This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] NEED HELP with removing virus

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:40:43 AM, on 1/22/2009
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1232619122890
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1232648794984
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe CAN You help me remove a virus and some bad files in my computer..i will be checking my post daily for response… thank you
hello

Please run the MGA Diagnostic Tool and post back the report it shall produce:
  • Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program
  • Click "Continue"
  • Ensure that the "Windows" tab is selected (it should be by default).
  • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.
Diagnostic Report (1.7.0110.1):
—————————————–
WGA Data–>
Validation Status: Genuine
Validation Code: 0
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-J8BM6-MXPH6-3R2BW
Windows Product Key Hash: YMRVitCEjlJfwDQfjDvm97FbWA4=
Windows Product ID: 55277-OEM-2111907-00103
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 5.1.2600.2.00010300.2.0.hom
ID: {444A51FB-2F59-405E-B3DE-694B61BCBE2B}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.69.2
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1
Resolution Status: N/A

WgaER Data–>
ThreatID(s): N/A
Version: N/A

WGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data–>
Office Status: 114 Blocked VLK 2
Microsoft Office XP Professional with FrontPage - 114 Blocked VLK 2
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-171-1_FA827CE6-153-8007007e_FA827CE6-180-8007007e

Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data–>

Other data–>
Office Details: {444A51FB-2F59-405E-B3DE-694B61BCBE2B}1.7.0110.15.1.2600.2.00010300.2.0.homx32*****-*****-*****-*****-3R2BW55277-OEM-2111907-001032S-1-5-21-1087710066-1912864936-3727745746System ManufacturerProduct NamePhoenix Technologies, LTD6.00 PG20030318000000.000000+000EMACHINESF5F33B570184204B04090409Pacific Standard Time(GMT-08:00)02eMachinesT2482 114

Licensing Data–>
N/A

HWID Data–>
N/A

OEM Activation 1.0 Data–>
BIOS string matches: yes
Marker string from BIOS: 1D4E0:emachines inc|1D4E0:Gateway, Inc
Marker string from OEMBIOS.DAT: EMACHINES

OEM Activation 2.0 Data–>
N/A

here is new hijack file i just upgraded to windows xp pro help me find the right way to remove any virus or any bad files on my hijack thanks. inLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:26:14 PM, on 1/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1232619122890
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1232648794984
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

–
End of file - 4406 bytes
hello

Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2 X86-based PC ( Uniprocessor Free : AMD Athlon™ XP 2400+ ) BIOS : Phoenix - AwardBIOS v6.00PG USER : Cristina ( Administrator ) BOOT : Normal boot Antivirus : avast! antivirus 4.8.1296 [VPS 090123-0] 4.8.1296 (Activated) A:\ (USB) C:\ (Local Disk) - NTFS - Total:74 Go (Free:67 Go) D:\ (CD or DVD) E:\ (CD or DVD) Fri 01/23/2009|12:04 ———————-\\ Search.. No infections found ! (second file) 1 - "C:\Rooter$\Rooter_1.txt" - Fri 01/23/2009|12:05 ———————-\\ Scan completed at 12:05 ! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\*PNP0501 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ACPI_HAL HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ftdisk HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AAVMKER4 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AFD HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALG HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_APPMGMT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASCTRM HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASWMON2 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASWRDR HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASWSP HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASWTDI HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASWUPDSV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AUDIOSRV HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_ANTIVIRUS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_MAIL_SCANNER HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_AVAST!_WEB_SCANNER HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BEEP HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BITS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BROWSER HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CDFS HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CDUDF_XP I got the first file on but the second one did not come out .. so i hope you can help me. the second file i went to the folder and copy what the folder called (rkeys )is that the right one . what my point is i hope those are the right files … thanks for your time . i look in my temporary files when i check what file s are in there from the internet . it seems i see like a snake kinda file .. is that a worm or a virus….? thank you
hello

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised by a trained Security Analyst

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is Unchecked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
here it is —- System - GMER 1.0.14 —- SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF7180576] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF7180432] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF7180910] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF718000A] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF718050C] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF717FF4A] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF717FFAE] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF718062C] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF71805EC] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF718076C] —- User IAT/EAT - GMER 1.0.14 —- IAT C:\WINDOWS\system32\services.exe[576] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00370002 IAT C:\WINDOWS\system32\services.exe[576] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00370000 —- Devices - GMER 1.0.14 —- AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software) AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) —- Disk sectors - GMER 1.0.14 —- Disk \Device\Harddisk0\DR0 sector 60: copy of MBR —- EOF - GMER 1.0.14 —-
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Malwarebytes' Anti-Malware 1.33 Database version: 1654 Windows 5.1.2600 Service Pack 2 1/23/2009 11:15:35 PM mbam-log-2009-01-23 (23-15-35).txt Scan type: Quick Scan Objects scanned: 50029 Time elapsed: 3 minute(s), 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Saturday, January 24, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Saturday, January 24, 2009 16:35:23 Records in database: 1699477 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Files scanned: 35189 Threat name: 53 Infected objects: 75 Suspicious objects: 0 Duration of the scan: 01:15:46 File name / Threat name / Threats count C:\Program Files\Common Files\CMEII\CMEIIAPI.dll Infected: not-a-virus:AdWare.Win32.Gator.6051 1 C:\Program Files\Common Files\CMEII\GAppMgr.dll Infected: not-a-virus:AdWare.Win32.Gator.6051 1 C:\Program Files\Common Files\CMEII\GController.dll Infected: not-a-virus:AdWare.Win32.Gator.6051 1 C:\Program Files\Common Files\CMEII\GDwldEng.dll Infected: not-a-virus:AdWare.Win32.Gator.3124 1 C:\Program Files\Common Files\CMEII\GIocl.dll Infected: not-a-virus:AdWare.Win32.Gator.6051 1 C:\Program Files\Common Files\CMEII\GIoclClient.dll Infected: not-a-virus:AdWare.Win32.Gator.6051 1 C:\Program Files\Common Files\CMEII\GMTProxy.dll Infected: not-a-virus:AdWare.Win32.Gator.6051 1 C:\Program Files\Common Files\CMEII\GObjs.dll Infected: not-a-virus:AdWare.Win32.Gator.6051 1 C:\Program Files\Common Files\CMEII\GStore.dll Infected: not-a-virus:AdWare.Win32.Gator.6051 1 C:\Program Files\Common Files\CMEII\GStoreServer.dll Infected: not-a-virus:AdWare.Win32.Gator.6051 1 C:\Program Files\Common Files\CMEII\Gtools.dll Infected: not-a-virus:AdWare.Win32.Gator.6051 1 C:\Program Files\Common Files\cprnllec\erdrfrne\pdfjnrjp.exe Infected: not-a-virus:AdWare.Win32.Gator.a 1 C:\Program Files\Common Files\GMT\egIEEngine.dll Infected: not-a-virus:AdWare.Win32.Gator.5017 1 C:\Program Files\Common Files\GMT\GatorRes.dll Infected: not-a-virus:AdWare.Win32.Gator.6041 1 C:\Program Files\Common Files\GMT\GatorStubSetup.exe Infected: not-a-virus:AdWare.Win32.Gator.6034 1 C:\Program Files\Common Files\GMT\gtrawbm.fil Infected: not-a-virus:AdWare.Win32.Gator.a 1 C:\Program Files\Common Files\GMT\GUninstaller.exe Infected: not-a-virus:AdWare.Win32.Gator.6053 1 C:\Program Files\CxtPls\CxtPls.dll Infected: Trojan-Downloader.Win32.Envolo.a 1 C:\Program Files\CxtPls\uninstaller.exe Infected: not-a-virus:AdWare.Win32.Apropos.f 1 C:\Program Files\CxtPls\WinGenerics.dll Infected: not-a-virus:AdWare.Win32.Apropos.f 1 C:\Program Files\INSTAFINK\InstaFinderK_inst.exe Infected: not-a-virus:AdWare.Win32.404Search.h 1 C:\Program Files\Kazaa\TopSearch.dll Infected: not-a-virus:AdWare.Win32.Altnet.d 1 C:\Program Files\SurfSideKick 2\SskCore.dll Infected: not-a-virus:AdWare.Win32.TotalVelocity.ac 1 C:\Program Files\SurfSideKick 2\uA.tmp Infected: not-a-virus:AdWare.Win32.SurfSide.c 1 C:\Program Files\SurfSideKick 2\uB.tmp Infected: not-a-virus:AdWare.Win32.TotalVelocity.aa 1 C:\Program Files\Web_Rebates\WebRebates1.exe Infected: not-a-virus:AdWare.Win32.WebRebates.d 1 C:\Program Files\Windows Media Player\wmplayer.exe.tmp Infected: Trojan-Downloader.Win32.Small.alt 1 C:\Qoobox\Quarantine\C\Program Files\CSBB\CSAOLINST.DLL.vir Infected: not-a-virus:AdWare.Win32.ClearSearch.j 1 C:\Qoobox\Quarantine\C\Program Files\CSBB\CSIEINST.DLL.vir Infected: not-a-virus:AdWare.Win32.ClearSearch.ap 1 C:\Qoobox\Quarantine\C\Program Files\CSBB\CSLDRUPDATER.DLL.vir Infected: not-a-virus:AdWare.Win32.ClearSearch.r 1 C:\Qoobox\Quarantine\C\Program Files\CSBB\CSTMINST.DLL.vir Infected: not-a-virus:AdWare.Win32.ClearSearch.o 1 C:\Qoobox\Quarantine\C\Program Files\CSBB\CSTVINST.DLL.vir Infected: not-a-virus:AdWare.Win32.ClearSearch.a 1 C:\Qoobox\Quarantine\C\Program Files\CSBB\FNuninstaller.EXE.vir Infected: not-a-virus:AdWare.Win32.ClearSearch.o 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\2504041110.exe.vir Infected: not-a-virus:AdWare.Win32.VirtualBouncer.c 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\2504041110.exe.vir Infected: not-a-virus:AdWare.Win32.VirtualBouncer.e 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\banematt.exe.vir Infected: Trojan-Dropper.Win32.SurfSide.a 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\CSV7P070.exe.vir Infected: not-a-virus:AdWare.Win32.IGetNet.c 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\desktrf-162813.exe.vir Infected: not-a-virus:AdWare.Win32.Beginto.b 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\HelperInstaller.exe.vir Infected: Trojan-Dropper.Win32.Delf.z 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\thin-8-1-x-x.exe.vir Infected: not-a-virus:AdWare.Win32.BetterInternet 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\Verti1.exe.vir Infected: Trojan-Downloader.Win32.Envolo.b 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\Verti1.exe.vir Infected: Trojan-Downloader.Win32.Envolo.c 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\WebRebates_Auto_InstallSilent.exe.vir Infected: not-a-virus:AdWare.Win32.WebRebates.g 1 C:\Qoobox\Quarantine\C\WINDOWS\bundles\WebRebates_Auto_InstallSilent.exe.vir Infected: not-a-virus:AdWare.Win32.WebRebates.d 2 C:\Qoobox\Quarantine\C\WINDOWS\bundles\WebRebates_Auto_InstallSilent.exe.vir Infected: not-a-virus:AdWare.Win32.WebRebates.c 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\Cache\cxtpls_loader.exe.vir Infected: not-a-virus:AdWare.Win32.Apropos.b 1 C:\temporary\install201.exe Infected: Trojan.Win32.SecondThought.an 1 C:\WINDOWS\Downloaded Program Files\on-line.exe Infected: Trojan-Dropper.Win32.Small.xu 1 C:\WINDOWS\systb.exe Infected: not-a-virus:AdWare.Win32.ImiBar.d 1 C:\WINDOWS\system32\actsetup.exe Infected: Backdoor.Win32.Lamebot.e 1 C:\WINDOWS\system32\dsktrf.dll Infected: not-a-virus:AdWare.Win32.HotSearchBar.b 1 C:\WINDOWS\system32\IdleUI.dll Infected: Trojan-Spy.Win32.Idly.c 1 C:\WINDOWS\system32\imode.exe Infected: Backdoor.Win32.Lamebot.f 1 C:\WINDOWS\system32\ln_reco.exe Infected: not-a-virus:AdWare.Win32.BetterInternet 1 C:\WINDOWS\system32\lttjgq.exe Infected: Trojan-Downloader.Win32.Agent.ae 1 C:\WINDOWS\system32\msnav32.exe Infected: Trojan-Downloader.Win32.Agent.on 1 C:\WINDOWS\system32\PopOops.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g 1 C:\WINDOWS\system32\PopOops2.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g 1 C:\WINDOWS\system32\randreco.exe Infected: not-a-virus:AdWare.Win32.BetterInternet 1 C:\WINDOWS\system32\saiehook.dll Infected: not-a-virus:AdWare.Win32.180Solutions 1 C:\WINDOWS\system32\stcloader.exe Infected: Trojan.Win32.SecondThought.av 1 C:\WINDOWS\system32\svcqoc.exe Infected: not-a-virus:AdWare.Win32.Adstart.b 1 C:\WINDOWS\system32\svcqod.exe Infected: not-a-virus:AdWare.Win32.Adstart.b 1 C:\WINDOWS\system32\svcqof.exe Infected: not-a-virus:AdWare.Win32.Adstart.d 1 C:\WINDOWS\system32\SWLAD1.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g 1 C:\WINDOWS\system32\SWLAD2.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g 1 C:\WINDOWS\system32\udxregqr.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.b 1 C:\WINDOWS\system32\windhge32.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.h 1 C:\WINDOWS\system32\windhginst3.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.b 1 C:\WINDOWS\system32\windhgk32.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.a 1 C:\WINDOWS\system32\winonb32(2).dll Infected: Packed.Win32.Klone.g 1 C:\WINDOWS\system32\winupdtl.exe Infected: Trojan.Win32.SecondThought.bd 1 C:\WINDOWS\system32\winwim32(2).dll Infected: Packed.Win32.Klone.g 1 C:\WINDOWS\wupdt.exe Infected: Trojan-Downloader.Win32.Intexp.b 1 The selected area was scanned. i need to get rid of this it looks bad … please help thanks i do not know how to do it
hello

Please download the OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\Program Files\Common Files\CMEII\CMEIIAPI.dll
    C:\Program Files\Common Files\CMEII\GAppMgr.dll
    C:\Program Files\Common Files\CMEII\GController.dll
    C:\Program Files\Common Files\CMEII\GDwldEng.dll
    C:\Program Files\Common Files\CMEII\GIocl.dll
    C:\Program Files\Common Files\CMEII\GIoclClient.dll
    C:\Program Files\Common Files\CMEII\GMTProxy.dll
    C:\Program Files\Common Files\CMEII\GObjs.dll
    C:\Program Files\Common Files\CMEII\GStore.dll
    C:\Program Files\Common Files\CMEII\GStoreServer.dll
    C:\Program Files\Common Files\CMEII\Gtools.dll
    C:\Program Files\Common Files\cprnllec\erdrfrne\pdfjnrjp.exe
    C:\Program Files\Common Files\GMT\egIEEngine.dll
    C:\Program Files\Common Files\GMT\GatorRes.dll
    C:\Program Files\Common Files\GMT\GatorStubSetup.exe
    C:\Program Files\Common Files\GMT\gtrawbm.fil
    C:\Program Files\Common Files\GMT\GUninstaller.exe
    C:\Program Files\CxtPls\CxtPls.dll
    C:\Program Files\CxtPls\uninstaller.exe
    C:\Program Files\CxtPls\WinGenerics.dll
    C:\Program Files\INSTAFINK\InstaFinderK_inst.exe
    C:\Program Files\Kazaa\TopSearch.dll
    C:\Program Files\SurfSideKick 2\SskCore.dll
    C:\Program Files\SurfSideKick 2\uA.tmp
    C:\Program Files\SurfSideKick 2\uB.tmp
    C:\Program Files\Web_Rebates\WebRebates1.exe
    C:\Program Files\Windows Media Player\wmplayer.exe.tmp
    C:\temporary\install201.exe
    C:\WINDOWS\Downloaded Program Files\on-line.exe
    C:\WINDOWS\systb.exe
    C:\WINDOWS\system32\actsetup.exe
    C:\WINDOWS\system32\dsktrf.dll
    C:\WINDOWS\system32\IdleUI.dll
    C:\WINDOWS\system32\imode.exe
    C:\WINDOWS\system32\ln_reco.exe
    C:\WINDOWS\system32\lttjgq.exe
    C:\WINDOWS\system32\msnav32.exe
    C:\WINDOWS\system32\PopOops.dll
    C:\WINDOWS\system32\PopOops2.dll
    C:\WINDOWS\system32\randreco.exe
    C:\WINDOWS\system32\saiehook.dll
    C:\WINDOWS\system32\stcloader.exe
    C:\WINDOWS\system32\svcqoc.exe
    C:\WINDOWS\system32\svcqod.exe
    C:\WINDOWS\system32\svcqof.exe
    C:\WINDOWS\system32\SWLAD1.dll
    C:\WINDOWS\system32\SWLAD2.dll
    C:\WINDOWS\system32\udxregqr.exe
    C:\WINDOWS\system32\windhge32.exe
    C:\WINDOWS\system32\windhginst3.exe
    C:\WINDOWS\system32\windhgk32.exe
    C:\WINDOWS\system32\winonb32(2).dll
    C:\WINDOWS\system32\winupdtl.exe
    C:\WINDOWS\system32\winwim32(2).dll
    C:\WINDOWS\wupdt.exe
    
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== File/Folder C:\Program Files\Common Files\CMEII\CMEIIAPI.dll not found. File/Folder C:\Program Files\Common Files\CMEII\GAppMgr.dll not found. File/Folder C:\Program Files\Common Files\CMEII\GController.dll not found. File/Folder C:\Program Files\Common Files\CMEII\GDwldEng.dll not found. File/Folder C:\Program Files\Common Files\CMEII\GIocl.dll not found. File/Folder C:\Program Files\Common Files\CMEII\GIoclClient.dll not found. File/Folder C:\Program Files\Common Files\CMEII\GMTProxy.dll not found. File/Folder C:\Program Files\Common Files\CMEII\GObjs.dll not found. File/Folder C:\Program Files\Common Files\CMEII\GStore.dll not found. File/Folder C:\Program Files\Common Files\CMEII\GStoreServer.dll not found. File/Folder C:\Program Files\Common Files\CMEII\Gtools.dll not found. File/Folder C:\Program Files\Common Files\cprnllec\erdrfrne\pdfjnrjp.exe not found. File/Folder C:\Program Files\Common Files\GMT\egIEEngine.dll not found. DllUnregisterServer procedure not found in C:\Program Files\Common Files\GMT\GatorRes.dll C:\Program Files\Common Files\GMT\GatorRes.dll NOT unregistered. C:\Program Files\Common Files\GMT\GatorRes.dll moved successfully. C:\Program Files\Common Files\GMT\GatorStubSetup.exe moved successfully. C:\Program Files\Common Files\GMT\gtrawbm.fil moved successfully. C:\Program Files\Common Files\GMT\GUninstaller.exe moved successfully. C:\Program Files\CxtPls\CxtPls.dll unregistered successfully. C:\Program Files\CxtPls\CxtPls.dll moved successfully. C:\Program Files\CxtPls\uninstaller.exe moved successfully. LoadLibrary failed for C:\Program Files\CxtPls\WinGenerics.dll C:\Program Files\CxtPls\WinGenerics.dll NOT unregistered. C:\Program Files\CxtPls\WinGenerics.dll moved successfully. C:\Program Files\INSTAFINK\InstaFinderK_inst.exe moved successfully. C:\Program Files\Kazaa\TopSearch.dll unregistered successfully. C:\Program Files\Kazaa\TopSearch.dll moved successfully. DllUnregisterServer procedure not found in C:\Program Files\SurfSideKick 2\SskCore.dll C:\Program Files\SurfSideKick 2\SskCore.dll NOT unregistered. C:\Program Files\SurfSideKick 2\SskCore.dll moved successfully. C:\Program Files\SurfSideKick 2\uA.tmp moved successfully. C:\Program Files\SurfSideKick 2\uB.tmp moved successfully. C:\Program Files\Web_Rebates\WebRebates1.exe moved successfully. C:\Program Files\Windows Media Player\wmplayer.exe.tmp moved successfully. C:\temporary\install201.exe moved successfully. C:\WINDOWS\Downloaded Program Files\on-line.exe moved successfully. C:\WINDOWS\systb.exe moved successfully. C:\WINDOWS\system32\actsetup.exe moved successfully. C:\WINDOWS\system32\dsktrf.dll unregistered successfully. C:\WINDOWS\system32\dsktrf.dll moved successfully. LoadLibrary failed for C:\WINDOWS\system32\IdleUI.dll C:\WINDOWS\system32\IdleUI.dll NOT unregistered. C:\WINDOWS\system32\IdleUI.dll moved successfully. C:\WINDOWS\system32\imode.exe moved successfully. C:\WINDOWS\system32\ln_reco.exe moved successfully. C:\WINDOWS\system32\lttjgq.exe moved successfully. C:\WINDOWS\system32\msnav32.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\PopOops.dll C:\WINDOWS\system32\PopOops.dll NOT unregistered. C:\WINDOWS\system32\PopOops.dll moved successfully. C:\WINDOWS\system32\PopOops2.dll unregistered successfully. C:\WINDOWS\system32\PopOops2.dll moved successfully. C:\WINDOWS\system32\randreco.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\saiehook.dll C:\WINDOWS\system32\saiehook.dll NOT unregistered. C:\WINDOWS\system32\saiehook.dll moved successfully. C:\WINDOWS\system32\stcloader.exe moved successfully. C:\WINDOWS\system32\svcqoc.exe moved successfully. C:\WINDOWS\system32\svcqod.exe moved successfully. C:\WINDOWS\system32\svcqof.exe moved successfully. C:\WINDOWS\system32\SWLAD1.dll unregistered successfully. C:\WINDOWS\system32\SWLAD1.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\SWLAD2.dll C:\WINDOWS\system32\SWLAD2.dll NOT unregistered. C:\WINDOWS\system32\SWLAD2.dll moved successfully. C:\WINDOWS\system32\udxregqr.exe moved successfully. C:\WINDOWS\system32\windhge32.exe moved successfully. C:\WINDOWS\system32\windhginst3.exe moved successfully. C:\WINDOWS\system32\windhgk32.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\winonb32(2).dll C:\WINDOWS\system32\winonb32(2).dll NOT unregistered. C:\WINDOWS\system32\winonb32(2).dll moved successfully. C:\WINDOWS\system32\winupdtl.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\winwim32(2).dll C:\WINDOWS\system32\winwim32(2).dll NOT unregistered. C:\WINDOWS\system32\winwim32(2).dll moved successfully. C:\WINDOWS\wupdt.exe moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Cristina\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Cristina\LOCALS~1\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Cristina\LOCALS~1\Temp\Cookies\index.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Cristina\LOCALS~1\Temp\~DF6281.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5e4.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_f0.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01262009_094525 HERE IT IS THE LOG FROM OT MOVE IT SORRY I HAD TO STOP MY AVAST SO THIS COULD WORK …IT IS BACK ON NOW. just let me know when i turn all programs when following your instuctions ….thanks merced
hello

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.
Disable any script blocking protection. HOW do i do this ? do that mean turn off my antivirus software or explain i will do the after your reply thanks
DDS (Ver_09-01-19.01) - NTFSx86 Run by [removed] at 10:45:17.35 on Tue 01/27/2009 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.223.76 [GMT -8:00] AV: avast! antivirus 4.8.1296 [VPS 090127-0] *On-access scanning disabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Cristina\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ mStart Page = about:blank uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/ BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: {fdd3b846-8d59-4ffb-8758-209b6ad74acc} - c:\program files\microsoft money\system\mnyviewer.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\80211g~1.lnk - c:\program files\11g usb adapter\Wifiusb.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program files\microsoft money\system\mnyviewer.dll DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232619122890 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1232648794984 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-1-22 111184] R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-22 20560] R4 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-1-22 155160] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-1-22 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-1-22 352920] S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;c:\windows\system32\drivers\rt2500usb.sys [2006-8-29 79616] =============== Created Last 30 ================ 2009-01-26 09:34 –d—– C:\_OTMoveIt 2009-01-26 08:38 –d—– c:\program files\11g USB adapter 2009-01-26 08:35 6,745,428 a——- c:\documents and settings\cristina\a90-211wg-01.zip 2009-01-26 08:34 26,496 ac—— c:\windows\system32\dllcache\usbstor.sys 2009-01-24 13:15 –d—– C:\Projects 2009-01-24 13:15 –d—– C:\Libs 2009-01-23 17:09 250 a——- c:\windows\gmer.ini 2009-01-23 12:04 –d—– C:\Rooter$ 2009-01-22 16:34 –d—– c:\windows\system32\CatRoot_bak 2009-01-22 13:27 221,184 a——- c:\windows\system32\wmpns.dll 2009-01-22 13:25 4,274,816 ——– c:\windows\system32\nv4_disp.dll 2009-01-22 13:23 –d—– c:\windows\ServicePackFiles 2009-01-22 13:20 2,897,920 ——– c:\windows\system32\xpsp2res.dll 2009-01-22 13:19 19,528 a——- c:\windows\002190_.tmp 2009-01-22 13:15 –d—– c:\windows\EHome 2009-01-22 11:29 –d—– c:\program files\Trend Micro 2009-01-22 11:20 –d—– C:\meche fix files 2009-01-22 10:20 –d—– c:\documents and settings\cristina\.housecall6.6 2009-01-22 02:50 1,060,864 a——- c:\windows\system32\MFC71.dll 2009-01-22 02:50 499,712 a——- c:\windows\system32\MSVCP71.dll 2009-01-22 02:50 348,160 a——- c:\windows\system32\MSVCR71.dll 2009-01-22 02:33 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-01-22 02:21 –d—– c:\windows\system32\PreInstall 2009-01-22 02:21 22,752 a——- c:\windows\system32\spupdsvc.exe 2009-01-22 02:21 –d-h— c:\windows\$hf_mig$ 2009-01-22 02:19 –d—– c:\windows\system32\bits 2009-01-22 02:17 351,232 a——- c:\windows\system32\winhttp.dll 2009-01-22 02:17 18,944 a——- c:\windows\system32\qmgrprxy.dll 2009-01-22 02:17 438,784 ——– c:\windows\system32\xpob2res.dll 2009-01-22 02:17 8,192 ——– c:\windows\system32\bitsprx2.dll 2009-01-22 02:17 7,168 ——– c:\windows\system32\bitsprx3.dll 2009-01-22 02:13 31,768 a——- c:\windows\system32\wucltui.dll.mui 2009-01-22 02:13 18,456 a——- c:\windows\system32\wuaueng.dll.mui 2009-01-22 02:13 23,576 a——- c:\windows\system32\wuaucpl.cpl.mui 2009-01-22 02:13 23,576 a——- c:\windows\system32\wuapi.dll.mui 2009-01-22 02:13 –d—– c:\windows\system32\SoftwareDistribution 2009-01-22 02:07 410,984 a——- c:\windows\system32\deploytk.dll 2009-01-22 02:07 73,728 a——- c:\windows\system32\javacpl.cpl 2009-01-22 01:41 a-dshr– C:\cmdcons 2009-01-22 01:39 161,792 a——- c:\windows\SWREG.exe 2009-01-22 01:39 98,816 a——- c:\windows\sed.exe 2009-01-22 01:21 –d—– c:\docume~1\cristina\applic~1\Malwarebytes 2009-01-22 01:21 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-01-22 01:21 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-22 01:21 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-01-22 01:21 –d—– c:\program files\Malwarebytes' Anti-Malware ==================== Find3M ==================== 2009-01-22 13:29 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2004-08-23 03:31 192,512 a——- c:\windows\inf\rmoem.exe 2002-11-14 09:32 55,808 a——- c:\windows\inf\devcon.exe ============= FINISH: 10:45:48.00 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-01-19.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 11/11/2004 6:05:04 PM System Uptime: 1/27/2009 10:41:10 AM (0 hours ago) Motherboard: First International Computer, Inc. | | AM37 Processor: AMD Athlon™ XP 2400+ | Socket A | 1987/133mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 75 GiB total, 67.975 GiB free. D: is CDROM () E: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Realtek RTL8139/810x Family Fast Ethernet NIC Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_90121509&REV_10\3&61AAA01&0&58 Manufacturer: Realtek Name: Realtek RTL8139/810x Family Fast Ethernet NIC PNP Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_90121509&REV_10\3&61AAA01&0&58 Service: rtl8139 ==== System Restore Points =================== RP31: 1/22/2009 1:39:59 AM - ComboFix created restore point RP32: 1/22/2009 2:06:26 AM - Installed Java™ 6 Update 11 RP33: 1/22/2009 2:18:50 AM - Software Distribution Service 3.0 RP34: 1/22/2009 2:19:02 AM - Installed Windows XP KB842773. RP35: 1/22/2009 2:20:12 AM - Installed Windows Installer KB893803v2. RP36: 1/22/2009 2:20:57 AM - Installed Windows XP KB892130. RP37: 1/22/2009 2:21:05 AM - Installed Windows XP KB898461. RP38: 1/22/2009 2:28:03 AM - Removed Norton AntiVirus 2003 RP39: 1/22/2009 12:49:42 PM - install wndows xp sp2 meche RP40: 1/22/2009 1:19:27 PM - Installed Windows XP Service Pack 2. RP41: 1/23/2009 11:00:31 PM - System Checkpoint RP42: 1/26/2009 8:36:59 AM - Installed 802.11g USB adapter RP43: 1/26/2009 8:38:05 AM - Installed 802.11g USB adapter ==== Installed Programs ====================== 56Kbps Internal Modem 802.11g USB adapter Adobe Acrobat 5.0 Adobe Flash Player 10 ActiveX Alt Win America Online AOL Coach Version 1.0(Build:20020823.1) AOL Instant Messenger (SM) avast! Antivirus Context Display Easy CD & DVD Creator 6 HijackThis 2.0.2 InstaFinderK Java™ 6 Update 11 Kazaa 3.0 Lexmark X1100 Series Linksys Wireless-G USB Network Adapter Malwarebytes' Anti-Malware Mavis Beacon Teaches Typing Microsoft Money 2002 Microsoft Money 2002 System Pack Microsoft Office XP Media Content Microsoft Office XP Professional with FrontPage Microsoft Works 6.0 PowerDVD ProSavageDDR and Utilities Realtek AC'97 Audio Realtek RTL8139/810x Fast Ethernet NIC Driver Setup RON Display S3Display S3Gamma2 S3Info2 S3Overlay SereneScreen Aquarium The Print Shop Deluxe III Update for Windows XP (KB898461) URL Display Viewpoint Media Player (Remove Only) WebFldrs XP Winamp (remove only) Windows Backup Utility Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Windows XP Service Pack 2 ==== Event Viewer Messages From Past Week ======== 1/22/2009 12:09:14 PM, error: Service Control Manager [7000] - The wscsvc service failed to start due to the following error: The executable program that this service is configured to run in does not implement the service. 1/22/2009 12:02:24 PM, error: NetBT [4311] - Initialization failed because the driver device could not be created. 1/22/2009 11:08:05 AM, error: Service Control Manager [7016] - The SmartLinkService service has reported an invalid current state 0. 1/22/2009 11:03:45 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 1/22/2009 11:02:31 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AmdK7 aswSP aswTdi Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip 1/22/2009 11:02:31 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/22/2009 11:02:31 AM, error: Service Control Manager [7001] - The Messenger service depends on the NetBIOS Interface service which failed to start because of the following error: A device attached to the system is not functioning. 1/22/2009 11:02:31 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/22/2009 11:02:31 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBT service which failed to start because of the following error: A device attached to the system is not functioning. 1/22/2009 10:58:41 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AmdK7 aswSP Fips 1/22/2009 1:30:14 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: viaagp 1/22/2009 1:30:14 AM, error: Service Control Manager [7022] - The Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS) service hung on starting. 1/22/2009 12:40:09 AM, error: DCOM [10000] - Unable to start a DCOM Server: {9BBCF06C-DCD7-495D-80DF-CDD5399D0FF8}. The error: "%2" Happened while starting this command: C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe -Embedding 1/25/2009 12:48:15 PM, error: PlugPlayManager [11] - The device Root\LEGACY_GMER\0000 disappeared from the system without first being prepared for removal. 1/22/2009 1:39:39 AM, information: Windows File Protection [64004] - The protected system file user32.dll could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.1106 The specific error code is 0x800b0100 [No signature was present in the subject. ]. ==== End Of File ===========================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI