Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

I need help with Virus/Trojan removal badly please help

Options
  • 09-03-2009 2:25pm
    #1
    Closed Accounts Posts: 15


    im doing Crt III Info Tech,, but im not the brightest spark so please bare with me,, i really need some help.

    i dont know how i got it,, but i have a trojan of sorts which has something to do wit the recycler thingy on my usb (thats where it shows up the most)..

    if i goto mycomputer & double click my usb or hard drives it says windows cannot find "RECYCLER-S-2-3-20-100032244-100013959-100022051-1685.com" make sure you type the file correctly etc.. but by clicking folders tab you can still browse the drive..

    i have been using SuperantiSpyware Free for sometime now & usually it worked wonders for me but now it wont update,, i went to the site & downloaded the latest SASDEFINITIONS.EXE, ran it,, yet when it starts back up it says an update is available but it wont start downloading it. it shows what updates are available,, opens the download window but wont download updates.

    a friend of mine used Kaspersy Internet security to remove it successfully however when i install Kaspersky it wont run kaspersky, it installs,, but it wont run, (my friend already had kasperky installed, he also gave me the latest updates downloaded a few hours before the time of this post, but the program wont open so I cant apply them)

    i uninstalled kaspersky & installed bitdefender, it runs but it wont get the latest updates.. it found a lot of trojans after scanning but it didnt sort the recycler problem & it still wont update.. ive since tried reinstalling kasperky again

    i then found this forum & followed instructions in "I think I have a virus" - Please Read & Try BEFORE Posting (Updated 03/02/09)

    i went through all steps.. installed malwarebytes but it will not let me get the latest updates.. it tells me to change firewall settings, i did, but it still wouldnt update

    it wont let me get the latest windows updates,, i think the trojan is blocking its ability to connect to automatic updates... i try to goto various antivirus websites to try other products but im pretty sure the trojan is blocking them.. i had a setup file for XPservice pack 3.. but it failed halfway through & wouldnt add all the updates & said your computer may not run correctly

    below are the log files pasted into this post...

    Malwarebytes' Anti-Malware 1.34
    Database version: 1749
    Windows 5.1.2600 Service Pack 3

    9/03/2009 9:53:56 PM
    mbam-log-2009-03-09 (21-53-55).txt

    Scan type: Full Scan (C:\|G:\|)
    Objects scanned: 134992
    Time elapsed: 1 hour(s), 16 minute(s), 58 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 1
    Registry Keys Infected: 38
    Registry Values Infected: 13
    Registry Data Items Infected: 12
    Folders Infected: 3
    Files Infected: 24

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    C:\Program Files\Mozilla Firefox\components\iamfamous.dll (Trojan.Agent) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{5d2631e5-8696-7543-50b2-f674cd4308eb} (Trojan.Fakealert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7d5dd829-6c90-42c5-b54c-2afa82f988ba} (Rogue.Installer) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{51d81dd5-55b7-497f-95db-d356429bb54e} (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7c109800-a5d5-438f-9640-18d17e168b88} (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929cd6e-2062-44a4-b2c5-2c7e78fbab38} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8a0dcbdb-6e20-489c-9041-c1e8a0352e75} (Adware.Mirar) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{90b5a95a-afd5-4d11-b9bd-a69d53d22226} (Adware.Hotbar) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8109fd3d-d891-4f80-8339-50a4913ace6f} (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Mirar (Adware.Mirar) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\PlayMP3 (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\FBrowsingAdvisor (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Web Application (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explsbsm.exelper Objects (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\freshplay (Trojan.DNSChanger) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{9a9c9b68-f908-4aab-8d0c-10ea8997f37e} (Adware.Mirar) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{51d81dd5-55b7-497f-95db-d356429bb54e} (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\searchassistant (Trojan.Zlob) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\searchassistant (Trojan.Zlob) -> Delete on reboot.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl (Trojan.Zlob) -> Delete on reboot.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -> Delete on reboot.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\searchurl (Trojan.Zlob) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl (Trojan.Zlob) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\searchurl (Trojan.Zlob) -> Delete on reboot.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.

    Folders Infected:
    C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\527631 (Trojan.BHO) -> Quarantined and deleted successfully.

    Files Infected:
    C:\regxpcom.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP625\A0139482.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP625\A0139483.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP625\A0139485.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP625\A0139486.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP626\A0139562.dll (Adware.PlayMp3z) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP628\A0141147.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Temp\xpre.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\Abbr (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\ActivationCode (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\ProductCode (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
    C:\autorun.inf (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\RECYCLER\S-2-3-20-100032244-100013959-100022051-1685.com (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\i7v501gc.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\mCym70iY.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\drivers\senekawxvasnbu.sys (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Program Files\Mozilla Firefox\components\iamfamous.dll (Trojan.Agent) -> Delete on reboot.
    C:\WINDOWS\system32\MSGMAN32.DLL (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gaopdxkdibcepu.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gaopdxruboivxb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\senekadqyouppa.dat (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\senekamcipqute.dat (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\senekauwkioylt.dat (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\senekawwbyqxyl.dat (Trojan.Agent) -> Quarantined and deleted successfully.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:45:22 PM, on 9/03/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\SPRINT~1.0OF\Sprint\CAgent.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\Program Files\SMSC\Seticon.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\D-Link\AirPlus XtremeG DWL-G132\AirPlusCFG.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\INTERN~2\mum.exe
    C:\Program Files\Registry Mechanic\RegMech.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\WINDOWS\system32\wuauclt.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {21816447-6E97-4B5D-80D9-125323131347} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O2 - BHO: (no name) - {EA60B7BE-C6EF-4176-8DD8-BBFC045C75F6} - (no file)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [ABBYY Community Agent] C:\PROGRA~1\SPRINT~1.0OF\Sprint\CAgent.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [SetIcon] C:\Program Files\SMSC\Seticon.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [D-Link AirPlus XtremeG DWL-G132] C:\Program Files\D-Link\AirPlus XtremeG DWL-G132\AirPlusCFG.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-21-57989841-573735546-682003330-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O20 - AppInit_DLLs: cjzmxj.dll C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
    O20 - Winlogon Notify: hgGvuRig - hgGvuRig.dll (file missing)
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 6734 bytes


    Rooter Log..

    Microsoft Windows XP Professional (5.1.2600) Service Pack 3

    A:\ [Removable] (Total:0 Mo/Free:0 Mo)
    C:\ [Fixed] - NTFS - (Total:38162 Mo/Free:2973 Mo)
    D:\ [Removable] (Total:0 Mo/Free:0 Mo)
    E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
    F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
    G:\ [Removable] (Total:1903 Mo/Free:224 Mo)

    Mon 09/03/2009|22:48

    \\ Processes..

    --Locked-- [System Process]
    System
    \SystemRoot\System32\smss.exe
    \??\C:\WINDOWS\system32\csrss.exe
    \??\C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\SPRINT~1.0OF\Sprint\CAgent.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\Program Files\SMSC\Seticon.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\D-Link\AirPlus XtremeG DWL-G132\AirPlusCFG.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\INTERN~2\mum.exe
    C:\Program Files\Registry Mechanic\RegMech.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\cmd.exe
    C:\Rooter$\RK.exe

    \\ Search..

    ==> VUNDO <==

    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\mCym70iY.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe
    Trojan ! .. C:\WINDOWS\system32\i7v501gc.exe

    \\ Tasks

    C:\WINDOWS\tasks\At1.job
    C:\WINDOWS\tasks\At11.job
    C:\WINDOWS\tasks\At12.job
    C:\WINDOWS\tasks\At13.job
    C:\WINDOWS\tasks\At14.job
    C:\WINDOWS\tasks\At15.job
    C:\WINDOWS\tasks\At16.job
    C:\WINDOWS\tasks\At17.job
    C:\WINDOWS\tasks\At18.job
    C:\WINDOWS\tasks\At19.job
    C:\WINDOWS\tasks\At2.job
    C:\WINDOWS\tasks\At21.job
    C:\WINDOWS\tasks\At22.job
    C:\WINDOWS\tasks\At23.job
    C:\WINDOWS\tasks\At24.job
    C:\WINDOWS\tasks\At25.job
    C:\WINDOWS\tasks\At26.job
    C:\WINDOWS\tasks\At27.job
    C:\WINDOWS\tasks\At28.job
    C:\WINDOWS\tasks\At29.job
    C:\WINDOWS\tasks\At3.job
    C:\WINDOWS\tasks\At31.job
    C:\WINDOWS\tasks\At32.job
    C:\WINDOWS\tasks\At33.job
    C:\WINDOWS\tasks\At34.job
    C:\WINDOWS\tasks\At35.job
    C:\WINDOWS\tasks\At36.job
    C:\WINDOWS\tasks\At37.job
    C:\WINDOWS\tasks\At38.job
    C:\WINDOWS\tasks\At39.job
    C:\WINDOWS\tasks\At4.job
    C:\WINDOWS\tasks\At41.job
    C:\WINDOWS\tasks\At42.job
    C:\WINDOWS\tasks\At43.job
    C:\WINDOWS\tasks\At44.job
    C:\WINDOWS\tasks\At45.job
    C:\WINDOWS\tasks\At46.job
    C:\WINDOWS\tasks\At47.job
    C:\WINDOWS\tasks\At48.job
    C:\WINDOWS\tasks\At5.job
    C:\WINDOWS\tasks\At6.job
    C:\WINDOWS\tasks\At7.job
    C:\WINDOWS\tasks\At8.job
    C:\WINDOWS\tasks\At9.job

    \\ ROOTKIT !!



    1 - "C:\Rooter$\Rooter_1.txt" - Mon 09/03/2009|22:49

    \\ Scan completed at 22:49


    i dont know what to do now. can anyone help please?


Comments

  • Registered Users Posts: 28,118 ✭✭✭✭drunkmonkey


    Microsoft do a 90 day free trail of windows live one care, I've found installing it can get rid of most viruses, you can remove it once it's cleaned up the pc....try it and see how it goes....it works 9/10 times.....

    http://onecare.live.com/standard/en-ie/default.htm


  • Closed Accounts Posts: 15 shadow187


    will do,, also just tried to use kaspersky online scanner,,
    failed on updates...


    also,, ive infected my other computer,, but it has no net access,, nor can i give it net access, this pc ive given log files for is not mine,, & im not allowed to connect my one to the net, infected with the same thing.. any ideas what should i do about it??

    Program is starting. Please wait...
    Update source selected: http://www.kaspersky.com
    Downloading file: packages/kos-bin-winnt-redist.jar
    Downloading file: packages/kos-bin-winnt-engine.jar
    Downloading file: packages/kos-bin-winnt.jar
    Downloading file: packages/kos-extras.jar
    Program has started.

    Program database is being updated. Please wait...
    Update source selected: http://downloads2.kaspersky-labs.com/
    Downloading file: index/master.xml.klz
    Failed to connect to update source: downloads2.kaspersky-labs.com
    Update source selected: http://downloads4.kaspersky-labs.com/
    Downloading file: index/master.xml.klz
    Failed to connect to update source: downloads4.kaspersky-labs.com
    Update source selected: ftp://downloads2.kaspersky-labs.com/
    Downloading file: index/master.xml.klz
    Update source selected: ftp://downloads4.kaspersky-labs.com/
    Downloading file: index/master.xml.klz
    Update source selected: ftp://downloads3.kaspersky-labs.com/
    Downloading file: index/master.xml.klz
    Update source selected: ftp://downloads5.kaspersky-labs.com/
    Downloading file: index/master.xml.klz
    Update source selected: http://downloads5.kaspersky-labs.com/
    Downloading file: index/master.xml.klz
    Failed to connect to update source: downloads5.kaspersky-labs.com
    Update source selected: http://downloads3.kaspersky-labs.com/
    Downloading file: index/master.xml.klz
    Failed to connect to update source: downloads3.kaspersky-labs.com
    Update source selected: ftp://downloads1.kaspersky-labs.com/
    Downloading file: index/master.xml.klz
    Update source selected: http://downloads1.kaspersky-labs.com/
    Downloading file: index/master.xml.klz
    Failed to connect to update source: downloads1.kaspersky-labs.com

    Update has failed. Program has failed to start. Close the Kaspersky Online Scanner 7.0 window and open it again to install the program. You must be online to update the Kaspersky Online Scanner 7 database. With the latest database updates, you can find new viruses and other threats. Please go online to use Kaspersky Online Scanner 7. [ERROR: Failed to connect to update source]


  • Registered Users Posts: 28,118 ✭✭✭✭drunkmonkey


    try the windows one, and see how it goes, avast the free edition also has a boot scanner built in, it might cath a few http://www.avast.com/eng/programs.html between the 2 programs you should be able to fix it...start with windows one care then avast..


  • Closed Accounts Posts: 15 shadow187


    ok thanks.. 1/3 of the downloading windowsliveonecare

    will let you know how it goes


  • Closed Accounts Posts: 15 shadow187


    Windows Live OneCare cannot continue

    The Windows Live OneCare service is not working or has stopped. To correct this problem, try restarting your computer. If the problem continues, click below to get help..

    im uninstalling,, but im not going to reinstall if it requires going thru the download process i went thru wen first installing, i dont have the brandwidth...

    now trying avast,, unless someone has a better idea.. someone please help ASAP..
    i wont be able to get online again for a week or so & need to sort this problem out as quickly as possible..

    thanks


  • Advertisement
  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    none of those suggestions will help so don't waste your time

    Please download OTMoveIt3 by OldTimer
    • Save it to your desktop.
    • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
      :Processes
      explorer.exe
      
      :Services
      
      :Reg
      
      :Files
      C:\WINDOWS\system32\i7v501gc.exe 
      C:\WINDOWS\system32\mCym70iY.exe 
      C:\WINDOWS\tasks\At*.job
      
      :Commands
      [purity]
      [emptytemp]
      [start explorer]
      [Reboot]
      
    • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTMoveIt3
    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




    Download ComboFix from one of these locations:

    Link 1
    Link 2


    * IMPORTANT !!! Save ComboFix.exe to your Desktop

    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    RcAuto1.gif


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    whatnext.png


    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.


  • Closed Accounts Posts: 15 shadow187


    problem.. i installed Avg to try my luck while i was waiting for someone to reply with a solution,, i ran OTMoveIt3 & had to reboot, but when i went to run combo fix it said avg was running in background & would cause problems.. it wasnt fully disabling by right clicking it in the notification area so i tried to uninstall avg thinking it would be the best wayto disable it but for some reason it wont uninstall. avg still loads up after logging onto windows but its not running properly now..

    this is the error message when trying to uninstall

    Local machine: installation failed
    Installation:
    Error: Action failed for registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: creating registry key....
    Error 0x80070005

    im guessing ive messed it up,, any ideas how should i proceed??
    should I still run combofix even though it says it may cause damage?
    also i noticed in when you were helping someone else you told them to rename combofix.exe to combo-fix.exe.. it wasnt in your instructions for my problem but im just wondering if you accidently left that part out or if just wasnt supposed to..

    this was the log for OTMoveIt3 before attempting to uninstall avg..

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    File/Folder C:\WINDOWS\system32\i7v501gc.exe not found.
    File/Folder C:\WINDOWS\system32\mCym70iY.exe not found.
    C:\WINDOWS\tasks\At1.job moved successfully.
    C:\WINDOWS\tasks\At10.job moved successfully.
    C:\WINDOWS\tasks\At11.job moved successfully.
    C:\WINDOWS\tasks\At12.job moved successfully.
    C:\WINDOWS\tasks\At13.job moved successfully.
    C:\WINDOWS\tasks\At14.job moved successfully.
    C:\WINDOWS\tasks\At15.job moved successfully.
    C:\WINDOWS\tasks\At16.job moved successfully.
    C:\WINDOWS\tasks\At17.job moved successfully.
    C:\WINDOWS\tasks\At18.job moved successfully.
    C:\WINDOWS\tasks\At19.job moved successfully.
    C:\WINDOWS\tasks\At2.job moved successfully.
    C:\WINDOWS\tasks\At20.job moved successfully.
    C:\WINDOWS\tasks\At21.job moved successfully.
    C:\WINDOWS\tasks\At22.job moved successfully.
    C:\WINDOWS\tasks\At23.job moved successfully.
    C:\WINDOWS\tasks\At24.job moved successfully.
    C:\WINDOWS\tasks\At25.job moved successfully.
    C:\WINDOWS\tasks\At26.job moved successfully.
    C:\WINDOWS\tasks\At27.job moved successfully.
    C:\WINDOWS\tasks\At28.job moved successfully.
    C:\WINDOWS\tasks\At29.job moved successfully.
    C:\WINDOWS\tasks\At3.job moved successfully.
    C:\WINDOWS\tasks\At30.job moved successfully.
    C:\WINDOWS\tasks\At31.job moved successfully.
    C:\WINDOWS\tasks\At32.job moved successfully.
    C:\WINDOWS\tasks\At33.job moved successfully.
    C:\WINDOWS\tasks\At34.job moved successfully.
    C:\WINDOWS\tasks\At35.job moved successfully.
    C:\WINDOWS\tasks\At36.job moved successfully.
    C:\WINDOWS\tasks\At37.job moved successfully.
    C:\WINDOWS\tasks\At38.job moved successfully.
    C:\WINDOWS\tasks\At39.job moved successfully.
    C:\WINDOWS\tasks\At4.job moved successfully.
    C:\WINDOWS\tasks\At40.job moved successfully.
    C:\WINDOWS\tasks\At41.job moved successfully.
    C:\WINDOWS\tasks\At42.job moved successfully.
    C:\WINDOWS\tasks\At43.job moved successfully.
    C:\WINDOWS\tasks\At44.job moved successfully.
    C:\WINDOWS\tasks\At45.job moved successfully.
    C:\WINDOWS\tasks\At46.job moved successfully.
    C:\WINDOWS\tasks\At47.job moved successfully.
    C:\WINDOWS\tasks\At48.job moved successfully.
    C:\WINDOWS\tasks\At5.job moved successfully.
    C:\WINDOWS\tasks\At6.job moved successfully.
    C:\WINDOWS\tasks\At7.job moved successfully.
    C:\WINDOWS\tasks\At8.job moved successfully.
    C:\WINDOWS\tasks\At9.job moved successfully.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\etilqs_ctvkGo0tBpM6GAKQoWG9 scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\etilqs_ctvkGo0tBpM6GAKQoWG9-journal scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\etilqs_iLxjgIyio5FdAz99owV1 scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\~DF30C.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    Windows Temp folder emptied.
    Java cache emptied.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\OfflineCache\index.sqlite scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
    FireFox cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03102009_022544

    Files moved on Reboot...
    File C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\etilqs_ctvkGo0tBpM6GAKQoWG9 not found!
    File C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\etilqs_ctvkGo0tBpM6GAKQoWG9-journal not found!
    File C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\etilqs_iLxjgIyio5FdAz99owV1 not found!
    C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\~DF30C.tmp moved successfully.
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\OfflineCache\index.sqlite moved successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_001_ moved successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_002_ moved successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_003_ moved successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_MAP_ moved successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\urlclassifier3.sqlite moved successfully.

    this is the OTMoveIt3 log from after the avg problem,, i still havnt ran ComboFix.exe yet. waiting for your thoughts on what i should do about avg not uninstalling..

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    File/Folder C:\WINDOWS\system32\i7v501gc.exe not found.
    File/Folder C:\WINDOWS\system32\mCym70iY.exe not found.
    File/Folder C:\WINDOWS\tasks\At*.job not found.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\etilqs_v79LJUlycod99B0z7vwa scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\~DFA850.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    Windows Temp folder emptied.
    Java cache emptied.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\XUL.mfl scheduled to be deleted on reboot.
    FireFox cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03102009_030911

    Files moved on Reboot...
    File C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\etilqs_v79LJUlycod99B0z7vwa not found!
    C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\~DFA850.tmp moved successfully.
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_001_ moved successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_002_ moved successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_003_ moved successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_MAP_ moved successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\urlclassifier3.sqlite moved successfully.
    C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\XUL.mfl moved successfully.


    Ive messed it right up havnt I??


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    We only rename it if the malware is stopping it from running, which I don't think it is in this case


    We will sort out the AVG issue later, go ahead and run ComboFix in the mean time


  • Closed Accounts Posts: 15 shadow187


    I had to run combofix in safemode.. i didnt want to run properly in normal mode.. dunno why,, figured it was the avg issue...

    ComboFix 09-03-06.02 - Resource Worker 2009-03-10 3:40:29.1 - NTFSx86 MINIMAL
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.239.130 [GMT 10:00]
    Running from: c:\documents and settings\Resource Worker\Desktop\ComboFix.exe
    AV: AVG Internet Security *On-access scanning enabled* (Outdated)
    AV: BitDefender Antivirus *On-access scanning disabled* (Outdated)
    FW: AVG Firewall *enabled*
    FW: BitDefender Firewall *disabled*

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .
    ADS - explorer.exe: deleted 5581 bytes in 3 streams.

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\bold.log
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    c:\documents and settings\Resource Worker\err.log
    c:\documents and settings\Resource Worker\ResErrors.log
    C:\install.exe
    c:\program files\Common Files\companion wizard
    c:\program files\Common Files\companion wizard\CompWiz.xml
    c:\program files\install provider
    c:\program files\install provider\InstallProvider.dlldat
    c:\windows\system32\caflegqv.ini
    c:\windows\system32\cjzmxj.dll
    c:\windows\system32\gaopdxcounter
    c:\windows\system32\gaopdxkdibcepu.dll
    c:\windows\system32\GMVxwyay.ini
    c:\windows\system32\GMVxwyay.ini2
    c:\windows\system32\lxqhnewa.dll
    c:\windows\system32\mdm.exe
    c:\windows\system32\setup.ini
    c:\windows\system32\VGNonUvw.ini
    c:\windows\system32\VGNonUvw.ini2
    c:\windows\Tasks\wqfxwjmn.job

    BITS: Possible infected sites

    hxxp://www.criticalsetup.com
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    \Legacy_QUADRASERV.SYS
    \Service_quadraserv.sys


    ((((((((((((((((((((((((( Files Created from 2009-02-09 to 2009-03-09 )))))))))))))))))))))))))))))))
    .

    2009-03-10 02:25 . 2009-03-10 02:25 <DIR> d
    C:\_OTMoveIt
    2009-03-10 01:35 . 2009-03-10 01:35 <DIR> d
    c:\windows\system32\drivers\Avg
    2009-03-10 01:35 . 2009-03-10 01:48 <DIR> d
    c:\documents and settings\Resource Worker\Application Data\AVGTOOLBAR
    2009-03-10 01:35 . 2009-03-10 01:35 98,440 --a
    c:\windows\system32\drivers\avgldx86.sys
    2009-03-10 01:35 . 2009-03-10 01:35 90,632 --a
    c:\windows\system32\drivers\avgtdix.sys
    2009-03-10 01:35 . 2009-03-10 01:35 12,936 --a
    c:\windows\system32\drivers\avgrkx86.sys
    2009-03-10 01:35 . 2009-03-10 01:35 10,520 --a
    c:\windows\system32\avgrsstx.dll
    2009-03-10 01:33 . 2009-03-10 01:33 <DIR> d
    c:\program files\AVG
    2009-03-10 01:33 . 2009-03-10 02:00 <DIR> d
    c:\documents and settings\All Users\Application Data\avg8
    2009-03-10 01:33 . 2009-03-10 01:33 50,968 --a
    c:\windows\system32\avgfwdx.dll
    2009-03-10 01:33 . 2009-03-10 01:33 29,208 --a
    c:\windows\system32\drivers\avgfwdx.sys
    2009-03-10 00:19 . 2009-03-10 01:02 <DIR> d----c--- c:\windows\system32\DRVSTORE
    2009-03-09 22:48 . 2009-03-09 22:49 <DIR> d
    C:\Rooter$
    2009-03-09 22:19 . 2009-03-09 22:19 <DIR> d
    c:\program files\Trend Micro
    2009-03-09 20:31 . 2009-03-09 20:31 <DIR> d
    c:\documents and settings\Resource Worker\Application Data\Malwarebytes
    2009-03-09 20:31 . 2009-03-09 20:31 <DIR> d
    c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-03-09 20:17 . 2009-03-09 20:18 <DIR> d
    C:\9-03-2009
    2009-03-09 20:16 . 2009-03-09 20:17 <DIR> d
    c:\program files\ERUNT
    2009-03-08 12:00 . 2006-12-29 00:31 19,569 --a
    c:\windows\000001_.tmp
    2009-03-08 11:53 . 2009-03-08 11:53 <DIR> d
    c:\windows\system32\CatRoot_bak
    2009-03-07 22:48 . 2009-03-09 22:04 <DIR> d
    c:\program files\SUPERAntiSpyware
    2009-03-07 17:33 . 2009-03-07 17:33 <DIR> d
    c:\windows\system32\logs
    2009-03-07 17:08 . 2009-03-07 20:29 <DIR> d
    c:\program files\Common Files\BitDefender
    2009-03-07 15:30 . 2009-03-07 15:30 <DIR> d
    c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
    2009-03-04 20:33 . 2009-03-07 23:36 75,264 --a
    c:\windows\system32\drivers\quadraserv.sys
    2009-03-04 18:56 . 2009-03-10 02:33 <DIR> d
    C:\! Completed Downloads (utorrent)
    2009-02-19 20:12 . 2009-02-19 20:12 <DIR> d
    c:\program files\Yahoo!

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-09 17:55
    d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2009-03-09 16:33
    d
    w c:\documents and settings\Resource Worker\Application Data\uTorrent
    2009-03-07 12:48
    d
    w c:\documents and settings\Resource Worker\Application Data\SUPERAntiSpyware.com
    2009-03-07 12:17
    d
    w c:\program files\Common Files\Wise Installation Wizard
    2009-03-04 11:18
    d
    w c:\program files\Free FLV Converter
    2009-02-20 01:42 278,528 ----a-w c:\windows\system32\TubeFinder.exe
    2009-02-19 10:12
    d
    w c:\documents and settings\All Users\Application Data\yahoo!
    2009-02-12 11:47
    d
    w c:\documents and settings\All Users\Application Data\McAfee
    2009-02-12 11:42
    d
    w c:\documents and settings\All Users\Application Data\SiteAdvisor
    2009-01-31 01:40
    d--h--w c:\program files\InstallShield Installation Information
    2009-01-29 06:56
    d
    w c:\documents and settings\Resource Worker\Application Data\EmailNotifier
    2009-01-29 06:55
    d
    w c:\documents and settings\All Users\Application Data\Megaupload
    2009-01-29 06:55
    d
    w c:\documents and settings\All Users\Application Data\EmailNotifier
    2009-01-23 14:00
    d
    w c:\documents and settings\Resource Worker\Application Data\Internode
    2009-01-23 09:35
    d
    w c:\program files\Internode
    2009-01-20 12:51 1,033,728 ----a-w c:\windows\explorer.exe
    1998-12-09 02:53 99,840 ----a-w c:\program files\Common Files\IRAABOUT.DLL
    1998-12-09 02:53 70,144 ----a-w c:\program files\Common Files\IRAMDMTR.DLL
    1998-12-09 02:53 48,640 ----a-w c:\program files\Common Files\IRALPTTR.DLL
    1998-12-09 02:53 31,744 ----a-w c:\program files\Common Files\IRAWEBTR.DLL
    1998-12-09 02:53 186,368 ----a-w c:\program files\Common Files\IRAREG.DLL
    1998-12-09 02:53 17,920 ----a-w c:\program files\Common Files\IRASRIAL.DLL
    2008-10-04 08:23 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008100420081005\index.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-15 68856]
    "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "InternodeUsage"="c:\progra~1\INTERN~2\mum.exe" [2008-11-30 1340416]
    "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-04 4363504]
    "RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ABBYY Community Agent"="c:\progra~1\SPRINT~1.0OF\Sprint\CAgent.exe" [2001-02-01 241664]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
    "SetIcon"="c:\program files\SMSC\Seticon.exe" [2003-07-29 40960]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "D-Link AirPlus XtremeG DWL-G132"="c:\program files\D-Link\AirPlus XtremeG DWL-G132\AirPlusCFG.exe" [2007-11-12 1327104]
    "ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-10 1235736]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\Resource Worker\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=cjzmxj.dll avgrsstx.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Picture Transfer Software.lnk]
    backup=c:\windows\pss\KODAK Picture Transfer Software.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
    backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
    backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ulead Photo Express 3.0 SE Calendar Checker.lnk]
    backup=c:\windows\pss\Ulead Photo Express 3.0 SE Calendar Checker.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
    NvQTwk [X]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
    --a
    2008-04-14 10:12 15360 c:\windows\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    --a
    2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nForce APU1 Utilities]
    -ra
    2002-06-18 14:25 45056 c:\windows\system32\NVATray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
    -ra
    2002-05-24 12:42 372736 c:\windows\system32\nwiz.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "NVSvc"=2 (0x2)
    "ptssvc"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\WINDOWS\\system32\\sessmgr.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Microsoft Office\\Office\\1033\\WFXMSRVR.EXE"=
    "%windir%\\explorer.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

    R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-03-10 12936]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-03-10 98440]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-03-10 90632]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-09-03 8944]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-09-03 55024]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-10 231704]
    R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [2009-03-10 1212184]
    R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2008-06-01 34064]
    R2 WILPAR;Wordcraft Parallel Driver;c:\windows\system32\drivers\WILPAR.SYS [2004-11-24 13504]
    R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2009-03-10 29208]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-09-03 7408]
    S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [2007-03-04 377920]
    S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2004-11-22 20160]
    S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2009-03-10 29208]
    S3 MTK;Media Technology Kernel Driver;c:\windows\system32\Drivers\mtk.sys --> c:\windows\system32\Drivers\mtk.sys [?]
    S4 ptssvc;ptssvc;c:\program files\KODAK\KODAK Picture Transfer Software\PTSsvc.exe [2004-12-16 45056]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00ced8d5-3546-11dd-82b8-00195b799914}]
    \Shell\Auto\command - G:\rox.exe MobileZero.hta
    \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL rox.exe MobileZero.hta
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{21816447-6E97-4B5D-80D9-125323131347} - (no file)
    BHO-{EA60B7BE-C6EF-4176-8DD8-BBFC045C75F6} - (no file)
    WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
    Notify-hgGvuRig - hgGvuRig.dll


    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.google.com.au
    uSearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
    mSearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
    uInternet Connection Wizard,ShellNext = iexplore
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
    FF - ProfilePath - c:\documents and settings\Resource Worker\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\
    FF - prefs.js: browser.search.selectedEngine - qtl
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au
    FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
    FF - prefs.js: network.proxy.type - 4
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll

    ---- FIREFOX POLICIES ----
    FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-10 03:48:39
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Other Running Processes
    .
    c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    c:\progra~1\AVG\AVG8\avgam.exe
    c:\progra~1\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\program files\Internode\mum.exe
    c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
    .
    **************************************************************************
    .
    Completion time: 2009-03-10 4:00:58 - machine was rebooted [Resource Worker]
    ComboFix-quarantined-files.txt 2009-03-09 18:00:47

    Pre-Run: 23,873,126,400 bytes free
    Post-Run: 23,565,975,552 bytes free

    237 --- E O F --- 2009-01-15 09:47:12



    also avg keeps trying to do an automatic scan, i tried to cancel the scan but it wont,,


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    hello

    Please download OTMoveIt3 by OldTimer
    • Save it to your desktop.
    • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
      :Processes
      explorer.exe
      
      :Services
      
      :Reg
      
      :Files
      c:\windows\system32\drivers\quadraserv.sys
      :Commands
      [purity]
      [emptytemp]
      [start explorer]
      [Reboot]
      
    • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTMoveIt3
    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



    Download RootRepeal.zip and unzip it to your Desktop.
    • Double click RootRepeal.exe to start the program
    • Click on the Report tab at the bottom of the program window
    • Click the Scan button
    • In the Select Scan dialog, check:

      • Drivers
      • Files
      • Processes
      • SSDT
      • Stealth Objects
      • Hidden Services
      [*]Click the OK button
      [*]In the next dialog, select all drives showing
      [*]Click OK to start the scan
      Note: The scan can take some time. DO NOT run any other programs while the scan is running
      [*]When the scan is complete, the Save Report button will become available
      [*]Click this and save the report to your Desktop as RootRepeal.txt
      If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.

      To attach a file, do the following:
      • Click Add Reply
      • Under the reply panel is the Attachments Panel
      • Browse for the attachment file you want to upload, then click the green Upload button
      • Once it has uploaded, click the Manage Current Attachments drop down box
      • Click on attach_add.png to insert the attachment into your post


    • Advertisement
    • Closed Accounts Posts: 15 shadow187


      ========== PROCESSES ==========
      Process explorer.exe killed successfully.
      ========== SERVICES/DRIVERS ==========
      ========== REGISTRY ==========
      ========== FILES ==========
      c:\windows\system32\drivers\quadraserv.sys moved successfully.
      ========== COMMANDS ==========
      File delete failed. C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\etilqs_KRQZO0YcWBG03FP3uIeS scheduled to be deleted on reboot.
      File delete failed. C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\~DFEDF8.tmp scheduled to be deleted on reboot.
      User's Temp folder emptied.
      User's Temporary Internet Files folder emptied.
      User's Internet Explorer cache folder emptied.
      Local Service Temp folder emptied.
      File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
      Local Service Temporary Internet Files folder emptied.
      Windows Temp folder emptied.
      Java cache emptied.
      File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\XUL.mfl scheduled to be deleted on reboot.
      FireFox cache emptied.
      Temp folders emptied.
      Explorer started successfully

      OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03102009_051313

      Files moved on Reboot...
      File C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\etilqs_KRQZO0YcWBG03FP3uIeS not found!
      C:\DOCUME~1\RESOUR~1\LOCALS~1\Temp\~DFEDF8.tmp moved successfully.
      File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
      C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_001_ moved successfully.
      C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_002_ moved successfully.
      C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_003_ moved successfully.
      C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_MAP_ moved successfully.
      C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\urlclassifier3.sqlite moved successfully.
      C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\XUL.mfl moved successfully.



      ROOTREPEAL (c) AD, 2007-2008
      ==================================================
      Scan Time: 2009/03/10 05:27
      Program Version: Version 1.2.3.0
      Windows Version: Windows XP SP3
      ==================================================

      Drivers
      Name: dump_atapi.sys
      Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
      Address: 0xF5B3F000 Size: 98304 File Visible: No
      Status: -

      Name: dump_WMILIB.SYS
      Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
      Address: 0xF9DE8000 Size: 8192 File Visible: No
      Status: -

      Name: rootrepeal.sys
      Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
      Address: 0xF4C8B000 Size: 45056 File Visible: No
      Status: -

      Hidden/Locked Files
      Path: C:\hiberfil.sys
      Status: Locked to the Windows API!

      Path: C:\WINDOWS\temp\a8a2b42c-a8b9-4962-8c42-af296bc6be69.tmp
      Status: Visible to the Windows API, but not on disk.

      Path: C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP615\A0135942.exe:log.dump
      Status: Visible to the Windows API, but not on disk.

      Path: C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP616\A0135971.exe:log.dump
      Status: Visible to the Windows API, but not on disk.

      Path: C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP616\A0136030.exe:log.dump
      Status: Visible to the Windows API, but not on disk.

      Path: C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP616\A0136085.exe:log.dump
      Status: Visible to the Windows API, but not on disk.

      Path: C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP616\A0136164.exe:log.dump
      Status: Visible to the Windows API, but not on disk.

      Path: C:\System Volume Information\_restore{710F2722-40B9-470F-8D92-E6DCF4D1002A}\RP617\A0136204.exe:log.dump
      Status: Visible to the Windows API, but not on disk.

      Path: C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\urlclassifier3.sqlite
      Status: Size mismatch (API: 7618560, Raw: 4825088)

      Path: C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\_CACHE_001_
      Status: Size mismatch (API: 90107, Raw: 88496)

      Path: C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\09BE45DDd01
      Status: Visible to the Windows API, but not on disk.

      Path: C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\147D0E40d01
      Status: Visible to the Windows API, but not on disk.

      Path: C:\Documents and Settings\Resource Worker\Local Settings\Application Data\Mozilla\Firefox\Profiles\y7c76lao.default\Cache\C19F9CD6d01
      Status: Visible to the Windows API, but not on disk.

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\Administration\Newsletter\Sept 05\In the past month we have been subjected to a barrage of housing news beginning with the changes in Public Housing in NSW.doc
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\Archive\Archive File 10 Jan 05\archive organisations & Communities\Viability Project - REACH\A BRIEF HISTORY OF ROCKHAMPTON COMMUNITY HOUSING PROJECT TO 10-11-01.doc
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\Archive\Archive File 10 Jan 05\archive organisations & Communities\Viability Project - REACH\TO ROCKHAMPTON AND ENVIRONS HOUSING VIABILITY PROJECT WORKIN.doc
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Billion dollar expansion for Moura mine_ 28-01-2005_ ABC News Online_files\news_bulletin_real_bband.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Billion dollar expansion for Moura mine_ 28-01-2005_ ABC News Online_files\news_bulletin_real_dial.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Billion dollar expansion for Moura mine_ 28-01-2005_ ABC News Online_files\news_bulletin_win_bband.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Billion dollar expansion for Moura mine_ 28-01-2005_ ABC News Online_files\news_bulletin_win_dial.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Coastal councils seek sea change 'burden' funds » ABC Central QLD » Local News_files\abcbanner_local.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Coastal councils seek sea change 'burden' funds » ABC Central QLD » Local News_files\bannercurve.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Coastal councils seek sea change 'burden' funds » ABC Central QLD » Local News_files\cloud_increasing_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Coastal councils seek sea change 'burden' funds » ABC Central QLD » Local News_files\gn02logo_nologo.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Coastal councils seek sea change 'burden' funds » ABC Central QLD » Local News_files\localstyle.css
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Coastal councils seek sea change 'burden' funds » ABC Central QLD » Local News_files\mostly_cloudy_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Coastal councils seek sea change 'burden' funds » ABC Central QLD » Local News_files\possible_thunderstorm_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Coastal councils seek sea change 'burden' funds » ABC Central QLD » Local News_files\regionstyle.css
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\abcbanner_local.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\bannercurve.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\bar020823.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\cloud_increasing_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\gn02links.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\gn02logo_nologo.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\localpic1.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\localpic2.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\localstyle.css
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\mostly_cloudy_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\possible_thunderstorm_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\CQ pipeline expected to boost electricity supply » ABC Central QLD » Local News_files\regionstyle.css
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Govt promises coal infrastructure boost_ 31-01-2005_ ABC News Online_files\news_bulletin_real_bband.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Govt promises coal infrastructure boost_ 31-01-2005_ ABC News Online_files\news_bulletin_real_dial.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Govt promises coal infrastructure boost_ 31-01-2005_ ABC News Online_files\news_bulletin_win_bband.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Govt promises coal infrastructure boost_ 31-01-2005_ ABC News Online_files\news_bulletin_win_dial.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Mayor defends Capricorn Coast future » ABC Central QLD » Local News_files\possible_thunderstorm_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\agencyname.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\banner.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\ChristineDonaldson.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\custom.css
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\famcustom.css
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\forms.css
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\IanMcKeague.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\MartinPentecost.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\MelindaKnox.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\MelissaMinter.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\MichaelWhite.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\primarynav.js
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\qglayout.css
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\qglogo.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\RickBichse.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\RobynGreen.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\spacer.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\SusanGlasson.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Ministerial Regional Community Forums Forum members Fitzroy-Central West Queensland_files\TamaraFreeman.jpg
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Rail proposal boost for coal industry » ABC Central QLD » Local News_files\possible_thunderstorm_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Real estate\Real Estate, Property, Land and Homes for Sale, lease and rent - realestate_com_au_files
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\1pix.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\abcbanner_local.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\abc_logo.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\bannercurve.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\bar020823.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\cloud_increasing_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\email.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\FFFFFF.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\gn02links.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\gn02logo_nologo.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\localpic1.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\localpic2.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\localstyle.css
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\mostly_cloudy_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\possible_thunderstorm_sm.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\print.gif
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\regionstyle.css
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Steady number of sales for Rockhampton, research shows » ABC Central QLD » Local News_files\scripts.js
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\The Courier-Mail Infrastructure boom [27jan05]_files\site=finance&section=homepage&adsize=300x250&pagepos=1
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\The Courier-Mail Infrastructure boom [27jan05]_files\site=thecouriermail&section=business&adsize=468x60&pagepos=1
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\The Courier-Mail New mine helps town shrug off tragic past [29jan05]_files\ninnbarthecouriermail.js
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Townsville Bulletin Real estate stays strong [ 25jan05 ]_files\site=townsville&section=news&adsize=468x60&pagepos=1.htm
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Rocky & Environs\Rocky affordable housing special interest group\Butterfly Housing Assn - Low Income Home Ownership Project1.pdf
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Rocky & Environs\Rocky affordable housing special interest group\FW Cluster Special Interest Group Objectives Outcomes.htm
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Rocky & Environs\Rocky affordable housing special interest group\MEETING DOCUMENTATION Affordable Housing Meeting 100305.htm
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Rocky & Environs\Rocky affordable housing special interest group\Feasibility study into affordable housing trust letter1.doc
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Rocky & Environs\Rocky affordable housing special interest group\RE Affordable Housing Report for today's meeting (attempt 2).htm
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Rocky & Environs\Rocky affordable housing special interest group\URGENT TODAY'S MEETING POSTPONED - AFFORDABLE HOUSING MEETING.htm
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\Regional CH Forums\Forum Oct 04 Emerald\Presentations & info for Final Report\REGIONAL STRUCTURES TO SUPPORT SOLUTIONS AND MEET REGIONAL CHALLENGES joined.doc
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Real estate\Real Estate Australia - Property for sale lease and rent on-line Australia wide2_files\102117~1.JPG
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Real estate\Real Estate Australia - Property for sale lease and rent on-line Australia wide2_files\102117~2.JPG
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Real estate\Real Estate Australia - Property for sale lease and rent on-line Australia wide2_files\102140~1.JPG
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Real estate\Real Estate Australia - Property for sale lease and rent on-line Australia wide2_files\102140~2.JPG
      Status: Locked to the Windows API!

      Path: C:\Documents and Settings\Resource Worker\My Documents\Administration\CHRW\Resource Worker\My Documents\CHRW\CH Providers & Communities CQ\Regional Information\Real estate\Real Estate Australia - Property for sale lease and rent on-line Australia wide2_files\102149~1.JPG
      StatuSSDT
      #: 257 Function Name: NtTerminateProcess
      Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xf5edbf20

      figured i would just post it because it only seemed as long as some of the first logs/reports i posted.. hope its alright


    • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


      looking good

      Please download ATF Cleaner by Atribune.
        Double-click
      ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.
      If you use Firefox browser
        Click
      Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
      If you use Opera browser
        Click
      Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
      Click Exit on the Main menu to close the program.




      Please download Malwarebytes' Anti-Malware from Here or Here

      Double Click mbam-setup.exe to install the application.
      • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
      • If an update is found, it will download and install the latest version.
      • Once the program has loaded, select "Perform Quick Scan", then click Scan.
      • The scan may take some time to finish,so please be patient.
      • When the scan is complete, click OK, then Show Results to view the results.
      • Make sure that everything is checked, and click Remove Selected.
      • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
      • Copy&Paste the entire report in your next reply.
      Extra Note:
      If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






      Go to Kaspersky website and perform an online antivirus scan.
      1. Read through the requirements and privacy statement and click on Accept button.
      2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
      3. When the downloads have finished, click on Settings.
      4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
          Spyware, Adware, Dialers, and other potentially dangerous programs
          Archives
          Mail databases
        [*]Click on My Computer under Scan.
        [*]Once the scan is complete, it will display the results. Click on View Scan Report.
        [*]You will see a list of infected items there. Click on Save Report As....
        [*]Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.


      5. Closed Accounts Posts: 15 shadow187


        first parts done,, malwarebytes updated successfully & scan was completed with nothing found,, but my wireless usb adapter is heating up which im pretty sure i slowing my connection a bit.. been on for nearly 10 hours minus a few short periods..
        6:34am here.. been on since 8pm last night,, 27% complete downloading updates for kaspersky online scanner, will post results when done


        Malwarebytes' Anti-Malware 1.34
        Database version: 1828
        Windows 5.1.2600 Service Pack 3

        10/03/2009 6:16:21 AM
        mbam-log-2009-03-10 (06-16-21).txt

        Scan type: Quick Scan
        Objects scanned: 71177
        Time elapsed: 16 minute(s), 3 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 0
        Registry Values Infected: 0
        Registry Data Items Infected: 0
        Folders Infected: 0
        Files Infected: 0

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        (No malicious items detected)

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        (No malicious items detected)

        Folders Infected:
        (No malicious items detected)

        Files Infected:
        (No malicious items detected)


      6. Closed Accounts Posts: 15 shadow187


        dang.. they've added more definitions.. it started saying the updates were 56673kb (approx.) now it says 83754kb.. it also was saying it was at over 60% now its saying 4%.. it still says its transferred 46129kb.. its taken an hour to get thus far.. guessing its gunna take another hour..

        just curious as to how much more you think needs to be done. we're nearly done right? not rushing you... im just being nagged at to get off the computer.. not so much the computer,, just the net..


      7. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        this is just cleaning left overs, not essential

        post a new HJT log if you want to leave that other step, then we should be done


      8. Closed Accounts Posts: 15 shadow187


        sorry, i passed out for a while,, it finished the update part just after I posted last message, scan has just tick over 3hrs running time,, still at 82%.. 1threat found so far,, cant view any info for it just yet.. im a bit rested up now so i think i might just leave it finish.. should i do a HJT scan again after it finishes & post the log or?

        im guessing its taking so long cuz when i came to this pc avg was running its schedualed scan. i have stopped the scan.. but it still seems to be going extremely slow...


      9. Closed Accounts Posts: 15 shadow187


        dang that took forever...

        KASPERSKY ONLINE SCANNER 7 REPORT
        Tuesday, March 10, 2009
        Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
        Kaspersky Online Scanner 7 version: 7.0.25.0
        Program database last update: Monday, March 09, 2009 20:56:02
        Records in database: 1883538

        Scan settings:
        Scan using the following database: extended
        Scan archives: yes
        Scan mail databases: yes

        Scan area - My Computer:
        A:\
        C:\
        D:\
        E:\
        F:\
        G:\

        Scan statistics:
        Files scanned: 61498
        Threat name: 2
        Infected objects: 2
        Suspicious objects: 0
        Duration of the scan: 07:03:37


        File name / Threat name / Threats count
        C:\mango4\old data\wendy to work on\DIR106763\Outlook.pst Infected: EICAR-Test-File 1
        C:\Qoobox\Quarantine\C\WINDOWS\system32\gaopdxkdibcepu.dll.vir Infected: Rootkit.Win32.TDSS.gxu 1

        The selected area was scanned.

        also,, avg updated again in the background, but it keeps trying to get me to restart.. but i was waiting to hear back to see what to do next cuz kaspersky only scanned it hasnt removed anything yet...


      10. Closed Accounts Posts: 15 shadow187


        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 8:39:52 PM, on 10/03/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16791)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        C:\PROGRA~1\AVG\AVG8\avgfws8.exe
        C:\WINDOWS\system32\svchost.exe
        C:\PROGRA~1\AVG\AVG8\avgam.exe
        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
        C:\PROGRA~1\AVG\AVG8\avgnsx.exe
        C:\PROGRA~1\SPRINT~1.0OF\Sprint\CAgent.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd.exe
        C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
        C:\Program Files\SMSC\Seticon.exe
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\Program Files\D-Link\AirPlus XtremeG DWL-G132\AirPlusCFG.exe
        C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
        C:\PROGRA~1\AVG\AVG8\avgtray.exe
        C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\PROGRA~1\INTERN~2\mum.exe
        C:\Program Files\Registry Mechanic\RegMech.exe
        C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        C:\WINDOWS\system32\taskmgr.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
        O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O4 - HKLM\..\Run: [ABBYY Community Agent] C:\PROGRA~1\SPRINT~1.0OF\Sprint\CAgent.exe
        O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
        O4 - HKLM\..\Run: [SetIcon] C:\Program Files\SMSC\Seticon.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [D-Link AirPlus XtremeG DWL-G132] C:\Program Files\D-Link\AirPlus XtremeG DWL-G132\AirPlusCFG.exe
        O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
        O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
        O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
        O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        O4 - HKUS\S-1-5-21-57989841-573735546-682003330-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O20 - AppInit_DLLs: cjzmxj.dll avgrsstx.dll
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
        O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
        O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
        O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

        --
        End of file - 6843 bytes


      11. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        fix this with HJT

        O20 - AppInit_DLLs: cjzmxj.dll avgrsstx.dll


        reboot and post a new HJT Log


      12. Closed Accounts Posts: 15 shadow187


        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 10:40:52 PM, on 10/03/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16791)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        C:\PROGRA~1\AVG\AVG8\avgfws8.exe
        C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
        C:\WINDOWS\system32\svchost.exe
        C:\PROGRA~1\AVG\AVG8\avgam.exe
        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
        C:\PROGRA~1\AVG\AVG8\avgnsx.exe
        C:\WINDOWS\Explorer.EXE
        C:\PROGRA~1\SPRINT~1.0OF\Sprint\CAgent.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd.exe
        C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
        C:\Program Files\SMSC\Seticon.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\Program Files\D-Link\AirPlus XtremeG DWL-G132\AirPlusCFG.exe
        C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
        C:\PROGRA~1\AVG\AVG8\avgtray.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\PROGRA~1\INTERN~2\mum.exe
        C:\Program Files\Registry Mechanic\RegMech.exe
        C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        C:\WINDOWS\system32\taskmgr.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
        C:\Program Files\Mozilla Firefox\firefox.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
        O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O4 - HKLM\..\Run: [ABBYY Community Agent] C:\PROGRA~1\SPRINT~1.0OF\Sprint\CAgent.exe
        O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
        O4 - HKLM\..\Run: [SetIcon] C:\Program Files\SMSC\Seticon.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [D-Link AirPlus XtremeG DWL-G132] C:\Program Files\D-Link\AirPlus XtremeG DWL-G132\AirPlusCFG.exe
        O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
        O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
        O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
        O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        O4 - HKUS\S-1-5-21-57989841-573735546-682003330-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
        O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
        O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
        O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

        --
        End of file - 6803 bytes


      13. Advertisement
      14. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        your logs are clean

        Follow these steps to uninstall Combofix and tools used in the removal of malware
        • Click START then RUN
        • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
          CF_Cleanup.png




        Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
        • Click the Pt. Restauration button and press OK to the prompts.
        • Click the Corbeille button and press OK to the prompt.
        • Click the Fichiers temp button and press OK to the prompt.
        • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
        • Once it is done click the Suppression button and let it remove anything it finds.
        • Close the program



        Please download JavaRa to your desktop and unzip it to its own folder
        • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
        • Accept any prompts.
        • Open JavaRa.exe again and select Search For Updates.
        • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.




        Below I have included a number of recommendations for how to protect your computer against malware infections.
        • Keep Windows updated by regularly checking their website at :
          http://windowsupdate.microsoft.com/
          This will ensure your computer has always the latest security updates available installed on your computer.

        • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

        • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

        • Make Internet Explorer more secure
          • Click Start > Run
          • Type Inetcpl.cpl & click OK
          • Click on the Security tab
          • Click Reset all zones to default level
          • Make sure the Internet Zone is selected & Click Custom level
          • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
          • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
        • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

        • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

        • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
          secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
          blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
          Here


          If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
          • NoScript - for blocking ads and other potential website attacks
          • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

        • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

        • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

        • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

        • Please read my guide on how to prevent malware and about safe computing here
        Thank you for your patience, and performing all of the procedures requested.


      15. Closed Accounts Posts: 15 shadow187


        thanks a lot,, i really appreciate it.. had to get off the net last night beore you posted back otherwise i would have thanked you sooner..

        if you dont mind, i still have to go thru a similar process with my other computer,, which has no net access (is that going to be a problem performing any steps?) but i wont be able to get around to that one for a little while,, so i'll post the logs required when i can..

        thanks again


      16. Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        sure post this log when you get at it

        Download Rooter.exe to your desktop
        • Then doubleclick it to start the tool
        • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here



        any idea when the net problem started ?


      17. Closed Accounts Posts: 15 shadow187


        it could be put on the net.. jbut its not my internet connection,, i dont pay for it, just allowed to get on the net every so often on the bill payers computer,, which is the computer you just helped me clean up..

        been using firefox for over a year or so.. i rarely use internet explorer,, only when mozilla gives me hassles downloading files from hyperlink style download links.. with firefox you cant right click, save target as.. or save file as (a feature that firefox should add), wit firefox you click it & it usually opens a new tab/window or opened the mp3/video file etc with mediaplayer which im not too fond of.. but i agree,, firefox is definately better..


      Advertisement