Caysee
Topic Starter
I was getting uncontrollable amounts of popups to the point that I had to use another computer to search the internet for answers. I've found help to stop the popups but I don't think I'm done. I've used Malwarebytes' Anti-Malware and that seemed to make a big difference. I then did the online scan with Kaspersky and this is the scan report:
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, December 31, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, December 30, 2008 23:44:17
Records in database: 1534331
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Files scanned: 155173
Threat name: 15
Infected objects: 19
Suspicious objects: 0
Duration of the scan: 02:53:43
File name / Threat name / Threats count
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: Trojan-Downloader.Win32.Agent.alr 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.ct 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:Downloader.Win32.WinFixer.gv 2
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.bm 2
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.au 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.am 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.ar 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: Trojan.Win32.BHO.gos 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.ao 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.k 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.a 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:Downloader.Win32.WinFixer.x 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\25.tmp Infected: not-a-virus:Downloader.Win32.WinFixer.o 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\26.tmp Infected: not-a-virus:Downloader.Win32.WinFixer.o 1
C:\WINDOWS\BBStore\DSS\DSSAGENT.EXE Infected: not-a-virus:AdWare.Win32.Background 1
The selected area was scanned.
I've run the ComboFix.exe and this is the log:
ComboFix 08-12-30.02 - Kimberly 2008-12-31 15:11:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.138 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro PC-cillin Internet Security *On-access scanning enabled* (Outdated)
FW: Trend Micro PC-cillin Internet Security (Firewall) *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Kimberly\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\404Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
.
2008-12-31 00:47 . 2008-12-31 00:47 d——– c:\windows\ERUNT
2008-12-31 00:45 . 2008-12-31 01:12 d——– C:\SDFix
2008-12-30 00:23 . 2008-12-31 14:36 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-30 00:23 . 2008-12-30 00:23 1,409 –a—— c:\windows\QTFont.for
2008-12-29 23:09 . 2008-12-29 23:09 d——– c:\documents and settings\Kimberly\Application Data\Malwarebytes
2008-12-29 23:08 . 2008-12-29 23:09 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-29 23:08 . 2008-12-29 23:08 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-29 23:08 . 2008-12-03 19:59 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 23:08 . 2008-12-03 19:59 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-29 21:56 . 2008-12-29 21:56 d——– c:\program files\CCleaner
2008-12-29 21:53 . 2008-12-29 21:53 d——– c:\program files\RogueRemover FREE
2008-12-29 21:39 . 2008-12-12 00:57 78,336 –a—— c:\windows\system32\Agent.OMZ.Fix.exe
2008-12-25 00:12 . 2008-12-28 23:28 d——– c:\program files\MediaCoder
2008-12-25 00:05 . 2004-03-03 18:05 1,839,104 –a—— c:\windows\system32\NCTAudioFile2.dll
2008-12-25 00:05 . 2003-02-11 14:36 1,703,936 –a—— c:\windows\system32\NCTAudioFile.dll
2008-12-25 00:05 . 2003-02-11 14:38 892,928 –a—— c:\windows\system32\NCTAudioInformation.dll
2008-12-25 00:05 . 2003-02-11 14:39 647,168 –a—— c:\windows\system32\NCTAudioLibrary.dll
2008-12-25 00:05 . 2004-05-20 13:07 335,872 –a—— c:\windows\system32\NCTAudioVisualization2.dll
2008-12-25 00:05 . 2003-02-11 14:37 327,680 –a—— c:\windows\system32\NCTAudioGrabber.dll
2008-12-25 00:05 . 2004-03-02 19:07 315,392 –a—— c:\windows\system32\NCTAudioPlayer2.dll
2008-12-25 00:05 . 2001-05-16 17:54 309,616 –a—— c:\windows\system32\wmv8dmod.dll
2008-12-25 00:05 . 2004-03-02 19:14 307,200 –a—— c:\windows\system32\NCTAudioRecord2.dll
2008-12-25 00:05 . 2001-03-26 04:41 245,760 –a—— c:\windows\system32\mp4sds32.ax
2008-12-25 00:05 . 2004-05-20 14:24 196,608 –a—— c:\windows\system32\NCTWMAFile2.dll
2008-12-25 00:04 . 2000-05-22 06:00 647,872 –a—— c:\windows\system32\MSCOMCT2.OCX
2008-12-25 00:04 . 2002-07-23 11:05 413,760 –a—— c:\windows\system32\mpg4c32.dll
2008-12-25 00:04 . 1999-05-06 23:00 140,288 –a—— c:\windows\system32\comdlg32.ocx
2008-12-25 00:04 . 2000-07-15 06:00 101,888 –a—— c:\windows\system32\VB6STKIT.DLL
2008-12-24 23:57 . 2008-12-28 23:29 d——– c:\program files\Common Files\AVSMedia
2008-12-24 23:57 . 2008-12-24 23:57 d——– c:\documents and settings\Kimberly\Application Data\AVS4YOU
2008-12-24 23:57 . 2008-12-24 23:57 d——– c:\documents and settings\All Users\Application Data\AVS4YOU
2008-12-24 23:57 . 2006-03-03 10:02 658,432 –a—— c:\windows\system32\cc3270mt.dll
2008-12-24 23:56 . 2008-12-28 23:29 d——– c:\program files\AVS4YOU
2008-12-24 23:56 . 2003-05-21 13:50 24,576 –a—— c:\windows\system32\msxml3a.dll
2008-12-23 20:37 . 2008-12-23 20:37 d——– c:\documents and settings\Kimberly\Application Data\Amazon
2008-12-23 20:36 . 2008-12-23 20:36 d——– c:\program files\Amazon
2008-11-20 11:00 . 2008-11-20 11:00 d——– c:\documents and settings\Victoria\.realobjects
2008-11-20 08:11 . 2008-12-04 11:46 d——– c:\documents and settings\Victoria\Application Data\U3
2008-11-09 11:13 . 2008-11-09 11:13 d——– c:\program files\Walmart MP3 Music Downloads
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 02:47 ——— d—–w c:\program files\Google
2008-12-29 23:18 ——— d—–w c:\program files\Rhapsody
2008-12-26 22:13 ——— d—–w c:\documents and settings\Victoria\Application Data\Skype
2008-12-26 22:12 ——— d—–w c:\documents and settings\Victoria\Application Data\skypePM
2008-12-13 06:40 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
2008-11-19 00:32 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-27 01:33 125,160 —-a-w c:\documents and settings\Kimberly\Application Data\GDIPFONTCACHEV1.DAT
2008-10-24 11:10 453,632 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 13:01 283,648 ——w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 13:11 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:57 332,800 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ——w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:15 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-03 10:15 247,326 ——w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ——w c:\windows\system32\dllcache\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ——w c:\windows\system32\dllcache\msxml3.dll
2008-01-27 00:56 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-12-11 23:42 104,048 -c–a-w c:\documents and settings\Guest\Application Data\GDIPFONTCACHEV1.DAT
2007-01-27 02:10 722,176 -c–a-w c:\documents and settings\Kimberly\gotomypc_428.exe
2006-02-11 18:39 56 -csh–r c:\windows\system32\A1067E525C.sys
2007-01-25 00:40 6,998 -csha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="c:\program files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 176201]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Creative WebCam Tray"="c:\program files\Creative\Shared Files\CamTray.exe" [2005-03-29 258048]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-20 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-02-02 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 823362]
"Lexmark X6100 Series"="c:\program files\Lexmark X6100 Series\lxbfbmgr.exe" [2003-09-23 57344]
"HostManager"="c:\program files\Common Files\AOL\1139541727\ee\AOLSoftware.exe" [2006-05-09 50760]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-09 270648]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-20 213936]
"PD0620 STISvc"="P0620Pin.dll" [2005-05-10 c:\windows\system32\P0620Pin.dll]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2006-09-17 1454143]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-12-13 630915]
Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [2003-06-08 16432]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2007-08-09 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=lqvkhx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139541727\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139541727\\ee\\aim6.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R2 Tmfilter;Tmfilter;c:\windows\system32\drivers\TmXPFlt.sys [2005-08-30 205328]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2005-08-30 290889]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2005-08-30 585792]
R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\Tmpreflt.sys [2005-08-30 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2005-08-30 262215]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-02-12 24652]
S2 mrtRate;mrtRate; []
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-12-31 c:\windows\Tasks\dpvfoiob.job
- c:\windows\system32\rundll32.exe [2004-08-04 06:00]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = localhost
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
c:\windows\Downloaded Program Files\FileOpenInstall.dll - O16 -: {CE8267C2-D41A-4A50-A69D-F32B5C289F14}
hxxp://taxwebwlbs2.trendmls.com/Resources/webpublisher/installer/fileopen.cab
c:\windows\Downloaded Program Files\FileOpenInstall.OSD
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-31 15:23:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-12-31 15:25:21
ComboFix-quarantined-files.txt 2008-12-31 20:24:54
Pre-Run: 129,183,383,552 bytes free
Post-Run: 130,511,286,272 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
215 — E O F — 2008-12-19 04:05:00
I'm hoping that someone can tell me if there is anything more I can do to be sure the computer is clean.
Thank you!
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, December 31, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, December 30, 2008 23:44:17
Records in database: 1534331
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Files scanned: 155173
Threat name: 15
Infected objects: 19
Suspicious objects: 0
Duration of the scan: 02:53:43
File name / Threat name / Threats count
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: Trojan-Downloader.Win32.Agent.alr 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.ct 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:Downloader.Win32.WinFixer.gv 2
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.bm 2
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.au 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.am 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.ar 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: Trojan.Win32.BHO.gos 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.ao 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.k 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.a 1
C:\Documents and Settings\Victoria\Local Settings\Temp\~freesetup.exe Infected: not-a-virus:Downloader.Win32.WinFixer.x 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\25.tmp Infected: not-a-virus:Downloader.Win32.WinFixer.o 1
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\26.tmp Infected: not-a-virus:Downloader.Win32.WinFixer.o 1
C:\WINDOWS\BBStore\DSS\DSSAGENT.EXE Infected: not-a-virus:AdWare.Win32.Background 1
The selected area was scanned.
I've run the ComboFix.exe and this is the log:
ComboFix 08-12-30.02 - Kimberly 2008-12-31 15:11:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.138 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro PC-cillin Internet Security *On-access scanning enabled* (Outdated)
FW: Trend Micro PC-cillin Internet Security (Firewall) *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Kimberly\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\404Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
.
2008-12-31 00:47 . 2008-12-31 00:47 d——– c:\windows\ERUNT
2008-12-31 00:45 . 2008-12-31 01:12 d——– C:\SDFix
2008-12-30 00:23 . 2008-12-31 14:36 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-30 00:23 . 2008-12-30 00:23 1,409 –a—— c:\windows\QTFont.for
2008-12-29 23:09 . 2008-12-29 23:09 d——– c:\documents and settings\Kimberly\Application Data\Malwarebytes
2008-12-29 23:08 . 2008-12-29 23:09 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-29 23:08 . 2008-12-29 23:08 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-29 23:08 . 2008-12-03 19:59 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 23:08 . 2008-12-03 19:59 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-29 21:56 . 2008-12-29 21:56 d——– c:\program files\CCleaner
2008-12-29 21:53 . 2008-12-29 21:53 d——– c:\program files\RogueRemover FREE
2008-12-29 21:39 . 2008-12-12 00:57 78,336 –a—— c:\windows\system32\Agent.OMZ.Fix.exe
2008-12-25 00:12 . 2008-12-28 23:28 d——– c:\program files\MediaCoder
2008-12-25 00:05 . 2004-03-03 18:05 1,839,104 –a—— c:\windows\system32\NCTAudioFile2.dll
2008-12-25 00:05 . 2003-02-11 14:36 1,703,936 –a—— c:\windows\system32\NCTAudioFile.dll
2008-12-25 00:05 . 2003-02-11 14:38 892,928 –a—— c:\windows\system32\NCTAudioInformation.dll
2008-12-25 00:05 . 2003-02-11 14:39 647,168 –a—— c:\windows\system32\NCTAudioLibrary.dll
2008-12-25 00:05 . 2004-05-20 13:07 335,872 –a—— c:\windows\system32\NCTAudioVisualization2.dll
2008-12-25 00:05 . 2003-02-11 14:37 327,680 –a—— c:\windows\system32\NCTAudioGrabber.dll
2008-12-25 00:05 . 2004-03-02 19:07 315,392 –a—— c:\windows\system32\NCTAudioPlayer2.dll
2008-12-25 00:05 . 2001-05-16 17:54 309,616 –a—— c:\windows\system32\wmv8dmod.dll
2008-12-25 00:05 . 2004-03-02 19:14 307,200 –a—— c:\windows\system32\NCTAudioRecord2.dll
2008-12-25 00:05 . 2001-03-26 04:41 245,760 –a—— c:\windows\system32\mp4sds32.ax
2008-12-25 00:05 . 2004-05-20 14:24 196,608 –a—— c:\windows\system32\NCTWMAFile2.dll
2008-12-25 00:04 . 2000-05-22 06:00 647,872 –a—— c:\windows\system32\MSCOMCT2.OCX
2008-12-25 00:04 . 2002-07-23 11:05 413,760 –a—— c:\windows\system32\mpg4c32.dll
2008-12-25 00:04 . 1999-05-06 23:00 140,288 –a—— c:\windows\system32\comdlg32.ocx
2008-12-25 00:04 . 2000-07-15 06:00 101,888 –a—— c:\windows\system32\VB6STKIT.DLL
2008-12-24 23:57 . 2008-12-28 23:29 d——– c:\program files\Common Files\AVSMedia
2008-12-24 23:57 . 2008-12-24 23:57 d——– c:\documents and settings\Kimberly\Application Data\AVS4YOU
2008-12-24 23:57 . 2008-12-24 23:57 d——– c:\documents and settings\All Users\Application Data\AVS4YOU
2008-12-24 23:57 . 2006-03-03 10:02 658,432 –a—— c:\windows\system32\cc3270mt.dll
2008-12-24 23:56 . 2008-12-28 23:29 d——– c:\program files\AVS4YOU
2008-12-24 23:56 . 2003-05-21 13:50 24,576 –a—— c:\windows\system32\msxml3a.dll
2008-12-23 20:37 . 2008-12-23 20:37 d——– c:\documents and settings\Kimberly\Application Data\Amazon
2008-12-23 20:36 . 2008-12-23 20:36 d——– c:\program files\Amazon
2008-11-20 11:00 . 2008-11-20 11:00 d——– c:\documents and settings\Victoria\.realobjects
2008-11-20 08:11 . 2008-12-04 11:46 d——– c:\documents and settings\Victoria\Application Data\U3
2008-11-09 11:13 . 2008-11-09 11:13 d——– c:\program files\Walmart MP3 Music Downloads
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 02:47 ——— d—–w c:\program files\Google
2008-12-29 23:18 ——— d—–w c:\program files\Rhapsody
2008-12-26 22:13 ——— d—–w c:\documents and settings\Victoria\Application Data\Skype
2008-12-26 22:12 ——— d—–w c:\documents and settings\Victoria\Application Data\skypePM
2008-12-13 06:40 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
2008-11-19 00:32 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-27 01:33 125,160 —-a-w c:\documents and settings\Kimberly\Application Data\GDIPFONTCACHEV1.DAT
2008-10-24 11:10 453,632 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 13:01 283,648 ——w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 13:11 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:57 332,800 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ——w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:15 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-03 10:15 247,326 ——w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ——w c:\windows\system32\dllcache\win32k.sys
2008-09-04 16:42 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ——w c:\windows\system32\dllcache\msxml3.dll
2008-01-27 00:56 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-12-11 23:42 104,048 -c–a-w c:\documents and settings\Guest\Application Data\GDIPFONTCACHEV1.DAT
2007-01-27 02:10 722,176 -c–a-w c:\documents and settings\Kimberly\gotomypc_428.exe
2006-02-11 18:39 56 -csh–r c:\windows\system32\A1067E525C.sys
2007-01-25 00:40 6,998 -csha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="c:\program files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 176201]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Creative WebCam Tray"="c:\program files\Creative\Shared Files\CamTray.exe" [2005-03-29 258048]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-20 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-02-02 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 823362]
"Lexmark X6100 Series"="c:\program files\Lexmark X6100 Series\lxbfbmgr.exe" [2003-09-23 57344]
"HostManager"="c:\program files\Common Files\AOL\1139541727\ee\AOLSoftware.exe" [2006-05-09 50760]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-09 270648]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-20 213936]
"PD0620 STISvc"="P0620Pin.dll" [2005-05-10 c:\windows\system32\P0620Pin.dll]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2006-09-17 1454143]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-12-13 630915]
Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [2003-06-08 16432]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2007-08-09 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=lqvkhx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139541727\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139541727\\ee\\aim6.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R2 Tmfilter;Tmfilter;c:\windows\system32\drivers\TmXPFlt.sys [2005-08-30 205328]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2005-08-30 290889]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2005-08-30 585792]
R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\Tmpreflt.sys [2005-08-30 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2005-08-30 262215]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-02-12 24652]
S2 mrtRate;mrtRate; []
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-12-31 c:\windows\Tasks\dpvfoiob.job
- c:\windows\system32\rundll32.exe [2004-08-04 06:00]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = localhost
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
c:\windows\Downloaded Program Files\FileOpenInstall.dll - O16 -: {CE8267C2-D41A-4A50-A69D-F32B5C289F14}
hxxp://taxwebwlbs2.trendmls.com/Resources/webpublisher/installer/fileopen.cab
c:\windows\Downloaded Program Files\FileOpenInstall.OSD
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-31 15:23:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-12-31 15:25:21
ComboFix-quarantined-files.txt 2008-12-31 20:24:54
Pre-Run: 129,183,383,552 bytes free
Post-Run: 130,511,286,272 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
215 — E O F — 2008-12-19 04:05:00
I'm hoping that someone can tell me if there is anything more I can do to be sure the computer is clean.
Thank you!