Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Rootkit svchost.exe (*** hidden *** )[AUTO] xzlbgaows


  • This topic is locked This topic is locked
10 replies to this topic

#1 PcRebel

PcRebel

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:31 PM

Posted 01 April 2010 - 01:32 AM

Compaq Presario 6000 Series XP Pro SP2 Pent 4 CPU 1.90 GHz 1 Gig ram
My network became completely disabled and plugging straight into the modem was no help so I had to to reformat/reinstall last night. I hoped that might solve the problem, and it did, but only very briefly. When I open IE 6 I am very limited to website access. Most of them say the site can't be found. Can't install AV protection. Tried AVG but setup says I don't have internet connection. Can't enable windows firewall, says access denied. Only got a couple of updates from Microsoft and can't get any more. The update icon in taskbar says downloading updates but stays at 0%. Can't access Microsoft websites or any websites having to do with AV or any type of malware programs. Barely managed to install Malwarebytes and Spywareblaster but can't update either of them. Says I have no internet connection. Tremendous amount of errors logged in event viewer such as:
DCOM got error "The service cannot be started, either because it is disabled or

because it has no enabled devices associated with it. " attempting to start the

service BITS with arguments "" in order to run the server:
{4991D34B-80A1-4291-83B6-3328366B9097}

The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: Access is denied. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Malwarebytes found the infection below and removed it several times before I reformatted but it kept reappearing. It also found it again a little while ago (since reinstall) and said it removed it but if it did, I'm sure it's back again lurking in there somewhere. Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. This is where my problems seemed to originate from in the beginning.

I currently am able to access bleepingcomputer.com website only by using AOL. IE can't find it. That's really strange since AOL is only a front end on IE. Is there any advice or immediate measures I can take as I won't have web access much longer? I would very much appreciate any help at all. Thanks in advance. Here is the log from DDS. Attach.txt and ark.txt are attached.

DDS (Ver_10-03-17.01) - NTFSx86
Run by Dawn at 23:33:31.57 on Wed 03/31/2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.991.505 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\AOL\1270058127\ee\AOLSoftware.exe
C:\Program Files\AOL 9.5\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\AOL 9.5\shellmon.exe
C:\Documents and Settings\Dawn\Application Data\mjusbsp\magicJack.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Dawn\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uURLSearchHooks: AOL Toolbar Search Class: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - c:\program files\aol toolbar\aoltb.dll
mURLSearchHooks: AOL Toolbar Search Class: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - c:\program files\aol toolbar\aoltb.dll
BHO: AOL Toolbar Loader: {3ef64538-8b54-4573-b48f-4d34b0238ab2} - c:\program files\aol toolbar\aoltb.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AOL Toolbar: {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - c:\program files\aol toolbar\aoltb.dll
uRun: [cdloader] "c:\documents and settings\dawn\application data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [AOL Fast Start] "c:\program files\aol 9.5\AOL.EXE" -b
mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [HostManager] c:\program files\common files\aol\1270058127\ee\AOLSoftware.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

============= SERVICES / DRIVERS ===============

S2 xzlbgaows;Config Center;c:\windows\system32\svchost.exe -k netsvcs [2004-8-3 14336]

=============== Created Last 30 ================

2010-04-01 02:45:29 16 ----a-w- c:\windows\system\cmicnfg.ini
2010-04-01 02:38:14 0 d--h--w- c:\windows\system32\GroupPolicy
2010-04-01 02:19:15 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2010-04-01 02:19:15 1071088 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2010-04-01 02:19:14 0 d-----w- c:\program files\SpywareBlaster
2010-03-31 22:31:31 0 d-----w- c:\docume~1\dawn\applic~1\Malwarebytes
2010-03-31 22:31:28 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-31 22:31:25 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-31 22:31:24 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-31 22:31:24 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-31 17:57:27 0 d-----w- c:\docume~1\dawn\applic~1\AOL
2010-03-31 17:56:47 0 d-----w- c:\docume~1\alluse~1\applic~1\Viewpoint
2010-03-31 17:56:46 0 d-----w- c:\program files\Viewpoint
2010-03-31 17:56:32 0 d-----w- c:\docume~1\alluse~1\applic~1\AOL Toolbar
2010-03-31 17:56:31 0 d-----w- c:\program files\AOL Toolbar
2010-03-31 17:56:29 0 d-----w- c:\program files\common files\Software Update Utility
2010-03-31 17:56:01 33588 ----a-r- c:\windows\system32\drivers\wanatw4.sys
2010-03-31 17:55:16 0 d-----w- c:\program files\common files\aolshare
2010-03-31 17:55:16 0 d-----w- c:\program files\common files\aol
2010-03-31 17:55:16 0 d-----w- c:\program files\AOL 9.5
2010-03-31 07:29:41 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-03-31 07:29:41 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-31 06:27:08 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-03-31 06:27:08 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-03-31 06:27:07 0 d-----w- c:\docume~1\dawn\applic~1\mjusbsp
2010-03-31 06:26:52 59264 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-03-31 06:26:52 59264 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-03-31 06:26:47 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2010-03-31 06:26:43 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-03-31 06:26:43 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-03-31 03:57:45 0 d-s---w- c:\documents and settings\dawn\UserData
2010-03-31 03:34:26 0 d-----w- c:\windows\system32\PreInstall
2010-03-31 03:34:25 22752 ----a-w- c:\windows\system32\spupdsvc.exe
2010-03-31 03:34:23 0 d--h--w- c:\windows\$hf_mig$
2010-03-31 03:02:33 0 d-s---w- c:\windows\system32\Microsoft
2010-03-31 03:02:19 8192 ----a-w- c:\windows\REGLOCS.OLD
2010-03-31 02:55:13 0 d-sh--w- c:\documents and settings\all users\DRM
2010-03-31 02:54:39 0 d--h--w- c:\program files\WindowsUpdate
2010-03-31 02:53:35 0 d-----w- c:\program files\common files\MSSoap
2010-03-31 02:51:37 0 d-----w- c:\program files\Online Services
2010-03-31 02:51:29 0 d-----w- c:\program files\Messenger
2010-03-31 02:51:25 0 d-----w- c:\program files\MSN Gaming Zone
2010-03-31 02:50:34 0 d-----w- c:\program files\Windows NT
2010-03-30 21:39:35 0 d-----w- c:\program files\common files\ODBC
2010-03-30 21:39:31 0 d-----w- c:\program files\common files\SpeechEngines
2010-03-30 21:38:58 0 d-----r- c:\documents and settings\all users\Documents

==================== Find3M ====================

2010-03-31 02:52:11 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-23 14:54:52 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-23 14:54:52 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-02-12 01:22:31 103752 ----a-w- c:\windows\system32\AOLDial.dll
2010-02-12 01:22:17 33400 ----a-w- c:\windows\system32\drivers\atwpkt264.sys
2010-02-12 01:22:15 24904 ----a-w- c:\windows\system32\drivers\atwpkt2.sys
2004-08-04 01:07:00 166555 --sha-r- c:\windows\system32\qzjqw.dll

============= FINISH: 23:34:32.35 ===============


Attached Files



BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:31 PM

Posted 02 April 2010 - 01:42 PM

Hello there,

Seems you're infected with a quite a variety of different infections here. One of them seems to be Conficker.

See if you can get Combofix to run if not we'll try something else.

Download and Run ComboFix

Note to readers of this post other than the starter of this thread:
ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance of an expert.

Download Combofix from any of the links below, and save it to your desktop.
Link 1
Link 2

Please refer to this page for full instructions on how to run ComboFix.
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click ComboFix.exe to start the program. Agree to the prompts.
  • When ComboFix is finished, a log report (C:\ComboFix.txt) will open. Post back with it.
Leave your computer alone while ComboFix is running.

ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may call it to stall.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 PcRebel

PcRebel
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:31 PM

Posted 02 April 2010 - 10:51 PM

Hi extremeboy, Thank you so much for your help! I managed to get Avast installed by downloading the setup to a flash drive. Needless to say sirens went off immediately and the flash drive must have gotten infected the minute I opened it. Avast found these:
BV:AutoRun-5[Wrm] was found in F:\Autorun.inf file
BV:AutoRun-5[Wrm] was found in G:\Autorun.inf file
BV:AutoRun-5[Wrm] was found in G:\Autorun.inf file
BV:AutoRun-5[Wrm] was found in G:\Autorun.inf file
Win32:Confi[Wrm] was found in C:\System Volume Information
They were quarantined but I just wanted them gone so I deleted them. I knew it was still wormy though even though I was now able to download MS updates. Ohhhh, the Conficker worm is one nasty nightmare! Just wanted to fill you in on that bit of info before I posted the ComboFix log. I'll be waiting to hear back from you to tell me what the next step is. Thanks again and have a nice night! thumbup2.gif

ComboFix 10-04-01.02 - Dawn 04/02/2010 23:29:54.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.991.739 [GMT -4:00]
Running from: c:\documents and settings\Dawn\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100402-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\AppPatch\AcAdProc.dll
c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((( Files Created from 2010-03-03 to 2010-04-03 )))))))))))))))))))))))))))))))
.

2010-04-02 08:51 . 2010-04-02 08:51 -------- d-----w- c:\windows\system32\scripting
2010-04-02 08:51 . 2010-04-02 08:51 -------- d-----w- c:\windows\l2schemas
2010-04-02 08:51 . 2010-04-02 08:51 -------- d-----w- c:\windows\system32\en
2010-04-02 01:01 . 2008-04-14 00:12 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-04-02 00:50 . 2010-04-02 08:48 -------- d-----w- c:\windows\ServicePackFiles
2010-04-02 00:25 . 2004-08-04 03:29 25471 ------w- c:\windows\system32\drivers\watv10nt.sys
2010-04-02 00:25 . 2004-08-04 03:29 22271 ------w- c:\windows\system32\drivers\watv06nt.sys
2010-04-02 00:25 . 2004-08-04 03:29 11935 ------w- c:\windows\system32\drivers\wadv11nt.sys
2010-04-02 00:25 . 2004-08-04 03:29 11871 ------w- c:\windows\system32\drivers\wadv09nt.sys
2010-04-02 00:25 . 2004-08-04 03:29 11807 ------w- c:\windows\system32\drivers\wadv07nt.sys
2010-04-02 00:25 . 2004-08-04 03:29 11295 ------w- c:\windows\system32\drivers\wadv08nt.sys
2010-04-02 00:21 . 2004-08-04 03:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
2010-04-01 23:11 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-04-01 23:11 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-04-01 23:09 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-04-01 23:08 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-04-01 23:00 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-04-01 23:00 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-04-01 22:59 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-04-01 22:59 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-04-01 22:59 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-04-01 22:59 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2010-04-01 22:59 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-04-01 22:59 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-04-01 22:59 . 2009-06-25 08:25 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2010-04-01 22:59 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-04-01 22:59 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-04-01 22:59 . 2009-12-08 19:26 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-04-01 22:59 . 2009-12-08 19:27 2189184 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-04-01 22:59 . 2009-12-08 18:43 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-04-01 22:52 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-04-01 22:47 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-04-01 22:47 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-04-01 22:39 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-04-01 22:38 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-04-01 22:38 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-04-01 19:24 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-04-01 19:24 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-04-01 19:24 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-04-01 19:24 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-04-01 19:24 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-04-01 19:24 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-04-01 19:24 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-04-01 19:24 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-04-01 19:23 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2010-04-01 19:23 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2010-04-01 19:23 . 2010-04-01 19:23 -------- d-----w- c:\program files\Alwil Software
2010-04-01 02:38 . 2010-04-01 02:38 -------- d--h--w- c:\windows\system32\GroupPolicy
2010-04-01 02:36 . 2010-04-02 17:34 13104 ----a-w- c:\documents and settings\Dawn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-01 02:19 . 2010-04-03 03:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-01 02:19 . 2005-08-26 00:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2010-04-01 02:19 . 2010-04-01 02:19 -------- d-----w- c:\program files\SpywareBlaster
2010-03-31 23:10 . 2010-03-31 23:10 -------- d-----w- c:\documents and settings\Dawn\Local Settings\Application Data\tjnet
2010-03-31 22:31 . 2010-03-31 22:31 -------- d-----w- c:\documents and settings\Dawn\Application Data\Malwarebytes
2010-03-31 22:31 . 2009-02-11 15:19 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-31 22:31 . 2009-02-11 15:19 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-31 22:31 . 2010-03-31 22:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-31 22:31 . 2010-03-31 22:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-31 18:50 . 2010-03-31 18:50 -------- d-----w- c:\documents and settings\Dawn\Local Settings\Application Data\AOL Toolbar
2010-03-31 17:57 . 2010-03-31 17:57 -------- d-----w- c:\documents and settings\Dawn\Application Data\AOL
2010-03-31 17:50 . 2010-03-31 17:50 43496 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol_single\4337.185.4.1\noneCodesignFilesBundle.exe
2010-03-31 17:40 . 2010-03-31 17:50 48321040 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol_single\4337.185.4.1\setup.exe
2010-03-31 17:40 . 2010-03-31 17:40 335 ----a-w- c:\windows\nsreg.dat
2010-03-31 07:31 . 2010-03-31 07:31 -------- d-----w- c:\windows\Sun
2010-03-31 07:30 . 2010-03-31 07:30 503808 ----a-w- c:\documents and settings\Dawn\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7f5a6fa7-n\msvcp71.dll
2010-03-31 07:30 . 2010-03-31 07:30 499712 ----a-w- c:\documents and settings\Dawn\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7f5a6fa7-n\jmc.dll
2010-03-31 07:30 . 2010-03-31 07:30 348160 ----a-w- c:\documents and settings\Dawn\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7f5a6fa7-n\msvcr71.dll
2010-03-31 07:30 . 2010-03-31 07:30 -------- d-----w- c:\program files\Common Files\Java
2010-03-31 07:29 . 2010-03-31 07:29 61440 ----a-w- c:\documents and settings\Dawn\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6bbabe67-n\decora-sse.dll
2010-03-31 07:29 . 2010-03-31 07:29 12800 ----a-w- c:\documents and settings\Dawn\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6bbabe67-n\decora-d3d.dll
2010-03-31 07:29 . 2010-03-31 07:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-31 07:29 . 2010-03-31 07:29 -------- d-----w- c:\program files\Java
2010-03-31 06:39 . 2010-03-31 06:54 864256 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\ocp\ocpinst.exe
2010-03-31 06:38 . 2010-03-31 06:54 6144 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\afix\ocfcheck.dll
2010-03-31 06:38 . 2010-03-31 06:54 390704 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\afix\WinsockFix.exe
2010-03-31 06:38 . 2010-03-31 06:54 99464 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\sm\sminstlp.exe
2010-03-31 06:38 . 2010-03-31 06:54 63024 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\ocp\instSup.dll
2010-03-31 06:38 . 2010-03-31 06:54 61440 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\vwpt\VPPrePop.exe
2010-03-31 06:38 . 2010-03-31 06:53 1104960 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\toolbar\toolbar.exe
2010-03-31 06:38 . 2010-03-31 17:40 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2010-03-31 06:28 . 2010-02-26 23:51 6870864 ---ha-w- c:\documents and settings\Dawn\Application Data\mjusbsp\Upgrade\setup1.exe
2010-03-31 06:28 . 2010-02-26 23:45 743872 ---ha-w- c:\documents and settings\Dawn\Application Data\mjusbsp\Upgrade\install1.exe
2010-03-31 06:27 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-03-31 06:27 . 2010-04-03 00:30 -------- d-----w- c:\documents and settings\Dawn\Application Data\mjusbsp
2010-03-31 06:26 . 2008-04-13 18:45 60032 ----a-w- c:\windows\system32\drivers\usbaudio.sys
2010-03-31 06:26 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-03-31 03:57 . 2010-03-31 03:57 -------- d-sh--w- c:\documents and settings\Dawn\UserData
2010-03-31 03:47 . 2010-03-31 03:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive
2010-03-31 03:34 . 2007-07-27 14:41 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2010-03-31 03:34 . 2010-04-02 20:09 -------- d--h--w- c:\windows\$hf_mig$
2010-03-31 03:00 . 2004-08-04 01:07 41600 -c--a-w- c:\windows\system32\dllcache\weitekp9.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-02 08:56 . 2010-03-31 02:55 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-31 23:11 . 2010-03-31 17:55 -------- d-----w- c:\program files\AOL 9.5
2010-03-31 17:57 . 2010-03-31 17:55 -------- d-----w- c:\program files\Common Files\aol
2010-03-31 17:57 . 2010-03-31 17:55 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2010-03-31 17:57 . 2010-03-31 17:55 -------- d-----w- c:\program files\Common Files\aolshare
2010-03-31 17:56 . 2010-03-31 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-03-31 17:56 . 2010-03-31 17:56 -------- d-----w- c:\program files\Viewpoint
2010-03-31 17:56 . 2010-03-31 17:56 -------- d-----w- c:\program files\AOL Toolbar
2010-03-31 17:56 . 2010-03-31 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Toolbar
2010-03-31 17:56 . 2010-03-31 17:56 -------- d-----w- c:\program files\Common Files\Software Update Utility
2010-03-31 17:55 . 2010-03-31 17:55 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL OCP
2010-03-31 02:57 . 2010-03-31 02:57 -------- d-----w- c:\program files\microsoft frontpage
2010-03-31 02:52 . 2010-03-31 02:52 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-23 14:54 . 2010-03-23 14:54 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-23 14:54 . 2010-03-23 14:54 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-03-11 12:38 . 2004-08-04 01:07 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 01:07 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2004-08-04 01:07 17408 ------w- c:\windows\system32\corpol.dll
2010-02-26 23:51 . 2010-02-26 23:51 138584 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\ug00000\magicJack.dll
2010-02-26 23:51 . 2010-04-03 00:29 6870864 ---ha-w- c:\documents and settings\Dawn\Application Data\mjusbsp\in00000\setup.exe
2010-02-26 23:51 . 2010-02-26 23:51 6870864 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\ug00000\setup.exe
2010-02-26 23:51 . 2010-02-26 23:51 705936 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\magicJackLoader.exe
2010-02-26 23:51 . 2010-02-26 23:51 480608 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\octvqe1_apiw.dll
2010-02-26 23:51 . 2010-02-26 23:51 214360 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\TjVista.dll
2010-02-26 23:50 . 2010-02-26 23:50 324952 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\TjIpSys.dll
2010-02-26 23:50 . 2010-02-26 23:50 615792 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\SJHandsetMagicJack.dll
2010-02-26 23:50 . 2010-02-26 23:50 87384 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\st00000\mjsetup.exe
2010-02-26 23:50 . 2010-02-26 23:50 138584 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\st00000\magicJack.dll
2010-02-26 23:50 . 2010-02-26 23:50 138584 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\magicJack.dll
2010-02-26 23:46 . 2010-02-26 23:46 12526424 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\magicJack.exe
2010-02-26 23:45 . 2010-04-03 00:29 743872 ---ha-w- c:\documents and settings\Dawn\Application Data\mjusbsp\ar00000\install.exe
2010-02-26 23:45 . 2010-02-26 23:45 743872 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\ug00000\install.exe
2010-02-26 23:45 . 2010-02-26 23:45 87384 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\in00000\mjsetup.exe
2010-02-26 23:45 . 2010-02-26 23:45 138584 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\in00000\magicJack.dll
2010-02-26 23:44 . 2010-02-26 23:44 138584 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\lr00000\magicJack.dll
2010-02-26 23:43 . 2010-02-26 23:43 441704 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\ug00000\magicJackSplash.exe
2010-02-26 23:43 . 2010-02-26 23:43 441704 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\st00000\magicJackSplash.exe
2010-02-26 23:43 . 2010-02-26 23:43 441704 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\magicJackSplash.exe
2010-02-26 23:43 . 2010-02-26 23:43 441704 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\in00000\magicJackSplash.exe
2010-02-26 23:43 . 2010-02-26 23:43 50520 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\cdloader2.exe
2010-02-12 01:22 . 2010-02-12 01:22 103752 ----a-w- c:\windows\system32\AOLDial.dll
2010-02-12 01:22 . 2010-02-12 01:22 33400 ----a-w- c:\windows\system32\drivers\atwpkt264.sys
2010-02-12 01:22 . 2010-02-12 01:22 24904 ----a-w- c:\windows\system32\drivers\atwpkt2.sys
2010-01-22 21:40 . 2010-01-22 21:40 102400 ----a-w- c:\documents and settings\All Users\Application Data\AOL Toolbar\ieToolbar\resources\en-US\aoltbres.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Dawn\Application Data\mjusbsp\cdloader2.exe" [2010-02-26 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="c:\program files\Common Files\AOL\1270058127\ee\AOLSoftware.exe" [2010-02-10 41800]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 16:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Dawn\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3818:TCP"= 3818:TCP:dnegd

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/1/2010 3:24 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/1/2010 3:24 PM 20560]
S2 xzlbgaows;Config Center;c:\windows\system32\svchost.exe -k netsvcs [8/3/2004 9:07 PM 14336]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
xzlbgaows
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Cmaudio - cmicnfg.cpl



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-02 23:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xzlbgaows]
"ServiceDll"="c:\windows\system32\qzjqw.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3728)
c:\windows\system32\WININET.dll
c:\windows\system32\IEFRAME.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-04-02 23:48:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-03 03:47

Pre-Run: 30,802,751,488 bytes free
Post-Run: 30,918,078,464 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 4191B7941805C7EE480AA33927706110


#4 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:31 PM

Posted 03 April 2010 - 10:54 AM

Thanks for the description of what happened. It's looking good but still a few things we need to do here.

First...

Download and Run FlashDisinfector
  • Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden file named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

Run ComboFix with CFScript

We will run ComboFix again. This time, the instructions are slightly different.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are unsure how.
  • Open notepad (Start>Run>"notepad") and copy/paste the text in the quotebox below into it:
    CODE
    Driver::
    xzlbgaows
    NetSvc::
    xzlbgaows
    RegLock::
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xzlbgaows]
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3818:TCP"=-
    Save this as CFScript.txt, in the same location as ComboFix.exe. (This should be your desktop.)

    Refering to the picture above, drag CFScript into ComboFix.exe.
When finished, it shall produce a log for you at "C:\ComboFix.txt". Post back with that log.

Do not mouseclick ComboFix's window while it's running. That may cause it to stall

Update and Scan with MalwareBytes Anti-Malware
  • Launch Malwarebytes' Anti-Malware
  • Go to the Update tab
  • Select Check for Update and let MBAM download and install any available updates.
  • After the update is complete go to the Scanner tab.
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Post back with those logs in your next reply:
-Combofix log
-Malwarebytes Anti-Malware log

-How's your computer running now? Better?
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#5 PcRebel

PcRebel
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:31 PM

Posted 03 April 2010 - 03:16 PM

Hi EB, Almost afraid to say it but it's running like a new one. Shhh! clapping.gif Here's my logs. Please let me know if there's anything else I need to do and any other prevention steps I could take. Have a great evening and a gazillion thanks! You da man! busy.gif

ComboFix 10-04-03.01 - Dawn 04/03/2010 15:34:46.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.991.745 [GMT -4:00]
Running from: c:\documents and settings\Dawn\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dawn\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100403-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_XZLBGAOWS
-------\Service_xzlbgaows


((((((((((((((((((((((((( Files Created from 2010-03-03 to 2010-04-03 )))))))))))))))))))))))))))))))
.

2010-04-02 18:45 . 2009-08-13 15:16 512000 -c----w- c:\windows\system32\dllcache\jscript.dll
2010-04-02 08:51 . 2010-04-02 08:51 -------- d-----w- c:\windows\system32\scripting
2010-04-02 08:51 . 2010-04-02 08:51 -------- d-----w- c:\windows\l2schemas
2010-04-02 08:51 . 2010-04-02 08:51 -------- d-----w- c:\windows\system32\en
2010-04-02 01:01 . 2008-04-14 00:12 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-04-02 00:50 . 2010-04-02 08:48 -------- d-----w- c:\windows\ServicePackFiles
2010-04-02 00:25 . 2004-08-04 03:29 25471 ------w- c:\windows\system32\drivers\watv10nt.sys
2010-04-02 00:25 . 2004-08-04 03:29 22271 ------w- c:\windows\system32\drivers\watv06nt.sys
2010-04-02 00:25 . 2004-08-04 03:29 11935 ------w- c:\windows\system32\drivers\wadv11nt.sys
2010-04-02 00:25 . 2004-08-04 03:29 11871 ------w- c:\windows\system32\drivers\wadv09nt.sys
2010-04-02 00:25 . 2004-08-04 03:29 11807 ------w- c:\windows\system32\drivers\wadv07nt.sys
2010-04-02 00:25 . 2004-08-04 03:29 11295 ------w- c:\windows\system32\drivers\wadv08nt.sys
2010-04-02 00:21 . 2004-08-04 03:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
2010-04-01 23:11 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-04-01 23:11 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-04-01 23:09 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-04-01 23:08 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-04-01 23:00 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-04-01 23:00 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-04-01 22:59 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-04-01 22:59 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-04-01 22:59 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-04-01 22:59 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2010-04-01 22:59 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-04-01 22:59 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-04-01 22:59 . 2009-06-25 08:25 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2010-04-01 22:59 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-04-01 22:59 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-04-01 22:59 . 2009-12-08 19:26 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-04-01 22:59 . 2009-12-08 19:27 2189184 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-04-01 22:59 . 2009-12-08 18:43 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-04-01 22:52 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-04-01 22:47 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-04-01 22:47 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-04-01 22:39 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-04-01 22:38 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-04-01 22:38 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-04-01 19:24 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-04-01 19:24 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-04-01 19:24 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-04-01 19:24 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-04-01 19:24 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-04-01 19:24 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-04-01 19:24 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-04-01 19:24 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-04-01 19:23 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2010-04-01 19:23 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2010-04-01 19:23 . 2010-04-01 19:23 -------- d-----w- c:\program files\Alwil Software
2010-04-01 02:38 . 2010-04-01 02:38 -------- d--h--w- c:\windows\system32\GroupPolicy
2010-04-01 02:36 . 2010-04-02 17:34 13104 ----a-w- c:\documents and settings\Dawn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-01 02:19 . 2010-04-03 19:19 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-01 02:19 . 2005-08-26 00:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2010-04-01 02:19 . 2010-04-03 04:57 -------- d-----w- c:\program files\SpywareBlaster
2010-03-31 23:10 . 2010-03-31 23:10 -------- d-----w- c:\documents and settings\Dawn\Local Settings\Application Data\tjnet
2010-03-31 22:31 . 2010-03-31 22:31 -------- d-----w- c:\documents and settings\Dawn\Application Data\Malwarebytes
2010-03-31 22:31 . 2009-02-11 15:19 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-31 22:31 . 2009-02-11 15:19 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-31 22:31 . 2010-03-31 22:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-31 22:31 . 2010-03-31 22:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-31 18:50 . 2010-03-31 18:50 -------- d-----w- c:\documents and settings\Dawn\Local Settings\Application Data\AOL Toolbar
2010-03-31 17:57 . 2010-03-31 17:57 -------- d-----w- c:\documents and settings\Dawn\Application Data\AOL
2010-03-31 17:40 . 2010-03-31 17:40 335 ----a-w- c:\windows\nsreg.dat
2010-03-31 07:31 . 2010-03-31 07:31 -------- d-----w- c:\windows\Sun
2010-03-31 07:30 . 2010-03-31 07:30 -------- d-----w- c:\program files\Common Files\Java
2010-03-31 07:29 . 2010-03-31 07:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-31 07:29 . 2010-03-31 07:29 -------- d-----w- c:\program files\Java
2010-03-31 06:38 . 2010-03-31 17:40 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2010-03-31 06:27 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-03-31 06:27 . 2010-04-03 19:50 -------- d-----w- c:\documents and settings\Dawn\Application Data\mjusbsp
2010-03-31 06:26 . 2008-04-13 18:45 60032 ----a-w- c:\windows\system32\drivers\usbaudio.sys
2010-03-31 06:26 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-03-31 03:47 . 2010-03-31 03:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive
2010-03-31 03:34 . 2007-07-27 14:41 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2010-03-31 03:34 . 2010-04-02 20:09 -------- d--h--w- c:\windows\$hf_mig$

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-02 08:56 . 2010-03-31 02:55 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-31 23:11 . 2010-03-31 17:55 -------- d-----w- c:\program files\AOL 9.5
2010-03-31 17:57 . 2010-03-31 17:55 -------- d-----w- c:\program files\Common Files\aol
2010-03-31 17:57 . 2010-03-31 17:55 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2010-03-31 17:57 . 2010-03-31 17:55 -------- d-----w- c:\program files\Common Files\aolshare
2010-03-31 17:56 . 2010-03-31 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-03-31 17:56 . 2010-03-31 17:56 -------- d-----w- c:\program files\Viewpoint
2010-03-31 17:56 . 2010-03-31 17:56 -------- d-----w- c:\program files\AOL Toolbar
2010-03-31 17:56 . 2010-03-31 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Toolbar
2010-03-31 17:56 . 2010-03-31 17:56 -------- d-----w- c:\program files\Common Files\Software Update Utility
2010-03-31 17:55 . 2010-03-31 17:55 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL OCP
2010-03-31 17:50 . 2010-03-31 17:50 43496 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol_single\4337.185.4.1\noneCodesignFilesBundle.exe
2010-03-31 17:50 . 2010-03-31 17:40 48321040 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol_single\4337.185.4.1\setup.exe
2010-03-31 07:30 . 2010-03-31 07:30 503808 ----a-w- c:\documents and settings\Dawn\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7f5a6fa7-n\msvcp71.dll
2010-03-31 07:30 . 2010-03-31 07:30 499712 ----a-w- c:\documents and settings\Dawn\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7f5a6fa7-n\jmc.dll
2010-03-31 07:30 . 2010-03-31 07:30 348160 ----a-w- c:\documents and settings\Dawn\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7f5a6fa7-n\msvcr71.dll
2010-03-31 07:29 . 2010-03-31 07:29 61440 ----a-w- c:\documents and settings\Dawn\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6bbabe67-n\decora-sse.dll
2010-03-31 07:29 . 2010-03-31 07:29 12800 ----a-w- c:\documents and settings\Dawn\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6bbabe67-n\decora-d3d.dll
2010-03-31 06:54 . 2010-03-31 06:39 864256 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\ocp\ocpinst.exe
2010-03-31 06:54 . 2010-03-31 06:38 6144 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\afix\ocfcheck.dll
2010-03-31 06:54 . 2010-03-31 06:38 390704 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\afix\WinsockFix.exe
2010-03-31 06:54 . 2010-03-31 06:38 99464 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\sm\sminstlp.exe
2010-03-31 06:54 . 2010-03-31 06:38 63024 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\ocp\instSup.dll
2010-03-31 06:54 . 2010-03-31 06:38 61440 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\vwpt\VPPrePop.exe
2010-03-31 06:53 . 2010-03-31 06:38 1104960 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4327.165.1\comps\toolbar\toolbar.exe
2010-03-31 02:57 . 2010-03-31 02:57 -------- d-----w- c:\program files\microsoft frontpage
2010-03-31 02:52 . 2010-03-31 02:52 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-03-23 14:54 . 2010-03-23 14:54 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-23 14:54 . 2010-03-23 14:54 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-03-11 12:38 . 2004-08-04 01:07 832512 ------w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 01:07 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2004-08-04 01:07 17408 ------w- c:\windows\system32\corpol.dll
2010-02-26 23:51 . 2010-02-26 23:51 138584 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\ug00000\magicJack.dll
2010-02-26 23:51 . 2010-04-03 19:51 6870864 ---ha-w- c:\documents and settings\Dawn\Application Data\mjusbsp\in00000\setup.exe
2010-02-26 23:51 . 2010-03-31 06:28 6870864 ---ha-w- c:\documents and settings\Dawn\Application Data\mjusbsp\Upgrade\setup1.exe
2010-02-26 23:51 . 2010-02-26 23:51 6870864 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\ug00000\setup.exe
2010-02-26 23:51 . 2010-02-26 23:51 705936 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\magicJackLoader.exe
2010-02-26 23:51 . 2010-02-26 23:51 480608 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\octvqe1_apiw.dll
2010-02-26 23:51 . 2010-02-26 23:51 214360 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\TjVista.dll
2010-02-26 23:50 . 2010-02-26 23:50 324952 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\TjIpSys.dll
2010-02-26 23:50 . 2010-02-26 23:50 615792 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\SJHandsetMagicJack.dll
2010-02-26 23:50 . 2010-02-26 23:50 87384 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\st00000\mjsetup.exe
2010-02-26 23:50 . 2010-02-26 23:50 138584 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\st00000\magicJack.dll
2010-02-26 23:50 . 2010-02-26 23:50 138584 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\magicJack.dll
2010-02-26 23:46 . 2010-02-26 23:46 12526424 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\magicJack.exe
2010-02-26 23:45 . 2010-04-03 19:50 743872 ---ha-w- c:\documents and settings\Dawn\Application Data\mjusbsp\ar00000\install.exe
2010-02-26 23:45 . 2010-03-31 06:28 743872 ---ha-w- c:\documents and settings\Dawn\Application Data\mjusbsp\Upgrade\install1.exe
2010-02-26 23:45 . 2010-02-26 23:45 743872 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\ug00000\install.exe
2010-02-26 23:45 . 2010-02-26 23:45 87384 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\in00000\mjsetup.exe
2010-02-26 23:45 . 2010-02-26 23:45 138584 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\in00000\magicJack.dll
2010-02-26 23:44 . 2010-02-26 23:44 138584 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\lr00000\magicJack.dll
2010-02-26 23:43 . 2010-02-26 23:43 441704 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\ug00000\magicJackSplash.exe
2010-02-26 23:43 . 2010-02-26 23:43 441704 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\st00000\magicJackSplash.exe
2010-02-26 23:43 . 2010-02-26 23:43 441704 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\magicJackSplash.exe
2010-02-26 23:43 . 2010-02-26 23:43 441704 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\in00000\magicJackSplash.exe
2010-02-26 23:43 . 2010-02-26 23:43 50520 ----a-w- c:\documents and settings\Dawn\Application Data\mjusbsp\cdloader2.exe
2010-02-12 01:22 . 2010-02-12 01:22 103752 ----a-w- c:\windows\system32\AOLDial.dll
2010-02-12 01:22 . 2010-02-12 01:22 33400 ----a-w- c:\windows\system32\drivers\atwpkt264.sys
2010-02-12 01:22 . 2010-02-12 01:22 24904 ----a-w- c:\windows\system32\drivers\atwpkt2.sys
2010-01-22 21:40 . 2010-01-22 21:40 102400 ----a-w- c:\documents and settings\All Users\Application Data\AOL Toolbar\ieToolbar\resources\en-US\aoltbres.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Dawn\Application Data\mjusbsp\cdloader2.exe" [2010-02-26 50520]
"AOL Fast Start"="c:\program files\AOL 9.5\AOL.EXE" [2010-03-23 29520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="c:\program files\Common Files\AOL\1270058127\ee\AOLSoftware.exe" [2010-02-10 41800]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 16:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Dawn\\Application Data\\mjusbsp\\magicJack.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/1/2010 3:24 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/1/2010 3:24 PM 20560]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-03 15:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2456)
c:\windows\system32\WININET.dll
c:\windows\system32\IEFRAME.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AOL 9.5\waol.exe
c:\program files\Common Files\AOL\ACS\AOLacsd.exe
c:\program files\AOL 9.5\shellmon.exe
c:\documents and settings\Dawn\Application Data\mjusbsp\magicJack.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-04-03 15:58:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-03 19:58
ComboFix2.txt 2010-04-03 03:48

Pre-Run: 31,814,594,560 bytes free
Post-Run: 31,753,523,200 bytes free

- - End Of File - - C63BDF0E8781556258E535A898487DD3


Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3930

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

4/3/2010 4:17:28 PM
mbam-log-2010-04-03 (16-17-28).txt

Scan type: Quick scan
Objects scanned: 96270
Time elapsed: 6 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#6 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:31 PM

Posted 03 April 2010 - 03:37 PM

Hello.

That's looking great. I'm glad I could help. smile.gif

Now, let's get one final scan before we wrap up. smile.gif

Run ESET Online Scan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the button.
  13. Push
You can refer to this animation by neomage if needed.

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply.

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#7 PcRebel

PcRebel
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:31 PM

Posted 03 April 2010 - 06:44 PM

Hi, well ESET did find one thing ohmy.gif but I'm wondering if it was a false positive because it was a tool that I downloaded from Kaspersky.com. What do you think? I sure am glad to have you coaching me! crazy.gif Here is the ESET log and I attached the DDS logs.

C:\Documents and Settings\Dawn\My Documents\SETUPS\Autorun-Virus-Removal-Tool.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined


Attached Files



#8 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:31 PM

Posted 03 April 2010 - 06:50 PM

Hello.

Yup, that's fine. Looking great. Let's cleanup then.

Please follow/read the steps below to remove the tools we used and for some more information. smile.gif


Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything assoicated with it.

Download and Run OTC

We will now remove the tools we used during this fix using OTC.
  • Download OTC by OldTimer and save it to your desktop.
  • Double click icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.

System A bit Slow? Try StartupLight

You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.

If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.


Congratulations! You now appear clean! specool.gif

Now that you are clean, please follow and read some of the prevention tips below.

Preventing Infections in the Future


Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

Some of the main things you should consider to perform/read are:
  • Disabling Autorun/Play on Flash-Drive/Removable Drives
  • Avoid gaming sites, underground web pages, pirated software sites, and Peer to Peer Programs
  • Keep Windows Updated through going to Windows Updates
  • Updating Non-Microsoft Programs
  • Keeping Security softwares updated

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Update all programs regularly - Make sure you update all the programs you have installed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help and thank you for choosing Bleeping Computer as you malware removal source.
Don't forget to tell your friends about us and Good luck thumbup2.gif


If you have no more questions, comments or problems please tell us, so we can close off the topic.

Thanks smile.gif

With Regards,
Extremeboy

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#9 PcRebel

PcRebel
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:31 PM

Posted 03 April 2010 - 07:18 PM

Hi Extremeboy,
Nope, no more questions and thanks a lot for the tips. You did a very accurate and thorough job helping me get the "wormy critters" out of my pc, as well as taught me a few things in the process. There's no way to tell you how grateful I am so I'll say it again....You Da Man! thumbup.gif

#10 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:31 PM

Posted 03 April 2010 - 08:16 PM

You're very welcome. I'm glad I was able to help out smile.gif

Happy surfing again and good luck in the future.

~Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#11 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:31 PM

Posted 03 April 2010 - 08:19 PM

Hello.

Since the problem appears to be resolved, this topic is now Closed. Glad we could help smile.gif
If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users