Running windows vista and having issues with windows updates that do not seem to be fixable by non-malware tools. Here is a link to the thread before things turned malware related and was requested to be started fresh here:
http://www.bleepingcomputer.com/forums/topic455492.html/page__st__15While searching for those tools I came across and ran microsoft security scanner which found and removed 5 items:
TrojanClicker:ASX/Wimad.cp
TrojanDownloader:ASX/Wimad.AN
TrojanDownloader:ASX/Wimad.BQ
TrojanDownloader:ASX/Wimad.CJ
TrojanDownloader:ASX/Wimad.W
After this discovery it was requested that I update and run malwarebytes which came up clean.
It was also requested that I run security check, here is the log:
Results of screen317's Security Check version 0.99.41
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled!
BullGuard Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware version 1.61.0.1400
CCleaner
JavaFX 2.1.0
Java 7 Update 4
Adobe Flash Player 11.1.102.55
Adobe Reader X (10.1.3)
````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: 1 %
````````````````````End of Log`````````````````````` It was also requested that I run superantispyware, here is the log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 06/04/2012 at 06:01 PM
Application Version : 5.0.1150
Core Rules Database Version : 8681
Trace Rules Database Version: 6493
Scan type : Complete Scan
Total Scan Time : 00:50:24
Operating System Information
Windows Vista Home Premium 32-bit, Service Pack 2 (Build 6.00.6002)
UAC On - Limited User (Administrator User)
Memory items scanned : 698
Memory threats detected : 0
Registry items scanned : 36615
Registry threats detected : 0
File items scanned : 52385
File threats detected : 20
Adware.Tracking Cookie
C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Cookies\IKNIMN1Q.txt [ /atdmt.com ]
C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Cookies\AD0F33K5.txt [ /c1.atdmt.com ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\ENAPIIEX.txt [ Cookie:scott@ads.pointroll.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\OUK3IQT4.txt [ Cookie:scott@ad.yieldmanager.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\XNVW8Y7U.txt [ Cookie:scott@pointroll.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\D0BNCQPH.txt [ Cookie:scott@microsoftsto.112.2o7.net/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\XD3FZDHM.txt [ Cookie:scott@adxpose.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\EZPK15W6.txt [ Cookie:scott@casalemedia.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\LPDY8WEH.txt [ Cookie:scott@interclick.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\JV29I1F3.txt [ Cookie:scott@dmtracker.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\O2L5JSD2.txt [ Cookie:scott@h.atdmt.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\PBWU140Z.txt [ Cookie:scott@lucidmedia.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\S9RJDGUA.txt [ Cookie:scott@c1.atdmt.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\2JWB7R1G.txt [ Cookie:scott@a1.interclick.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\O5QIPYJG.txt [ Cookie:scott@adsonar.com/adserving ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\CUGEJEA8.txt [ Cookie:scott@imrworldwide.com/cgi-bin ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\HV9KIM1J.txt [ Cookie:scott@revsci.net/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\P4L6INTL.txt [ Cookie:scott@invitemedia.com/ ]
C:\USERS\SCOTT\AppData\Roaming\Microsoft\Windows\Cookies\Low\1MAHDSOK.txt [ Cookie:scott@c.atdmt.com/ ]
C:\USERS\SCOTT\Cookies\AD0F33K5.txt [ Cookie:scott@c1.atdmt.com/ ]
It was also requested that I run GMER, here is the log:
GMER 1.0.15.15641 -
http://www.gmer.netRootkit scan 2012-06-05 07:58:02
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST375064 rev.3.CH
Running: 80q00qdp.exe; Driver: C:\Users\Scott\AppData\Local\Temp\kwldypod.sys
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe[3644] USER32.dll!SetScrollInfo + 4 764E71DC 3 Bytes [09, 90, 90]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74787817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [747DA86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7478BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7477F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [747875E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7477E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [747B8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7478DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7477FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7477FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [747771CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7480CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [747AC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7477D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74776853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7477687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1356] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74782AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler@Heartbeat 0x80 0xCA 0xBF 0x03 ...
---- EOF - GMER 1.0.15 ----
Note: I originally ran GMER last night but I was unable to finish it before I had to head to work so I stopped it and ran it again this morning. I am noting this because I am unsure if that was a good thing or not.
Thanks to everyone so much who has assisted me so far on this, it is truly appreciated.
4