Jump to content

I need help cleaning a virus from my computer


Recommended Posts

Hi, I have a problem with my computer -- I'm getting notices form the Malwarebytes program that it is constantly blocking access to malicious sites. (outgoing) I think I followed the instructions given and am attaching the requested files. Let me know if I did anything wrong or attached the wrong files. Thank you, Judy

THE DDS FILE:

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18

Run by Judy at 14:22:24 on 2011-09-03

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.172 [GMT -4:00]

.

AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}

.

============== Running Processes ===============

.

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe

C:\Program Files\Logitech\Logitech Vid\vid.exe

C:\Program Files\I8kfanGUI\I8kfanGUI.exe

C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Google\Update\GoogleUpdate.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\VERIZONDM\bin\sprtsvc.exe

C:\WINDOWS\System32\svchost.exe -k imgsvc

C:\Program Files\VERIZONDM\bin\tgsrvc.exe

C:\Program Files\Common Files\Authentium\AntiVirus5\vsedsps.exe

C:\Program Files\Common Files\Authentium\AntiVirus5\vseamps.exe

C:\Program Files\Common Files\Authentium\AntiVirus5\vseqrts.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

.

============== Pseudo HJT Report ===============

.

uInternet Settings,ProxyOverride = <local>

mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers runtime\YontooIEClient_2.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File

TB: Download Energy Toolbar: {2bae58c2-79f9-45d1-a286-81f911301c3a} - c:\program files\p2p_energy\tbP2P1.dll

TB: Discover USA Toolbar: {48405d3d-2674-4cd8-b1ef-9a719443bd3f} - c:\program files\search_usa\tbSea0.dll

TB: Download Energy Toolbar: {ad708c09-d51b-45b3-9d28-4eba2681febf} - c:\program files\download_energy\tbDow1.dll

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll

EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe"

uRun: [Logitech Vid] "c:\program files\logitech\logitech vid\vid.exe" -bootmode

uRun: [i8kfangui] c:\program files\i8kfangui\I8kfanGUI.exe /startup

uRun: [AROReminder] c:\program files\aro 2011\aro.exe -rem

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\FirstStart.exe" /OM

mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide

mRun: [Alcmtr] ALCMTR.EXE

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [Txipibikixezib] rundll32.exe "c:\windows\idudixenibekepem.dll",Startup

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min

dRunOnce: [RunNarrator] Narrator.exe

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

TCP: DhcpNameServer = 192.168.1.1 192.168.1.1

TCP: Interfaces\{66C8DB40-0463-4ACE-AFF2-AB9F7DEC0263} : DhcpNameServer = 192.168.1.1 192.168.1.1

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

Notify: AtiExtEvent - Ati2evxx.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\documents and settings\judy\application data\mozilla\firefox\profiles\j52sfuq9.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=

FF - prefs.js: browser.search.selectedEngine - Bing

FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 64242

FF - prefs.js: network.proxy.type - 0

FF - component: c:\documents and settings\judy\application data\mozilla\firefox\profiles\j52sfuq9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll

FF - component: c:\documents and settings\judy\application data\mozilla\firefox\profiles\j52sfuq9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll

FF - component: c:\documents and settings\judy\application data\mozilla\firefox\profiles\j52sfuq9.default\extensions\{f370bed8-2381-4f22-aea6-e7bd238668af}\components\FFExternalAlert.dll

FF - component: c:\documents and settings\judy\application data\mozilla\firefox\profiles\j52sfuq9.default\extensions\{f370bed8-2381-4f22-aea6-e7bd238668af}\components\RadioWMPCore.dll

FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll

FF - plugin: c:\documents and settings\judy\application data\facebook\npfbplugin_1_0_3.dll

FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll

FF - plugin: c:\program files\google\picasa3\npPicasa3.dll

FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll

FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll

FF - plugin: c:\program files\olympus\ib utilities\firefox plugin\npIbInst.dll

.

---- FIREFOX POLICIES ----

FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(yahoo.homepage.dontask, true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(extentions.y2layers.installId, 0f23a4c7-fef6-4ad8-9201-717df781bb56

FF - user.js: extentions.y2layers.installId - 032cccb3-48a5-48fa-a037-36f99cf47c05

FF - user.js: extentions.y2layers.installId - 5c10a373-8026-4409-80e1-8ecd03661f88

.

============= SERVICES / DRIVERS ===============

.

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-9-1 11608]

R1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [2011-1-31 14464]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-9-1 136360]

R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-9-1 269480]

R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-9-1 66616]

R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-5-4 366640]

R2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\verizondm\bin\sprtsvc.exe [2010-9-2 206120]

R2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\verizondm\bin\tgsrvc.exe [2010-9-2 185640]

R2 vseamps;vseamps;c:\program files\common files\authentium\antivirus5\vseamps.exe [2010-4-8 117288]

R2 vsedsps;vsedsps;c:\program files\common files\authentium\antivirus5\vsedsps.exe [2010-4-8 117288]

R2 vseqrts;vseqrts;c:\program files\common files\authentium\antivirus5\vseqrts.exe [2010-4-8 154152]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-5-4 22712]

S2 ClipSrv32;ClipBook ;c:\windows\system32\wmploc32.exe --> c:\windows\system32\wmploc32.exe [?]

S2 CryptSvc32;Cryptographic Services ;c:\windows\system32\quartz32.exe --> c:\windows\system32\quartz32.exe [?]

S2 DcomLaunch32;DCOM Server Process Launcher ;c:\windows\system32\rasman32.exe --> c:\windows\system32\rasman32.exe [?]

S2 Dhcp32;DHCP Client ;c:\windows\system32\odtext3232.exe --> c:\windows\system32\odtext3232.exe [?]

S2 dmadmin3232;Logical Disk Manager Administrative Service ;c:\windows\system32\rtm32.exe --> c:\windows\system32\rtm32.exe [?]

S2 ERSvc32;Error Reporting Service ;c:\windows\system32\netui032.exe --> c:\windows\system32\netui032.exe [?]

S2 ERSvc3232;Error Reporting Service ;c:\windows\system32\wshatm32.exe --> c:\windows\system32\wshatm32.exe [?]

S2 FontCache3.0.0.032;Windows Presentation Foundation Font Cache 3.0.0.0 ;c:\windows\system32\pdh32.exe --> c:\windows\system32\pdh32.exe [?]

S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-16 135664]

S2 helpsvc32;Help and Support ;c:\windows\system32\inetpp32.exe --> c:\windows\system32\inetpp32.exe [?]

S2 LMIRescue_5ebd5304-3ca6-47cb-9603-d9a4b6ab657b;LogMeIn Rescue (5ebd5304-3ca6-47cb-9603-d9a4b6ab657b);"c:\docume~1\sarah\locals~1\temp\lmir0001.tmp\lmi_rescue_srv.exe" -service -sid 5ebd5304-3ca6-47cb-9603-d9a4b6ab657b --> c:\docume~1\sarah\locals~1\temp\lmir0001.tmp\LMI_Rescue_srv.exe [?]

S2 NtLmSsp32;NT LM Security Support Provider ;c:\windows\system32\wmasf32.exe --> c:\windows\system32\wmasf32.exe [?]

S2 srvA00;srvA00;c:\windows\system32\svchost.exe -k netsvcs [2002-8-29 14336]

S2 UPS32;Uninterruptible Power Supply ;c:\windows\system32\shimeng32.exe --> c:\windows\system32\shimeng32.exe [?]

S2 vsedsps32;vsedsps ;c:\windows\system32\kbdhu32.exe --> c:\windows\system32\kbdhu32.exe [?]

S2 wuauserv3232;Automatic Updates ;c:\windows\system32\iaspolcy32.exe --> c:\windows\system32\iaspolcy32.exe [?]

S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-16 135664]

S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-5-4 41272]

.

=============== Created Last 30 ================

.

2011-09-02 11:39:20 -------- d-----w- c:\documents and settings\judy\application data\Sammsoft

2011-09-02 11:39:05 -------- d-----w- c:\program files\ARO 2011

2011-09-02 11:27:52 -------- d-----w- c:\windows\system32\wbem\repository\FS

2011-09-02 11:27:52 -------- d-----w- c:\windows\system32\wbem\Repository

2011-09-02 01:36:43 -------- d-----w- c:\documents and settings\judy\application data\Avira

2011-09-02 01:28:39 -------- d-----w- c:\windows\system32\NtmsData

2011-09-02 01:26:38 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2011-09-02 01:26:37 -------- d-----w- c:\program files\Avira

2011-09-02 01:26:37 -------- d-----w- c:\documents and settings\all users\application data\Avira

2011-08-10 04:27:56 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys

2011-08-10 04:25:31 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys

2011-08-07 19:29:11 -------- d-----w- c:\windows\system32\XPSViewer

2011-08-07 19:28:20 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll

2011-08-07 19:27:24 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2011-08-07 19:27:24 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2011-08-07 19:27:24 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

2011-08-07 19:27:24 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2011-08-07 19:27:24 575488 ------w- c:\windows\system32\xpsshhdr.dll

2011-08-07 19:27:24 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2011-08-07 19:27:24 1676288 ------w- c:\windows\system32\xpssvcs.dll

2011-08-07 19:27:24 117760 ------w- c:\windows\system32\prntvpt.dll

2011-08-07 19:27:24 -------- d-----w- C:\cafb26ef80a2c6c95fde60

2011-08-05 23:32:33 -------- d-----w- c:\windows\SxsCaPendDel

.

==================== Find3M ====================

.

2011-09-03 10:59:23 0 ----a-w- c:\windows\Ggulusaxup.bin

2011-08-13 11:23:55 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-07-28 11:09:31 0 ---ha-w- c:\documents and settings\judy\bnecqblmkb.tmp

2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys

2011-07-06 23:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-07-06 23:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-06-28 13:39:09 398760 ----a-r- c:\windows\system32\cpnprt2.cid

2011-06-24 14:10:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2011-06-23 18:36:30 916480 ----a-w- c:\windows\system32\wininet.dll

2011-06-23 18:36:30 43520 ----a-w- c:\windows\system32\licmgr10.dll

2011-06-23 18:36:30 1469440 ------w- c:\windows\system32\inetcpl.cpl

2011-06-23 12:05:13 385024 ----a-w- c:\windows\system32\html.iec

2011-06-20 17:44:52 293376 ----a-w- c:\windows\system32\winsrv.dll

.

=================== ROOTKIT ====================

.

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net

Windows 5.1.2600 Disk: WDC_WD3200AAJS-22RYA0 rev.12.01B01 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3

.

device: opened successfully

user: MBR read successfully

.

Disk trace:

called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x83A644C0]<<

_asm { MOV EAX, [ESP+0x4]; MOV ECX, [0x83a6b8a4]; PUSH ESI; MOV ESI, [ESP+0xc]; PUSH EDI; MOV EDI, [ESI+0x60]; CMP EAX, [0x83a6b730]; JNZ 0x1f; MOV [ESP+0xc], ECX; }

1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x83F21AB8]

3 CLASSPNP[0xF76BCFD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000067[0x83F25510]

5 ACPI[0xF7533620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x83F7A940]

\Driver\atapi[0x83E73C58] -> IRP_MJ_CREATE -> 0x83A644C0

error: Read A device attached to the system is not functioning.

kernel: MBR read successfully

_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [bP+0x0], CH; JL 0x2e; JNZ 0x3a; }

detected disk devices:

detected hooks:

\Driver\atapi DriverStartIo -> 0x83A642E0

user & kernel MBR OK

Warning: possible TDL3 rootkit infection !

.

============= FINISH: 14:23:11.65 ===============

ark.zip

protection-log-2011-09-03.zip

Link to post
Share on other sites

post-32477-1261866970.gif

Logs will be closed if you haven't replied within 3 days

Please do not attach the scan results from Combofx. Use copy/paste.

DO NOT use any TOOLS such as Combofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.

Vista and Windows 7 users:

1. These tools MUST be run from the executable. (.exe) every time you run them

2. With Admin Rights (Right click, choose "Run as Administrator")

Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.

Click the Tools menu, and then click Folder Options.

Click the View tab.

Uncheck "Hide file extensions for known file types."

Under the "Hidden files" folder, select "Show hidden files and folders."

Uncheck "Hide protected operating system files."

Click Apply, and then click OK.

Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.

Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.

When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:

Double-click on the Folder Options icon.

Click on the View tab.

If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.

Click on Show Hidden Files or Folders.

Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.

Remove the checkmark from the checkbox labeled Hide extensions for known file types.

Remove the checkmark from the checkbox labeled Hide protected operating system files.

Please do not delete anything unless instructed to.

Next:

Close all browsers before running ATF: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.

Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.

Under Main choose: Select All

Click the Empty Selected button.

If you use Firefox browser

  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser

  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from one of these locations:

Link 1

Link 2 If using this link, Right Click and select Save As.

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
  • Double click on ComboFix.exe & follow the prompts.
    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.
    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RC1.png

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC2-1.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.

2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.

3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.

4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.

Link to post
Share on other sites

Thank you for the detailed instructions. Here is the log from Combofx.

My computer seems to be running fine -- but I'm still getting those Malwarebytes blocking malicious sites - outgoing messages. The numbers are 208.87.32.69 and 208.87.33.151.

ComboFix 11-09-06.01 - Judy 09/06/2011 6:49.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.226 [GMT -4:00]

Running from: c:\documents and settings\Judy\Desktop\ComboFix.exe

AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\chrome\xulcache.jar

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\defaults\preferences\xulcache.js

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\install.rdf

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\chrome.manifest

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\chrome\xulcache.jar

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\defaults\preferences\xulcache.js

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\install.rdf

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\chrome.manifest

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\chrome\xulcache.jar

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\defaults\preferences\xulcache.js

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\install.rdf

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\chrome.manifest

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\chrome\xulcache.jar

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\defaults\preferences\xulcache.js

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\install.rdf

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\chrome.manifest

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\chrome\xulcache.jar

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\defaults\preferences\xulcache.js

c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ssyjpskv.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\install.rdf

c:\documents and settings\All Users\Application Data\Tarma Installer

c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll

c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll

c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat

c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe

c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\chrome\xulcache.jar

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\defaults\preferences\xulcache.js

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\install.rdf

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\chrome.manifest

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\chrome\xulcache.jar

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\defaults\preferences\xulcache.js

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\install.rdf

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\chrome.manifest

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\chrome\xulcache.jar

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\defaults\preferences\xulcache.js

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\install.rdf

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\chrome.manifest

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\chrome\xulcache.jar

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\defaults\preferences\xulcache.js

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\install.rdf

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\chrome.manifest

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\chrome\xulcache.jar

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\defaults\preferences\xulcache.js

c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\ol1vjjil.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\install.rdf

c:\documents and settings\Carlos\Local Settings\Application Data\{EDB2B720-1EBA-4E3A-A069-F9BD2DB6AB07}

c:\documents and settings\Carlos\Local Settings\Application Data\{EDB2B720-1EBA-4E3A-A069-F9BD2DB6AB07}\chrome.manifest

c:\documents and settings\Carlos\Local Settings\Application Data\{EDB2B720-1EBA-4E3A-A069-F9BD2DB6AB07}\chrome\content\_cfg.js

c:\documents and settings\Carlos\Local Settings\Application Data\{EDB2B720-1EBA-4E3A-A069-F9BD2DB6AB07}\chrome\content\overlay.xul

c:\documents and settings\Carlos\Local Settings\Application Data\{EDB2B720-1EBA-4E3A-A069-F9BD2DB6AB07}\install.rdf

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\chrome\xulcache.jar

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\defaults\preferences\xulcache.js

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\install.rdf

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\chrome.manifest

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\chrome\xulcache.jar

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\defaults\preferences\xulcache.js

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\install.rdf

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\chrome.manifest

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\chrome\xulcache.jar

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\defaults\preferences\xulcache.js

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\install.rdf

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\chrome.manifest

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\chrome\xulcache.jar

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\defaults\preferences\xulcache.js

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\install.rdf

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\chrome.manifest

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\chrome\xulcache.jar

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\defaults\preferences\xulcache.js

c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\install.rdf

c:\documents and settings\Judy\bnecqblmkb.tmp

c:\documents and settings\Judy\Local Settings\Application Data\{0552773B-9454-476F-BB46-0DD997757BFD}

c:\documents and settings\Judy\Local Settings\Application Data\{0552773B-9454-476F-BB46-0DD997757BFD}\chrome.manifest

c:\documents and settings\Judy\Local Settings\Application Data\{0552773B-9454-476F-BB46-0DD997757BFD}\chrome\content\_cfg.js

c:\documents and settings\Judy\Local Settings\Application Data\{0552773B-9454-476F-BB46-0DD997757BFD}\chrome\content\overlay.xul

c:\documents and settings\Judy\Local Settings\Application Data\{0552773B-9454-476F-BB46-0DD997757BFD}\install.rdf

c:\documents and settings\Judy\My Documents\4711.doc

c:\documents and settings\Judy\Recent\Thumbs.db

c:\documents and settings\Judy\WINDOWS

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\chrome\xulcache.jar

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\defaults\preferences\xulcache.js

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{1c0c2173-192d-44ab-8e73-24b8a849ac5d}\install.rdf

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\chrome.manifest

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\chrome\xulcache.jar

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\defaults\preferences\xulcache.js

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{7ee1a7a7-7316-4fb7-b8ba-6768b74e6cfe}\install.rdf

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\chrome.manifest

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\chrome\xulcache.jar

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\defaults\preferences\xulcache.js

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{ab634b6a-0d12-491e-aae9-57fa4bb9c05c}\install.rdf

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\chrome.manifest

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\chrome\xulcache.jar

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\defaults\preferences\xulcache.js

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{b3b94d55-1261-4cc1-8e58-fc3e06b675db}\install.rdf

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\chrome.manifest

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\chrome\xulcache.jar

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\defaults\preferences\xulcache.js

c:\documents and settings\Larry\Application Data\Mozilla\Firefox\Profiles\zxuu3ont.default\extensions\{e4c5c43c-78be-4fe4-883e-a68db2eddf61}\install.rdf

c:\documents and settings\Sarah\WINDOWS

c:\program files\messenger\msmsgsin.exe

c:\windows\idudixenibekepem.dll

c:\windows\TEMP\logishrd\LVPrcInj01.dll

c:\windows\winhelp.ini

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Legacy_WUAUSERV32

.

.

((((((((((((((((((((((((( Files Created from 2011-08-06 to 2011-09-06 )))))))))))))))))))))))))))))))

.

.

2011-09-02 11:39 . 2011-09-02 11:39 -------- d-----w- c:\documents and settings\Judy\Application Data\Sammsoft

2011-09-02 11:39 . 2011-09-04 13:14 -------- d-----w- c:\program files\ARO 2011

2011-09-02 11:27 . 2011-09-02 11:27 -------- d-----w- c:\windows\system32\wbem\Repository

2011-09-02 01:36 . 2011-09-02 01:36 -------- d-----w- c:\documents and settings\Judy\Application Data\Avira

2011-09-02 01:28 . 2011-09-03 15:32 -------- d-----w- c:\windows\system32\NtmsData

2011-09-02 01:26 . 2011-09-02 11:33 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2011-09-02 01:26 . 2011-09-02 11:33 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys

2011-09-02 01:26 . 2010-06-17 19:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys

2011-09-02 01:26 . 2010-06-17 19:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys

2011-09-02 01:26 . 2011-09-02 01:26 -------- d-----w- c:\program files\Avira

2011-09-02 01:26 . 2011-09-02 01:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira

2011-08-10 04:27 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys

2011-08-10 04:25 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys

2011-08-07 19:29 . 2011-08-07 19:29 -------- d-----w- c:\program files\MSBuild

2011-08-07 19:28 . 2011-08-07 19:28 -------- d-----w- c:\program files\Reference Assemblies

2011-08-07 19:28 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll

2011-08-07 19:27 . 2011-08-07 19:28 -------- d-----w- C:\cafb26ef80a2c6c95fde60

2011-08-07 19:27 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2011-08-07 19:27 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2011-08-07 19:27 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2011-08-07 19:27 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll

2011-08-07 19:27 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2011-08-07 19:27 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-08-13 11:23 . 2011-07-15 19:40 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-07-15 13:29 . 2002-08-29 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-07-08 14:02 . 2002-08-29 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys

2011-07-06 23:52 . 2011-05-04 15:45 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-07-06 23:52 . 2011-05-04 15:45 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-06-28 13:39 . 2011-01-06 10:49 398760 ----a-r- c:\windows\system32\cpnprt2.cid

2011-06-24 14:10 . 2010-01-27 23:48 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2011-06-23 18:36 . 2002-08-29 12:00 916480 ----a-w- c:\windows\system32\wininet.dll

2011-06-23 18:36 . 2002-08-29 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll

2011-06-23 18:36 . 2002-08-29 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

2011-06-23 12:05 . 2010-01-29 22:44 385024 ----a-w- c:\windows\system32\html.iec

2011-06-20 17:44 . 2002-08-29 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll

2011-09-01 02:37 . 2011-03-24 09:48 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]

2011-07-15 04:46 195360 ----a-w- c:\program files\Yontoo Layers Runtime\YontooIEClient_2.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{48405d3d-2674-4cd8-b1ef-9a719443bd3f}"= "c:\program files\Search_USA\tbSea0.dll" [2010-10-17 2735200]

"{2bae58c2-79f9-45d1-a286-81f911301c3a}"= "c:\program files\P2P_Energy\tbP2P1.dll" [2010-10-17 2735200]

"{ad708c09-d51b-45b3-9d28-4eba2681febf}"= "c:\program files\Download_Energy\tbDow1.dll" [2010-07-22 2515552]

.

[HKEY_CLASSES_ROOT\clsid\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}]

.

[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]

.

[HKEY_CLASSES_ROOT\clsid\{ad708c09-d51b-45b3-9d28-4eba2681febf}]

.

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{2BAE58C2-79F9-45D1-A286-81F911301C3A}"= "c:\program files\P2P_Energy\tbP2P1.dll" [2010-10-17 2735200]

"{48405D3D-2674-4CD8-B1EF-9A719443BD3F}"= "c:\program files\Search_USA\tbSea0.dll" [2010-10-17 2735200]

"{AD708C09-D51B-45B3-9D28-4EBA2681FEBF}"= "c:\program files\Download_Energy\tbDow1.dll" [2010-07-22 2515552]

.

[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]

.

[HKEY_CLASSES_ROOT\clsid\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}]

.

[HKEY_CLASSES_ROOT\clsid\{ad708c09-d51b-45b3-9d28-4eba2681febf}]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-02-16 39408]

"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2009-11-26 95632]

"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-07-16 5458704]

"i8kfangui"="c:\program files\I8kfanGUI\I8kfanGUI.exe" [2007-02-16 856064]

"AROReminder"="c:\program files\ARO 2011\aro.exe" [2011-01-25 2312048]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]

"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2009-11-26 54672]

"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"RunNarrator"="Narrator.exe" [2008-04-14 53760]

.

c:\documents and settings\Carlos\Start Menu\Programs\Startup\

OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\srvA00]

@="service"

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\AIM\\aim.exe"=

"c:\\Program Files\\SoulseekNS\\slsk.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\LimeWire\\LimeWire.exe"=

"c:\\Program Files\\eMule\\emule.exe"=

"c:\\Program Files\\eMulePlus\\eMule.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\FrostWire\\FrostWire.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"67:UDP"= 67:UDP:DHCP Server

.

R1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [1/31/2011 11:33 PM 14464]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/1/2011 9:26 PM 136360]

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5/4/2011 11:45 AM 366640]

R2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\VERIZONDM\bin\sprtsvc.exe [9/2/2010 5:46 AM 206120]

R2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\VERIZONDM\bin\tgsrvc.exe [9/2/2010 5:46 AM 185640]

R2 vseamps;vseamps;c:\program files\Common Files\Authentium\AntiVirus5\vseamps.exe [4/8/2010 4:46 PM 117288]

R2 vsedsps;vsedsps;c:\program files\Common Files\Authentium\AntiVirus5\vsedsps.exe [4/8/2010 4:46 PM 117288]

R2 vseqrts;vseqrts;c:\program files\Common Files\Authentium\AntiVirus5\vseqrts.exe [4/8/2010 4:46 PM 154152]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5/4/2011 11:45 AM 22712]

S2 ClipSrv32;ClipBook ;c:\windows\system32\wmploc32.exe --> c:\windows\system32\wmploc32.exe [?]

S2 CryptSvc32;Cryptographic Services ;c:\windows\system32\quartz32.exe --> c:\windows\system32\quartz32.exe [?]

S2 DcomLaunch32;DCOM Server Process Launcher ;c:\windows\system32\rasman32.exe --> c:\windows\system32\rasman32.exe [?]

S2 Dhcp32;DHCP Client ;c:\windows\system32\odtext3232.exe --> c:\windows\system32\odtext3232.exe [?]

S2 dmadmin3232;Logical Disk Manager Administrative Service ;c:\windows\system32\rtm32.exe --> c:\windows\system32\rtm32.exe [?]

S2 ERSvc32;Error Reporting Service ;c:\windows\system32\netui032.exe --> c:\windows\system32\netui032.exe [?]

S2 ERSvc3232;Error Reporting Service ;c:\windows\system32\wshatm32.exe --> c:\windows\system32\wshatm32.exe [?]

S2 FontCache3.0.0.032;Windows Presentation Foundation Font Cache 3.0.0.0 ;c:\windows\system32\pdh32.exe --> c:\windows\system32\pdh32.exe [?]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/16/2010 5:44 PM 135664]

S2 helpsvc32;Help and Support ;c:\windows\system32\inetpp32.exe --> c:\windows\system32\inetpp32.exe [?]

S2 LMIRescue_5ebd5304-3ca6-47cb-9603-d9a4b6ab657b;LogMeIn Rescue (5ebd5304-3ca6-47cb-9603-d9a4b6ab657b);"c:\docume~1\Sarah\LOCALS~1\Temp\LMIR0001.tmp\LMI_Rescue_srv.exe" -service -sid 5ebd5304-3ca6-47cb-9603-d9a4b6ab657b --> c:\docume~1\Sarah\LOCALS~1\Temp\LMIR0001.tmp\LMI_Rescue_srv.exe [?]

S2 NtLmSsp32;NT LM Security Support Provider ;c:\windows\system32\wmasf32.exe --> c:\windows\system32\wmasf32.exe [?]

S2 srvA00;srvA00;c:\windows\system32\svchost.exe -k netsvcs [8/29/2002 8:00 AM 14336]

S2 UPS32;Uninterruptible Power Supply ;c:\windows\system32\shimeng32.exe --> c:\windows\system32\shimeng32.exe [?]

S2 vsedsps32;vsedsps ;c:\windows\system32\kbdhu32.exe --> c:\windows\system32\kbdhu32.exe [?]

S2 wuauserv3232;Automatic Updates ;c:\windows\system32\iaspolcy32.exe --> c:\windows\system32\iaspolcy32.exe [?]

S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/16/2010 5:44 PM 135664]

S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [5/4/2011 11:45 AM 41272]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

getPlusHelper REG_MULTI_SZ getPlusHelper

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

srvA00

.

Contents of the 'Scheduled Tasks' folder

.

2011-02-01 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

.

2011-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-16 21:44]

.

2011-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-16 21:44]

.

2011-02-01 c:\windows\Tasks\ParetoLogic Update Version2.job

- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]

.

.

------- Supplementary Scan -------

.

uInternet Settings,ProxyOverride = <local>

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

TCP: DhcpNameServer = 192.168.1.1 192.168.1.1

DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

FF - ProfilePath - c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=

FF - prefs.js: browser.search.selectedEngine - Bing

FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 64242

FF - prefs.js: network.proxy.type - 0

FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(yahoo.homepage.dontask, true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(extentions.y2layers.installId, 0f23a4c7-fef6-4ad8-9201-717df781bb56

FF - user.js: extentions.y2layers.installId - 032cccb3-48a5-48fa-a037-36f99cf47c05

FF - user.js: extentions.y2layers.installId - 5c10a373-8026-4409-80e1-8ecd03661f88

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

HKLM-Run-Txipibikixezib - c:\windows\idudixenibekepem.dll

SafeBoot-klmdb.sys

AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\docume~1\ALLUSE~1\APPLIC~1\TARMAI~1\{889DF~1\Setup.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-09-06 07:17

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net

Windows 5.1.2600 Disk: WDC_WD3200AAJS-22RYA0 rev.12.01B01 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3

.

device: opened successfully

user: MBR read successfully

error: Read A device attached to the system is not functioning.

kernel: MBR read successfully

detected disk devices:

detected hooks:

\Driver\atapi DriverStartIo -> 0x83BC12E0

user & kernel MBR OK

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\srvA00]

"servicedll"="\\?\globalroot\Device\HarddiskVolume1\WINDOWS\Temp\srvA00.tmp"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Windows\AutorunsDisabled]

"Appinit_Dlls"="c:\\WINDOWS\\system32\\nmevtmsg32.dll"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'winlogon.exe'(768)

c:\windows\system32\Ati2evxx.dll

c:\windows\system32\l3codeca.acm

.

- - - - - - - > 'explorer.exe'(3116)

c:\windows\system32\WININET.dll

c:\windows\TEMP\logishrd\LVPrcInj01.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\System32\Ati2evxx.exe

c:\windows\system32\Ati2evxx.exe

c:\windows\system32\rundll32.exe

c:\program files\Avira\AntiVir Desktop\avguard.exe

c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Avira\AntiVir Desktop\avshadow.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe

c:\program files\iPod\bin\iPodService.exe

.

**************************************************************************

.

Completion time: 2011-09-06 07:24:50 - machine was rebooted

ComboFix-quarantined-files.txt 2011-09-06 11:24

.

Pre-Run: 275,988,094,976 bytes free

Post-Run: 277,145,915,392 bytes free

.

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

.

- - End Of File - - 606FCDBBD41D2CEC743EC66C90115E4A

Link to post
Share on other sites

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:

Click Start > Run type Notepad click OK.

This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::

FireFox::
FF - ProfilePath - c:\documents and settings\Judy\Application Data\Mozilla\Firefox\Profiles\j52sfuq9.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 64242
FF - prefs.js: network.proxy.type - 0

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;

2.Click Save As... Change the directory to your desktop;

3.Change the Save as type to "All Files";

4.Type in the file name: CFScript

5.Click Save ...

CFScriptB-4.gif

Drag CFScript.txt into ComboFix.exe

Then post the results log using Copy / Paste

Also please describe how your computer behaves at the moment.

Link to post
Share on other sites

if the data led on the hard drive is flashing then it's still working.

You can do this:

If CF still stalls, have him bring up Task Manage using CTRL+ALT+DELETE. See if any of these processes are running, and End Task on them one at a time and see if it frees up CF:

pev

findstr

sed

grep

nircmd

nircmd

swsc

* .. or any other process that has the .cfexe extension except for CFxxx.cfexe

Link to post
Share on other sites

if the data led on the hard drive is flashing then it's still working.

You can do this:

If CF still stalls, have him bring up Task Manage using CTRL+ALT+DELETE. See if any of these processes are running, and End Task on them one at a time and see if it frees up CF:

pev

findstr

sed

grep

nircmd

nircmd

swsc

* .. or any other process that has the .cfexe extension except for CFxxx.cfexe

There are a whole bunch of processes running - the only one of those that I saw was pev -- when I tried to end process I couldn't tell if it worked or not - its still listed in the window.

It is still flashing.

Link to post
Share on other sites

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18

Run by Judy at 19:30:12 on 2011-09-06

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.126 [GMT -4:00]

.

AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}

.

============== Running Processes ===============

.

C:\WINDOWS\system32\svchost.exe -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\svchost.exe -k imgsvc

C:\WINDOWS\Explorer.EXE

C:\ComboFix\CF17582.3XE

C:\WINDOWS\PEV.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

.

============== Pseudo HJT Report ===============

.

uInternet Settings,ProxyOverride = <local>

mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers runtime\YontooIEClient_2.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

TB: Download Energy Toolbar: {2bae58c2-79f9-45d1-a286-81f911301c3a} - c:\program files\p2p_energy\tbP2P1.dll

TB: Discover USA Toolbar: {48405d3d-2674-4cd8-b1ef-9a719443bd3f} - c:\program files\search_usa\tbSea0.dll

TB: Download Energy Toolbar: {ad708c09-d51b-45b3-9d28-4eba2681febf} - c:\program files\download_energy\tbDow1.dll

TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll

EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe"

uRun: [Logitech Vid] "c:\program files\logitech\logitech vid\vid.exe" -bootmode

uRun: [i8kfangui] c:\program files\i8kfangui\I8kfanGUI.exe /startup

uRun: [AROReminder] c:\program files\aro 2011\aro.exe -rem

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\FirstStart.exe" /OM

mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min

dRunOnce: [RunNarrator] Narrator.exe

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

TCP: DhcpNameServer = 192.168.1.1 192.168.1.1

TCP: Interfaces\{66C8DB40-0463-4ACE-AFF2-AB9F7DEC0263} : DhcpNameServer = 192.168.1.1 192.168.1.1

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

Notify: AtiExtEvent - Ati2evxx.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\documents and settings\judy\application data\mozilla\firefox\profiles\j52sfuq9.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=

FF - prefs.js: browser.search.selectedEngine - Bing

FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 64242

FF - prefs.js: network.proxy.type - 0

FF - plugin: c:\documents and settings\judy\application data\facebook\npfbplugin_1_0_3.dll

FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll

FF - plugin: c:\program files\google\picasa3\npPicasa3.dll

FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll

FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll

FF - plugin: c:\program files\olympus\ib utilities\firefox plugin\npIbInst.dll

.

---- FIREFOX POLICIES ----

FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(yahoo.homepage.dontask, true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(extentions.y2layers.installId, 0f23a4c7-fef6-4ad8-9201-717df781bb56

FF - user.js: extentions.y2layers.installId - 032cccb3-48a5-48fa-a037-36f99cf47c05

FF - user.js: extentions.y2layers.installId - 5c10a373-8026-4409-80e1-8ecd03661f88

.

============= SERVICES / DRIVERS ===============

.

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-9-1 11608]

R1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [2011-1-31 14464]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-9-1 136360]

R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-9-1 269480]

R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-9-1 66616]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-5-4 22712]

S2 ClipSrv32;ClipBook ;c:\windows\system32\wmploc32.exe --> c:\windows\system32\wmploc32.exe [?]

S2 CryptSvc32;Cryptographic Services ;c:\windows\system32\quartz32.exe --> c:\windows\system32\quartz32.exe [?]

S2 DcomLaunch32;DCOM Server Process Launcher ;c:\windows\system32\rasman32.exe --> c:\windows\system32\rasman32.exe [?]

S2 Dhcp32;DHCP Client ;c:\windows\system32\odtext3232.exe --> c:\windows\system32\odtext3232.exe [?]

S2 dmadmin3232;Logical Disk Manager Administrative Service ;c:\windows\system32\rtm32.exe --> c:\windows\system32\rtm32.exe [?]

S2 ERSvc32;Error Reporting Service ;c:\windows\system32\netui032.exe --> c:\windows\system32\netui032.exe [?]

S2 ERSvc3232;Error Reporting Service ;c:\windows\system32\wshatm32.exe --> c:\windows\system32\wshatm32.exe [?]

S2 FontCache3.0.0.032;Windows Presentation Foundation Font Cache 3.0.0.0 ;c:\windows\system32\pdh32.exe --> c:\windows\system32\pdh32.exe [?]

S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-16 135664]

S2 helpsvc32;Help and Support ;c:\windows\system32\inetpp32.exe --> c:\windows\system32\inetpp32.exe [?]

S2 LMIRescue_5ebd5304-3ca6-47cb-9603-d9a4b6ab657b;LogMeIn Rescue (5ebd5304-3ca6-47cb-9603-d9a4b6ab657b);"c:\docume~1\sarah\locals~1\temp\lmir0001.tmp\lmi_rescue_srv.exe" -service -sid 5ebd5304-3ca6-47cb-9603-d9a4b6ab657b --> c:\docume~1\sarah\locals~1\temp\lmir0001.tmp\LMI_Rescue_srv.exe [?]

S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-5-4 366640]

S2 NtLmSsp32;NT LM Security Support Provider ;c:\windows\system32\wmasf32.exe --> c:\windows\system32\wmasf32.exe [?]

S2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\verizondm\bin\sprtsvc.exe [2010-9-2 206120]

S2 srvA00;srvA00;c:\windows\system32\svchost.exe -k netsvcs [2002-8-29 14336]

S2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\verizondm\bin\tgsrvc.exe [2010-9-2 185640]

S2 UPS32;Uninterruptible Power Supply ;c:\windows\system32\shimeng32.exe --> c:\windows\system32\shimeng32.exe [?]

S2 vseamps;vseamps;c:\program files\common files\authentium\antivirus5\vseamps.exe [2010-4-8 117288]

S2 vsedsps;vsedsps;c:\program files\common files\authentium\antivirus5\vsedsps.exe [2010-4-8 117288]

S2 vsedsps32;vsedsps ;c:\windows\system32\kbdhu32.exe --> c:\windows\system32\kbdhu32.exe [?]

S2 vseqrts;vseqrts;c:\program files\common files\authentium\antivirus5\vseqrts.exe [2010-4-8 154152]

S2 wuauserv3232;Automatic Updates ;c:\windows\system32\iaspolcy32.exe --> c:\windows\system32\iaspolcy32.exe [?]

S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-16 135664]

S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-5-4 41272]

.

=============== Created Last 30 ================

.

2011-09-06 20:04:49 -------- d-s---w- C:\ComboFix

2011-09-06 10:44:56 -------- d-sha-r- C:\cmdcons

2011-09-06 10:28:39 98816 ----a-w- c:\windows\sed.exe

2011-09-06 10:28:39 518144 ----a-w- c:\windows\SWREG.exe

2011-09-06 10:28:39 256000 ----a-w- c:\windows\PEV.exe

2011-09-06 10:28:39 208896 ----a-w- c:\windows\MBR.exe

2011-09-02 11:39:20 -------- d-----w- c:\documents and settings\judy\application data\Sammsoft

2011-09-02 11:39:05 -------- d-----w- c:\program files\ARO 2011

2011-09-02 11:27:52 -------- d-----w- c:\windows\system32\wbem\repository\FS

2011-09-02 11:27:52 -------- d-----w- c:\windows\system32\wbem\Repository

2011-09-02 01:36:43 -------- d-----w- c:\documents and settings\judy\application data\Avira

2011-09-02 01:28:39 -------- d-----w- c:\windows\system32\NtmsData

2011-09-02 01:26:38 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2011-09-02 01:26:37 -------- d-----w- c:\program files\Avira

2011-09-02 01:26:37 -------- d-----w- c:\documents and settings\all users\application data\Avira

2011-08-10 04:27:56 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys

2011-08-10 04:25:31 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys

.

==================== Find3M ====================

.

2011-09-05 10:27:02 0 ----a-w- c:\windows\Ggulusaxup.bin

2011-08-13 11:23:55 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys

2011-07-06 23:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-07-06 23:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-06-28 13:39:09 398760 ----a-r- c:\windows\system32\cpnprt2.cid

2011-06-24 14:10:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys

2011-06-23 18:36:30 916480 ----a-w- c:\windows\system32\wininet.dll

2011-06-23 18:36:30 43520 ----a-w- c:\windows\system32\licmgr10.dll

2011-06-23 18:36:30 1469440 ------w- c:\windows\system32\inetcpl.cpl

2011-06-23 12:05:13 385024 ----a-w- c:\windows\system32\html.iec

2011-06-20 17:44:52 293376 ----a-w- c:\windows\system32\winsrv.dll

.

=================== ROOTKIT ====================

.

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net

Windows 5.1.2600 Disk: WDC_WD3200AAJS-22RYA0 rev.12.01B01 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3

.

device: opened successfully

user: MBR read successfully

.

Disk trace:

called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x83BC14C0]<<

c:\docume~1\judy\locals~1\temp\catchme.sys

_asm { MOV EAX, [ESP+0x4]; MOV ECX, [0x83bc88a4]; PUSH ESI; MOV ESI, [ESP+0xc]; PUSH EDI; MOV EDI, [ESI+0x60]; CMP EAX, [0x83bc8730]; JNZ 0x1f; MOV [ESP+0xc], ECX; }

1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x83D5BAB8]

3 CLASSPNP[0xF74FBFD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000068[0x83D6CF18]

5 ACPI[0xF7372620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x83CFD940]

\Driver\atapi[0x83BE7510] -> IRP_MJ_CREATE -> 0x83BC14C0

error: Read A device attached to the system is not functioning.

kernel: MBR read successfully

_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [bP+0x0], CH; JL 0x2e; JNZ 0x3a; }

detected disk devices:

detected hooks:

\Driver\atapi DriverStartIo -> 0x83BC12E0

user & kernel MBR OK

Warning: possible TDL3 rootkit infection !

.

============= FINISH: 19:30:52.78 ===============

Link to post
Share on other sites

Looks like you have a RootKit and that's why combofix won't run.

Next:

Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    TDSSKillermain.png
  • If an infected file is detected, the default action will be Cure, click on Continue.
    TDSSKillerMal-1.png
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
    TDSSKillerSuspicious.png
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    TDSSKillerCompleted.png
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

please post the contents of that log TDSSKiller log.

Also please describe how your computer behaves at the moment.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.