I have had this problem before recently (albeit of a more lethal form).

The particular virus's main effect is to switch off Windows Firewall and Automatic Updates. It does not allow a System Restore. This virus is particularly tenacious when it comes to removing.

I am unable to run the GMER Rootkit Scanner because this always cause the computer to spectacularly crash and recover from "a serious error" in which it has to dump memory.

Here are requested logs:-

Malwarebytes' Anti-Malware


Database version: 7546

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

23/08/2011 11:00:28 AM

mbam-log-2011-08-23 (11-00-28).txt

Scan type: Quick scan

Objects scanned: 206180

Time elapsed: 16 minute(s), 29 second(s)

Memory Processes Infected: 1

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 1

Registry Data Items Infected: 3

Folders Infected: 0

Files Infected: 2

Memory Processes Infected:

c:\documents and settings\everyone else\local settings\application data\htl.exe (Trojan.FakeAlert) -> 1088 -> Unloaded process successfully.

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\1213316075 (Trojan.FakeAlert) -> Value: 1213316075 -> Quarantined and deleted successfully.

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

c:\documents and settings\everyone else\local settings\application data\htl.exe (Trojan.FakeAlert) -> Delete on reboot.

c:\documents and settings\everyone else\local settings\temp\0.8187281440886258.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.


DDS (Ver_2011-06-23.01) - NTFSx86

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21

Run by Everyone Else at 3:09:10 on 2011-08-24

Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.502.102 [GMT -7:00]


AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}


============== Running Processes ===============


C:\WINDOWS\system32\svchost.exe -k DcomLaunch


C:\WINDOWS\System32\svchost.exe -k netsvcs


C:\WINDOWS\System32\svchost.exe -k netsvcs




C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe

C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe

C:\Program Files\AVG\AVG9\avgwdsvc.exe

C:\Program Files\AVG\AVG9\avgfws9.exe


C:\Program Files\Dell Support Center\bin\sprtsvc.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program Files\AVG\AVG9\avgnsx.exe

C:\Program Files\AVG\AVG9\avgchsvx.exe

C:\Program Files\AVG\AVG9\avgrsx.exe

C:\Program Files\AVG\AVG9\avgcsrvx.exe




C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe

C:\Program Files\IObit\Advanced SystemCare 4\Suo10_SmartRAM.exe

C:\Documents and Settings\All Users\Application Data\Mozilla Firefox\firefox.exe


C:\Documents and Settings\All Users\Application Data\Mozilla Firefox\plugin-container.exe

C:\Program Files\Microsoft Office\Office\WINWORD.EXE

C:\Documents and Settings\Everyone Else\Desktop\Defogger.exe


============== Pseudo HJT Report ===============


BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

uRun: [Advanced SystemCare 4] "c:\program files\iobit\advanced systemcare 4\ASCTray.exe"

uRun: [smartRAM] "c:\program files\iobit\advanced systemcare 4\Suo10_SmartRAM.exe" /m

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab

DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175715926328

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab

DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

TCP: DhcpNameServer =

TCP: Interfaces\{CDE026FF-8337-41F3-A59A-1E5CDFE7AAE8} : DhcpNameServer =


================= FIREFOX ===================


FF - ProfilePath - c:\documents and settings\everyone else\application data\mozilla\firefox\profiles\se7t3lqv.default\

FF - prefs.js: browser.startup.homepage - www.google.com


============= SERVICES / DRIVERS ===============



=============== File Associations ===============



=============== Created Last 30 ================



==================== Find3M ====================



============= FINISH: 3:11:34.76 ===============





DDS (Ver_2011-06-23.01)


Microsoft Windows XP Home Edition

Boot Device: \Device\HarddiskVolume2

Install Date: 14/05/2006 3:06:09 PM

System Uptime: 23/08/2011 11:46:46 PM (4 hours ago)


Motherboard: Dell Inc. | | 0JC474

Processor: Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2793/800mhz


==== Disk Partitions =========================


A: is Removable

C: is FIXED (NTFS) - 146 GiB total, 2.223 GiB free.


E: is FIXED (NTFS) - 298 GiB total, 76.002 GiB free.

F: is Removable


==== Disabled Device Manager Items =============


==== System Restore Points ===================


RP1545: 07/08/2011 11:34:08 PM - System Checkpoint

RP1546: 10/08/2011 6:07:32 PM - System Checkpoint

RP1547: 11/08/2011 3:27:12 AM - Software Distribution Service 3.0

RP1548: 11/08/2011 4:19:01 AM - Software Distribution Service 3.0

RP1549: 12/08/2011 10:53:41 AM - System Checkpoint

RP1550: 13/08/2011 11:06:03 AM - System Checkpoint

RP1551: 14/08/2011 11:54:52 PM - System Checkpoint

RP1552: 16/08/2011 12:49:09 AM - System Checkpoint

RP1553: 17/08/2011 1:26:24 AM - System Checkpoint

RP1554: 19/08/2011 10:28:50 AM - System Checkpoint

RP1555: 20/08/2011 2:56:52 PM - System Checkpoint

RP1556: 22/08/2011 12:01:13 AM - System Checkpoint

RP1557: 23/08/2011 5:35:39 PM - System Checkpoint


==== Event Viewer Messages From Past Week ========


22/08/2011 4:43:07 PM, error: Service Control Manager [7016] - The BrSplService service has reported an invalid current state 0.

19/08/2011 9:33:59 PM, error: Service Control Manager [7034] - The Brother Popup Suspend service for Resource manager service terminated unexpectedly. It has done this 1 time(s).

19/08/2011 9:33:55 PM, error: Service Control Manager [7034] - The IMF Service service terminated unexpectedly. It has done this 1 time(s).

19/08/2011 9:27:29 PM, error: Service Control Manager [7034] - The SupportSoft Sprocket Service (dellsupportcenter) service terminated unexpectedly. It has done this 1 time(s).

18/08/2011 8:29:02 AM, error: Service Control Manager [7022] - The Windows Image Acquisition (WIA) service hung on starting.

17/08/2011 2:34:11 PM, error: Service Control Manager [7034] - The IMAPI CD-Burning COM Service service terminated unexpectedly. It has done this 1 time(s).

17/08/2011 11:53:04 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).

17/08/2011 11:49:50 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).


==== End Of File ===========================

  • Staff

Hi and welcome to Malwarebytes.

Please update MBAM, run a Quick Scan, and post its log.

Next, please visit this webpage for instructions for running ComboFix:


  • When the tool is finished, it will produce a report for you.
  • Please post the contents of C:\ComboFix.txt along with a new DDS log so we may continue cleaning the system.

Malwarebytes' Anti-Malware


Database version: 7600

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

28/08/2011 11:51:58 PM

mbam-log-2011-08-28 (23-51-57).txt

Scan type: Quick scan

Objects scanned: 210296

Time elapsed: 1 hour(s), 57 minute(s), 41 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

ComboFix 11-08-28.01 - Everyone Else 29/08/2011 1:59.3.2 - x86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.502.279 [GMT -7:00]

Running from: c:\documents and settings\Everyone Else\Desktop\ComboFix.exe


/wow section - STAGE 4


/wow section - STAGE 6A


/wow section - STAGE 33

grep: temp2401: No such file or directory

The system cannot execute the specified program.


ComboFix encountered a terminal error!! Please upload this file - C:\ComboFix_error.dat

to: http://www.bleepingcomputer.com/submit-malware.php?channel=4


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))





Infected copy of c:\windows\system32\userinit.exe was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\userinit.exe


Infected copy of c:\windows\system32\user32.dll was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\user32.dll


Infected copy of c:\windows\system32\lsass.exe was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\lsass.exe


Infected copy of c:\windows\system32\ws2help.dll was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\ws2help.dll


Infected copy of c:\windows\system32\ws2_32.dll was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\ws2_32.dll


Infected copy of c:\windows\system32\drivers\kbdclass.sys was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\kbdclass.sys


Infected copy of c:\windows\system32\usp10.dll was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\usp10.dll


Infected copy of c:\windows\system32\msimg32.dll was found and disinfected

Restored copy from - c:\windows\ServicePackFiles\i386\msimg32.dll


Infected copy of c:\windows\Winlogon.exe was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\winlogon.exe


c:\windows\explorer.exe . . . is infected!!


Infected copy of c:\windows\system32\spoolsv.exe was found and disinfected

Restored copy from - c:\windows\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe


Infected copy of c:\windows\system32\lpk.dll was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\lpk.dll


Infected copy of c:\windows\system32\comres.dll was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\comres.dll


Infected copy of c:\windows\system32\mfc40u.dll was found and disinfected

Restored copy from - c:\windows\$hf_mig$\KB2387149\SP3QFE\mfc40u.dll


Infected copy of c:\windows\system32\svchost.exe was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\svchost.exe


Infected copy of c:\windows\system32\msgsvc.dll was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\msgsvc.dll


Infected copy of c:\windows\system32\uxtheme.dll was found and disinfected

Restored copy from - c:\windows\ServicePackFiles\i386\uxtheme.dll


Infected copy of c:\program files\internet explorer\iexplore.exe was found and disinfected

Restored copy from - c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe


Infected copy of c:\windows\system32\midimap.dll was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\midimap.dll


Infected copy of c:\windows\system32\wuauclt.exe was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\wuauclt.exe


Infected copy of c:\windows\system32\comctl32.dll was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\comctl32.dll


c:\windows\system32\debug.exe . . . is infected!!


Infected copy of c:\windows\system32\drivers\acpiec.sys was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\acpiec.sys


Infected copy of c:\windows\system32\drivers\ndis.sys was found and disinfected

Restored copy from - c:\windows\ERDNT\cache\ndis.sys


((((((((((((((((((((((((( Files Created from 2011-07-28 to 2011-08-29 )))))))))))))))))))))))))))))))



No new files created in this timespan



(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))



c:\windows\system32\mswsock.dll ... is infected !!


c:\windows\system32\svchost.exe ... Infected -- Win32.Qhost !!

-c----w- 14,336 2004-08-04 10:00 c:\windows\$NtServicePackUninstall$\svchost.exe

----a-w- 14,336 2008-04-14 00:12 c:\windows\ERDNT\cache\svchost.exe

----a-w- 22,096 2011-08-29 08:45 c:\windows\Prefetch\SVCHOST.EXE-2D5FBD18.pf

------w- 14,336 2008-04-14 00:12 c:\windows\ServicePackFiles\i386\svchost.exe

----a-w- 14,336 2008-04-14 00:12 c:\windows\system32\svchost.exe


Entries: 5 (5)

Directories: 0 Files: 5

Bytes: 79,440 Blocks: 156



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))



*Note* empty entries & legit default entries are not shown




"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-05-28 412560]

"SmartRAM"="c:\program files\IObit\Advanced SystemCare 4\Suo10_SmartRAM.exe" [2011-05-28 512400]









"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-29 98304]



















SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.


[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 9.0 Tray Icon.lnk]

backup=c:\windows\pss\AOL 9.0 Tray Icon.lnkCommon Startup


[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]

backup=c:\windows\pss\Microsoft Office.lnkCommon Startup


[HKEY_LOCAL_MACHINE\software\microsoft\security center]





"DisableNotifications"= 1 (0x1)




"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=


"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=



Contents of the 'Scheduled Tasks' folder


2011-08-29 c:\windows\Tasks\ASC4_PerformanceMonitor.job

- c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe [2011-08-06 21:46]



------- Supplementary Scan -------


TCP: DhcpNameServer =

FF - ProfilePath - c:\documents and settings\Everyone Else\Application Data\Mozilla\Firefox\Profiles\se7t3lqv.default\

FF - prefs.js: browser.startup.homepage - www.google.com





catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-08-29 02:24

Windows 5.1.2600 Service Pack 3 NTFS


scanning hidden processes ...


scanning hidden autostart entries ...


scanning hidden files ...


scan completed successfully

hidden files: 0




--------------------- LOCKED REGISTRY KEYS ---------------------


[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)






------------------------ Other Running Processes ------------------------



c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe

c:\program files\IObit\Advanced SystemCare 4\ASCService.exe


c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Dell Support Center\bin\sprtsvc.exe




Completion time: 2011-08-29 02:31:30 - machine was rebooted

ComboFix-quarantined-files.txt 2011-08-29 09:31

ComboFix2.txt 2011-08-05 13:03

ComboFix3.txt 2010-03-29 07:46


Pre-Run: 5,336,641,536 bytes free

Post-Run: 5,449,437,184 bytes free


- - End Of File - - E39BB81844D8C1B375BD67E1F495C658


DDS (Ver_2011-06-23.01) - NTFSx86

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21

Run by Everyone Else at 2:34:07 on 2011-08-29

Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.502.145 [GMT -7:00]



============== Running Processes ===============


C:\WINDOWS\system32\svchost.exe -k DcomLaunch


C:\WINDOWS\System32\svchost.exe -k netsvcs


C:\WINDOWS\System32\svchost.exe -k netsvcs



C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe

C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe

C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe


C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Dell Support Center\bin\sprtsvc.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc



C:\Program Files\Dell Support Center\bin\sprtcmd.exe

C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe

C:\Program Files\IObit\Advanced SystemCare 4\Suo10_SmartRAM.exe



C:\Documents and Settings\All Users\Application Data\Mozilla Firefox\firefox.exe

C:\Documents and Settings\All Users\Application Data\Mozilla Firefox\plugin-container.exe


============== Pseudo HJT Report ===============


BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

uRun: [Advanced SystemCare 4] "c:\program files\iobit\advanced systemcare 4\ASCTray.exe"

uRun: [smartRAM] "c:\program files\iobit\advanced systemcare 4\Suo10_SmartRAM.exe" /m

mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime


IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab

DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175715926328

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab

DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

TCP: DhcpNameServer =

TCP: Interfaces\{CDE026FF-8337-41F3-A59A-1E5CDFE7AAE8} : DhcpNameServer =


================= FIREFOX ===================


FF - ProfilePath - c:\documents and settings\everyone else\application data\mozilla\firefox\profiles\se7t3lqv.default\

FF - prefs.js: browser.startup.homepage - www.google.com


============= SERVICES / DRIVERS ===============



=============== File Associations ===============



=============== Created Last 30 ================



==================== Find3M ====================



============= FINISH: 2:35:31.17 ===============





DDS (Ver_2011-06-23.01)


Microsoft Windows XP Home Edition

Boot Device: \Device\HarddiskVolume2

Install Date: 14/05/2006 3:06:09 PM

System Uptime: 29/08/2011 2:20:46 AM (0 hours ago)


Motherboard: Dell Inc. | | 0JC474

Processor: Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2793/800mhz


==== Disk Partitions =========================


A: is Removable

C: is FIXED (NTFS) - 146 GiB total, 5.132 GiB free.


E: is FIXED (NTFS) - 298 GiB total, 80.646 GiB free.

F: is Removable


==== Disabled Device Manager Items =============


==== System Restore Points ===================


RP1545: 07/08/2011 11:34:08 PM - System Checkpoint

RP1546: 10/08/2011 6:07:32 PM - System Checkpoint

RP1547: 11/08/2011 3:27:12 AM - Software Distribution Service 3.0

RP1548: 11/08/2011 4:19:01 AM - Software Distribution Service 3.0

RP1549: 12/08/2011 10:53:41 AM - System Checkpoint

RP1550: 13/08/2011 11:06:03 AM - System Checkpoint

RP1551: 14/08/2011 11:54:52 PM - System Checkpoint

RP1552: 16/08/2011 12:49:09 AM - System Checkpoint

RP1553: 17/08/2011 1:26:24 AM - System Checkpoint

RP1554: 19/08/2011 10:28:50 AM - System Checkpoint

RP1555: 20/08/2011 2:56:52 PM - System Checkpoint

RP1556: 22/08/2011 12:01:13 AM - System Checkpoint

RP1557: 23/08/2011 5:35:39 PM - System Checkpoint

RP1558: 24/08/2011 6:02:24 PM - System Checkpoint

RP1559: 27/08/2011 4:32:55 PM - System Checkpoint

RP1560: 28/08/2011 5:20:46 PM - System Checkpoint

RP1561: 29/08/2011 1:19:59 AM - IObit Uninstaller restore point

RP1562: 29/08/2011 1:26:01 AM - Removed AVG Free 9.0

RP1563: 29/08/2011 1:41:06 AM - Installed AVG Free 9.0


==== Event Viewer Messages From Past Week ========


27/08/2011 12:39:14 AM, error: System Error [1003] - Error code 000000d1, parameter1 0000000c, parameter2 00000002, parameter3 00000000, parameter4 aa625a38.

27/08/2011 1:30:27 AM, error: System Error [1003] - Error code 000000d1, parameter1 0000000c, parameter2 00000002, parameter3 00000000, parameter4 aa666a38.

26/08/2011 2:54:43 AM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The system cannot find the file specified.

25/08/2011 9:36:25 PM, error: System Error [1003] - Error code 000000d1, parameter1 f6c88858, parameter2 00000002, parameter3 00000001, parameter4 8263eb27.

25/08/2011 12:21:20 PM, error: Service Control Manager [7022] - The AVG Free WatchDog service hung on starting.

24/08/2011 4:14:49 AM, error: System Error [1003] - Error code 000000d1, parameter1 01e8c1bc, parameter2 00000002, parameter3 00000000, parameter4 f8443af2.

24/08/2011 3:48:55 AM, error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort1.

24/08/2011 3:47:08 AM, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period.

23/08/2011 10:24:02 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).

23/08/2011 10:20:02 AM, error: Service Control Manager [7022] - The Windows Image Acquisition (WIA) service hung on starting.

22/08/2011 4:43:07 PM, error: Service Control Manager [7016] - The BrSplService service has reported an invalid current state 0.

22/08/2011 2:40:58 AM, error: Service Control Manager [7034] - The SupportSoft Sprocket Service (dellsupportcenter) service terminated unexpectedly. It has done this 1 time(s).

22/08/2011 2:40:58 AM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).


==== End Of File ===========================

  • Staff


Delete your copy of ComboFix. Grab a fresh copy and save it to your Desktop, but do not run it yet. Before you download it, rename it to sega.com

Please reboot to Safe Mode (tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu).

Click Start --> Run, and enter this command exactly as shown:

"%userprofile%\desktop\sega.com" /killall /nombr

See if it will run successfully now. Stop it after half an hour of no activity.

  • 2 weeks later...

Sorry about the long delay in reply.

After the ComboFix application, it appears that all trace of the virus has been removed. ComboFix did download quite a bunch of Windows files that were either damaged or missing. I also had to remove and reinstall AVG.

While there seem to be no further issues with this virus, what all of this updating now seems to have resulted in is a computer that runs extremely slowly. For example, if I am playing music or a video on Media Player and have a couple of other largeish programs (say Microsoft Word and Firefox) open at the same time, the sound quality on Media player is constantly crackly or the picture keeps skipping, often unless I set Task Manager priority to High. Often when I have the dozen or so programs open that I frequently used to before when working with no problems, this can take some 30 seconds to a minute to switch between windows. Moving a large file of around 100 megs between folders took some 25 minutes when it would take 5 or so before. The mouse movements are often jerky and erratic. Even in typing this, there is a lag of a few seconds before the words that I have just typed will appear. I have tried resetting the computer to the point before this virus infection occurred but it will still not recognise the changes made and insists that none have been made - something that was a facet of this virus.

I will run the suggested Sega.com program and see if that picks up anything. Otherwise any suggestions?

Link to post
Share on other sites

  • Staff


Please post the log created by ComboFix.

Next, please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

Next, download my Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me know how things are running now and what issues remain.


  • 4 weeks later...
  • Staff

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

