This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Bancos Trojan

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Lets try this:


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

Reglock::
[HKEY_LOCAL_MACHINE\SOFTWARE\SOS]
Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\SOS]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Ran ComboFix with the new CFSCript. The "SOS" key was removed from the registry, however it came back upon startup.

Here are the ComboFix and HiJackThis Logs. All logs are prior to restart.


ComboFix

ComboFix 09-01-05.05 - Charlie 2009-01-06 20:59:40.12 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.569 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Charlie\Desktop\CFScript.txt
FW: Webroot Internet Security Essentials *disabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-12-07 to 2009-01-07 )))))))))))))))))))))))))))))))
.

2009-01-04 18:13 . 2009-01-04 18:13 d——– c:\documents and settings\Kelli\Application Data\Apple Computer
2008-12-30 13:58 . 2008-12-30 13:58 d——– c:\program files\ASUS
2008-12-30 13:58 . 2004-02-27 00:00 962,612 –a—— c:\windows\system32\mfc42d.dll
2008-12-30 13:58 . 2004-02-17 00:00 434,252 –a—— c:\windows\system32\MSVCRTD.DLL
2008-12-30 13:58 . 2005-01-28 03:44 24,576 -ra—— c:\windows\system32\AsIO.dll
2008-12-30 13:58 . 2004-09-07 11:41 5,120 –a—— c:\windows\system32\drivers\AsInsHelp64.sys
2008-12-30 13:58 . 2004-10-14 04:52 4,962 -ra—— c:\windows\system32\drivers\AsIO.sys
2008-12-30 13:58 . 2004-03-10 14:31 3,328 –a—— c:\windows\system32\drivers\AsInsHelp32.sys
2008-12-30 13:57 . 2008-12-30 13:57 5,950 –a—— c:\windows\Ascd_tmp.ini
2008-12-30 12:28 . 2008-12-30 12:28 48,035 –a—— c:\windows\BS_DEF.sys
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\documents and settings\Charlie\Application Data\Malwarebytes
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-29 20:19 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 20:19 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-29 19:13 . 2008-12-29 19:13 d——– c:\program files\ERUNT
2008-12-28 20:59 . 2008-12-28 20:59 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-12-27 14:03 . 2008-12-27 14:03 d——– c:\documents and settings\Kelli\Application Data\HP
2008-12-20 13:22 . 2009-01-04 18:06 d——– c:\documents and settings\Kelli\Application Data\HPAppData
2008-12-19 21:02 . 2009-01-04 20:01 d——– c:\documents and settings\Charlie\Application Data\HPAppData
2008-12-19 20:58 . 2008-12-19 20:58 d——– c:\documents and settings\Charlie\Application Data\HP
2008-12-19 20:54 . 2008-12-19 20:54 d——– c:\documents and settings\All Users\Application Data\WEBREG
2008-12-19 20:53 . 2008-12-19 20:53 d——– c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-12-19 20:53 . 2007-10-30 04:25 49,920 -ra—— c:\windows\system32\drivers\HPZid412.sys
2008-12-19 20:53 . 2007-10-30 04:25 16,496 -ra—— c:\windows\system32\drivers\HPZipr12.sys
2008-12-19 20:52 . 2007-11-08 09:52 271,704 -ra—— c:\windows\system32\hpzids01.dll
2008-12-19 20:52 . 2007-10-20 18:25 117,760 –a—— c:\windows\system32\hpzll5mu.dll
2008-12-19 20:52 . 2007-10-30 04:25 21,568 -ra—— c:\windows\system32\drivers\HPZius12.sys
2008-12-19 20:51 . 2007-10-30 04:11 581,632 -ra—— c:\windows\system32\hpotscl6.dll
2008-12-19 20:51 . 2007-10-30 04:25 372,736 -ra—— c:\windows\system32\hppldcoi.dll
2008-12-19 20:51 . 2007-10-30 04:25 309,760 -ra—— c:\windows\system32\difxapi.dll
2008-12-19 20:51 . 2007-10-30 04:11 303,104 -ra—— c:\windows\system32\hpovst15.dll
2008-12-19 20:46 . 2008-12-19 20:46 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-19 20:46 . 2008-12-19 20:46 d——– c:\documents and settings\All Users\Application Data\HP
2008-12-19 20:45 . 2008-12-19 20:45 d——– c:\program files\Common Files\Hewlett-Packard
2008-12-19 20:44 . 2008-12-19 20:46 d——– c:\program files\Hewlett-Packard
2008-12-19 20:43 . 2008-04-13 14:45 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2008-12-19 20:43 . 2008-04-13 14:45 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2008-12-19 20:43 . 2008-04-13 14:47 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-12-19 20:43 . 2008-04-13 14:47 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2008-12-19 20:42 . 2008-12-19 20:54 157,480 –a—— c:\windows\hpoins27.dat
2008-12-19 20:42 . 2008-01-18 10:56 932 ——— c:\windows\hpomdl27.dat
2008-12-10 21:14 . 2008-12-10 21:14 d——– c:\windows\system32\ernet explorer
2008-12-09 16:22 . 2008-10-03 05:02 247,326 —–c— c:\windows\system32\dllcache\strmdll.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-07 01:56 ——— d—–w c:\program files\PestPatrol
2009-01-06 16:40 7,304 —-a-w c:\windows\TMP0001.TMP
2008-12-30 18:58 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-30 18:17 ——— d—–w c:\program files\Common Files\InstallShield
2008-12-20 01:48 ——— d—–w c:\program files\HP
2008-12-09 00:07 ——— d—–w c:\program files\Common Files\Adobe
2008-12-07 05:02 ——— d—–w c:\program files\Java
2008-12-01 22:08 ——— d—–w c:\program files\TrojanHunter 5.0
2008-12-01 22:02 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-01 22:02 ——— d—–w c:\program files\Panda Security
2008-12-01 22:02 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-01 22:00 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-12-01 21:58 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-01 21:58 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-27 05:39 ——— d—–w c:\program files\iTunes
2008-11-27 05:34 ——— d—–w c:\program files\Common Files\LightScribe
2008-11-27 05:33 ——— d—–w c:\program files\Bonjour
2008-11-27 04:08 ——— d—–w c:\documents and settings\Charlie\Application Data\TrojanHunter
2008-11-26 05:31 ——— d—–w c:\documents and settings\All Users\Application Data\PrevxCSI
2008-11-25 22:40 ——— d—–w c:\program files\QuickTime
2008-11-25 22:25 2,001 —-a-w c:\program files\uninstal.log
2008-11-21 18:41 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-21 18:20 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-11-21 18:20 10,671 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-11-21 17:02 ——— d—–w c:\documents and settings\Charlie\Application Data\Symantec
2008-11-21 05:08 ——— d—–w c:\program files\AVG
2008-11-21 04:02 ——— d—–w c:\program files\F-Group
2008-11-20 21:44 ——— d—–w c:\program files\Trend Micro
2008-11-20 20:24 164 —-a-w C:\install.dat
2008-11-20 20:14 ——— d—–w c:\program files\Rhapsody
2008-11-19 03:02 ——— d—–w c:\program files\Exterminate It!
2008-11-13 22:11 1,553,272 —-a-w c:\windows\WRSetup.dll
2008-11-12 21:02 29,808 —-a-w c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 21:02 23,152 —-a-w c:\windows\system32\drivers\sshrmd.sys
2008-11-12 21:02 170,608 —-a-w c:\windows\system32\drivers\ssidrv.sys
2008-11-10 10:43 410,984 —-a-w c:\windows\system32\deploytk.dll
2008-10-23 22:27 183,120 —-a-w c:\windows\system32\PnkBstrB.exe
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-08-03 01:11 22,328 —-a-w c:\documents and settings\Charlie\Application Data\PnkBstrK.sys
2002-05-21 15:00 1,362 —-a-r c:\program files\ReadMe.txt
.

((((((((((((((((((((((((((((( snapshot_2009-01-01_17.10.52.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-15 02:17:55 102,400 —-a-r c:\windows\Installer\{3DE0053C-FD9A-483E-B7C9-B06E4392206E}\iTunesIco.exe
+ 2009-01-04 23:13:34 102,400 —-a-r c:\windows\Installer\{3DE0053C-FD9A-483E-B7C9-B06E4392206E}\iTunesIco.exe
- 2009-01-01 21:44:09 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-03 04:27:48 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-01 21:44:09 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-03 04:27:48 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-01 21:44:09 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-03 04:27:48 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-30 16:21:37 59,984 —-a-w c:\windows\system32\perfc009.dat
+ 2009-01-02 02:54:58 59,780 —-a-w c:\windows\system32\perfc009.dat
- 2008-12-30 16:21:37 397,890 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-02 02:54:58 397,560 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-06 16:41:57 16,384 —-atw c:\windows\temp\Perflib_Perfdata_610.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 –a—— c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kmw_run.exe"="c:\windows\system32\kmw_run.exe" [2006-08-03 106496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"ADUserMon"="c:\program files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 147456]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 86016]
"Deskup"="c:\program files\Iomega\DriveIcons\deskup.exe" [2002-07-16 32768]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="c:\windows\system32\nwiz.exe" [2008-10-07 1630208]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"PestPatrol Control Center"="c:\progra~1\PESTPA~1\PPControl.exe" [2004-11-15 98304]
"PPMemCheck"="c:\progra~1\PESTPA~1\PPMemCheck.exe" [2004-04-02 148480]
"CookiePatrol"="c:\progra~1\PESTPA~1\CookiePatrol.exe" [2005-01-10 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2008-11-13 6273400]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-03-28 724992]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\EA GAMES\\Command & Conquer Generals Zero Hour\\game.dat"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-10-02 29808]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-07-07 24652]
S3 BS_DEF;BS_DEF;c:\windows\BS_DEF.sys [2008-12-30 48035]
S3 EraserUtilDrv10621;EraserUtilDrv10621;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10621.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10621.sys [?]
S4 WRConsumerService;Webroot Client Service;c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [2008-10-20 1086840]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-01-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- a:\,d:\,e:\,f:\,g:\,h:\ []

2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- a:\","c:\","d:\","e:\","f:\","g:\","H:\" []

2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]

2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- a:\","c:\","d:\","e:\","f:\","g:\","H:\" []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.wlns.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O16 -: DirectAnimation Java Classes - c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\Downloaded Program Files\WSSystemInformation.dll - O16 -: {03DF0933-6E10-4D32-9835-B9A815622831}
hxxps://gopublic.wspan.com/secure/DLLs/WSSystemInformation.cab
c:\windows\Downloaded Program Files\WSSystemInformation.inf

c:\windows\Downloaded Program Files\CONFLICT.1\Manager.exe - c:\windows\Downloaded Program Files\CONFLICT.1\DownloadManagerV2.ocx
O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
c:\windows\Downloaded Program Files\DownloadManagerV2.inf

c:\windows\Downloaded Program Files\ScmDirCtl.dll - O16 -: {52454909-B15F-11D3-83A3-000083613743}
hxxps://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
c:\windows\Downloaded Program Files\ScmDirCtl.inf

c:\windows\Downloaded Program Files\WSEmul3.ocx - O16 -: {6FC2871E-004B-4141-B9C0-59708BD96CCE}
hxxps://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
c:\windows\Downloaded Program Files\wsemul3.inf

c:\windows\Downloaded Program Files\CONFLICT.1\WSMap.vbs - c:\windows\Downloaded Program Files\CONFLICT.1\WSFileIO3.dll
O16 -: {7B72C3FC-34B5-4504-B4BE-EB38971A0888}
hxxps://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
c:\windows\Downloaded Program Files\CONFLICT.1\wsfileio3.inf

c:\windows\Downloaded Program Files\WSPrint3.ocx - O16 -: {7DB7E238-1425-4434-8B05-6453AD6A49C6}
hxxps://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
c:\windows\Downloaded Program Files\wsprint3.inf

c:\windows\Downloaded Program Files\WSKeyBoardTranslator.dll - O16 -: {85788258-6ACF-4FC1-A2CD-3BD248065AB9}
hxxps://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
c:\windows\Downloaded Program Files\WSKeyBoardTranslator.inf

c:\windows\Downloaded Program Files\WSMap.vbs - c:\windows\Downloaded Program Files\WSFileIO2.dll
O16 -: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D}
hxxps://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
c:\windows\Downloaded Program Files\wsfileio2.inf

c:\windows\Downloaded Program Files\WSBrowserConfig.dll - O16 -: {9145A52A-9B22-4858-AEE7-74D6C7D3F366}
hxxps://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
c:\windows\Downloaded Program Files\wsbrowserconfig.inf

c:\windows\Downloaded Program Files\WSCustInstSrv.dll - O16 -: {A4D41E3A-613D-11D3-85B2-400011500081}
hxxps://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
c:\windows\Downloaded Program Files\WSCustInst.inf

c:\windows\Downloaded Program Files\wspancal.dll - O16 -: {D4233B6D-88A0-11D3-BC29-400011500032}
hxxps://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
c:\windows\Downloaded Program Files\wspancal.inf

c:\windows\WSODBC32.dll - c:\windows\Downloaded Program Files\SCMCtl1.dll
O16 -: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D}
hxxps://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
c:\windows\Downloaded Program Files\WSSCM1.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-06 21:02:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*NULL*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6A1B6362-99C8-11D1-ABE1-00C04FC30999} èÿÿÿvk , 0 ÐÿÿÿM S O L A P D i m e n s i o n C l a s s øÿÿÿ¨ÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ ( à ÿÿÿÿ <  ProgID øÿÿÿ° øÿÿÿÀ èÿÿÿvk < è ÀÿÿÿM S O l a p A d m i n . M S O L A P D i m e n s i o n . 1 øÿÿÿИÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ Àà ÿÿÿÿ 8  VersionIndependentProgIDèÿÿÿvk r 
 Qèÿÿÿvk 8 È  ÀÿÿÿM S O l a p A d m i n . M S O L A P D i m e n s i o n  ÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ @ à ÿÿÿÿ  r  InprocServer32 Øÿÿÿlh 
CÇÚhuõT0 
sQ ˆÿÿÿC : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ S y s t e m \ O L E D B \ M S M D G D R V . D L L Øÿÿÿvk
0   ThreadingModel ðÿÿÿb o t h ðÿÿÿ˜   ÿÿÿnk ¶.‹ÀlÇ °  h ÿÿÿÿ Èà ÿÿÿÿ
.  MSOlapAdmin.MSOLAPDimensions.1 èÿÿÿvk . Ø  ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s ¨ÿÿÿnk ‘‹ÀlÇ P  ÿÿÿÿÿÿÿÿ è à ÿÿÿÿ N  CLSID ðÿÿÿlh  [‹¸èÿÿÿvk N   ¨ÿÿÿ{ 6 A 1 B 6 3 5 F - 9 9 C 8 - 1 1 D 1 - A B E 1 - 0 0 C 0 4 F C 3 0 9 9 9 } øÿÿÿx ÿÿÿnk ‘‹ÀlÇ °  ÿÿÿÿ °
à ÿÿÿÿ
.  MSOlapAdmin.MSOLAPDimensions èÿÿÿvk . x
 ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s øÿÿÿ`
¨ÿÿÿnk ‘‹ÀlÇ ð  ÿÿÿÿÿÿÿÿ à ÿÿÿÿ N  CLSID ðÿÿÿlh ¸
[‹¸èÿÿÿvk N 8 ¨ÿÿÿ{ 6 A 1 B 6 3 5 F - 9 9 C 8 - 1 1 D 1 - A B E 1 - 0 0 C 0 4 F C 3 0 9 9 9 } øÿÿÿ ˆÿÿÿnk ‘‹ÀlÇ @ò   ÿÿÿÿ `à ÿÿÿÿ0 . & {6A1B635F-99C8-11D1-ABE1-00C04FC30999} èÿÿÿvk . ( ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s øÿÿÿ¨ÿÿÿnk ‘‹ÀlÇ ˜ ÿÿÿÿÿÿÿÿ èà ÿÿÿÿ >  ProgID øÿÿÿèøÿÿÿèèÿÿÿvk >  øÿÿÿÐðÿÿÿb o t h hbin   ]
@="MSOLAPDimension Class"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6A1B6362-99C8-11D1-ABE1-00C04FC30999} èÿÿÿvk , 0 ÐÿÿÿM S O L A P D i m e n s i o n C l a s s øÿÿÿ¨ÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ ( à ÿÿÿÿ <  ProgID øÿÿÿ° øÿÿÿÀ èÿÿÿvk < è ÀÿÿÿM S O l a p A d m i n . M S O L A P D i m e n s i o n . 1 øÿÿÿИÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ Àà ÿÿÿÿ 8  VersionIndependentProgIDèÿÿÿvk r 
 Qèÿÿÿvk 8 È  ÀÿÿÿM S O l a p A d m i n . M S O L A P D i m e n s i o n  ÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ @ à ÿÿÿÿ  r  InprocServer32 Øÿÿÿlh 
CÇÚhuõT0 
sQ ˆÿÿÿC : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ S y s t e m \ O L E D B \ M S M D G D R V . D L L Øÿÿÿvk
0   ThreadingModel ðÿÿÿb o t h ðÿÿÿ˜   ÿÿÿnk ¶.‹ÀlÇ °  h ÿÿÿÿ Èà ÿÿÿÿ
.  MSOlapAdmin.MSOLAPDimensions.1 èÿÿÿvk . Ø  ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s ¨ÿÿÿnk ‘‹ÀlÇ P  ÿÿÿÿÿÿÿÿ è à ÿÿÿÿ N  CLSID ðÿÿÿlh  [‹¸èÿÿÿvk N   ¨ÿÿÿ{ 6 A 1 B 6 3 5 F - 9 9 C 8 - 1 1 D 1 - A B E 1 - 0 0 C 0 4 F C 3 0 9 9 9 } øÿÿÿx ÿÿÿnk ‘‹ÀlÇ °  ÿÿÿÿ °
à ÿÿÿÿ
.  MSOlapAdmin.MSOLAPDimensions èÿÿÿvk . x
 ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s øÿÿÿ`
¨ÿÿÿnk ‘‹ÀlÇ ð  ÿÿÿÿÿÿÿÿ à ÿÿÿÿ N  CLSID ðÿÿÿlh ¸
[‹¸èÿÿÿvk N 8 ¨ÿÿÿ{ 6 A 1 B 6 3 5 F - 9 9 C 8 - 1 1 D 1 - A B E 1 - 0 0 C 0 4 F C 3 0 9 9 9 } øÿÿÿ ˆÿÿÿnk ‘‹ÀlÇ @ò   ÿÿÿÿ `à ÿÿÿÿ0 . & {6A1B635F-99C8-11D1-ABE1-00C04FC30999} èÿÿÿvk . ( ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s øÿÿÿ¨ÿÿÿnk ‘‹ÀlÇ ˜ ÿÿÿÿÿÿÿÿ èà ÿÿÿÿ >  ProgID øÿÿÿèøÿÿÿèèÿÿÿvk >  øÿÿÿÐðÿÿÿb o t h hbin   \InprocServer32]
@="c:\\Program Files\\Common Files\\System\\OLE DB\\MSMDGDRV.DLL"
"ThreadingModel"="both"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6A1B6362-99C8-11D1-ABE1-00C04FC30999} èÿÿÿvk , 0 ÐÿÿÿM S O L A P D i m e n s i o n C l a s s øÿÿÿ¨ÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ ( à ÿÿÿÿ <  ProgID øÿÿÿ° øÿÿÿÀ èÿÿÿvk < è ÀÿÿÿM S O l a p A d m i n . M S O L A P D i m e n s i o n . 1 øÿÿÿИÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ Àà ÿÿÿÿ 8  VersionIndependentProgIDèÿÿÿvk r 
 Qèÿÿÿvk 8 È  ÀÿÿÿM S O l a p A d m i n . M S O L A P D i m e n s i o n  ÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ @ à ÿÿÿÿ  r  InprocServer32 Øÿÿÿlh 
CÇÚhuõT0 
sQ ˆÿÿÿC : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ S y s t e m \ O L E D B \ M S M D G D R V . D L L Øÿÿÿvk
0   ThreadingModel ðÿÿÿb o t h ðÿÿÿ˜   ÿÿÿnk ¶.‹ÀlÇ °  h ÿÿÿÿ Èà ÿÿÿÿ
.  MSOlapAdmin.MSOLAPDimensions.1 èÿÿÿvk . Ø  ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s ¨ÿÿÿnk ‘‹ÀlÇ P  ÿÿÿÿÿÿÿÿ è à ÿÿÿÿ N  CLSID ðÿÿÿlh  [‹¸èÿÿÿvk N   ¨ÿÿÿ{ 6 A 1 B 6 3 5 F - 9 9 C 8 - 1 1 D 1 - A B E 1 - 0 0 C 0 4 F C 3 0 9 9 9 } øÿÿÿx ÿÿÿnk ‘‹ÀlÇ °  ÿÿÿÿ °
à ÿÿÿÿ
.  MSOlapAdmin.MSOLAPDimensions èÿÿÿvk . x
 ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s øÿÿÿ`
¨ÿÿÿnk ‘‹ÀlÇ ð  ÿÿÿÿÿÿÿÿ à ÿÿÿÿ N  CLSID ðÿÿÿlh ¸
[‹¸èÿÿÿvk N 8 ¨ÿÿÿ{ 6 A 1 B 6 3 5 F - 9 9 C 8 - 1 1 D 1 - A B E 1 - 0 0 C 0 4 F C 3 0 9 9 9 } øÿÿÿ ˆÿÿÿnk ‘‹ÀlÇ @ò   ÿÿÿÿ `à ÿÿÿÿ0 . & {6A1B635F-99C8-11D1-ABE1-00C04FC30999} èÿÿÿvk . ( ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s øÿÿÿ¨ÿÿÿnk ‘‹ÀlÇ ˜ ÿÿÿÿÿÿÿÿ èà ÿÿÿÿ >  ProgID øÿÿÿèøÿÿÿèèÿÿÿvk >  øÿÿÿÐðÿÿÿb o t h hbin   \ProgID]
@="MSOlapAdmin.MSOLAPDimension.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6A1B6362-99C8-11D1-ABE1-00C04FC30999} èÿÿÿvk , 0 ÐÿÿÿM S O L A P D i m e n s i o n C l a s s øÿÿÿ¨ÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ ( à ÿÿÿÿ <  ProgID øÿÿÿ° øÿÿÿÀ èÿÿÿvk < è ÀÿÿÿM S O l a p A d m i n . M S O L A P D i m e n s i o n . 1 øÿÿÿИÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ Àà ÿÿÿÿ 8  VersionIndependentProgIDèÿÿÿvk r 
 Qèÿÿÿvk 8 È  ÀÿÿÿM S O l a p A d m i n . M S O L A P D i m e n s i o n  ÿÿÿnk ¶.‹ÀlÇ   ÿÿÿÿÿÿÿÿ @ à ÿÿÿÿ  r  InprocServer32 Øÿÿÿlh 
CÇÚhuõT0 
sQ ˆÿÿÿC : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ S y s t e m \ O L E D B \ M S M D G D R V . D L L Øÿÿÿvk
0   ThreadingModel ðÿÿÿb o t h ðÿÿÿ˜   ÿÿÿnk ¶.‹ÀlÇ °  h ÿÿÿÿ Èà ÿÿÿÿ
.  MSOlapAdmin.MSOLAPDimensions.1 èÿÿÿvk . Ø  ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s ¨ÿÿÿnk ‘‹ÀlÇ P  ÿÿÿÿÿÿÿÿ è à ÿÿÿÿ N  CLSID ðÿÿÿlh  [‹¸èÿÿÿvk N   ¨ÿÿÿ{ 6 A 1 B 6 3 5 F - 9 9 C 8 - 1 1 D 1 - A B E 1 - 0 0 C 0 4 F C 3 0 9 9 9 } øÿÿÿx ÿÿÿnk ‘‹ÀlÇ °  ÿÿÿÿ °
à ÿÿÿÿ
.  MSOlapAdmin.MSOLAPDimensions èÿÿÿvk . x
 ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s øÿÿÿ`
¨ÿÿÿnk ‘‹ÀlÇ ð  ÿÿÿÿÿÿÿÿ à ÿÿÿÿ N  CLSID ðÿÿÿlh ¸
[‹¸èÿÿÿvk N 8 ¨ÿÿÿ{ 6 A 1 B 6 3 5 F - 9 9 C 8 - 1 1 D 1 - A B E 1 - 0 0 C 0 4 F C 3 0 9 9 9 } øÿÿÿ ˆÿÿÿnk ‘‹ÀlÇ @ò   ÿÿÿÿ `à ÿÿÿÿ0 . & {6A1B635F-99C8-11D1-ABE1-00C04FC30999} èÿÿÿvk . ( ÈÿÿÿM S O L A P D i m e n s i o n s C l a s s øÿÿÿ¨ÿÿÿnk ‘‹ÀlÇ ˜ ÿÿÿÿÿÿÿÿ èà ÿÿÿÿ >  ProgID øÿÿÿèøÿÿÿèèÿÿÿvk >  øÿÿÿÐðÿÿÿb o t h hbin   \VersionIndependentProgID]
@="MSOlapAdmin.MSOLAPDimension"
.
Completion time: 2009-01-06 21:03:44
ComboFix-quarantined-files.txt 2009-01-07 02:03:29
ComboFix2.txt 2009-01-05 01:09:52
ComboFix3.txt 2009-01-03 04:23:22
ComboFix4.txt 2009-01-03 02:31:53
ComboFix5.txt 2009-01-07 01:59:07

Pre-Run: 52,646,604,800 bytes free
Post-Run: 53,009,289,216 bytes free

385 — E O F — 2008-12-18 01:19:28



HiJackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:50 PM, on 1/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\system32\kmw_run.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wlns.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [kmw_run.exe] "C:\WINDOWS\system32\kmw_run.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [ADUserMon] "C:\Program Files\Iomega\AutoDisk\ADUserMon.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [Deskup] "C:\Program Files\Iomega\DriveIcons\deskup.exe" /IMGSTART
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PestPatrol Control Center] "c:\PROGRA~1\PESTPA~1\PPControl.exe"
O4 - HKLM\..\Run: [PPMemCheck] "c:\PROGRA~1\PESTPA~1\PPMemCheck.exe"
O4 - HKLM\..\Run: [CookiePatrol] "c:\PROGRA~1\PESTPA~1\CookiePatrol.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O16 - DPF: {03DF0933-6E10-4D32-9835-B9A815622831} (WSSystemInfo Class) - https://gopublic.wspan.com/secure/DLLs/WSSy…Information.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {52454909-B15F-11D3-83A3-000083613743} (SCMDir Class) - https://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1173070605140
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1173112912250
O16 - DPF: {6FC2871E-004B-4141-B9C0-59708BD96CCE} (WSEmul Control 3) - https://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {7B72C3FC-34B5-4504-B4BE-EB38971A0888} (WSFileIO Class 3) - https://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
O16 - DPF: {7DB7E238-1425-4434-8B05-6453AD6A49C6} (WSPrint3 Control) - https://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
O16 - DPF: {85788258-6ACF-4FC1-A2CD-3BD248065AB9} (WSKeyboardMap Class) - https://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
O16 - DPF: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D} (WSFileIO Class 2) - https://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
O16 - DPF: {9145A52A-9B22-4858-AEE7-74D6C7D3F366} (BrowserConfig Class) - https://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
O16 - DPF: {A4D41E3A-613D-11D3-85B2-400011500081} (WSCustInst Class) - https://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D4233B6D-88A0-11D3-BC29-400011500032} (WspGoCal Class) - https://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D} (SCM Class1) - https://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe

–
End of file - 10787 bytes
Download and Run Registry Search
Download (LINK >>>) Registry Search (<<< LINK) to your desktop.
  • Right click on the compressed RegSearch folder, and choose "Extract All". In the box that pops open, click "Next", then "Next" again, and then "Finish". You now have another RegSearch folder on your desktop.
  • Open the new folder, and double click on regsearch.exe
  • In the top window copy/paste the following line
    • SOS
  • Click OK and Registry Search will scan your registry for the file(s), and a Notepad box will open with a report.
  • Please save the text file at you desktop and call it found-entries.
Paste the results in your reply
Results of registry search: Windows Registry Editor Version 5.00 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.6.0 ; Results at 1/7/2009 11:45:33 PM for strings: ; 'sos' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxUtilities.SOSTools] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxUtilities.SOSTools] @="SOSTools Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxUtilities.SOSTools\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxUtilities.SOSTools\CurVer] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxUtilities.SOSTools\CurVer] @="AxUtilities.SOSTools.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxUtilities.SOSTools.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxUtilities.SOSTools.1] @="SOSTools Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AxUtilities.SOSTools.1\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12520F70-D1D2-3698-A7BE-1D7089E4007F}] @="SosClientApi.WSCreateAccount.AccountManagementService" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12520F70-D1D2-3698-A7BE-1D7089E4007F}\InprocServer32] "Class"="SosClientApi.WSCreateAccount.AccountManagementService" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12520F70-D1D2-3698-A7BE-1D7089E4007F}\InprocServer32\4.3.15.3] "Class"="SosClientApi.WSCreateAccount.AccountManagementService" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12520F70-D1D2-3698-A7BE-1D7089E4007F}\ProgId] @="SosClientApi.WSCreateAccount.AccountManagementService" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5545373D-46CD-4FEC-9F6E-8880EBCA0DF3}] @="SOSTools Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5545373D-46CD-4FEC-9F6E-8880EBCA0DF3}\ProgID] @="AxUtilities.SOSTools.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5545373D-46CD-4FEC-9F6E-8880EBCA0DF3}\VersionIndependentProgID] @="AxUtilities.SOSTools" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56A49C5C-F6DD-3F33-988C-9CCF2C90CC7E}] @="SosClientApi.ClientAPI" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56A49C5C-F6DD-3F33-988C-9CCF2C90CC7E}\InprocServer32] "Class"="SosClientApi.ClientAPI" "Assembly"="SOSClientApi, Version=4.3.15.3, Culture=neutral, PublicKeyToken=9b8afe2c706a1860" "CodeBase"="file:///C:/Program Files/Webroot/WebrootSecurity/Backup/SOSClientApi.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56A49C5C-F6DD-3F33-988C-9CCF2C90CC7E}\InprocServer32\4.3.15.3] "Class"="SosClientApi.ClientAPI" "Assembly"="SOSClientApi, Version=4.3.15.3, Culture=neutral, PublicKeyToken=9b8afe2c706a1860" "CodeBase"="file:///C:/Program Files/Webroot/WebrootSecurity/Backup/SOSClientApi.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56A49C5C-F6DD-3F33-988C-9CCF2C90CC7E}\ProgId] @="SosClientApi.ClientAPI" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{594417FA-10E0-394B-9900-AE85AB83E771}] @="SosClientApi.WSCreateAccount.AuthHeader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{594417FA-10E0-394B-9900-AE85AB83E771}\InprocServer32] "Class"="SosClientApi.WSCreateAccount.AuthHeader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{594417FA-10E0-394B-9900-AE85AB83E771}\InprocServer32\4.3.15.3] "Class"="SosClientApi.WSCreateAccount.AuthHeader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{594417FA-10E0-394B-9900-AE85AB83E771}\ProgId] @="SosClientApi.WSCreateAccount.AuthHeader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{614A9E74-C178-3F52-8E19-11EEF6EC61D0}] @="SosClientApi.WSCreateAccount.UserAccount" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{614A9E74-C178-3F52-8E19-11EEF6EC61D0}\InprocServer32] "Class"="SosClientApi.WSCreateAccount.UserAccount" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{614A9E74-C178-3F52-8E19-11EEF6EC61D0}\InprocServer32\4.3.15.3] "Class"="SosClientApi.WSCreateAccount.UserAccount" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{614A9E74-C178-3F52-8E19-11EEF6EC61D0}\ProgId] @="SosClientApi.WSCreateAccount.UserAccount" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6DE9B5A-9AA9-46B4-87E0-FC85E4A51530}] @="sosCompress.ace" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6DE9B5A-9AA9-46B4-87E0-FC85E4A51530}\InprocServer32] @="C:\\Program Files\\Webroot\\WebrootSecurity\\Backup\\sosCompress.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6DE9B5A-9AA9-46B4-87E0-FC85E4A51530}\ProgID] @="sosCompress.ace" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA9D2F91-F759-4B99-96B0-3F7F4F2D6377}] @="SosClientApi.RightClickProtect" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA9D2F91-F759-4B99-96B0-3F7F4F2D6377}\InprocServer32] "Class"="SosClientApi.RightClickProtect" "Assembly"="SOSClientApi, Version=4.3.15.3, Culture=neutral, PublicKeyToken=9b8afe2c706a1860" "CodeBase"="file:///C:/Program Files/Webroot/WebrootSecurity/Backup/SOSClientApi.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA9D2F91-F759-4B99-96B0-3F7F4F2D6377}\InprocServer32\4.3.15.3] "Class"="SosClientApi.RightClickProtect" "Assembly"="SOSClientApi, Version=4.3.15.3, Culture=neutral, PublicKeyToken=9b8afe2c706a1860" "CodeBase"="file:///C:/Program Files/Webroot/WebrootSecurity/Backup/SOSClientApi.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA9D2F91-F759-4B99-96B0-3F7F4F2D6377}\ProgId] @="SosClientApi.RightClickProtect" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9145AC9-C4B6-44E9-BD69-5AA18C9E45B8}] @="SosClientApi.UploadAgentApi" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9145AC9-C4B6-44E9-BD69-5AA18C9E45B8}\InprocServer32] "Class"="SosClientApi.UploadAgentApi" "Assembly"="SOSClientApi, Version=4.3.15.3, Culture=neutral, PublicKeyToken=9b8afe2c706a1860" "CodeBase"="file:///C:/Program Files/Webroot/WebrootSecurity/Backup/SOSClientApi.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9145AC9-C4B6-44E9-BD69-5AA18C9E45B8}\InprocServer32\4.3.15.3] "Class"="SosClientApi.UploadAgentApi" "Assembly"="SOSClientApi, Version=4.3.15.3, Culture=neutral, PublicKeyToken=9b8afe2c706a1860" "CodeBase"="file:///C:/Program Files/Webroot/WebrootSecurity/Backup/SOSClientApi.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9145AC9-C4B6-44E9-BD69-5AA18C9E45B8}\ProgId] @="SosClientApi.UploadAgentApi" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C55F0A34-4286-4094-905E-75CBD8BF0776}] @="sosbutton.Button" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C55F0A34-4286-4094-905E-75CBD8BF0776}\InprocServer32] @="C:\\Program Files\\Webroot\\WebrootSecurity\\Backup\\sosbutton.ocx" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C55F0A34-4286-4094-905E-75CBD8BF0776}\ProgID] @="sosbutton.Button" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C55F0A34-4286-4094-905E-75CBD8BF0776}\ToolboxBitmap32] @="C:\\Program Files\\Webroot\\WebrootSecurity\\Backup\\sosbutton.ocx, 30000" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Components\FC9E92CC2CB71D119A12000A9CE1A22A] ; Contents of value: ; 26,!!gxsf(Ng]qF`H{LsOSBShortCutFiles>(nT]jI{jf(=1&L[-81-] ; "1033"=hex(7):32,00,36,00,2c,00,21,00,21,00,67,00,78,00,73,00,66,00,28,00,4e,\ 00,67,00,5d,00,71,00,46,00,60,00,48,00,7b,00,4c,00,73,00,4f,00,53,00,42,00,\ 53,00,68,00,6f,00,72,00,74,00,43,00,75,00,74,00,46,00,69,00,6c,00,65,00,73,\ 00,3e,00,28,00,6e,00,54,00,5d,00,6a,00,49,00,7b,00,6a,00,66,00,28,00,3d,00,\ 31,00,26,00,4c,00,5b,00,2d,00,38,00,31,00,2d,00,5d,00,00,00,00,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{000C0507-0000-0000-C000-000000000046}] @="IMsoShMemory" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0D348102-F24E-3D76-A617-AAB07C646D02}] @="_SosApiException" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{31899FEF-2813-4481-8175-003FA5732B2E}] @="_ISOSToolsEvents" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{38BDDC6E-10A9-4BEF-ABFD-EB9A6D005221}] @="ISOSTools4" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5B67A351-5587-41C3-A6D3-5944AF6C2C70}] @="ISOSTools3" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6BED47DB-B5FD-4472-BEEB-B0CF4D35EA65}] @="ISOSTools2" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B9C91B46-13EF-4A6F-A247-4D2A78D67A2F}] @="ISOSTools" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{1EE8BA4F-293D-31FD-93AC-D341ACCDB1B4}\4.3.15.3] "Class"="SosClientApi.WSCreateAccount.ReturnCode" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{498A37BB-79C9-37EF-9964-7E203C9E0634}\2.0.4.1] "Class"="SOSTools.AppSettings+StringSettingsType" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{5B1AD245-17C5-3408-A0C8-622AE206BD6C}\2.0.4.1] "Class"="SOSTools.TypeLog" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{66C9C965-54FA-3734-8C34-EBA1CDA0A113}\2.0.11.3] "Class"="SOSTools.ConfigurationType" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{77873750-B9C6-3C7C-B7DC-ED110C6BC75A}\2.0.4.1] "Class"="SOSTools.AppSettings+BooleanSettingsType" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{81B6CA41-17B3-399D-A8AE-BAC134BD29F0}\2.0.11.3] "Class"="SOSTools.SysLog+Type" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{C11E2E28-1B2B-39C5-8991-313EADA79DCC}\4.3.15.3] "Class"="SosClientApi.UaResource" "Assembly"="SOSClientApi, Version=4.3.15.3, Culture=neutral, PublicKeyToken=9b8afe2c706a1860" "CodeBase"="file:///C:/Program Files/Webroot/WebrootSecurity/Backup/SOSClientApi.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Record\{DD6E836A-DB5C-37D4-86A1-2C06144AC837}\2.0.4.1] "Class"="SOSTools.ConfigurationType" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sosbutton.Button] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sosbutton.Button] @="sosbutton.Button" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sosbutton.Button\Clsid] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.ClientAPI] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.ClientAPI] @="SosClientApi.ClientAPI" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.ClientAPI\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.RightClickProtect] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.RightClickProtect] @="SosClientApi.RightClickProtect" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.RightClickProtect\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.UploadAgentApi] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.UploadAgentApi] @="SosClientApi.UploadAgentApi" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.UploadAgentApi\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.WSCreateAccount.AccountManagementService] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.WSCreateAccount.AccountManagementService] @="SosClientApi.WSCreateAccount.AccountManagementService" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.WSCreateAccount.AccountManagementService\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.WSCreateAccount.AuthHeader] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.WSCreateAccount.AuthHeader] @="SosClientApi.WSCreateAccount.AuthHeader" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.WSCreateAccount.AuthHeader\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.WSCreateAccount.UserAccount] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.WSCreateAccount.UserAccount] @="SosClientApi.WSCreateAccount.UserAccount" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SosClientApi.WSCreateAccount.UserAccount\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sosCompress.ace] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sosCompress.ace] @="sosCompress.ace" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sosCompress.ace\Clsid] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3106A314-D008-4567-A85D-5A5AD1D3E363}\8.0] @="sosCompress" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3106A314-D008-4567-A85D-5A5AD1D3E363}\8.0\0\win32] @="C:\\Program Files\\Webroot\\WebrootSecurity\\Backup\\sosCompress.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D8F0BDA9-3F22-4FA0-B695-8DEC09CAD0EB}\1.0] @="sosbutton" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D8F0BDA9-3F22-4FA0-B695-8DEC09CAD0EB}\1.0\0\win32] @="C:\\Program Files\\Webroot\\WebrootSecurity\\Backup\\sosbutton.ocx" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E046C856-4110-3983-95F2-C41D2A772F41}\4.3] @="SOS Client API" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E046C856-4110-3983-95F2-C41D2A772F41}\4.3\0\win32] @="C:\\Program Files\\Webroot\\WebrootSecurity\\Backup\\SOSClientAPI.tlb" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\178D146DA28EA9D4F8A35C0ECCA1BF4E] "1F3B805BA42A0C233B0158879691FE82"="c?\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\50D24CD8B0860B148887C6412D6420BD\Features] "QuickTimeInternet"=".zqkYPsOP=l_]X3`T%J[{BdMSFZ,s=B2FXqJ.NPYE2S~R1+_X@e0Mh'_'!ceE7eZJ!n%Z=yj)yoGjyYki!7k5]uyi=9k.U(wA)N&4rtB6h_b2@pX=rz0Az[^j?v3pZBU19zkX}V{xD[109la%}&x}8GmzkSb9BbQCsi2Q7(Bd?v-$uoupzZu)ryT)y!t(9fsJbZocP0]Kk^rxIU3)='}+@)MHf70{iN&0BP}.9p^5V3$jdszP)JwYQ(1X=G}LNC(qloWq!LOs4Xbo?k'X)Viy,oIrHZEXGsES95igcYfu2@7@Mvr6SfSp=ctYIEyW@tBx]~3vXB_y8=+z2?ZxK=?)fiu_@aND?hc&1%E2bY5Y)X2_@~sb95Jnq[2u3R1~O_,FC&A0?]l_Oj]}lg!D%$+XUwq~=RevdSl`GJ3UIx%1V@lI=7J3dviV+7fBpHuZ~Ibf=}NJJx,=vskRYh-@LTBh9hM.I`hT@okGamN8*trh8ac@AC97)7n`&UG1{*Y+@E`fwbx6G{LuE65&AB0U?'_VRuvh%`+e^ChfQpXb9+Qg1[O8FuyQ{}_I=_NR=@UEqhl]i$Q,l0'S}qF]AeER{3.fpVVB1k5Xhz!F=TJ1NR=PHz4ZY&ktg6lz9_sVWOs0*+9}Gh[%31y)9c{Jp?NGv{,L%3$V-wl==NMUe.A,.~J1XJ-Gx7ow8aPiH[)6l8HUF=SyDi~e9P_iBH~CksxvIx.)[GzY=~Evif}A93FHaWD[lkYWA$wlEYgp!@]9W9v%6EHq@TQ7=0J?O4%+t12_(*}Z9ICRS_4tksq?R@%+JMzN@g=hoAz5dz]Vlvmh3-DD9H%U5`cC&Dlfnw2+Yfm09*AkpVE)dL+*I1NF$9&LAR(gg$Bfg@]V(Uv8^(a*9ku@KD??W.bS)^j9mE&T?cZ,R1kbwzqbo}7]T8$x=iWLrcSHUBKqnm?AD17g=,ugtHrZ~BS-!Ril5Kc(@.tL5*A8Cd!&M`RO+bs0=m`RRV9rDgVUmO7NUT*69y]fHV3$(jxp_uBR-EQw8Hv{*[%NVw&CgeA?AZ$y9q{)W3Ro0[%bI=yUNPOA9+RnxE]Lg_=sgzSa7$''9?'Xq'`CKWenjd}+-*Td=I0J2wroC!hzThndP`(,AhKJ8'OrX8ky7g2I1-VQ==k,HcVk~7GZ%V`lFk&R?czXZGJ_A{ub.vcl`]A,A`G&(*{~ov?'blol.}Wv?Nh,sEtvERa{~@}xkw^-=~oBmAfINiM=^2N,D1SS=@D%)yumPuJ{G@%0b*WL?D,z[oQB6s$.X$.R='eLA,dQ@u`YpCnsosSXQGI69-{{G0Xtqf(m}bgD.0ia8b^bn7^YgMJ+@l(-9`TV9?sjVwFV`(k@]jG2)cTL9sxKwmmotx8-{)%nO,YWAA$HV3%Xjqsa@&7XYRz`@[EVx9'~a5Pcj7{UD7Bw@g'rkPioH]&QPhXH*f(-9N5-~5xeurnV_bXlbeg~8ISD=k42QRft1*9pW[z]9*ny'7V{O-U%S8HpF'@c9LHE2D9oKcdX=[PVWF1A9q@51^),yiy)02)VqXgw?lb,ADOoKB`BJ-Y['Lc1?+}}`9tOkfMQuickTimeEssentials" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A18B9BCCF76123843B502D0A3480043B\Features] "WebReg"="=xLp3J(jo8SNZ$5YxF0!@FJTIpP^0=j%MF@*QjiQpIA[@l*YM9,1_`6def_R]_9z,@.Dt?4KoYBxVX02mEI)ZhUNU=a]d7yl*'('-x0v8^3gW?F53^TZ7U'N*fg@0b`]+@_nhX7PRFws=CBt^*x3A?JP-D)To6v-a1zzwdIe!AH~-`eO2PeJQnH]Fz*7*@Q=HYMtIgqGMPNihYz)l8'uzT.8EWjMld*}q@bQ39f*j?0$`@_fOEJQ&_*LJ9_isy+xALQ6q!qPbqHU!@8L,3xAmgGuChPkmELrh?W576V}Kzu1`Eo?(_aJE?}[_`_u5,&NxmM~Jem]D=_F5_dM+3wzUqWIy^a!i?rGRL[Evl]Gu($^4~F{SA8vdFR2_8}&F9oorR~q5@5r`un9x^BkTo_(j.nh79YG9(YquSOSnmIi8J0zH=!h2WO~k53,?&XyI]RcZ=oARp]m^`f7VMbMwax$D?Dk-me_AMNR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F65865963B6B0EB4ABB0F894B53E0233\Features] "AppleSoftwareUpdate"="15?%n%iWs=,E&5u5w[eR=}uyqC2$5AJw']^Z]fR_TQ?B20utg(.L?N3&lrLW]=9fmturW?Yf}fKb.'_apI4!8fTO=9.}t`bY^%E=)BK]]^473=Q9V*LEukGnH&5W=46ub8Zx?`,lU@f.,f.JsZxcz9MXl[W2{@fg(B$oDHjUw=_Bj-mv0d7H~MyTSbPYc9gDnYoI${fi1WB`2ZiNH@squ`^VhDU1.~gK0J00a=H5*A=Ei%O24K8K*z{.^82R73@h[wqTX3!]pC(zr?HB~'+5oul=+!{dQPR(==Ut9B*g69%Z7k4IQJER$=e5e.v3X7{A9Yw5AETNa8I`3`!G.{~Gv8hB1@%~@?44U=?zEaDk@WU,&To44@kA2CE6W(zfz,%%^kIIH9)=J&?VPPtyC.A&2.8!i?+i(&r]SosQzDIoyO-ox=)y['Eq7PU-i4,('PwW[8%D]2CT%C`&&['Q&&mBI9Xh[cZ}7HEtQcEE-K!V=@QwAP1)7klbxqWU(343)A(Z^dWs{kpUZ^EB`cihm=tX!&u5+K+DLH(*N{hM$?])V)S6f9ASCq4+v9Bq39^kX?9]5`bv(B7!WQyrp?.%2p`5u5xQ&'QGlP@W~?cE_ei}*^C6Ep)J$1e,g@SM8FjQX*jVI+!S3nGf?9A?A'Zx}s)5A6z,O]B&X@iCqA70dq'dnFWopYNN1=[_'-%Vjl(yp3a,f(EM2=Cxxrz6k[7v=hxHL^&0t9u?0GKJ-cmHmi5d6!(I!97st-j.YW9^" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2052111302-1123561945-839522115-1004\Products\6BDFDFF6066A3A1499A7BE60C1F5C606\Features] "Datastore"="RN83EW{'I9B9Z8zG=EPjB3&5,B^pf(V%eqFgkW_B83&5,B^pf(V%eqFgkW_B=xLp3J(jo8SNZ$5YxF0!pIA[@l*YM9,1_`6def_R]_9z,@.Dt?4KoYBxVX02mEI)ZhUNU=a]d7yl*'('-x0v8^3gW?F53^TZ7U'N*fg@0b`]+@_nhX7PRFws=CBt^*x3A?JP-D)To6v-a1zzwdIe!AH~-`eO2PeJQnH]Fz*7*@Q=HYMtIgqGMPNihYz)l8'uzT.8EWjMOEJQ&_*LJ9_isy+xALQ6q!qPbqHU!@8L,3xAmgGuChPkmELrh?W576V}Kzu1`Eo?(_aJE?}[_`_u5,&NxmM~Jem]D=_F5_dM+3wzUqWIy^a!i?rGRL[Evl]Gu($^4~F{SA8vdFR2_8}&F9oorR~q5@5r`un9x^BkTo_(j.nh79YG9(YquSOSnmIi8J0zH=!h2WO~k53,?&XyI]RcZ=oARp]m^`f7VMbMwax$D?Dk-me_AMNR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\errorsoshi.com] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsoshi.com] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsoshi.com\www] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rossosalice.it] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rossosalice.it\www] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\errorsoshi.com] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\errorsoshi.com\www] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\rossosalice.it] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\rossosalice.it\www] [HKEY_LOCAL_MACHINE\SOFTWARE\SOS] [HKEY_LOCAL_MACHINE\SOFTWARE\SOS\Internet Settings] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\errorsoshi.com] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsoshi.com] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsoshi.com\www] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rossosalice.it] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rossosalice.it\www] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\errorsoshi.com] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\errorsoshi.com\www] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\rossosalice.it] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\rossosalice.it\www] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\errorsoshi.com] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsoshi.com] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsoshi.com\www] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rossosalice.it] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rossosalice.it\www] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\errorsoshi.com] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\errorsoshi.com\www] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\rossosalice.it] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\rossosalice.it\www] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\errorsoshi.com] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsoshi.com] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsoshi.com\www] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rossosalice.it] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rossosalice.it\www] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\errorsoshi.com] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\errorsoshi.com\www] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\rossosalice.it] [HKEY_USERS\S-1-5-21-2052111302-1123561945-839522115-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\rossosalice.it\www] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\errorsoshi.com] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsoshi.com] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsoshi.com\www] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rossosalice.it] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\rossosalice.it\www] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\errorsoshi.com] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\errorsoshi.com\www] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\rossosalice.it] [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\rossosalice.it\www] ; End Of The Log…
After doing a file search, I have found that I do have an "SOS" backup program running. It is associated with my Webroot Spysweeper. I didn't realize I had it. I believe it was downloaded with the latest update of Spysweeper that I did a couple months ago. I saw a "Backup" tab on the Spysweeper window, but didn't know it had anything to do with the "SOS" file. It is all making sense now. I see there is an "SOS backup" uninstall program. Since I don't use the backup feature, I think I will go ahead and uninstall the program, unless you think I should do something different. I'm guessing that is where the "SOS" registry key is coming from. If the "SOS" registry key is coming from the Webroot backup program, why does CA/Pest Patrol consider it a file associated with the Bancos Trojan??

why does CA/Pest Patrol consider it a file associated with the Bancos Trojan??

I don't have any answers for that.

Uninstall the SOS backup and lets see where we stand.
The "SOS backup" program uninstaller, wouldn't work, so I uninstalled the SpySweeper program completely. The "SOS" registry key was gone after startup. That apparently is the program that is putting the "SOS" key in the registry. So, is it safe to say the "SOS" key is NOT associated with the Bancos Trojan??

So, is it safe to say the "SOS" key is NOT associated with the Bancos Trojan??

Not with what you had installed. I have seen sos with a following bad file which indicates Bancos Trojan.
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    To be on the safe side, I would also change all my passwords.


    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • Winpatrol

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI