INFECTED ... Internet Security 2010 ... of course...lol HELP please

View previous topic View next topic Go down

INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 30th December 2009, 8:13 pm

Ok yes I am one of the many with this nasty disease in my pc.. I can not access TSK Manager in any mode and so far no luck with any malware remover this thing is blocking all. I can delete the Trojons it keeps regenerating at start up but I have had no luck removing it in itself. I do have a few Virus protection programs but they seem to have let it through anyway :sad: I went to Hijackthis and got that and here is the log . I sure hope you can help before I throw this paper weight out the window...lol Thank you so much...




Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 12:57:02 PM, on 12/30/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dldncoms.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\winupdate86.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Ideazon\ZEngine\Zboard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\InternetSecurity2010\IS2010.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - {2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: {4ffb2e62-d813-faba-fbf4-a16f6a265448} - {844562a6-f61a-4fbf-abaf-318d26e2bff4} - (no file)
O2 - BHO: (no name) - {A77D3539-581D-450C-9E44-A84C415A6172} - (no file)
O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - (no file)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: (no name) - {FC719FCA-B254-443E-921E-0CF495DE4639} - (no file)
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe
O4 - HKLM\..\Run: [McAfee Backup] "C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [mikezereh] Rundll32.exe "c:\windows\system32\tadebava.dll",a
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe
O4 - Startup: is-H8Q8V.lnk = C:\Documents and Settings\Vangie\Desktop\Virus Removal Tool\is-H8Q8V\startup.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Search - [You must be registered and logged in to see this link.]
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{7A3F0D92-0D36-45F8-9AD8-B83F444A49BD}: NameServer = 193.104.110.38,4.2.2.1,68.87.85.102 68.87.69.150
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Filter hijack: text/html - {2064ee25-0271-4f2a-9c48-f0f9b9752121} - (no file)
O20 - AppInit_DLLs: c:\windows\system32\tomatofi.dll,yeteyohi.dll c:\windows\system32\tadebava.dll
O21 - SSODL: higonekid - {fadd4f1e-fc9d-4bf5-af7b-d983f79cd01e} - (no file)
O21 - SSODL: ralonawan - {8fe7aabf-e591-42c3-ae4c-ccbc1cea9d2c} - c:\windows\system32\tadebava.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: gahurihor - {fadd4f1e-fc9d-4bf5-af7b-d983f79cd01e} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {8fe7aabf-e591-42c3-ae4c-ccbc1cea9d2c} - c:\windows\system32\tadebava.dll (file missing)
O23 - Service: McAfee Application Installer Cleanup (0244321261416926) (0244321261416926mcinstcleanup) - Unknown owner - C:\DOCUME~1\Vangie\LOCALS~1\Temp\024432~1.EXE (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: dldn_device - - C:\WINDOWS\system32\dldncoms.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)

--
End of file - 11410 bytes

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 30th December 2009, 8:28 pm

Help pritty please =)

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 30th December 2009, 8:28 pm

Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    R3 - URLSearchHook: (no name) - {2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: {4ffb2e62-d813-faba-fbf4-a16f6a265448} - {844562a6-f61a-4fbf-abaf-318d26e2bff4} - (no file)
    O2 - BHO: (no name) - {A77D3539-581D-450C-9E44-A84C415A6172} - (no file)
    O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - (no file)O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
    O3 - Toolbar: (no name) - {FC719FCA-B254-443E-921E-0CF495DE4639} - (no file)
    O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe
    O4 - HKLM\..\Run: [mikezereh] Rundll32.exe "c:\windows\system32\tadebava.dll",a
    O4 - HKCU\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
    O4 - HKCU\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe
    O8 - Extra context menu item: &Search - [You must be registered and logged in to see this link.]
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7A3F0D92-0D36-45F8-9AD8-B83F444A49BD}: NameServer = 193.104.110.38,4.2.2.1,68.87.85.102 68.87.69.150
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O18 - Filter hijack: text/html - {2064ee25-0271-4f2a-9c48-f0f9b9752121} - (no file)
    O20 - AppInit_DLLs: c:\windows\system32\tomatofi.dll,yeteyohi.dll c:\windows\system32\tadebava.dll
    O21 - SSODL: higonekid - {fadd4f1e-fc9d-4bf5-af7b-d983f79cd01e} - (no file)
    O21 - SSODL: ralonawan - {8fe7aabf-e591-42c3-ae4c-ccbc1cea9d2c} - c:\windows\system32\tadebava.dll (file missing)
    O22 - SharedTaskScheduler: gahurihor - {fadd4f1e-fc9d-4bf5-af7b-d983f79cd01e} - (no file)
    O22 - SharedTaskScheduler: tokatiluy - {8fe7aabf-e591-42c3-ae4c-ccbc1cea9d2c} - c:\windows\system32\tadebava.dll (file missing)
    O23 - Service: McAfee Application Installer Cleanup (0244321261416926) (0244321261416926mcinstcleanup) - Unknown owner - C:\DOCUME~1\Vangie\LOCALS~1\Temp\024432~1.EXE (file missing)
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)


  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 30th December 2009, 8:30 pm

I will try but I have downloaded and tried Malwarebytes but it wont let it run.. ok off to try *crosses fingers*

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 30th December 2009, 9:18 pm

ok I am nameing my first child after you ...lol j/k Thank you so much it seems to have worked. I do have two more questions for you though if you dont mind?

1st__ why did you have me check this box was something wrong with my zboard keyboard?
O4 - HKCU\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe

2nd__ What free virus protection program do you recommend because I am not very trusting of McAfee after this little episode..?


And thank you again so very much ! ! ! Hooray!
Dragoness

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 30th December 2009, 10:16 pm

My bad, we'll restore that soon. Please post the MBAM log, I doubt it's gone since vundo is present, and vundo doesn't die that easily.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 31st December 2009, 2:11 am

ok I will right now

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 31st December 2009, 2:16 am

ok wait.... are you talking to me because I dont get the part about restoring that soon, you lost me completely.. but I am following this post with the mbam log but fair warning... It is huge my pc was a massive mess... Yikes

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 31st December 2009, 2:16 am

Malwarebytes' Anti-Malware 1.42
Database version: 3456
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/30/2009 2:02:40 PM
mbam-log-2009-12-30 (14-02-32).txt

Scan type: Quick Scan
Objects scanned: 135682
Time elapsed: 13 minute(s), 20 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 157
Registry Values Infected: 8
Registry Data Items Infected: 12
Folders Infected: 35
Files Infected: 134

Memory Processes Infected:
C:\WINDOWS\system32\winupdate86.exe (Trojan.FakeAlert) -> No action taken.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\main.bho (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\main.bho.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{986a8ac1-ab4d-4f41-9068-4b01c0197867} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{a0e1054b-01ee-4d57-a059-4d99f339709f} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{8e3c68cd-f500-4a2a-8cb9-132bb38c3573} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\IS2010 (Rogue.InternetSecurity2010) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\fias4051 (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\irpinit_dlls (Spyware.Agent.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate86.exe (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.Zango) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security 2010 (Rogue.InternetSecurity2010) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3popularscreensavers (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\funwebproducts (Adware.MyWebSearch) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon86.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\winlogon86.exe) Good: (Userinit.exe) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\db (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\dwld (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\report (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\res2 (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\LocalService\Application Data\twain_32 (Trojan.Zbot) -> No action taken.
C:\Documents and Settings\NetworkService\Application Data\twain_32 (Trojan.Zbot) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\twain_32 (Trojan.Zbot) -> No action taken.
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> No action taken.
C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> No action taken.
C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> No action taken.
C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> No action taken.
C:\Program Files\FunWebProducts\Shared\Cache (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Avatar (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Game (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\icons (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\SrchAstt (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\SrchAstt\1.bin (Adware.MyWebSearch) -> No action taken.
C:\Program Files\ShoppingReport (Adware.ShopperReports) -> No action taken.
C:\Program Files\ShoppingReport\Bin (Adware.ShopperReports) -> No action taken.
C:\Program Files\ShoppingReport\Bin\2.5.0 (Adware.ShopperReports) -> No action taken.
C:\WINDOWS\system32\SystemX86 (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\twain_32 (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\twain32 (Backdoor.Bot) -> No action taken.
C:\Program Files\InternetSecurity2010 (Rogue.InternetSecurity2010) -> No action taken.

Files Infected:
C:\WINDOWS\system32\doheyesi.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\winupdate86.exe (Trojan.FakeAlert) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\Internet Explorer\MSIMG32.dll.vir (Adware.MyWebSearch) -> No action taken.
C:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> No action taken.
C:\WINDOWS\system32\lodayija.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\winhelper86.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\winlogon86.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Vangie\Local Settings\Temporary Internet Files\Content.IE5\5PN02XEI\dfghfghgfj[1].dll (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\Config.xml (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\ShoppingReport\cs\res2\WhiteList.dbs (Adware.ShopperReports) -> No action taken.
C:\Documents and Settings\LocalService\Application Data\twain_32\user.ds (Trojan.Zbot) -> No action taken.
C:\Documents and Settings\NetworkService\Application Data\twain_32\user.ds (Trojan.Zbot) -> No action taken.
C:\Documents and Settings\Nicholas.PAIN\Application Data\twain_32\user.ds (Trojan.Zbot) -> No action taken.
C:\Program Files\FunWebProducts\ScreenSaver\Images\003D9542.urr (Adware.MyWebSearch) -> No action taken.
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html (Adware.MyWebSearch) -> No action taken.
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html (Adware.MyWebSearch) -> No action taken.
C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn-new.html (Adware.MyWebSearch) -> No action taken.
C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn.html (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL.vir (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\mwsoestb.dll.vir (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache\001D9F9E (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache\00C7DBE1.bin (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache\0935142B.bin (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache\09351525.bin (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache\093515F0 (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache\0F4B3778.bin (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache\0F4B3882.bin (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache\0F4B3B60.bin (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache\0F4B3C6A.bin (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Cache\files.ini (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\History\search3 (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\ask_logo.gif (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.gif (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.htm (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\center.htm (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\index.htm (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\mid_dots.gif (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\mws_logo.gif (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\protect.htm (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\shocked.gif (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\stop.gif (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\systray.htm (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\systrayp.htm (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\tp_grad.gif (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Message\COMMON\warn.gif (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL.vir (Adware.MyWebSearch) -> No action taken.
C:\WINDOWS\system32\SystemX86\245.crack.zip (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\245.crack.zip.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\246.keygen.zip (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\246.keygen.zip.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\247.serial.zip (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\247.serial.zip.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\248.setup.zip (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\248.setup.zip.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\249.music.au (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\249.music.au.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\250.music2.au (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\250.music2.au.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\251.music3.au (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\251.music3.au.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\252.music.snd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\SystemX86\252.music.snd.kwd (Worm.Archive) -> No action taken.
C:\WINDOWS\system32\twain_32\user.ds.cla (Backdoor.Bot) -> No action taken.
C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.InternetSecurity2010) -> No action taken.
C:\Documents and Settings\Vangie\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk (Rogue.InternetSecurity2010) -> No action taken.
C:\WINDOWS\system32\drivers\str.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\GroupPolicy000.dat (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\GnuHashes.ini (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\41.exe (Trojan.FakeAlert) -> No action taken.

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 31st December 2009, 4:40 am

ok now I can't run a defrag No way!

ok nvm fixed that prob =)

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 31st December 2009, 4:43 pm

Hello.

  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste BOTH LOGS back here, use more than one post if needed.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 31st December 2009, 11:05 pm

First log

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 11/15/2006 10:16:26 AM
System Uptime: 12/31/2009 9:03:32 AM (7 hours ago)

Motherboard: Dell Inc. | | 0WG864
Processor: Intel(R) Pentium(R) D CPU 2.66GHz | Microprocessor | 2660/533mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 144 GiB total, 92.784 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP835: 12/19/2009 10:04:09 PM - System Checkpoint
RP836: 12/23/2009 9:05:18 AM - System Checkpoint
RP837: 12/24/2009 9:58:29 AM - System Checkpoint
RP838: 12/25/2009 1:25:23 PM - System Checkpoint
RP839: 12/27/2009 6:20:39 AM - System Checkpoint
RP840: 12/27/2009 12:44:04 PM - Installed AVG 9.0
RP841: 12/30/2009 12:44:14 PM - Installed HiJackThis
RP842: 12/30/2009 10:04:42 PM - Removed NetZeroInstallers

==== Installed Programs ======================

3D Groove Playback Engine
924PLC32
ABBYY FineReader 6.0 Sprint
Adobe Flash Player 10 ActiveX
Adobe Reader 7.0.8
Adobe Shockwave Player
Advanced SystemCare 3
AOLIcon
Apple Mobile Device Support
Apple Software Update
AutoUpdate
avast! Antivirus
Bonjour
Conexant D850 56K V.9x DFVc Modem
Corel Paint Shop Pro Photo XI
Curse Client
Dell CinePlayer
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Photo AIO Printer 924
Dell Support 3.2
Dell System Restore
Digital Content Portal
Digital Line Detect
Disney's Toontown Online
DivX Codec
DivX Converter
DivX Player
DivX Plus Web Player
Documentation & Support Launcher
DVD43 v3.9.0
EducateU
ELIcon
ESPNMotion
Games, Music, & Photos Launcher
High Definition Audio Driver Package - KB835221
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Intel(R) Matrix Storage Manager
Intel(R) PRO Network Connections
Internet Service Offers Launcher
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 17
Learn2 Player (Uninstall Only)
Legacy Charting 7.0
LimeWireTurbo
LiveUpdate 3.0 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Malwarebytes' Anti-Malware
McAfee SecurityCenter
MCU
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Digital Image Library 9 - Blocker
Microsoft Digital Image Standard 2006
Microsoft Digital Image Standard 2006 Editor
Microsoft Digital Image Standard 2006 Library
Microsoft Encarta Encyclopedia Standard 2006
Microsoft IntelliPoint 6.01
Microsoft IntelliType Pro 6.01
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works
Microsoft Works Suite 2006 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
Mirar
Modem Helper
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 7 Ultra Edition
NetWaiting
NVIDIA Drivers
NVIDIA nView Desktop Manager
Otto
Pando Media Booster
Qualxserve Service Agreement
Quicken 2007
QuickTime
RealPlayer Basic
SearchAssist
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
SPORE™
Symantec KB-DocID:2003093015493306
System Requirements Lab
TuneXP 1.5
Ulead GIF Animator 5
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
VC80CRTRedist - 8.0.50727.4053
Ventrilo Client
Viewpoint Media Player
Virtools 3D Life Player
VirtuaGirl HD
WebFldrs XP
WildTangent Web Driver
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 8
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
WinRAR archiver
Works Upgrade
World of Warcraft
WoWInterface UI Manager
Yahoo! Messenger
ZEngine

==== Event Viewer Messages From Past Week ========

12/30/2009 2:06:44 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
12/30/2009 12:47:37 PM, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
12/30/2009 11:56:38 AM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/30/2009 10:54:56 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Print Spooler service to connect.
12/30/2009 10:54:56 AM, error: Service Control Manager [7001] - The Fax service depends on the Print Spooler service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
12/30/2009 10:54:56 AM, error: Service Control Manager [7000] - The Print Spooler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
12/27/2009 7:28:15 PM, error: iastor [9] - The device, \Device\Ide\iaStor0, did not respond within the timeout period.
12/27/2009 4:42:48 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi eeCtrl Fips intelppm IPSec is-H8Q8Vdrv mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
12/27/2009 3:58:00 PM, error: Service Control Manager [7000] - The Symantec Core LC service failed to start due to the following error: The system cannot find the file specified.
12/27/2009 12:43:53 PM, error: Service Control Manager [7000] - The avgrkx86.sys service failed to start due to the following error: The parameter is incorrect.
12/27/2009 12:13:48 PM, error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s).
12/27/2009 11:32:49 AM, error: Cdrom [11] - The driver detected a controller error on \Device\CdRom1.
12/27/2009 10:53:27 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
12/27/2009 10:51:36 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McShield with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}
12/27/2009 10:51:36 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNASvc with arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
12/27/2009 10:49:51 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
12/27/2009 10:44:35 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD eeCtrl Fips intelppm IPSec mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
12/27/2009 10:44:35 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
12/27/2009 10:44:35 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/27/2009 10:44:35 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/27/2009 10:44:35 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
12/27/2009 10:44:35 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/27/2009 10:44:35 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/27/2009 10:43:44 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
12/27/2009 10:29:21 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
12/26/2009 2:41:25 PM, error: Print [19] - Sharing printer failed + 1722, Printer Quicken PDF Printer share name Printer.

==== End Of File ===========================

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 31st December 2009, 11:06 pm

2nd log


DDS (Ver_09-12-01.01) - NTFSx86
Run by Vangie at 16:01:53.10 on Thu 12/31/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2494 [GMT -7:00]

AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Protection System *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: avast! antivirus 4.8.1368 [VPS 091231-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dldncoms.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\rundll32.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Documents and Settings\Vangie\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = [You must be registered and logged in to see this link.]
uSearch Page =
uSearch Bar =
uDefault_Page_URL = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultUrl =

[You must be registered and logged in to see this link.]

ft_redir.jhtml&st=sb&searchfor={searchTerms}&gcht=sy
mWindow Title = Windows Internet Explorer provided by Comcast
mSearch Bar = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
mSearchAssistant =
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: {844562a6-f61a-4fbf-abaf-318d26e2bff4}: {4ffb2e62-d813-faba-fbf4-a16f6a265448}
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TB: {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - No File
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {FC719FCA-B254-443E-921E-0CF495DE4639} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup
mRun: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -startup
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [DLCCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCCtime.dll,_RunDLLEntry@16
StartupFolder: c:\docume~1\vangie\startm~1\programs\startup\is-h8q8v.lnk - c:\documents and settings\vangie\desktop\virus removal

tool\is-h8q8v\startup.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
dPolicies-system: DisableTaskMgr = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta

search bar\ENCSBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [You must be registered and logged in to see this link.]
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
LSA: Notification Packages = scecli c:\windows\system32\yonevena.dll c:\windows\system32\roboyove.dll c:\windows\system32\nuzepema.dll

tonokule.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-12-27 114768]
R1 is-H8Q8Vdrv;is-H8Q8Vdrv;c:\windows\system32\drivers\55173996.sys [2009-12-27 148496]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-11-4 214664]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-12-27 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-12-27 138680]
R2 dldn_device;dldn_device;c:\windows\system32\dldncoms.exe -service --> c:\windows\system32\dldncoms.exe -service [?]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-12-21 359952]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-12-21 144704]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-12-27 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-12-27 352920]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-12-21 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-12-21 35272]
S2 0244321261416926mcinstcleanup;McAfee Application Installer Cleanup (0244321261416926);c:\docume~1\vangie\locals~1\temp\024432~1.exe

c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\vangie\locals~1\temp\024432~1.exe

c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
S2 pqtbr;pqtbr;\??\c:\windows\system32\drivers\hrnseqjwstydy.sys --> c:\windows\system32\drivers\hrnseqjwstydy.sys [?]
S3 Alpham;Ideazon Merc Composite Keyboard Driver;c:\windows\system32\drivers\Alpham.sys [2005-12-4 34944]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2009-12-27 30104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2009-12-27 30104]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-12-21 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-12-21 40552]
S3 utqymtez;AVZ Kernel Driver;c:\windows\system32\drivers\utqymtez.sys [2009-12-30 7168]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-12-21 606736]
S4 Symantec Core LC;Symantec Core LC;"c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe" --> c:\program files\common

files\symantec shared\ccpd-lc\symlcsvc.exe [?]

=============== Created Last 30 ================

2009-12-31 04:52:47 0 d-sh--w- C:\found.000
2009-12-30 20:46:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 20:46:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-30 20:46:10 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-30 20:46:09 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-30 19:44:15 0 d-----w- c:\program files\TrendMicro
2009-12-30 17:49:49 7168 ----a-w- c:\windows\system32\drivers\utqymtez.sys
2009-12-27 20:00:14 238172 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-12-27 20:00:14 21272608 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-12-27 20:00:05 148496 ----a-w- c:\windows\system32\drivers\55173996.sys
2009-12-27 19:43:15 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2009-12-27 19:43:15 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2009-12-27 19:43:11 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2009-12-27 19:21:50 0 d-----w- c:\docume~1\vangie\applic~1\AVG8
2009-12-27 18:58:11 1640400 ----a-w- c:\windows\PCTBDCore.dll
2009-12-27 18:52:19 0 d-----w- c:\program files\Spyware Doctor
2009-12-27 18:52:19 0 d-----w- c:\program files\common files\PC Tools
2009-12-27 18:44:41 0 d-----w- c:\docume~1\alluse~1\applic~1\XoftSpySE
2009-12-27 18:02:59 0 d-----w- c:\docume~1\vangie\applic~1\Malwarebytes
2009-12-27 17:15:37 0 ----a-w- c:\windows\system32\14771.exe
2009-12-27 16:55:37 0 ----a-w- c:\windows\system32\21726.exe
2009-12-27 16:35:36 0 ----a-w- c:\windows\system32\5447.exe
2009-12-27 16:15:36 0 ----a-w- c:\windows\system32\19895.exe
2009-12-27 15:55:35 0 ----a-w- c:\windows\system32\19718.exe
2009-12-27 15:35:35 0 ----a-w- c:\windows\system32\18716.exe
2009-12-27 10:55:29 0 ----a-w- c:\windows\system32\16827.exe
2009-12-27 10:35:29 0 ----a-w- c:\windows\system32\23281.exe
2009-12-27 06:27:22 0 ----a-w- c:\windows\system32\17421.exe
2009-12-27 06:07:21 0 ----a-w- c:\windows\system32\12382.exe
2009-12-27 05:47:21 0 ----a-w- c:\windows\system32\292.exe
2009-12-27 05:27:21 0 ----a-w- c:\windows\system32\153.exe
2009-12-27 05:07:20 0 ----a-w- c:\windows\system32\3902.exe
2009-12-27 04:47:20 0 ----a-w- c:\windows\system32\14604.exe
2009-12-27 04:27:19 0 ----a-w- c:\windows\system32\32391.exe
2009-12-27 04:07:19 0 ----a-w- c:\windows\system32\5436.exe
2009-12-27 03:47:18 0 ----a-w- c:\windows\system32\4827.exe
2009-12-27 03:27:18 0 ----a-w- c:\windows\system32\11942.exe
2009-12-27 03:07:15 0 ----a-w- c:\windows\system32\2995.exe
2009-12-27 02:47:15 0 ----a-w- c:\windows\system32\491.exe
2009-12-27 02:27:14 0 ----a-w- c:\windows\system32\9961.exe
2009-12-27 01:27:08 0 ----a-w- c:\windows\system32\28145.exe
2009-12-27 01:07:07 0 ----a-w- c:\windows\system32\5705.exe
2009-12-27 00:47:07 0 ----a-w- c:\windows\system32\24464.exe
2009-12-27 00:27:06 0 ----a-w- c:\windows\system32\26962.exe
2009-12-27 00:07:06 0 ----a-w- c:\windows\system32\29358.exe
2009-12-26 23:47:05 0 ----a-w- c:\windows\system32\11478.exe
2009-12-26 23:27:05 0 ----a-w- c:\windows\system32\15724.exe
2009-12-26 23:07:04 0 ----a-w- c:\windows\system32\19169.exe
2009-12-26 22:47:04 0 ----a-w- c:\windows\system32\26500.exe
2009-12-26 22:27:03 0 ----a-w- c:\windows\system32\6334.exe
2009-12-26 22:07:02 0 ----a-w- c:\windows\system32\18467.exe
2009-12-21 17:39:56 13425 ----a-w- c:\windows\system32\Config.MPF
2009-12-21 17:35:32 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-21 17:35:32 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-12-21 17:35:32 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-21 17:35:30 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-12-21 17:35:08 0 d-----w- c:\program files\common files\McAfee
2009-12-21 17:35:07 0 d-----w- c:\program files\McAfee.com
2009-12-21 17:35:01 0 d-----w- c:\program files\McAfee
2009-12-21 17:32:36 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-12-16 16:51:47 61224 ----a-w- c:\documents and settings\vangie\GoToAssistDownloadHelper.exe

==================== Find3M ====================

2009-12-19 06:26:53 38504 ----a-w- c:\docume~1\vangie\applic~1\wklnhst.dat
2009-11-04 23:54:12 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-28 14:40:47 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 75776 ------w- c:\windows\system32\dllcache\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-21 05:38:36 25088 ------w- c:\windows\system32\dllcache\httpapi.dll
2009-10-20 16:20:16 265728 ------w- c:\windows\system32\dllcache\http.sys
2009-10-13 10:30:16 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-13 10:30:16 270336 ------w- c:\windows\system32\dllcache\oakley.dll
2009-10-12 13:38:19 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:19 149504 ------w- c:\windows\system32\dllcache\rastls.dll
2009-10-12 13:38:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:38:18 79872 ------w- c:\windows\system32\dllcache\raschap.dll
2009-10-11 11:17:27 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-06 20:56:48 4600 --sha-w- c:\windows\system32\KGyGaAvL.sys
2007-07-04 08:09:55 88 --sh--r- c:\windows\system32\385196AA1C.sys
2009-09-26 21:41:39 16384 --sha-w- c:\windows\system32\sonewibu.exe

============= FINISH: 16:03:01.87 ===============

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 31st December 2009, 11:40 pm

Hello.

You are running multiple antivirus', I see from the uninstall list you have AVG installed, along with Mcafee/avast. This is a bad idea as they can conflict and cause more problems. I would recommend that you remove Symantec to avoid conflict and other future problems.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    Advanced SystemCare 3
    J2SE Runtime Environment 5.0 Update 6
    LimeWireTurbo
    LiveUpdate 3.0 (Symantec Corporation)
    LiveUpdate Notice (Symantec Corporation)
    McAfee SecurityCenter
    Mirar
    Viewpoint Media Player

Completely Uninstall AVG software

Download and run avgremover.exe

For 32-Bit, Download: [You must be registered and logged in to see this link.]

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 1st January 2010, 5:51 am

Ok I followed the directions you gave and ran the avgremover then did a search to make sure it was gone and it didnt show up but when I ran the combofix it said avg was still there but there was no way I could see to stop the scan it just gave me a chance to try and remove avg again but I still could find no trace of it anywhere. I also could not remove Mirar I clicked remove it took me to a website that had a place to check to remove it but when I tried the page would just go blank and would go no farther I tried many times with the same result No way! so I am at a loss on both these item.. but the scan completed and will be posted below. Thank you so much for helping me with this mess :smile2:

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 1st January 2010, 5:52 am

ComboFix 09-12-31.07 - Vangie 12/31/2009 22:27:07.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2507 [GMT -7:00]
Running from: c:\documents and settings\Vangie\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1368 [VPS 091231-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Nicholas.PAIN\Application Data\020000005233b575648C.manifest
c:\documents and settings\Nicholas.PAIN\Application Data\020000005233b575648O.manifest
c:\documents and settings\Nicholas.PAIN\Application Data\020000005233b575648P.manifest
c:\documents and settings\Nicholas.PAIN\Application Data\020000005233b575648S.manifest
c:\documents and settings\Vangie\Application Data\020000005233b575648C.manifest
c:\documents and settings\Vangie\Application Data\020000005233b575648O.manifest
c:\documents and settings\Vangie\Application Data\020000005233b575648P.manifest
c:\documents and settings\Vangie\Application Data\020000005233b575648S.manifest
c:\program files\Common Files\Uninstall
c:\program files\Common
c:\recycler\NPROTECT
c:\recycler\NPROTECT\00328122.
c:\recycler\NPROTECT\00328137.
c:\recycler\NPROTECT\00328138.
c:\recycler\NPROTECT\00328153.
c:\recycler\NPROTECT\00328156.
c:\recycler\NPROTECT\00328168.
c:\recycler\NPROTECT\00328171.
c:\recycler\NPROTECT\00328179.
c:\recycler\NPROTECT\00328187.
c:\recycler\NPROTECT\00328221.
c:\recycler\NPROTECT\00328227.
c:\recycler\NPROTECT\00328261.
c:\recycler\NPROTECT\00328262.
c:\recycler\NPROTECT\00328279.
c:\recycler\NPROTECT\00328280.
c:\recycler\NPROTECT\00328289.
c:\recycler\NPROTECT\00328292.
c:\recycler\NPROTECT\00328293.
c:\recycler\NPROTECT\00328301.
c:\recycler\NPROTECT\00328319.
c:\recycler\NPROTECT\00328323.
c:\recycler\NPROTECT\00328467.
c:\recycler\NPROTECT\00328474.
c:\recycler\NPROTECT\00328475.
c:\recycler\NPROTECT\00328476.
c:\recycler\NPROTECT\00328527.
c:\recycler\NPROTECT\00328540.
c:\recycler\NPROTECT\00328541.
c:\recycler\NPROTECT\00328542.
c:\recycler\NPROTECT\00328562.
c:\recycler\NPROTECT\00328565.
c:\recycler\NPROTECT\00328585.
c:\recycler\NPROTECT\00328735.
c:\recycler\NPROTECT\00328802.
c:\recycler\NPROTECT\00328874.
c:\recycler\NPROTECT\00328900.
c:\recycler\NPROTECT\00328901.
c:\recycler\NPROTECT\00328902.
c:\recycler\NPROTECT\00328937.
c:\recycler\NPROTECT\00328938.
c:\recycler\NPROTECT\00328946.
c:\recycler\NPROTECT\00328947.
c:\recycler\NPROTECT\00328992.
c:\recycler\NPROTECT\00328998.
c:\recycler\NPROTECT\00329013.
c:\recycler\NPROTECT\00329034.
c:\recycler\NPROTECT\00329061.
c:\recycler\NPROTECT\00329098.
c:\recycler\NPROTECT\00329099.
c:\recycler\NPROTECT\00329100.
c:\recycler\NPROTECT\00329234.
c:\recycler\NPROTECT\00329275.
c:\recycler\NPROTECT\00329276.
c:\recycler\NPROTECT\00329277.
c:\recycler\NPROTECT\00329283.
c:\recycler\NPROTECT\00329285.
c:\recycler\NPROTECT\00329286.
c:\recycler\NPROTECT\00329310.
c:\recycler\NPROTECT\00329313.
c:\recycler\NPROTECT\00329320.
c:\recycler\NPROTECT\00329354.
c:\recycler\NPROTECT\00329364.
c:\recycler\NPROTECT\00329365.
c:\recycler\NPROTECT\00329366.
c:\recycler\NPROTECT\00329367.
c:\recycler\NPROTECT\00329368.
c:\recycler\NPROTECT\00329369.
c:\recycler\NPROTECT\00329370.
c:\recycler\NPROTECT\00329393.
c:\recycler\NPROTECT\00329402.
c:\recycler\NPROTECT\00329403.
c:\recycler\NPROTECT\00329424.
c:\recycler\NPROTECT\00329429.
c:\recycler\NPROTECT\00329479.
c:\recycler\NPROTECT\00329488.
c:\recycler\NPROTECT\00329502.
c:\recycler\NPROTECT\00329507.
c:\recycler\NPROTECT\00329508.
c:\recycler\NPROTECT\00329514.
c:\recycler\NPROTECT\00329523.
c:\recycler\NPROTECT\00329525.
c:\recycler\NPROTECT\00329542.
c:\recycler\NPROTECT\00329574.
c:\recycler\NPROTECT\00329577.
c:\recycler\NPROTECT\00329578.
c:\recycler\NPROTECT\00429642.
c:\recycler\NPROTECT\00429687.
c:\recycler\NPROTECT\00429832.
c:\recycler\NPROTECT\00430252.
c:\recycler\NPROTECT\00430258.
c:\recycler\NPROTECT\00430261.
c:\recycler\NPROTECT\00438658.
c:\recycler\NPROTECT\00438664.
c:\recycler\NPROTECT\00438698.
c:\recycler\NPROTECT\00438699.
c:\recycler\NPROTECT\00438716.
c:\recycler\NPROTECT\00438717.
c:\recycler\NPROTECT\00438726.
c:\recycler\NPROTECT\00438729.
c:\recycler\NPROTECT\00438730.
c:\recycler\NPROTECT\00438738.
c:\recycler\NPROTECT\00438756.
c:\recycler\NPROTECT\00438760.
c:\recycler\NPROTECT\00438858.
c:\recycler\NPROTECT\00438859.
c:\recycler\NPROTECT\00438860.
c:\recycler\NPROTECT\00438879.
c:\recycler\NPROTECT\00438883.
c:\recycler\NPROTECT\00438884.
c:\recycler\NPROTECT\00438907.
c:\recycler\NPROTECT\00438912.
c:\recycler\NPROTECT\00438955.
c:\recycler\NPROTECT\00438968.
c:\recycler\NPROTECT\00438969.
c:\recycler\NPROTECT\00438980.
c:\recycler\NPROTECT\00438981.
c:\recycler\NPROTECT\00438998.
c:\recycler\NPROTECT\00439002.
c:\recycler\NPROTECT\00439018.
c:\recycler\NPROTECT\00439036.
c:\recycler\NPROTECT\00439126.
c:\recycler\NPROTECT\00439156.
c:\recycler\NPROTECT\00439237.
c:\recycler\NPROTECT\00439238.
c:\recycler\NPROTECT\00439239.
c:\recycler\NPROTECT\00439274.
c:\recycler\NPROTECT\00439275.
c:\recycler\NPROTECT\00439283.
c:\recycler\NPROTECT\00439284.
c:\recycler\NPROTECT\00439329.
c:\recycler\NPROTECT\00439335.
c:\recycler\NPROTECT\00439350.
c:\recycler\NPROTECT\00439371.
c:\recycler\NPROTECT\00439412.
c:\recycler\NPROTECT\00439437.
c:\recycler\NPROTECT\00439438.
c:\recycler\NPROTECT\00439439.
c:\recycler\NPROTECT\00439527.
c:\recycler\NPROTECT\00439528.
c:\recycler\NPROTECT\00439529.
c:\recycler\NPROTECT\00439535.
c:\recycler\NPROTECT\00439537.
c:\recycler\NPROTECT\00439538.
c:\recycler\NPROTECT\00439542.
c:\recycler\NPROTECT\00439545.
c:\recycler\NPROTECT\00439552.
c:\recycler\NPROTECT\00439586.
c:\recycler\NPROTECT\00439595.
c:\recycler\NPROTECT\00439598.
c:\recycler\NPROTECT\00439599.
c:\recycler\NPROTECT\00439600.
c:\recycler\NPROTECT\00439601.
c:\recycler\NPROTECT\00439602.
c:\recycler\NPROTECT\00439603.
c:\recycler\NPROTECT\00439604.
c:\recycler\NPROTECT\00439631.
c:\recycler\NPROTECT\00439632.
c:\recycler\NPROTECT\00439648.
c:\recycler\NPROTECT\00439649.
c:\recycler\NPROTECT\00439667.
c:\recycler\NPROTECT\00439671.
c:\recycler\NPROTECT\00439677.
c:\recycler\NPROTECT\00439719.
c:\recycler\NPROTECT\00439723.
c:\recycler\NPROTECT\00439725.
c:\recycler\NPROTECT\00439730.
c:\recycler\NPROTECT\00439745.
c:\recycler\NPROTECT\00439751.
c:\recycler\NPROTECT\00439752.
c:\recycler\NPROTECT\00439753.
c:\recycler\NPROTECT\00439759.
c:\recycler\NPROTECT\00439769.
c:\recycler\NPROTECT\00439771.
c:\recycler\NPROTECT\00439789.
c:\windows\kb913800.exe
c:\windows\system32\11478.exe
c:\windows\system32\11942.exe
c:\windows\system32\12382.exe
c:\windows\system32\14604.exe
c:\windows\system32\14771.exe
c:\windows\system32\153.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\17421.exe
c:\windows\system32\18467.exe
c:\windows\system32\18716.exe
c:\windows\system32\19169.exe
c:\windows\system32\19718.exe
c:\windows\system32\19895.exe
c:\windows\system32\21726.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\32391.exe
c:\windows\system32\3902.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5436.exe
c:\windows\system32\5447.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
c:\windows\system32\b6UOM.vbs
c:\windows\system32\drivers\ndisrd.sys
c:\windows\system32\inUDJqzTABd5XOM.vbs
c:\windows\system32\ndisapi.dll
c:\windows\system32\SIntf16.dll
c:\windows\Tasks\rzijeckn.job
c:\windows\ynh.dx
C:\xcrashdump.dat

----- BITS: Possible infected sites -----

[You must be registered and logged in to see this link.]
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NDISRD
-------\Service_NDISRD


((((((((((((((((((((((((( Files Created from 2009-12-01 to 2010-01-01 )))))))))))))))))))))))))))))))
.

2009-12-31 04:52 . 2009-12-31 04:52 -------- d-----w- C:\found.000
2009-12-30 20:46 . 2009-12-03 23:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 20:46 . 2009-12-30 20:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-30 20:46 . 2009-12-03 23:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-30 20:46 . 2009-12-30 20:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-30 19:44 . 2009-12-30 19:44 388096 ----a-r- c:\documents and settings\Vangie\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2009-12-30 19:44 . 2009-12-30 19:44 -------- d-----w- c:\program files\TrendMicro
2009-12-30 17:49 . 2009-12-30 17:49 7168 ----a-w- c:\windows\system32\drivers\utqymtez.sys
2009-12-28 05:57 . 2008-04-13 16:44 2560 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2009-12-27 22:15 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-12-27 22:15 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-12-27 22:15 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-12-27 22:15 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-12-27 22:15 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-12-27 22:15 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-12-27 22:15 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-12-27 22:15 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-12-27 22:15 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-12-27 22:15 . 2009-12-27 22:15 -------- d-----w- c:\program files\Alwil Software
2009-12-27 20:00 . 2010-01-01 05:39 26943520 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-12-27 20:00 . 2008-07-08 21:54 148496 ----a-w- c:\windows\system32\drivers\55173996.sys
2009-12-27 19:43 . 2009-12-27 19:43 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-12-27 19:21 . 2009-12-27 19:21 -------- d-----w- c:\documents and settings\Vangie\Application Data\AVG8
2009-12-27 19:05 . 2009-12-27 19:05 -------- d-----w- c:\documents and settings\Vangie\Local Settings\Application Data\Threat Expert
2009-12-27 18:58 . 2009-11-10 17:28 1640400 ----a-w- c:\windows\PCTBDCore.dll
2009-12-27 18:52 . 2009-12-27 22:57 -------- d-----w- c:\program files\Spyware Doctor
2009-12-27 18:52 . 2009-12-27 22:57 -------- d-----w- c:\program files\Common Files\PC Tools
2009-12-27 18:44 . 2009-12-27 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\XoftSpySE
2009-12-27 18:02 . 2009-12-27 18:02 -------- d-----w- c:\documents and settings\Vangie\Application Data\Malwarebytes
2009-12-27 17:43 . 2009-12-27 17:43 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-12-21 17:35 . 2009-11-04 23:54 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-21 17:35 . 2009-11-04 23:54 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-12-21 17:35 . 2009-11-04 23:54 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-21 17:32 . 2009-11-04 23:53 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-12-17 23:54 . 2009-12-17 23:54 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2009-12-17 23:54 . 2009-12-17 23:54 -------- d-sh--w- c:\documents and settings\LocalService\IECompatCache
2009-12-16 16:51 . 2009-12-16 16:51 -------- d-----w- c:\documents and settings\Vangie\Local Settings\Application Data\Citrix
2009-12-16 16:51 . 2009-12-16 16:51 61224 ----a-w- c:\documents and settings\Vangie\GoToAssistDownloadHelper.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-01 05:36 . 2009-12-27 20:00 314636 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-01-01 05:11 . 2009-06-10 16:04 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-01-01 04:58 . 2006-11-15 22:06 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-01 04:58 . 2006-11-15 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-27 19:44 . 2009-03-20 01:32 -------- d-----w- c:\program files\AVG
2009-12-27 19:14 . 2008-03-11 20:03 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-20 05:21 . 2008-02-23 21:26 -------- d-----w- c:\program files\World of Warcraft
2009-12-20 02:44 . 2006-11-15 17:25 -------- d-----w- c:\program files\Dl_cats
2009-12-19 06:26 . 2006-11-15 23:42 38504 ----a-w- c:\documents and settings\Vangie\Application Data\wklnhst.dat
2009-11-22 02:02 . 2007-11-04 01:34 -------- d-----w- c:\program files\DivX
2009-11-22 02:02 . 2009-11-22 02:02 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-11-06 15:20 . 2006-10-20 03:42 -------- d-----w- c:\program files\Java
2009-11-06 15:19 . 2009-11-06 15:19 152576 ----a-w- c:\documents and settings\Vangie\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-04 23:54 . 2009-11-04 23:54 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-29 07:45 . 2005-08-16 09:18 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-24 19:06 . 2009-10-24 19:06 861 ----a-w- c:\documents and settings\Vangie\Application Data\Acreon\WowMatrix\Archives\HealBot\HealBot_Clean_WTF.bat
2009-10-21 05:38 . 2005-08-16 09:18 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2005-08-16 09:18 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 04:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2005-08-16 09:18 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2005-08-16 09:18 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2005-08-16 09:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 11:17 . 2008-11-23 00:22 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-06 20:56 . 2006-11-15 18:23 4600 --sha-w- c:\windows\system32\KGyGaAvL.sys
2007-07-04 08:09 . 2006-11-25 05:08 88 --sh--r- c:\windows\system32\385196AA1C.sys
2009-09-26 21:41 . 2009-09-26 21:41 16384 --sha-w- c:\windows\system32\sonewibu.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 106544]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-28 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-28 13918208]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728]

c:\documents and settings\Vangie\Start Menu\Programs\Startup\
is-H8Q8V.lnk - c:\documents and settings\Vangie\Desktop\Virus Removal Tool\is-H8Q8V\startup.exe [2009-12-27 65536]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeRAM XP
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryCleanFixMFC

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlccmon.exe]
2005-10-21 07:40 430080 ----a-w- c:\program files\Dell Photo AIO Printer 924\dlccmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2006-05-03 11:12 98304 ----a-w- c:\program files\Dell\Media Experience\DMXLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
2006-05-22 21:26 694272 ----a-w- c:\program files\dvd43\DVD43_Tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-09-29 19:01 67584 ----a-w- c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2006-07-06 12:15 151552 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2006-07-07 23:15 600896 ----a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 15:44 249856 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 15:44 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
2006-07-07 23:14 576320 ----a-w- c:\program files\Microsoft IntelliType Pro\itype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 19:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-09-28 00:19 13918208 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-09-28 00:19 86016 ----a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-11-04 15:30 413696 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-07-24 22:20 282624 ----a-w- c:\windows\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tweak UI]
2000-06-18 22:03 106544 ----a-w- c:\windows\system32\TWEAKUI.CPL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2006-10-25 00:10 4662776 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Ideazon\\ZEngine\\Zboard.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\dldncoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldnpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldntime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldnjswx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"57803:TCP"= 57803:TCP:Pando Media Booster
"57803:UDP"= 57803:UDP:Pando Media Booster
"56894:TCP"= 56894:TCP:Pando Media Booster
"56894:UDP"= 56894:UDP:Pando Media Booster

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/15/2006 2:46 PM 642560]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [12/27/2009 3:15 PM 114768]
R1 is-H8Q8Vdrv;is-H8Q8Vdrv;c:\windows\system32\drivers\55173996.sys [12/27/2009 1:00 PM 148496]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/27/2009 3:15 PM 20560]
R2 dldn_device;dldn_device;c:\windows\system32\dldncoms.exe -service --> c:\windows\system32\dldncoms.exe -service [?]
S2 pqtbr;pqtbr;\??\c:\windows\system32\drivers\hrnseqjwstydy.sys --> c:\windows\system32\drivers\hrnseqjwstydy.sys [?]
S3 Alpham;Ideazon Merc Composite Keyboard Driver;c:\windows\system32\drivers\Alpham.sys [12/4/2005 12:55 PM 34944]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\DRIVERS\avgfwdx.sys --> c:\windows\system32\DRIVERS\avgfwdx.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwdx.sys --> c:\windows\system32\DRIVERS\avgfwdx.sys [?]
S3 utqymtez;AVZ Kernel Driver;c:\windows\system32\drivers\utqymtez.sys [12/30/2009 10:49 AM 7168]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultUrl = [You must be registered and logged in to see this link.]
mWindow Title = Windows Internet Explorer provided by Comcast
mSearch Bar = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

BHO-{844562a6-f61a-4fbf-abaf-318d26e2bff4} - (no file)
WebBrowser-{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
WebBrowser-{FC719FCA-B254-443E-921E-0CF495DE4639} - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
MSConfigStartUp-Internet Security 2010 - c:\program files\InternetSecurity2010\IS2010.exe
MSConfigStartUp-NetZero_uoltray - c:\program files\NetZero\exec.exe
MSConfigStartUp-nwiz - nwiz.exe
MSConfigStartUp-spc_w - c:\program files\NZSearch\nzspc.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-12-31 22:38
Windows 5.1.2600 Service Pack 3 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, [You must be registered and logged in to see this link.]

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe >>UNKNOWN [0x8B184E30]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x8b184e30
\Driver\ACPI -> ACPI.sys @ 0xb7e97cb8
\Driver\iaStor -> 0x8b1840e8
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Intel(R) 82562V 10/100 Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xb7c96bb0
PacketIndicateHandler -> NDIS.sys @ 0xb7ca3a21
SendHandler -> NDIS.sys @ 0xb7c8187b
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7a,f7,25,ea,ad,9e,0c,4d,91,63,c7,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7a,f7,25,ea,ad,9e,0c,4d,91,63,c7,\

[HKEY_USERS\S-1-5-21-1051316268-97930376-468757803-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1051316268-97930376-468757803-1005\Software\SecuROM\License information*]
"datasecu"=hex:5a,14,c9,c2,fd,f3,92,d3,a0,ee,78,d2,61,db,20,d2,35,13,56,6e,0d,
f7,2f,09,6e,bc,44,b7,de,3f,16,4f,a6,78,87,90,4a,b1,74,f2,8b,70,52,3b,09,6f,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(4084)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\progra~1\MI1933~1\OFFICE11\MCPS.DLL

- - - - - - - > 'explorer.exe'(2564)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
c:\program files\Common Files\Ahead\Lib\NeroDigitalExt.dll
c:\program files\Common Files\Ahead\Lib\MSVCP71.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dldncoms.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-12-31 22:44:04 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-01 05:44

Pre-Run: 99,609,608,192 bytes free
Post-Run: 101,414,273,024 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 6F52F7C225C377889A162660C15EC0C3

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 1st January 2010, 5:56 am

wow I kind of feel stupid when I look at these scans and dont recognize a big junk of the programs...lol

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 1st January 2010, 3:06 pm


  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:

    KILLALL::

    File::
    c:\windows\system32\drivers\utqymtez.sys
    c:\windows\system32\drivers\55173996.sys

    Folder::
    C:\found.000

    SecCenter::
    {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    Driver::
    pqtbr
    utqymtez
    Avgfwdx
    Avgfwfd

    DDS::
    uSearchMigratedDefaultUrl = [You must be registered and logged in to see this link.]
    mSearch Bar = [You must be registered and logged in to see this link.]

  4. Save this as CFScript.txt, in the same location as ComboFix.exe



  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 1st January 2010, 9:12 pm

ok not sure what to do the avg remover is not working. It starts and runs a bunch of info across a page then closes by its self and I go in and check and it has removed nothing

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 1st January 2010, 9:15 pm

Okay, run the CFScript above, it will remove AVG anyway.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 1st January 2010, 9:21 pm

ok I will right now... *crosses fingers*

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 1st January 2010, 9:38 pm

ok I did what you said and it started its thing but it needed to restart my pc so I let it then when it restarted a little window said there was a newer versions of it available and did I want to update it... I said no because it was in the middle of something and you had said nothing about an update so it then went back to its thing for 3 seconds or so then I got the blue screen of death..lol IRQL_NOT_LESS_OR_EQUAL at the bottom of the creen it said Tech. Info stop: 0X0000000A (0X00000076, 0X0000001C, 0X00000000, 0X804FA276 dont know if that info helps or not... Should I try again and update this time and I ran this same scan last night but it didnt remove avg then either.. I feel so very lost...lol thank you again

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 1st January 2010, 10:01 pm

ok I restarted my pc and ran the scan again I still did not update it but no blue screen of death this time...lol


ComboFix 09-12-31.07 - Vangie 01/01/2010 14:46:27.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2655 [GMT -7:00]
Running from: c:\documents and settings\Vangie\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Vangie\Desktop\CFscript.txt
AV: avast! antivirus 4.8.1368 [VPS 100101-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

FILE ::
"c:\windows\system32\drivers\55173996.sys"
"c:\windows\system32\drivers\utqymtez.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\found.000
c:\found.000\dir0000.chk\Babylonian\Babylonian.lua
c:\found.000\dir0000.chk\Babylonian\Babylonian.toc
c:\found.000\dir0000.chk\Babylonian\Load.xml
c:\found.000\dir0000.chk\Babylonian\Support\LibRevision.lua
c:\found.000\dir0000.chk\Babylonian\Support\Load.xml
c:\found.000\dir0000.chk\Configator\Configator.lua
c:\found.000\dir0000.chk\Configator\Configator.toc
c:\found.000\dir0000.chk\Configator\lgpl.txt
c:\found.000\dir0000.chk\Configator\Load.xml
c:\found.000\dir0000.chk\Configator\PanelScroller.lua
c:\found.000\dir0000.chk\Configator\PanelScroller.xml
c:\found.000\dir0000.chk\Configator\ScrollSheet.lua
c:\found.000\dir0000.chk\Configator\SelectBox.lua
c:\found.000\dir0000.chk\Configator\SelectBox.xml
c:\found.000\dir0000.chk\Configator\Support\LibRevision.lua
c:\found.000\dir0000.chk\Configator\Support\Load.xml
c:\found.000\dir0000.chk\Load.xml
c:\windows\system32\drivers\55173996.sys
c:\windows\system32\drivers\utqymtez.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_PQTBR
-------\Legacy_UTQYMTEZ
-------\Service_Avgfwdx
-------\Service_Avgfwfd
-------\Service_pqtbr
-------\Service_utqymtez
-------\Legacy_is-H8Q8Vdrv
-------\Service_is-H8Q8Vdrv


((((((((((((((((((((((((( Files Created from 2009-12-01 to 2010-01-01 )))))))))))))))))))))))))))))))
.

2009-12-30 20:46 . 2009-12-03 23:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 20:46 . 2009-12-30 20:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-30 20:46 . 2009-12-03 23:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-30 20:46 . 2009-12-30 20:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-30 19:44 . 2009-12-30 19:44 388096 ----a-r- c:\documents and settings\Vangie\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2009-12-30 19:44 . 2009-12-30 19:44 -------- d-----w- c:\program files\TrendMicro
2009-12-28 05:57 . 2008-04-13 16:44 2560 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2009-12-27 22:15 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-12-27 22:15 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-12-27 22:15 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-12-27 22:15 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-12-27 22:15 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-12-27 22:15 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-12-27 22:15 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-12-27 22:15 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-12-27 22:15 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-12-27 22:15 . 2009-12-27 22:15 -------- d-----w- c:\program files\Alwil Software
2009-12-27 20:00 . 2010-01-01 21:52 31557664 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-12-27 19:43 . 2009-12-27 19:43 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-12-27 19:21 . 2009-12-27 19:21 -------- d-----w- c:\documents and settings\Vangie\Application Data\AVG8
2009-12-27 19:05 . 2009-12-27 19:05 -------- d-----w- c:\documents and settings\Vangie\Local Settings\Application Data\Threat Expert
2009-12-27 18:58 . 2009-11-10 17:28 1640400 ----a-w- c:\windows\PCTBDCore.dll
2009-12-27 18:52 . 2009-12-27 22:57 -------- d-----w- c:\program files\Spyware Doctor
2009-12-27 18:52 . 2009-12-27 22:57 -------- d-----w- c:\program files\Common Files\PC Tools
2009-12-27 18:44 . 2009-12-27 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\XoftSpySE
2009-12-27 18:02 . 2009-12-27 18:02 -------- d-----w- c:\documents and settings\Vangie\Application Data\Malwarebytes
2009-12-27 17:43 . 2009-12-27 17:43 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-12-21 17:35 . 2009-11-04 23:54 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-21 17:35 . 2009-11-04 23:54 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-12-21 17:35 . 2009-11-04 23:54 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-21 17:32 . 2009-11-04 23:53 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-12-17 23:54 . 2009-12-17 23:54 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2009-12-17 23:54 . 2009-12-17 23:54 -------- d-sh--w- c:\documents and settings\LocalService\IECompatCache
2009-12-16 16:51 . 2009-12-16 16:51 -------- d-----w- c:\documents and settings\Vangie\Local Settings\Application Data\Citrix
2009-12-16 16:51 . 2009-12-16 16:51 61224 ----a-w- c:\documents and settings\Vangie\GoToAssistDownloadHelper.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-01 21:52 . 2009-12-27 20:00 370892 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-01-01 05:11 . 2009-06-10 16:04 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-01-01 04:58 . 2006-11-15 22:06 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-01 04:58 . 2006-11-15 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-27 19:44 . 2009-03-20 01:32 -------- d-----w- c:\program files\AVG
2009-12-27 19:14 . 2008-03-11 20:03 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-20 05:21 . 2008-02-23 21:26 -------- d-----w- c:\program files\World of Warcraft
2009-12-20 02:44 . 2006-11-15 17:25 -------- d-----w- c:\program files\Dl_cats
2009-12-19 06:26 . 2006-11-15 23:42 38504 ----a-w- c:\documents and settings\Vangie\Application Data\wklnhst.dat
2009-11-22 02:02 . 2007-11-04 01:34 -------- d-----w- c:\program files\DivX
2009-11-22 02:02 . 2009-11-22 02:02 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-11-06 15:20 . 2006-10-20 03:42 -------- d-----w- c:\program files\Java
2009-11-06 15:19 . 2009-11-06 15:19 152576 ----a-w- c:\documents and settings\Vangie\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-04 23:54 . 2009-11-04 23:54 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-29 07:45 . 2005-08-16 09:18 916480 ------w- c:\windows\system32\wininet.dll
2009-10-24 19:06 . 2009-10-24 19:06 861 ----a-w- c:\documents and settings\Vangie\Application Data\Acreon\WowMatrix\Archives\HealBot\HealBot_Clean_WTF.bat
2009-10-21 05:38 . 2005-08-16 09:18 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2005-08-16 09:18 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 04:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2005-08-16 09:18 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2005-08-16 09:18 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2005-08-16 09:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 11:17 . 2008-11-23 00:22 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-06 20:56 . 2006-11-15 18:23 4600 --sha-w- c:\windows\system32\KGyGaAvL.sys
2007-07-04 08:09 . 2006-11-25 05:08 88 --sh--r- c:\windows\system32\385196AA1C.sys
2009-09-26 21:41 . 2009-09-26 21:41 16384 --sha-w- c:\windows\system32\sonewibu.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 106544]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-28 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-28 13918208]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 73728]

c:\documents and settings\Vangie\Start Menu\Programs\Startup\
is-H8Q8V.lnk - c:\documents and settings\Vangie\Desktop\Virus Removal Tool\is-H8Q8V\startup.exe [2009-12-27 65536]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlccmon.exe]
2005-10-21 07:40 430080 ----a-w- c:\program files\Dell Photo AIO Printer 924\dlccmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2006-05-03 11:12 98304 ----a-w- c:\program files\Dell\Media Experience\DMXLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
2006-05-22 21:26 694272 ----a-w- c:\program files\dvd43\DVD43_Tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-09-29 19:01 67584 ----a-w- c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2006-07-06 12:15 151552 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2006-07-07 23:15 600896 ----a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 15:44 249856 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 15:44 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
2006-07-07 23:14 576320 ----a-w- c:\program files\Microsoft IntelliType Pro\itype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 19:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-09-28 00:19 13918208 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-09-28 00:19 86016 ----a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-11-04 15:30 413696 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-07-24 22:20 282624 ----a-w- c:\windows\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tweak UI]
2000-06-18 22:03 106544 ----a-w- c:\windows\system32\TWEAKUI.CPL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2006-10-25 00:10 4662776 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Ideazon\\ZEngine\\Zboard.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\dldncoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldnpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldntime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dldnjswx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"57803:TCP"= 57803:TCP:Pando Media Booster
"57803:UDP"= 57803:UDP:Pando Media Booster
"56894:TCP"= 56894:TCP:Pando Media Booster
"56894:UDP"= 56894:UDP:Pando Media Booster

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/15/2006 2:46 PM 642560]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [12/27/2009 3:15 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/27/2009 3:15 PM 20560]
R2 dldn_device;dldn_device;c:\windows\system32\dldncoms.exe -service --> c:\windows\system32\dldncoms.exe -service [?]
S3 Alpham;Ideazon Merc Composite Keyboard Driver;c:\windows\system32\drivers\Alpham.sys [12/4/2005 12:55 PM 34944]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultUrl = [You must be registered and logged in to see this link.]
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-01-01 14:54
Windows 5.1.2600 Service Pack 3 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, [You must be registered and logged in to see this link.]

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe >>UNKNOWN [0x8B1839C0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x8b1839c0
\Driver\ACPI -> ACPI.sys @ 0xb7e97cb8
\Driver\iaStor -> 0x8b183c78
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Intel(R) 82562V 10/100 Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xb7c96bb0
PacketIndicateHandler -> NDIS.sys @ 0xb7ca3a21
SendHandler -> NDIS.sys @ 0xb7c8187b
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7a,f7,25,ea,ad,9e,0c,4d,91,63,c7,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7a,f7,25,ea,ad,9e,0c,4d,91,63,c7,\

[HKEY_USERS\S-1-5-21-1051316268-97930376-468757803-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1051316268-97930376-468757803-1005\Software\SecuROM\License information*]
"datasecu"=hex:5a,14,c9,c2,fd,f3,92,d3,a0,ee,78,d2,61,db,20,d2,35,13,56,6e,0d,
f7,2f,09,6e,bc,44,b7,de,3f,16,4f,a6,78,87,90,4a,b1,74,f2,8b,70,52,3b,09,6f,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(4080)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dldncoms.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-01-01 14:58:34 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-01 21:58
ComboFix2.txt 2010-01-01 05:44

Pre-Run: 101,422,665,728 bytes free
Post-Run: 101,379,244,032 bytes free

Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 569CE3FCDCAF35A2CD1F0CF9F6A1701D

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 1st January 2010, 10:49 pm

Submit a file for analysis.

  1. Please visit this website: [You must be registered and logged in to see this link.]
  2. Press the "Browse" button and locate the following file in bold:
    C:\WINDOWS\system32\sonewibu.exe
  3. Press the "Submit File button to submit the file for analysis.
  4. Allow it to be scanned, it could take a few minutes depending on server load.
  5. Copy and paste the result back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 1st January 2010, 11:18 pm

I searched and searched but there is no such file name as sonewibu =(

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 1st January 2010, 11:22 pm

Hello.
It has hȋdden attributes.


  1. Open My Computer.
  2. Go to Tools > Folder Options.
  3. Select the View tab.
  4. Scroll down to hȋdden files and folders.
  5. Select Show hȋdden files and folders.
  6. Uncheck (untick) Hide extensions of known file types.
  7. Uncheck (untick) Hide protected operating system files (Recommended).
  8. Click Yes when prompted.
  9. Click OK.
  10. Close My Computer.

Now can you see it?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 1st January 2010, 11:36 pm

yes.. So I am going to continue with the rest of the instructions now =)

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 1st January 2010, 11:40 pm

ok I did it, it scanned and I saw nothing that said results just these two things

Scan finished. 9 out of 20 scanners reported malware.

and


Additional info
File size: 16384 bytes
Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5: 85bec1004ed4bcc406f38f9537fbddd6
SHA1: 9a484650fa05d343c27b6202a0adb7276b82acb6

plus a huge list of different scanners and what they found but those wont paste here because of the pics in the names

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 2nd January 2010, 12:06 am

Hello.
Delete this file in bold:
c:\windows\system32\sonewibu.exe

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall

This will also reset your restore points.

How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 2nd January 2010, 12:31 am

hmm it still seems a little sluggish and now I have these on my desktop, 2 data base files used by my operating system ( at least thats what they say if I click on them ) ehthumbs.db and Thumbs.db and they have never been there before =/


and I still have AVG not running or working but it is still in my pc..

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 2nd January 2010, 12:42 am

Yeah, just leftover folders, we'll remove them soon.
Please post a new Hijack This log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 2nd January 2010, 10:58 pm

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 3:56:22 PM, on 1/2/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dldncoms.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [combofix] "C:\Combo-Fix\CF19193.cfxxe" /c "C:\Combo-Fix\C.bat"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: dldn_device - - C:\WINDOWS\system32\dldncoms.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6265 bytes

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 3rd January 2010, 12:09 am

Hello.

You can delete those two .db files.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [combofix] "C:\Combo-Fix\CF19193.cfxxe" /c "C:\Combo-Fix\C.bat"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe



  • Press "Fix Checked"
  • Close Hijack This.

I recommend you remove the Java Quick Starter because it's not needed.
To do so, follow these instructions.

Go to Start > Control Panel > Java.
In the Java control panel, open the click the Advanced tab. Click the + in front of Miscellaneous and uncheck the Java Quick Starter box.

See [You must be registered and logged in to see this link.] for more info.

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    c:\documents and settings\All Users\Application Data\avg9
    c:\documents and settings\Vangie\Application Data\AVG8
    c:\documents and settings\All Users\Application Data\McAfee
    c:\program files\Common Files\Symantec Shared
    c:\documents and settings\All Users\Application Data\Symantec
    c:\program files\AVG


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 3rd January 2010, 3:32 am

========== FILES ==========
c:\documents and settings\All Users\Application Data\avg9\Log folder moved successfully.
c:\documents and settings\All Users\Application Data\avg9 folder moved successfully.
c:\documents and settings\Vangie\Application Data\AVG8 folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\Supportability\MVT folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\Supportability folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\MSC\Cache folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\MSC folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\MBK\92948b65-08a6-4ac1-8cea-513bfa06ca9d folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\MBK folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\dspwrp folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\TextHub folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\incoming folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\20071026.021 folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\20071025.021 folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\20061116.036 folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs folder moved successfully.
c:\program files\Common Files\Symantec Shared\SPManifests folder moved successfully.
c:\program files\Common Files\Symantec Shared\EENGINE folder moved successfully.
c:\program files\Common Files\Symantec Shared\CCPD-LC folder moved successfully.
c:\program files\Common Files\Symantec Shared folder moved successfully.
c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\{6A90DE7F-6F89-4703-ABD9-CEBAD0C38E93} folder moved successfully.
c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine folder moved successfully.
c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus folder moved successfully.
c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate folder moved successfully.
c:\documents and settings\All Users\Application Data\Symantec folder moved successfully.
c:\program files\AVG\AVG8\log folder moved successfully.
c:\program files\AVG\AVG8\avgam folder moved successfully.
c:\program files\AVG\AVG8 folder moved successfully.
c:\program files\AVG folder moved successfully.

OTM by OldTimer - Version 3.1.4.0 log created on 01022010_203223

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Belahzur on 3rd January 2010, 9:32 pm

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall

This will also reset your restore points.

How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: INFECTED ... Internet Security 2010 ... of course...lol HELP please

Post by Dragoness00 on 4th January 2010, 3:00 am

appears to be better... Thank you so much.. and I dont know what that file was you had me remove that was part of my zboard when we first started this but it is working fine also so it didnt seem to effect it =).. I love this site and am recommending it to all my friends.. I thank you so very much.. I would have thrown it out the window if it wasnt for you Hooray!

Dragoness00
Novice
Novice

Posts Posts : 24
Joined Joined : 2009-12-30
Gender Gender : Female
OS OS : Windows XP
Points Points : 25718
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum