFC7-827D88FB4102}]
NameServer REG_SZ 85.255.112.108;85.255.112.167
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{735CAA80-4962-4E18-AFC7-827D88FB4102}]
DhcpNameServer REG_SZ [removed];[removed]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{FC765CAC-EF38-4264-AA8C-139657F7DCE5}]
NameServer REG_SZ 85.255.112.108;85.255.112.167
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\..\{735CAA80-4962-4E18-AFC7-827D88FB4102}]
NameServer REG_SZ 85.255.112.108;85.255.112.167
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\..\{735CAA80-4962-4E18-AFC7-827D88FB4102}]
DhcpNameServer REG_SZ [removed];[removed]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\..\{FC765CAC-EF38-4264-AA8C-139657F7DCE5}]
NameServer REG_SZ 85.255.112.108;85.255.112.167
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{735CAA80-4962-4E18-AFC7-827D88FB4102}]
NameServer REG_SZ 85.255.112.108;85.255.112.167
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{735CAA80-4962-4E18-AFC7-827D88FB4102}]
DhcpNameServer REG_SZ [removed];[removed]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{FC765CAC-EF38-4264-AA8C-139657F7DCE5}]
NameServer REG_SZ 85.255.112.108;85.255.112.167
==> WAREOUT <==



[F:18749][D:81]-> E:\DOCUME~1\KARATE~1\LOCALS~1\Temp
[F:1][D:0]-> E:\DOCUME~1\KARATE~1\Cookies
[F:7][D:3]-> E:\DOCUME~1\KARATE~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "E:\Lop SD\LopR_1.txt" - Mon 11/17/2008|19:37 - Option : [1]

——————–\\ Scan completed at 19:37:02
Hello

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    E:\WINDOWS\system32\JRYbLTwa.ini
    E:\WINDOWS\system32\JRYbLTwa.ini2
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File/Folder E:\WINDOWS\system32\JRYbLTwa.ini not found.
File/Folder E:\WINDOWS\system32\JRYbLTwa.ini2 not found.
========== COMMANDS ==========
File delete failed. E:\DOCUME~1\KARATE~1\LOCALS~1\Temp\~DFDD1E.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. E:\Documents and Settings\Karate America\Local Settings\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. E:\Documents and Settings\Karate America\Local Settings\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. E:\Documents and Settings\Karate America\Local Settings\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. E:\Documents and Settings\Karate America\Local Settings\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. E:\Documents and Settings\Karate America\Local Settings\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11182008_193100

Files moved on Reboot…
E:\DOCUME~1\KARATE~1\LOCALS~1\Temp\~DFDD1E.tmp moved successfully.
File move failed. E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
E:\Documents and Settings\Karate America\Local Settings\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\Cache\_CACHE_001_ moved successfully.
E:\Documents and Settings\Karate America\Local Settings\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\Cache\_CACHE_002_ moved successfully.
E:\Documents and Settings\Karate America\Local Settings\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\Cache\_CACHE_003_ moved successfully.
E:\Documents and Settings\Karate America\Local Settings\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\Cache\_CACHE_MAP_ moved successfully.
E:\Documents and Settings\Karate America\Local Settings\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\XUL.mfl moved successfully.





ComboFix 08-11-18.02 - Karate America 2008-11-18 19:51:11.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.301 [GMT -6:00]
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

E:\resycled
e:\resycled\boot.com
e:\windows\system32\124909
e:\windows\system32\124909\124909.dll
e:\windows\system32\aqqepamr.dll
e:\windows\system32\bqdobsjq.ini
e:\windows\system32\eftyrj.dll
e:\windows\system32\hmmlqrcu.ini
e:\windows\system32\honmfnss.ini
e:\windows\system32\ikpshxxl.ini
e:\windows\system32\jyuajdty.ini
e:\windows\system32\kdjjq.exe
e:\windows\system32\login.dll
e:\windows\system32\lxxhspki.dll
e:\windows\system32\mcrh.tmp
e:\windows\system32\melajsyp.ini
e:\windows\system32\ngifbhfc.ini
e:\windows\system32\nwilsbpk.ini
e:\windows\system32\pcrcscoi.dll
e:\windows\system32\pelbot.dll
e:\windows\system32\prfphbqa.ini
e:\windows\system32\sdxuggjw.ini
e:\windows\system32\soxpepul.ini
e:\windows\system32\uoxbduqx.ini
e:\windows\system32\whuvxsde.ini
e:\windows\system32\wxovetja.ini
e:\windows\system32\ykgovubm.ini
e:\windows\system32\ysrbufry.ini

.
((((((((((((((((((((((((( Files Created from 2008-10-19 to 2008-11-19 )))))))))))))))))))))))))))))))
.

2008-11-18 15:29 . 2008-11-18 15:29 d——– E:\_OTMoveIt
2008-11-17 19:15 . 2008-11-17 19:37 d——– E:\Lop SD
2008-11-17 17:17 . 2008-11-17 17:17 d——– e:\program files\Trend Micro
2008-11-17 16:05 . 2008-11-17 16:06 d——– e:\program files\ERUNT
2008-11-13 14:46 . 2008-11-18 17:19 d–h—– E:\$AVG8.VAULT$
2008-11-13 14:40 . 2008-11-13 14:40 97,928 –a—— e:\windows\system32\drivers\avgldx86.sys
2008-11-13 14:40 . 2008-11-13 14:40 10,520 –a—— e:\windows\system32\avgrsstx.dll
2008-11-13 14:39 . 2008-11-18 19:41 d——– e:\windows\system32\drivers\Avg
2008-11-13 14:39 . 2008-11-13 14:39 d——– e:\program files\AVG
2008-11-13 14:39 . 2008-11-13 16:49 d——– e:\documents and settings\Karate America\Application Data\AVGTOOLBAR
2008-11-13 14:39 . 2008-11-13 14:52 d——– e:\documents and settings\All Users\Application Data\avg8
2008-11-10 14:54 . 2008-11-10 14:54 d——– e:\program files\Free PDF to Word Doc Converter
2008-11-06 13:32 . 2008-11-17 19:19 d——– e:\program files\CCleaner
2008-11-06 13:25 . 2008-11-13 14:40 d——– e:\documents and settings\Administrator
2008-10-27 18:34 . 2008-10-27 18:34 145 –a—— e:\windows\system32\winver.bat
2008-10-27 14:53 . 2008-10-27 14:53 d——– e:\documents and settings\Karate America\Application Data\iPod2PC3
2008-10-27 14:53 . 2008-10-27 14:53 d——– e:\documents and settings\Karate America\Application Data\EurekaLog
2008-10-24 16:48 . 2008-11-12 19:18 d——– e:\documents and settings\Karate America\Application Data\LimeWire
2008-10-23 16:27 . 2008-10-27 15:06 d——– e:\documents and settings\Karate America\Application Data\Apple Computer
2008-10-23 16:26 . 2008-10-23 16:26 d——– e:\program files\iTunes
2008-10-23 16:26 . 2008-10-23 16:26 d——– e:\program files\iPod
2008-10-23 16:26 . 2008-10-23 16:26 d——– e:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-23 16:26 . 2008-04-17 12:12 107,368 –a—— e:\windows\system32\GEARAspi.dll
2008-10-23 16:26 . 2008-04-17 12:12 15,464 –a—— e:\windows\system32\drivers\GEARAspiWDM.sys
2008-10-23 16:25 . 2008-10-23 16:25 d——– e:\program files\Bonjour
2008-10-23 16:24 . 2008-10-23 16:25 d——– e:\program files\QuickTime
2008-10-23 16:24 . 2008-10-23 16:24 d——– e:\program files\Apple Software Update
2008-10-23 16:24 . 2008-10-23 16:26 d——– e:\documents and settings\All Users\Application Data\Apple Computer
2008-10-23 16:23 . 2008-10-23 16:26 d—-c— e:\windows\system32\DRVSTORE
2008-10-23 16:23 . 2008-10-23 16:24 d——– e:\program files\Common Files\Apple
2008-10-23 16:23 . 2008-10-01 12:01 32,000 –a—— e:\windows\system32\drivers\usbaapl.sys
2008-10-23 16:22 . 2008-10-23 16:22 d——– e:\documents and settings\All Users\Application Data\Apple
2008-10-23 15:14 . 2008-10-23 15:15 d——– e:\program files\LimeWire

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-18 07:31 ——— d—–w e:\documents and settings\All Users\Application Data\Google Updater
2008-11-18 01:20 ——— d—–w e:\program files\Common Files\Symantec Shared
2008-11-18 01:18 ——— d—–w e:\program files\Norton AntiVirus
2008-11-18 01:18 ——— d—–w e:\documents and settings\All Users\Application Data\Symantec
2008-11-06 19:40 ——— d—–w e:\program files\WebEx
2008-09-19 20:18 ——— d–h–w e:\program files\InstallShield Installation Information
2008-09-19 20:18 ——— d—–w e:\program files\NETGEAR
2006-09-22 16:13 28,672 —-a-w e:\documents and settings\Karate America\atwbxdet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="e:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="e:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-13 1234712]

e:\documents and settings\All Users\Start Menu\Programs\Startup\
ClubPRO 3000 Launcher.lnk - e:\windows\Installer\{237BB611-EAAF-4B6D-AA27-A5C7EB32F1E4}\NewShortcut9_237BB611EAAF4B6DAA27A5C7EB32F1E4.Exe [2006-09-22 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=,avgrsstx.dll pelbot.dll

[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=e:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=e:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=e:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=e:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=e:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=e:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^WG111v2 Smart Wizard Wireless Setting.lnk]
path=e:\documents and settings\All Users\Start Menu\Programs\Startup\WG111v2 Smart Wizard Wireless Setting.lnk
backup=e:\windows\pss\WG111v2 Smart Wizard Wireless Setting.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E:\WINDOWS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\e:\windows\system32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 e:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CP3MAIN]
–a—— 2006-04-07 18:21 159744 e:\emts\CP3Main.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Deskup]
–a—— 2002-07-16 10:55 32768 e:\program files\Iomega\DriveIcons\deskup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 02:41 49152 e:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Iomega Drive Icons]
–a—— 2002-08-13 14:30 86016 e:\program files\Iomega\DriveIcons\Imgicon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
–a—— 2001-10-12 15:45 69632 e:\program files\Analog Devices\SoundMAX\SMTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 03:27 144784 e:\program files\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"=e:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"DW6"="e:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe"
"DW4"="e:\program files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="e:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\Messenger\\msmsgs.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"e:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Program Files\\iTunes\\iTunes.exe"=
"e:\\Program Files\\LimeWire\\LimeWire.exe"=
"e:\\WINDOWS\\system32\\winver.exe"=
"e:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;e:\windows\system32\Drivers\avgldx86.sys [2008-11-13 97928]
R2 avg8wd;AVG Free8 WatchDog;e:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-13 231704]
R2 EAPPkt;Realtek EAPPkt Protocol;e:\windows\system32\DRIVERS\EAPPkt.sys [2008-09-19 66048]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;e:\windows\system32\DRIVERS\wg111v2.sys [2008-09-19 167808]
S3 SjyPkt;SjyPkt;\??\e:\windows\System32\Drivers\SjyPkt.sys [2008-09-19 13532]
.
Contents of the 'Scheduled Tasks' folder

2008-11-14 e:\windows\Tasks\AppleSoftwareUpdate.job
- e:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-11-18 e:\windows\Tasks\Symantec NetDetect.job
- e:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-07-19 17:26]
.
- - - - ORPHANS REMOVED - - - -

BHO-{0431D889-7867-4943-88E3-00F67A166149} - (no file)
BHO-{302D49CA-575B-4262-9B8C-2F26C2D9F83A} - (no file)
BHO-{4bc34151-94a7-4c20-aec4-4bea572a8c24} - e:\windows\system32\pelbot.dll
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-e:\windows\system32\kdjjq.exe - e:\windows\system32\kdjjq.exe
ShellExecuteHooks-{302D49CA-575B-4262-9B8C-2F26C2D9F83A} - (no file)
Notify-efcCrOfG - efcCrOfG.dll
Notify-winoyo32 - winoyo32.dll
MSConfigStartUp-ccApp - e:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-kdjjq - e:\windows\system32\kdjjq.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - e:\documents and settings\Karate America\Application Data\Mozilla\Firefox\Profiles\su40b0oo.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-18 19:57:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
———————— Other Running Processes ————————
.
e:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
e:\program files\Bonjour\mDNSResponder.exe
e:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
e:\progra~1\Iomega\System32\AppServices.exe
e:\windows\system32\HPZipm12.exe
e:\program files\Iomega\AutoDisk\ADService.exe
e:\windows\system32\msiexec.exe
e:\program files\AVG\AVG8\avgrsx.exe
e:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-11-18 20:04:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-19 02:03:55

Pre-Run: 26,905,243,648 bytes free
Post-Run: 26,794,811,392 bytes free

213 — E O F — 2008-10-25 08:00:56
Hello

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    e:\windows\system32\winver.bat
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    • e:\documents and settings\Karate America\atwbxdet.dll
  • Click on the Upload button
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.



Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI