This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Reoccuring Virus, Taskmanager disabled,

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is the Kasperspy log: ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Saturday, November 22, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Saturday, November 22, 2008 14:54:05 Records in database: 1402773 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 77240 Threat name: 1 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 02:33:24 File name / Threat name / Threats count C:\Documents and Settings\All Users\Documents\My Music\iTunes\02 Track 2 (statemachine).wma Infected: Trojan-Downloader.WMA.Wimad.k 1 C:\Documents and Settings\Margie\My Documents\My Music\iTunes\iTunes Music\02 Track 2 (statemachine).wma Infected: Trojan-Downloader.WMA.Wimad.k 1 The selected area was scanned.
GlooStik,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\Documents and Settings\All Users\Documents\My Music\iTunes\02 Track 2 (statemachine).wma
    C:\Documents and Settings\Margie\My Documents\My Music\iTunes\iTunes Music\02 Track 2 (statemachine).wma
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Also please let me see a final HijackThis log.
Heres the Combo Fix log, running HiJackThis now. :


ComboFix 08-11-21.04 - Margie 2008-11-22 15:29:14.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.221 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Margie\Desktop\CFScript.txt.txt
* Created a new restore point

FILE ::
c:\documents and settings\All Users\Documents\My Music\iTunes\02 Track 2 (statemachine).wma
c:\documents and settings\Margie\My Documents\My Music\iTunes\iTunes Music\02 Track 2 (statemachine).wma
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Documents\My Music\iTunes\02 Track 2 (statemachine).wma
c:\documents and settings\Margie\My Documents\My Music\iTunes\iTunes Music\02 Track 2 (statemachine).wma

.
((((((((((((((((((((((((( Files Created from 2008-10-22 to 2008-11-22 )))))))))))))))))))))))))))))))
.

2008-11-22 10:17 . 2008-11-22 10:17 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2008-11-22 10:15 . 2008-11-22 10:15 d——– c:\windows\ERUNT
2008-11-21 22:31 . 2008-11-21 22:31 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-21 22:31 . 2008-11-21 22:31 d——– c:\documents and settings\Margie\Application Data\Malwarebytes
2008-11-21 22:31 . 2008-11-21 22:31 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-21 22:31 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-21 22:31 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-21 21:06 . 2008-11-22 11:40 d——– C:\SDFix
2008-11-19 16:26 . 2008-11-21 22:26 d——– c:\windows\system32\dPI19
2008-11-11 21:33 . 2008-09-04 12:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-11 21:33 . 2008-10-24 06:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-08 13:08 . 2008-11-11 05:33 d——– c:\windows\system32\sX3i19
2008-10-29 20:01 . 2008-10-29 20:01 d——– c:\program files\Common Files\INCA Shared
2008-10-24 16:31 . 2008-10-24 16:32 d——– c:\documents and settings\All Users\Application Data\America's Army Deploy Client
2008-10-24 16:03 . 2008-10-24 16:03 98,304 –a—— c:\windows\system32\CmdLineExt.dll
2008-10-24 03:20 . 2008-10-15 11:34 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 23:51 ——— d—–w c:\program files\Incomplete
2008-11-19 22:41 ——— d—–w c:\program files\Microsoft Games
2008-11-09 00:03 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-09 00:03 ——— d—–w c:\program files\Common Files\InstallShield
2008-10-28 20:28 139,144 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-10-28 12:04 ——— d—–w c:\program files\LimeWire
2008-10-25 07:07 ——— d—–w c:\program files\Microsoft Silverlight
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2007-05-23 19:04 24,192 —-a-w c:\documents and settings\Margie\usbsermptxp.sys
2007-05-23 19:04 22,768 —-a-w c:\documents and settings\Margie\usbsermpt.sys
1995-07-21 21:55 129 —-a-w c:\documents and settings\Margie\SVGATEST.BAT
1995-07-21 21:21 195,130 —-a-w c:\documents and settings\Margie\CONTROL.EXE
1995-07-21 20:19 10,304 —-a-w c:\documents and settings\Margie\SGAFONTS.BIN
1995-07-21 20:08 5,692 —-a-w c:\documents and settings\Margie\BRF09.BIN
1995-07-21 20:08 3,618 —-a-w c:\documents and settings\Margie\BRFTITLE.BIN
1995-07-21 20:08 105,266 —-a-w c:\documents and settings\Margie\BRFMAIN.BIN
1995-07-21 20:07 9,119 —-a-w c:\documents and settings\Margie\BRF02.BIN
1995-07-21 14:59 62,611 —-a-w c:\documents and settings\Margie\AIRPOWER.EXE
1995-07-21 14:59 62,021 —-a-w c:\documents and settings\Margie\SVGADEMO.EXE
1995-07-21 14:54 386 —-a-w c:\documents and settings\Margie\BFPLYRS6.COM
1995-07-21 14:54 292 —-a-w c:\documents and settings\Margie\BFPLYBS6.COM
1995-07-21 14:53 606 —-a-w c:\documents and settings\Margie\BFCV0002.COM
1995-07-21 14:45 5,472 —-a-w c:\documents and settings\Margie\TEXT.BIN
1995-07-21 14:45 3,530 —-a-w c:\documents and settings\Margie\MGA3D.BIN
1995-07-21 14:45 3,034 —-a-w c:\documents and settings\Margie\MGAFONTS.BIN
1995-07-21 14:45 2,295 —-a-w c:\documents and settings\Margie\MUSICPP.BIN
1995-07-21 14:45 2,155 —-a-w c:\documents and settings\Margie\MSGTEXT.BIN
1995-07-21 14:45 14,455 —-a-w c:\documents and settings\Margie\MGA_BITZ.BIN
1995-07-21 14:43 293,326 —-a-w c:\documents and settings\Margie\SHAPES.COM
1995-07-21 14:30 1,886 —-a-w c:\documents and settings\Margie\BFRTULA.COM
1995-07-21 14:30 1,758 —-a-w c:\documents and settings\Margie\BFRKALUG.COM
1995-07-21 14:30 1,562 —-a-w c:\documents and settings\Margie\BFRSARAI.COM
1995-07-21 14:30 1,528 —-a-w c:\documents and settings\Margie\BFRLIVNY.COM
1995-07-21 14:30 1,336 —-a-w c:\documents and settings\Margie\BFRLIPIC.COM
1995-07-21 14:30 1,128 —-a-w c:\documents and settings\Margie\BFRDANKO.COM
1995-07-21 14:30 1,108 —-a-w c:\documents and settings\Margie\BFRUGLIC.COM
1995-07-21 14:27 2,070 —-a-w c:\documents and settings\Margie\RUSSA1WD.BIN
1995-07-21 14:26 9,390 —-a-w c:\documents and settings\Margie\NORTHRD.BIN
1995-07-21 14:26 608 —-a-w c:\documents and settings\Margie\NORTHRV.BIN
1995-07-21 14:26 10,534 —-a-w c:\documents and settings\Margie\SOUTHRD.BIN
1995-07-21 14:26 1,620 —-a-w c:\documents and settings\Margie\NORTHRL.BIN
1995-07-21 14:26 1,380 —-a-w c:\documents and settings\Margie\SOUTHRV.BIN
1995-07-21 14:26 1,364 —-a-w c:\documents and settings\Margie\SOUTHRL.BIN
1995-05-22 16:52 44,892 —-a-w c:\documents and settings\Margie\COASTDAT.EXE
1995-04-27 00:21 68,352 —-a-w c:\documents and settings\Margie\SVGAVESA.EXE
1995-04-12 14:04 177 —-a-w c:\documents and settings\Margie\ERR.BAT
1993-12-15 18:47 1,014 —-a-w c:\documents and settings\Margie\JTEST.COM
1993-11-01 17:19 69 —-a-w c:\documents and settings\Margie\DELETEME.BAT
2007-07-24 01:18 8,784 —-a-w c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-07-24 01:20 245,408 —-a-w c:\program files\mozilla firefox\plugins\unicows.dll
2008-06-14 03:47 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008061320080614\index.dat
.

((((((((((((((((((((((((((((( snapshot@2008-11-21_23.07.52.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 20:27:04 163,328 —-a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2008-11-22 15:15:36 6,922,240 —-a-w c:\windows\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-11-22 15:15:36 290,816 —-a-w c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 —-a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-11-22 15:15:24 6,922,240 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-11-22 15:15:24 290,816 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-06-06 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-06-06 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"LVCOMS"="c:\program files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 98304]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-09-30 1234712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 c:\windows\KHALMNPR.Exe]
"SoundMan"="SOUNDMAN.EXE" [2004-05-14 c:\windows\soundman.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]

c:\documents and settings\Margie\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-06-03 225280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP53"= SP5X_32.DLL
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
"VIDC.SP59"= SP5X_32.DLL

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-05-23 97928]
R1 lusbaudio;Logitech USB Microphone;c:\windows\system32\drivers\lvsound2.sys [2007-03-26 33280]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-06 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-06 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-05-23 76040]
R3 LVBulk;LVBulk Service;c:\windows\system32\DRIVERS\LVBulk.sys [2007-03-26 10261]
R3 LVVI500A;LVVI500A Service;c:\windows\system32\DRIVERS\lvvi500a.sys [2007-03-26 193574]
.
Contents of the 'Scheduled Tasks' folder

2008-11-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-22 15:33:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\HPZipm12.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Completion time: 2008-11-22 15:42:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-22 20:40:31
ComboFix2.txt 2008-11-22 04:13:31

Pre-Run: 73,544,282,112 bytes free
Post-Run: 73,531,686,912 bytes free

213 — E O F — 2008-11-12 08:04:37
HiJackThis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:44:37 PM, on 22/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Documents and Settings\Margie\My Documents\My Received Files\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1200777867359
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)

–
End of file - 6054 bytes
  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.


With that done, log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Please re-enable any security that was disabled.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Download and install the free version of WinPatrol - This program protects your computer in a variety of ways and will work well with your existing security software.
Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
I understand. :thumbup: Thanks for all your help. I think that this computer will live for another day! I will ask you if I come up with any questions. And thanks again….
GlooStik,

Sorry but I missed one.

[Please either print out these instructions for reference or copy/paste them in notepad and save to your desktop for access when in safe mode

Make all files and folders visible
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O4 - Startup: PowerReg Scheduler V3.exe
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

We Now Need To Boot Into Safemode

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.

Using Windows Explorer (Windows Key + E), locate the following file and DELETE it (if still present):
c:\documents and settings\Margie\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe <–This file

Restart your computer normally.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI