Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Need expert to confirm that a computer has been cleaned  (Read 9542 times)

0 Members and 1 Guest are viewing this topic.

mrpants

    Topic Starter


    Starter

    Need expert to confirm that a computer has been cleaned
    « on: August 01, 2010, 11:00:34 AM »
    Hello,

    Thanks in advance for helping.  My Dad's laptop got infected with a rootkit, and I am trying to confirm that everything has been cleaned off of it.  I'm somewhat competent, but definitely not an expert in malware removal.  And this is a little tricky, because the laptop is on the other side of the country, and I have to relay instructions to my Mom over the phone!  :)

    I was following instructions on another website, and my Mom had run Malwarebytes, SuperAntiSpyware and ComboFix a number of times.  They seemed to be removing things, but then they'd find more things later.  Specifically, ComboFix found this:

    RootKitAgent/Gen-TDSS[Rel]

    Also, after she said IE/FireFox weren't working, I discovered that the Internet Settings was pointing at a proxy running at 127.0.0.1:5643.  I had her clear  the proxy setting.

    Finally I found the awesome instructions at this site, and had her follow them.  I had her install Avast, which after a scan found and remove this:

    JS:FakeWarm-D[trj]

    She also confirmed that the Windows Firewall is enabled, she ran CCleaner, she ran SAS and MBAM, updated her JRE, and ran HijackThis.  I've got several logs here that I'll post, hopefully you can just ignore anything that you don't need.  One funky thing I've noticed is that ComboFix keeps showing a locked registry key.

    So...please help!  Is everything removed?  Is there anything else I should run to verify that things are clean?  And thanks again for any help.

    Quote
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4346

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.18928

    7/28/2010 9:58:24 AM
    mbam-log-2010-07-28 (09-58-24).txt

    Scan type: Full scan (C:\|)
    Objects scanned: 245057
    Time elapsed: 40 minute(s), 1 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Users\Erv\AppData\Local\Microsoft\Windows Live Contacts\{fff3f564-ea1e-4291-93b7-9054406628fc}\DBStore\tempedb.edb (Trojan.Dropper) -> No action taken.

    Quote
    ComboFix 10-07-27.05 - Erv 07/28/2010  21:20:58.7.2 - x86
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3037.1900 [GMT -4:00]
    Running from: c:\users\Erv\Desktop\ComboFix.exe
    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    (((((((((((((((((((((((((   Files Created from 2010-06-28 to 2010-07-29  )))))))))))))))))))))))))))))))
    .

    2010-07-29 01:24 . 2010-07-29 01:24   --------   d-----w-   c:\users\Erv\AppData\Local\temp
    2010-07-29 01:24 . 2010-07-29 01:24   --------   d-----w-   c:\users\Public\AppData\Local\temp
    2010-07-29 01:24 . 2010-07-29 01:24   --------   d-----w-   c:\users\Default\AppData\Local\temp
    2010-07-24 17:03 . 2010-07-24 17:12   680   ----a-w-   c:\users\Erv\AppData\Local\d3d9caps.dat
    2010-07-20 23:19 . 2010-07-20 23:19   2811   ----a-w-   c:\users\Erv\AppData\Local\ukepacajuhi.dll
    2010-07-20 23:17 . 2010-07-20 23:17   2811   ----a-w-   c:\users\Erv\AppData\Local\anoguheyekitenim.dll
    2010-07-20 23:08 . 2010-07-20 23:08   2811   ----a-w-   c:\users\Erv\AppData\Local\akefihutafuz.dll
    2010-07-20 23:03 . 2010-07-20 23:03   2811   ----a-w-   c:\users\Erv\AppData\Local\uqasixejigulu.dll
    2010-07-20 22:58 . 2010-07-20 22:58   2811   ----a-w-   c:\users\Erv\AppData\Local\eyoyobiq.dll
    2010-07-20 22:53 . 2010-07-20 22:53   2811   ----a-w-   c:\users\Erv\AppData\Local\uqaqivoqul.dll
    2010-07-20 22:49 . 2010-07-20 22:49   2811   ----a-w-   c:\users\Erv\AppData\Local\oforigapuqazef.dll
    2010-07-20 22:46 . 2010-07-20 22:46   2811   ----a-w-   c:\users\Erv\AppData\Local\uwetefacosaqo.dll
    2010-07-20 22:42 . 2010-07-20 22:42   2811   ----a-w-   c:\users\Erv\AppData\Local\iwacuzojazijulu.dll
    2010-07-20 22:39 . 2010-07-20 22:39   2811   ----a-w-   c:\users\Erv\AppData\Local\edacakih.dll
    2010-07-20 22:36 . 2010-07-20 22:36   2811   ----a-w-   c:\users\Erv\AppData\Local\awunayucu.dll
    2010-07-20 22:33 . 2010-07-20 22:33   2811   ----a-w-   c:\users\Erv\AppData\Local\efihoxuqux.dll
    2010-07-20 22:29 . 2010-07-20 22:29   2811   ----a-w-   c:\users\Erv\AppData\Local\usetizici.dll
    2010-07-20 22:25 . 2010-07-20 22:25   2811   ----a-w-   c:\users\Erv\AppData\Local\aqefuqoq.dll
    2010-07-19 01:29 . 2010-07-19 01:29   2811   ----a-w-   c:\users\Erv\AppData\Local\aharazoh.dll
    2010-07-19 01:27 . 2010-07-19 01:27   2811   ----a-w-   c:\users\Erv\AppData\Local\emejoqok.dll
    2010-07-19 01:11 . 2010-07-19 01:11   2811   ----a-w-   c:\users\Erv\AppData\Local\omuwojiy.dll
    2010-07-19 01:08 . 2010-07-24 19:12   --------   d-----w-   c:\users\Erv\AppData\Local\gdpleryjo

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-28 22:54 . 2009-09-13 23:53   12   ----a-w-   c:\windows\bthservsdp.dat
    2010-07-27 01:30 . 2010-06-23 21:42   63488   ----a-w-   c:\users\Erv\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
    2010-07-27 01:30 . 2010-06-23 21:42   117760   ----a-w-   c:\users\Erv\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2010-07-26 18:01 . 2009-09-20 18:05   --------   d-----w-   c:\users\Erv\AppData\Roaming\Skype
    2010-07-25 07:01 . 2009-09-14 00:26   --------   d-----w-   c:\programdata\Microsoft Help
    2010-06-23 22:24 . 2010-06-23 22:24   --------   d-----w-   c:\users\Erv\AppData\Roaming\Malwarebytes
    2010-06-23 22:24 . 2010-06-21 02:01   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
    2010-06-23 21:42 . 2010-06-23 21:42   52224   ----a-w-   c:\users\Erv\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
    2010-06-23 21:41 . 2010-06-23 21:41   --------   d-----w-   c:\users\Erv\AppData\Roaming\SUPERAntiSpyware.com
    2010-06-23 21:41 . 2010-06-23 21:41   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
    2010-06-23 21:41 . 2010-06-23 21:41   --------   d-----w-   c:\program files\SUPERAntiSpyware
    2010-06-21 07:27 . 2009-09-14 00:08   --------   d-----w-   c:\programdata\Lenovo
    2010-06-21 02:01 . 2010-06-21 02:01   --------   d-----w-   c:\programdata\Malwarebytes
    2010-06-20 23:43 . 2010-06-20 21:42   120   ----a-w-   c:\users\Erv\AppData\Local\Qzilutudi.dat
    2010-06-20 21:42 . 2010-06-20 21:42   0   ----a-w-   c:\users\Erv\AppData\Local\Hmamoboxagi.bin
    2010-06-12 11:45 . 2009-09-19 18:18   --------   d-----w-   c:\program files\Microsoft Silverlight
    2010-05-26 17:06 . 2010-06-11 19:32   34304   ----a-w-   c:\windows\system32\atmlib.dll
    2010-05-26 14:47 . 2010-06-11 19:32   289792   ----a-w-   c:\windows\system32\atmfd.dll
    2010-05-21 18:14 . 2009-10-03 11:59   221568   ------w-   c:\windows\system32\MpSigStub.exe
    2010-05-04 05:59 . 2010-06-11 19:32   916480   ----a-w-   c:\windows\system32\wininet.dll
    2010-05-04 05:55 . 2010-06-11 19:32   71680   ----a-w-   c:\windows\system32\iesetup.dll
    2010-05-04 05:55 . 2010-06-11 19:32   109056   ----a-w-   c:\windows\system32\iesysprep.dll
    2010-05-04 04:31 . 2010-06-11 19:32   133632   ----a-w-   c:\windows\system32\ieUnatt.exe
    2010-05-01 14:13 . 2010-06-11 19:32   2037248   ----a-w-   c:\windows\system32\win32k.sys
    2009-09-13 23:35 . 2009-09-13 23:33   8192   --sh--w-   c:\windows\Users\Default\NTUSER.DAT
    .

    (((((((((((((((((((((((((((((   SnapShot@2010-07-27_04.20.16   )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-01-21 01:58 . 2010-07-28 22:56   43742              c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2006-11-02 13:05 . 2010-07-28 22:56   82220              c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2009-09-14 00:16 . 2010-07-27 04:12   65536              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-09-14 00:16 . 2010-07-28 22:55   65536              c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-09-14 00:16 . 2010-07-27 04:12   49152              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-09-14 00:16 . 2010-07-28 22:55   49152              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-10-14 01:22 . 2010-07-28 14:00   2464              c:\windows\System32\WDI\ERCQueuedResolutions.dat
    - 2009-10-14 01:22 . 2010-07-27 02:47   2464              c:\windows\System32\WDI\ERCQueuedResolutions.dat
    + 2009-09-20 04:59 . 2010-07-28 22:56   7336              c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-441185088-231462502-4236882485-1003_UserData.bin
    + 2010-07-28 22:55 . 2010-07-28 22:55   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2010-07-27 02:47 . 2010-07-27 04:12   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2010-07-27 02:47 . 2010-07-27 04:12   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2010-07-28 22:55 . 2010-07-28 22:55   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2009-09-19 17:26 . 2010-07-29 01:19   263150              c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
    + 2006-11-02 12:47 . 2010-07-27 04:28   410840              c:\windows\System32\FNTCACHE.DAT
    - 2006-11-02 12:47 . 2010-07-24 18:48   410840              c:\windows\System32\FNTCACHE.DAT
    - 2009-09-14 00:16 . 2010-07-27 04:12   1376256              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-09-14 00:16 . 2010-07-28 22:55   1376256              c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    .
    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-05-13 26192168]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-06-07 2403568]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
    "snp2uvc"="c:\windows\vsnp2uvc.exe" [2007-07-11 569344]
    "TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-07-30 60192]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-10 1045800]
    "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2009-02-27 1202448]
    "TpShocks"="TpShocks.exe" [2008-06-07 181536]
    "TPHOTKEY"="c:\program files\Lenovo\HOTKEY\LVOSDSVC.exe" [2008-03-24 64368]
    "EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-06-04 242976]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-11-05 150040]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-11-05 178712]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-11-05 154136]
    "TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-05-24 487424]
    "LPManager"="c:\progra~1\Lenovo\LENOVO~2\LPMGR.exe" [2008-06-08 165208]
    "LPMailChecker"="c:\progra~1\Lenovo\LENOVO~2\LPMLCHK.exe" [2008-06-08 124248]
    "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2008-04-25 244208]
    "RoxioDragToDisc"="c:\program files\Lenovo\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 1116920]
    "CameraApplicationLauncher"="c:\program files\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe" [2009-02-03 16384]
    "Message Center Plus"="c:\program files\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-05-28 49976]
    "PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2008-10-26 632096]
    "BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2008-10-26 214576]
    "cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2008-06-25 3077432]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2008-3-17 752168]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux1"=wdmaud.drv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
    @="FSFilter System Recovery"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "VistaSp2"=hex(b):49,2e,f1,28,a8,39,ca,01

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-441185088-231462502-4236882485-1003]
    "EnableNotificationsRef"=dword:00000001

    R1 tvtumon;tvtumon;c:\windows\system32\DRIVERS\tvtumon.sys [2008-07-11 48192]
    R2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [2008-04-25 362992]
    R2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2008-04-25 309744]
    R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2008-04-25 166384]
    R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe

    R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-10-09 360448]
    R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
    R3 MUXP;My WiFi PAN Mux-IM Protocol Driver;c:\windows\system32\DRIVERS\mux.sys [2009-02-18 30768]
    R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2009-02-27 211216]
    R3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2008-04-25 313840]
    R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-25 1120752]
    S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2008-05-14 19496]
    S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2008-05-12 13480]
    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
    S2 LFKAS;Service of LFKA;c:\program files\Lenovo\ATK Hotkey\LFKAS.exe [2008-03-20 208896]
    S2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.EXE [2008-10-26 66848]
    S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2008-08-08 53325]
    S2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2008-05-24 520192]
    S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-09-21 112128]
    S3 MUXMP;My WiFi PAN MUX-IM Virtual Miniport Driver;c:\windows\system32\DRIVERS\mux.sys [2009-02-18 30768]
    S3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2009-03-04 4232704]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs   REG_MULTI_SZ      BthServ
    .
    Contents of the 'Scheduled Tasks' folder

    2010-06-13 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
    - c:\program files\PCDR5\pcdr5cuiw32.exe [2008-12-12 23:32]

    2010-07-29 c:\windows\Tasks\User_Feed_Synchronization-{C7A64150-A1CC-48A6-8F5D-6DEE28E3515C}.job
    - c:\windows\system32\msfeedssync.exe [2010-06-11 04:30]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local;<local>
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    FF - ProfilePath - c:\users\Erv\AppData\Roaming\Mozilla\Firefox\Profiles\9erowyon.default\
    FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
    FF - plugin: c:\users\Erv\AppData\Roaming\Mozilla\plugins\npatgpc.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size",  4096);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-07-28 21:24
    Windows 6.0.6002 Service Pack 2 NTFS

    scanning hidden processes ... 

    scanning hidden autostart entries ...

    scanning hidden files ... 

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'Explorer.exe'(5484)
    c:\windows\system32\btmmhook.dll
    .
    Completion time: 2010-07-28  21:26:41
    ComboFix-quarantined-files.txt  2010-07-29 01:26
    ComboFix2.txt  2010-07-28 22:47
    ComboFix3.txt  2010-07-27 17:48
    ComboFix4.txt  2010-07-27 04:22
    ComboFix5.txt  2010-07-29 01:20

    Pre-Run: 156,137,754,624 bytes free
    Post-Run: 156,110,184,448 bytes free

    - - End Of File - - 11680087136ECB595712BF4E2D85907A

    Quote
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4375

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.18928

    7/31/2010 6:25:39 PM
    mbam-log-2010-07-31 (18-25-39).txt

    Scan type: Quick scan
    Objects scanned: 140150
    Time elapsed: 4 minute(s), 45 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Quote
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 07/31/2010 at 04:09 PM

    Application Version : 4.39.1002

    Core Rules Database Version : 5296
    Trace Rules Database Version: 3108

    Scan type       : Complete Scan
    Total Scan Time : 00:29:20

    Memory items scanned      : 795
    Memory threats detected   : 0
    Registry items scanned    : 9762
    Registry threats detected : 0
    File items scanned        : 26271
    File threats detected     : 2

    Adware.Tracking Cookie
       C:\Users\Erv\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
       C:\Users\Erv\AppData\Roaming\Microsoft\Windows\Cookies\erv@atdmt[2].txt

    Quote
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 11:59:20 AM, on 8/1/2010
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18928)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    C:\Windows\System32\TpShocks.exe
    C:\Program Files\Lenovo\HOTKEY\LVOSDSVC.exe
    C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    C:\Program Files\Lenovo\LenovoCare\LPMGR.EXE
    C:\Program Files\Lenovo\LenovoCare\LPMLCHK.EXE
    C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\Zoom\TpScrex.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
    C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\PWMUIAux.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Windows\Explorer.exe
    C:\Program Files\Alwil Software\Avast5\avastUI.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HiJackThis\sniper.exe.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Password Manager Browser Helper Object - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
    O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\LVOSDSVC.exe
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
    O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\Lenovo\LENOVO~2\LPMLCHK.exe
    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"
    O4 - HKLM\..\Run: [RoxioDragToDisc] C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe
    O4 - HKLM\..\Run: [CameraApplicationLauncher] C:\Program Files\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe
    O4 - HKLM\..\Run: [Message Center Plus] C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe /start
    O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O9 - Extra 'Tools' menuitem: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\Lenovo\ATK Hotkey\ASLDRSrv.exe
    O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\Lenovo\ATK Hotkey\GFNEXSrv.exe
    O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    O23 - Service: ThinkPad PM Service for SL Series (IBMPMSVC) - Lenovo - C:\Windows\system32\ibmpmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: Service of LFKA (LFKAS) - Unknown owner - C:\Program Files\Lenovo\ATK Hotkey\LFKAS.exe
    O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
    O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe
    O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
    O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
    O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
    O23 - Service: SessionLauncher - Unknown owner - C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing)
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\Program Files\Lenovo\System Update\SUService.exe
    O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\Windows\System32\TPHDEXLG.exe
    O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
    O23 - Service: TSS Core Service (TSSCoreService) - Lenovo - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe
    O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
    O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
    O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    O23 - Service: TVT Windows Update Monitor (TVT_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 10820 bytes

    THANK YOU!!!

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Need expert to confirm that a computer has been cleaned
    « Reply #1 on: August 08, 2010, 05:10:23 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    Re-running ComboFix to remove infections:

    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Open notepad and copy/paste the text in the quotebox below into it:
      Quote
      KillAll::

      File::
      c:\users\Erv\AppData\Local\ukepacajuhi.dll
      c:\users\Erv\AppData\Local\anoguheyekitenim.dll
      c:\users\Erv\AppData\Local\akefihutafuz.dll
      c:\users\Erv\AppData\Local\uqasixejigulu.dll
      c:\users\Erv\AppData\Local\eyoyobiq.dll
      c:\users\Erv\AppData\Local\uqaqivoqul.dll
      c:\users\Erv\AppData\Local\oforigapuqazef.dll
      c:\users\Erv\AppData\Local\uwetefacosaqo.dll
      c:\users\Erv\AppData\Local\iwacuzojazijulu.dll
      c:\users\Erv\AppData\Local\edacakih.dll
      c:\users\Erv\AppData\Local\awunayucu.dll
      c:\users\Erv\AppData\Local\efihoxuqux.dll
      c:\users\Erv\AppData\Local\usetizici.dll
      c:\users\Erv\AppData\Local\aqefuqoq.dll
      c:\users\Erv\AppData\Local\aharazoh.dll
      c:\users\Erv\AppData\Local\emejoqok.dll
      c:\users\Erv\AppData\Local\omuwojiy.dll
      c:\users\Erv\AppData\Local\gdpleryjo

      Rootkit::

    • Save this as CFScript.txt, in the same location as ComboFix.exe



    • Referring to the picture above, drag CFScript into ComboFix.exe
    • When finished, it shall produce a log for you at C:\ComboFix.txt
    • Please post the contents of the log in your next reply.

    ==================================

    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O23 - Service: SessionLauncher - Unknown owner - C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing)


    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ====================================

    * Download the following tool: RootRepeal - Rootkit Detector
    * Direct download link is here: RootRepeal.zip

    * Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
    * Click this link to see a list of such programs and how to disable them.

    * Extract the program file to a new folder such as C:\RootRepeal
    * Run the program RootRepeal.exe and go to the REPORT tab and click on the Scan button.
    * Select ALL of the checkboxes and then click OK and it will start scanning your system.
    * If you have multiple drives you only need to check the C: drive or the one Windows is installed on.
    * When done, click on Save Report
    * Save it to the same location where you ran it from, such as C:RootRepeal
    * Save it as rootrepeal.txt
    * Then open that log and select all and copy/paste it back on your next reply please.
    * Close RootRepeal.
    Windows 8 and Windows 10 dual boot with two SSD's

    mrpants

      Topic Starter


      Starter

      Re: Need expert to confirm that a computer has been cleaned
      « Reply #2 on: August 08, 2010, 07:19:32 PM »
      Thanks for the reply.  Ran through the three apps.  Explorer.exe crashed during the beginning of the ComboFix scan.  HijackThis found the three items you listed (and we told it to fix them).  Here are the logs you asked for.

      Quote
      ComboFix 10-08-08.01 - Erv 08/08/2010  19:53:31.8.2 - x86
      Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3037.1578 [GMT -4:00]
      Running from: c:\users\Erv\Desktop\ComboFix.exe
      Command switches used :: c:\users\Erv\Desktop\CFScript.txt
      SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
      SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

      FILE ::
      "c:\users\Erv\AppData\Local\aharazoh.dll"
      "c:\users\Erv\AppData\Local\akefihutafuz.dll"
      "c:\users\Erv\AppData\Local\anoguheyekitenim.dll"
      "c:\users\Erv\AppData\Local\aqefuqoq.dll"
      "c:\users\Erv\AppData\Local\awunayucu.dll"
      "c:\users\Erv\AppData\Local\edacakih.dll"
      "c:\users\Erv\AppData\Local\efihoxuqux.dll"
      "c:\users\Erv\AppData\Local\emejoqok.dll"
      "c:\users\Erv\AppData\Local\eyoyobiq.dll"
      "c:\users\Erv\AppData\Local\gdpleryjo"
      "c:\users\Erv\AppData\Local\iwacuzojazijulu.dll"
      "c:\users\Erv\AppData\Local\oforigapuqazef.dll"
      "c:\users\Erv\AppData\Local\omuwojiy.dll"
      "c:\users\Erv\AppData\Local\ukepacajuhi.dll"
      "c:\users\Erv\AppData\Local\uqaqivoqul.dll"
      "c:\users\Erv\AppData\Local\uqasixejigulu.dll"
      "c:\users\Erv\AppData\Local\usetizici.dll"
      "c:\users\Erv\AppData\Local\uwetefacosaqo.dll"
      .

      (((((((((((((((((((((((((   Files Created from 2010-07-09 to 2010-08-09  )))))))))))))))))))))))))))))))
      .

      2010-08-08 23:58 . 2010-08-08 23:58   --------   d-----w-   c:\users\Public\AppData\Local\temp
      2010-08-08 23:58 . 2010-08-08 23:58   --------   d-----w-   c:\users\Default\AppData\Local\temp
      2010-08-08 23:51 . 2010-08-08 23:52   --------   d-----w-   C:\32788R22FWJFW
      2010-08-01 15:53 . 2010-08-01 15:53   --------   d-----w-   c:\program files\Trend Micro
      2010-08-01 15:41 . 2010-08-01 15:41   --------   d-----w-   c:\program files\Common Files\Java
      2010-08-01 15:40 . 2010-07-17 09:00   423656   ----a-w-   c:\windows\system32\deployJava1.dll
      2010-07-31 19:01 . 2010-07-31 19:01   --------   d-----w-   c:\program files\CCleaner
      2010-07-31 16:22 . 2010-06-28 20:37   46672   ----a-w-   c:\windows\system32\drivers\aswTdi.sys
      2010-07-31 16:22 . 2010-06-28 20:37   165456   ----a-w-   c:\windows\system32\drivers\aswSP.sys
      2010-07-31 16:22 . 2010-06-28 20:33   23376   ----a-w-   c:\windows\system32\drivers\aswRdr.sys
      2010-07-31 16:22 . 2010-06-28 20:32   17744   ----a-w-   c:\windows\system32\drivers\aswFsBlk.sys
      2010-07-31 16:22 . 2010-06-28 20:32   50256   ----a-w-   c:\windows\system32\drivers\aswMonFlt.sys
      2010-07-31 16:21 . 2010-06-28 20:57   38848   ----a-w-   c:\windows\avastSS.scr
      2010-07-31 16:21 . 2010-06-28 20:57   165032   ----a-w-   c:\windows\system32\aswBoot.exe
      2010-07-31 16:21 . 2010-07-31 16:21   --------   d-----w-   c:\programdata\Alwil Software
      2010-07-31 16:21 . 2010-07-31 16:21   --------   d-----w-   c:\program files\Alwil Software
      2010-07-30 23:00 . 2010-07-30 23:00   --------   d-----w-   c:\programdata\WindowsSearch
      2010-07-29 01:26 . 2010-08-08 23:59   --------   d-----w-   c:\users\Erv\AppData\Local\temp
      2010-07-27 00:34 . 2008-01-21 02:23   52792   ----a-w-   c:\windows\system32\drivers\volmgr.sys
      2010-07-24 17:03 . 2010-07-24 17:12   680   ----a-w-   c:\users\Erv\AppData\Local\d3d9caps.dat
      2010-07-19 01:08 . 2010-07-24 19:12   --------   d-----w-   c:\users\Erv\AppData\Local\gdpleryjo

      .
      ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-08-08 23:58 . 2009-09-13 23:53   12   ----a-w-   c:\windows\bthservsdp.dat
      2010-08-01 15:40 . 2009-09-14 00:13   --------   d-----w-   c:\program files\Java
      2010-07-26 18:01 . 2009-09-20 18:05   --------   d-----w-   c:\users\Erv\AppData\Roaming\Skype
      2010-07-25 07:01 . 2009-09-14 00:26   --------   d-----w-   c:\programdata\Microsoft Help
      2010-06-23 22:24 . 2010-06-23 22:24   --------   d-----w-   c:\users\Erv\AppData\Roaming\Malwarebytes
      2010-06-23 22:24 . 2010-06-21 02:01   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
      2010-06-23 21:41 . 2010-06-23 21:41   --------   d-----w-   c:\users\Erv\AppData\Roaming\SUPERAntiSpyware.com
      2010-06-23 21:41 . 2010-06-23 21:41   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
      2010-06-23 21:41 . 2010-06-23 21:41   --------   d-----w-   c:\program files\SUPERAntiSpyware
      2010-06-21 07:27 . 2009-09-14 00:08   --------   d-----w-   c:\programdata\Lenovo
      2010-06-21 02:01 . 2010-06-21 02:01   --------   d-----w-   c:\programdata\Malwarebytes
      2010-06-20 23:43 . 2010-06-20 21:42   120   ----a-w-   c:\users\Erv\AppData\Local\Qzilutudi.dat
      2010-06-20 21:42 . 2010-06-20 21:42   0   ----a-w-   c:\users\Erv\AppData\Local\Hmamoboxagi.bin
      2010-06-12 11:45 . 2009-09-19 18:18   --------   d-----w-   c:\program files\Microsoft Silverlight
      2010-05-26 17:06 . 2010-06-11 19:32   34304   ----a-w-   c:\windows\system32\atmlib.dll
      2010-05-26 14:47 . 2010-06-11 19:32   289792   ----a-w-   c:\windows\system32\atmfd.dll
      2010-05-21 18:14 . 2009-10-03 11:59   221568   ------w-   c:\windows\system32\MpSigStub.exe
      2009-09-13 23:35 . 2009-09-13 23:33   8192   --sh--w-   c:\windows\Users\Default\NTUSER.DAT
      .

      (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-05-13 26192168]
      "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
      "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-06-07 2403568]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
      "snp2uvc"="c:\windows\vsnp2uvc.exe" [2007-07-11 569344]
      "TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-07-30 60192]
      "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-10 1045800]
      "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2009-02-27 1202448]
      "TpShocks"="TpShocks.exe" [2008-06-07 181536]
      "TPHOTKEY"="c:\program files\Lenovo\HOTKEY\LVOSDSVC.exe" [2008-03-24 64368]
      "EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-06-04 242976]
      "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-11-05 150040]
      "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-11-05 178712]
      "Persistence"="c:\windows\system32\igfxpers.exe" [2008-11-05 154136]
      "TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-05-24 487424]
      "LPManager"="c:\progra~1\Lenovo\LENOVO~2\LPMGR.exe" [2008-06-08 165208]
      "LPMailChecker"="c:\progra~1\Lenovo\LENOVO~2\LPMLCHK.exe" [2008-06-08 124248]
      "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2008-04-25 244208]
      "RoxioDragToDisc"="c:\program files\Lenovo\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 1116920]
      "CameraApplicationLauncher"="c:\program files\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe" [2009-02-03 16384]
      "Message Center Plus"="c:\program files\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-05-28 49976]
      "PWMTRV"="c:\progra~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2008-10-26 632096]
      "BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2008-10-26 214576]
      "cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2008-06-25 3077432]
      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
      "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]

      c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
      Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2008-3-17 752168]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "EnableLUA"= 0 (0x0)
      "EnableUIADesktopToggle"= 0 (0x0)

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "aux1"=wdmaud.drv

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
      @="FSFilter System Recovery"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
      @="Service"

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
      "VistaSp2"=hex(b):49,2e,f1,28,a8,39,ca,01

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-441185088-231462502-4236882485-1003]
      "EnableNotificationsRef"=dword:00000001

      R1 tvtumon;tvtumon;c:\windows\system32\DRIVERS\tvtumon.sys [2008-07-11 48192]
      R2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [2008-04-25 362992]
      R2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2008-04-25 309744]
      R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2008-04-25 166384]
      R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
      R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2008-10-09 360448]
      R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
      R3 MUXP;My WiFi PAN Mux-IM Protocol Driver;c:\windows\system32\DRIVERS\mux.sys [2009-02-18 30768]
      R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2009-02-27 211216]
      R3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2008-04-25 313840]
      R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-25 1120752]
      S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2008-05-14 19496]
      S1 aswSP;aswSP; [x]
      S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2008-05-12 13480]
      S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
      S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
      S2 aswFsBlk;aswFsBlk; [x]
      S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
      S2 LFKAS;Service of LFKA;c:\program files\Lenovo\ATK Hotkey\LFKAS.exe [2008-03-20 208896]
      S2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.EXE [2008-10-26 66848]
      S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2008-08-08 53325]
      S2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2008-05-24 520192]
      S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-09-21 112128]
      S3 MUXMP;My WiFi PAN MUX-IM Virtual Miniport Driver;c:\windows\system32\DRIVERS\mux.sys [2009-02-18 30768]
      S3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2009-03-04 4232704]


      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      bthsvcs   REG_MULTI_SZ      BthServ
      .
      Contents of the 'Scheduled Tasks' folder

      2010-06-13 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
      - c:\program files\PCDR5\pcdr5cuiw32.exe [2008-12-12 23:32]

      2010-08-08 c:\windows\Tasks\User_Feed_Synchronization-{C7A64150-A1CC-48A6-8F5D-6DEE28E3515C}.job
      - c:\windows\system32\msfeedssync.exe [2010-06-11 04:30]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://www.google.com/
      uInternet Settings,ProxyOverride = *.local;<local>
      IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
      FF - ProfilePath - c:\users\Erv\AppData\Roaming\Mozilla\Firefox\Profiles\9erowyon.default\
      FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
      FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
      FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
      FF - plugin: c:\users\Erv\AppData\Roaming\Mozilla\plugins\npatgpc.dll
      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

      ---- FIREFOX POLICIES ----
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size",  4096);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
      .

      **************************************************************************
      scanning hidden processes ... 

      scanning hidden autostart entries ...

      scanning hidden files ... 

      scan completed successfully
      hidden files:

      **************************************************************************
      .
      --------------------- LOCKED REGISTRY KEYS ---------------------

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------

      - - - - - - - > 'Explorer.exe'(5064)
      c:\windows\system32\btmmhook.dll
      c:\windows\system32\btncopy.dll
      c:\program files\Lenovo\Drag-to-Disc\Shellex.dll
      c:\windows\system32\DLAAPI_W.DLL
      c:\program files\Lenovo\Drag-to-Disc\ShellRes.dll
      .
      ------------------------ Other Running Processes ------------------------
      .
      c:\windows\system32\ibmpmsvc.exe
      c:\program files\Lenovo\ATK Hotkey\ASLDRSrv.exe
      c:\program files\Lenovo\ATK Hotkey\GFNEXSrv.exe
      c:\program files\Alwil Software\Avast5\AvastSvc.exe
      c:\windows\system32\WLANExt.exe
      c:\program files\Lenovo\ATK Hotkey\LCONTROL.exe
      c:\program files\Lenovo\ATK Hotkey\LFKA.exe
      c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
      c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
      c:\program files\Intel\WiFi\bin\EvtEng.exe
      c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
      c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
      c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      c:\windows\System32\TPHDEXLG.exe
      c:\program files\Lenovo\Client Security Solution\tvttcsd.exe
      c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
      c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
      c:\windows\system32\DRIVERS\xaudio.exe
      c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
      c:\windows\System32\TpShocks.exe
      c:\program files\ThinkPad\Utilities\EZEJMNAP.EXE
      c:\program files\Lenovo\LenovoCare\LPMGR.EXE
      c:\program files\Lenovo\LenovoCare\LPMLCHK.EXE
      c:\windows\system32\igfxsrvc.exe
      c:\windows\System32\rundll32.exe
      c:\program files\Synaptics\SynTP\SynTPLpr.exe
      c:\program files\Lenovo\HOTKEY\TPONSCR.exe
      c:\program files\Lenovo\Zoom\TpScrex.exe
      c:\program files\Windows Media Player\wmpnscfg.exe
      c:\program files\Alwil Software\Avast5\AvastUI.exe
      c:\program files\Windows Media Player\wmpnetwk.exe
      c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
      c:\program files\Synaptics\SynTP\SynTPHelper.exe
      c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
      c:\program files\Windows Live\Contacts\wlcomm.exe
      c:\program files\Common Files\Lenovo\bmgr\bmgr32.exe
      c:\progra~1\ThinkPad\UTILIT~1\PWMUIAux.exe
      c:\windows\servicing\TrustedInstaller.exe
      .
      **************************************************************************
      .
      Completion time: 2010-08-08  20:10:46 - machine was rebooted
      ComboFix-quarantined-files.txt  2010-08-09 00:10
      ComboFix2.txt  2010-07-29 01:26
      ComboFix3.txt  2010-07-28 22:47
      ComboFix4.txt  2010-07-27 17:48
      ComboFix5.txt  2010-08-08 23:52

      Pre-Run: 155,796,467,712 bytes free
      Post-Run: 156,054,196,224 bytes free

      Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
      - - End Of File - - 6B95EF0C2089062471671A902954AACA

      Quote
      ROOTREPEAL (c) AD, 2007-2009
      ==================================================
      Scan Start Time:      2010/08/08 20:41
      Program Version:      Version 1.3.5.0
      Windows Version:      Windows Vista SP2
      ==================================================

      Drivers
      -------------------
      Name: dump_iaStor.sys
      Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
      Address: 0x8A30D000   Size: 897024   File Visible: No   Signed: -
      Status: -

      Name: rootrepeal.sys
      Image Path: C:\Windows\system32\drivers\rootrepeal.sys
      Address: 0xB41EA000   Size: 49152   File Visible: No   Signed: -
      Status: -

      Hidden/Locked Files
      -------------------
      Path: C:\hiberfil.sys
      Status: Locked to the Windows API!

      Path: C:\RRbackups
      Status: Locked to the Windows API!

      Path: \\?\C:\RRbackups\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\C
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\Documents and Settings
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\ProgramData
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\Q
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\S
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\SIS
      Status: Invisible to the Windows API!

      Path: C:\System Volume Information\{220e0802-9a9b-11df-921e-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{220e0950-9a9b-11df-921e-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{220e0b27-9a9b-11df-921e-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{220e0b40-9a9b-11df-921e-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{4daec1ca-99a5-11df-8ac2-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{51a3fab1-9937-11df-a544-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{51a3fad6-9937-11df-a544-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{79d0eb27-9a50-11df-be12-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{220e05ba-9a9b-11df-921e-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{0954818f-9ecf-11df-bd20-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{0954833e-9ecf-11df-bd20-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{095483d6-9ecf-11df-bd20-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{09548555-9ecf-11df-bd20-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{09548582-9ecf-11df-bd20-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{095487e2-9ecf-11df-bd20-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{09548889-9ecf-11df-bd20-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{220e0341-9a9b-11df-921e-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{220e0555-9a9b-11df-921e-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{7b21954a-82a2-11df-bbe8-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{8ef50608-9dd7-11df-a67a-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{8ef5067d-9dd7-11df-a67a-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{8ef50700-9dd7-11df-a67a-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{8ef50747-9dd7-11df-a67a-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{949db743-99a7-11df-8e39-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{edc2fe06-a348-11df-83e8-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: C:\System Volume Information\{f8c83c86-9753-11df-8bb3-90e6ba0b36c6}{3808876b-c176-4e48-b7ae-04046e6cc752}
      Status: Locked to the Windows API!

      Path: \\?\C:\RRbackups\C\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\C\0
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\2
      Status: Invisible to the Windows API!

      Path: \\?\C:\RRbackups\common\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\common\backups.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\bmgrmode.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\bt0.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\bt1.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\bt2.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\css.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\hints.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\mnd.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\regcerts.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\restore.log
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\rr.log
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\rr_bcdenum.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\SAM
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\secpolicy.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\settings.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\system.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\tvtcmn.dat
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\common\usersids.dat
      Status: Invisible to the Windows API!

      Path: \\?\C:\RRbackups\Documents and Settings\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\Documents and Settings\Administrator
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\Documents and Settings\Erv
      Status: Invisible to the Windows API!

      Path: \\?\C:\RRbackups\ProgramData\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\ProgramData\Lenovo
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\ProgramData\Microsoft
      Status: Invisible to the Windows API!

      Path: \\?\C:\RRbackups\Q\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\Q\0
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\Q\1
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\Q\2
      Status: Invisible to the Windows API!

      Path: \\?\C:\RRbackups\S\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\S\0
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\S\1
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\S\2
      Status: Invisible to the Windows API!

      Path: \\?\C:\RRbackups\SIS\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\SIS\C
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\SIS\Q
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\SIS\S
      Status: Invisible to the Windows API!

      Path: \\?\C:\RRbackups\C\0\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\C\0\Data0
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data1
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data10
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data100
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data101
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data102
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data103
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data104
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data105
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data106
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data107
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data108
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data109
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data11
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data110
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data111
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data112
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data113
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data114
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data115
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data28
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data29
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data3
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data30
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data31
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data32
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data33
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data34
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data35
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data36
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data37
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data38
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data39
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data4
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data40
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data41
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data42
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data43
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data44
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data45
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data47
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data48
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data49
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data5
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data50
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data51
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data52
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data53
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data54
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data55
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data56
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data57
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data58
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data59
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data6
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data60
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data61
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data62
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data63
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data64
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data66
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data67
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data68
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data69
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data7
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data70
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data71
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data72
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data73
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data74
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data75
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data76
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data77
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data78
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data79
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data8
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data80
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data81
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data82
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data83
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data117
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data118
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data119
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data12
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data120
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data121
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data122
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data123
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data124
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data125
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data126
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data127
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data128
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data129
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data13
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data130
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data131
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data132
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data133
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data134
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data136
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data137
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data138
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data139
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data14
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data140
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data141
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data142
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data143
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data144
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data145
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data146
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data147
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data148
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data149
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data15
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data150
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data151
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data152
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data153
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data155
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data156
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data157
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data158
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data159
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data16
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data160
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data161
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data162
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data163
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data164
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data165
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data166
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data167
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data168
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data169
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data17
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data170
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data171
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data172
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data116
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data135
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data154
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data173
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data192
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data210
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data23
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data27
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data46
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data65
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data84
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data174
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data175
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data176
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data177
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data178
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data179
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data18
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data180
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data181
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data182
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data183
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data184
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data185
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data186
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data187
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data188
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data189
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data19
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data190
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data191
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data193
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data194
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data195
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data196
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data197
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data198
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data199
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data2
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data20
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data200
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data201
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data202
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data203
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data204
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data205
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data206
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data207
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data208
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data209
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data21
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data211
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data212
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data213
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data214
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data215
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data216
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data217
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data218
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data219
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data22
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data220
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data221
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data222
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data223
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data224
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data225
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data226
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data227
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data228
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data229
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data230
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data231
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data232
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data233
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data234
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data235
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data236
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data237
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data238
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data239
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data24
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data240
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data241
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data242
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data243
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data244
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data245
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data246
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data247
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data248
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data249
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data25
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data250
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data26
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data85
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data86
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data87
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data88
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data89
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data9
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data90
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data91
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data92
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data93
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data94
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data95
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data96
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data97
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data98
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Data99
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\dats
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\EFSFile
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\HashFile
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\Info
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\0\TOCFile
      Status: Invisible to the Windows API!

      Path: \\?\C:\RRbackups\C\1\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\C\1\Data0
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data1
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data10
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data11
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data12
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data13
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data14
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data15
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data16
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data17
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data18
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data19
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data2
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data20
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data3
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data4
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data5
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data6
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data7
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data8
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Data9
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\dats
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\EFSFile
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\HashFile
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\Info
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\1\TOCFile
      Status: Invisible to the Windows API!

      Path: \\?\C:\RRbackups\C\2\*
      Status: Could not enumerate files with the Windows API (0x00000005)!


      Path: C:\RRbackups\C\2\Data0
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\2\Data1
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\2\Data10
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\2\Data11
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\2\Data12
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\2\Data2
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\2\Data3
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\2\Data4
      Status: Invisible to the Windows API!

      Path: C:\RRbackups\C\2\DaProcesses
      -------------------
      Path: System
      PID: 4   Status: Locked to the Windows API!

      Path: C:\Windows\System32\audiodg.exe
      PID: 1376   Status: Locked to the Windows API!

      SSDT
      -------------------
      #: 334   Function Name: NtTerminateProcess
      Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS" at address 0x8facc620

      ==EOF==

      Thanks again for your help.

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Need expert to confirm that a computer has been cleaned
      « Reply #3 on: August 09, 2010, 05:54:03 PM »
      Download Security Check by screen317 from one of the following links and save it to your desktop.

      Link 1
      Link 2

      * Unzip SecurityCheck.zip and a folder named Security Check should appear.
      * Open the Security Check folder and double-click Security Check.bat
      * Follow the on-screen instructions inside of the black box.
      * A Notepad document should open automatically called checkup.txt
      * Post the contents of that document in your next reply.

      Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

      =============================================

      I'd like to scan your machine with ESET OnlineScan

      •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESET OnlineScan
      •Click the button.
      •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      • Click on to download the ESET Smart Installer. Save it to your desktop.
      • Double click on the icon on your desktop.
      •Check
      •Click the button.
      •Accept any security warnings from your browser.
      •Check
      •Push the Start button.
      •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      •When the scan completes, push
      •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
      •Push the button.
      •Push
      A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

      Windows 8 and Windows 10 dual boot with two SSD's

      mrpants

        Topic Starter


        Starter

        Re: Need expert to confirm that a computer has been cleaned
        « Reply #4 on: August 09, 2010, 11:01:29 PM »
        Thanks again for your help.  BTW, the SecurityCheck info mentions downloading a zip and then running a bat, but the links go directly to the exe, so we just ran that.

        Quote
        Results of screen317's Security Check version 0.99.5 
         Windows Vista Service Pack 2 (UAC is disabled!)
         Internet Explorer 8 
        ``````````````````````````````
        Antivirus/Firewall Check:

         Windows Firewall Enabled! 
         avast! Free Antivirus   
         WMI entry may not exist for antivirus; attempting automatic update.
        ```````````````````````````````
        Anti-malware/Other Utilities Check:

         Malwarebytes' Anti-Malware   
         CCleaner     
         Java(TM) 6 Update 21 
         Adobe Flash Player 10.0.42.34 
        Adobe Reader 8.1.3
        Out of date Adobe Reader installed!
         Mozilla Firefox (3.6.8)
        ````````````````````````````````
        Process Check: 
        objlist.exe by Laurent

         Windows Defender MSASCui.exe
         Windows Defender MSASCui.exe   
         Alwil Software Avast5 AvastSvc.exe 
         Alwil Software Avast5 AvastUI.exe 
        ````````````````````````````````
        DNS Vulnerability Check:

         GREAT! (Not vulnerable to DNS cache poisoning)

        ``````````End of Log````````````

        Quote
        ESETSmartInstaller@High as downloader log:
        all ok
        # version=7
        # OnlineScannerApp.exe=1.0.0.1
        # OnlineScanner.ocx=1.0.0.6211
        # api_version=3.0.2
        # EOSSerial=40b7a6cf267d144a80aa75ddfb3f6933
        # end=finished
        # remove_checked=true
        # archives_checked=true
        # unwanted_checked=true
        # unsafe_checked=false
        # antistealth_checked=true
        # utc_time=2010-08-10 01:56:08
        # local_time=2010-08-09 09:56:08 (-0500, Eastern Daylight Time)
        # country="United States"
        # lang=1033
        # osver=6.0.6002 NT Service Pack 2
        # compatibility_mode=512 16777215 100 0 0 0 0 0
        # compatibility_mode=768 16777215 100 0 0 0 0 0
        # compatibility_mode=5892 16776573 100 100 0 118009845 0 0
        # compatibility_mode=8192 67108863 100 0 0 0 0 0
        # scanned=122159
        # found=4
        # cleaned=4
        # scan_time=3050
        C:\Qoobox\Quarantine\C\Users\Erv\AppData\Local\{871FEE34-44DD-4678-B482-1FDC3A8ACC0F}\chrome\content\overlay.xul.vir   probably a variant of Win32/Agent.NVQFFQI trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\Users\Erv\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\386b5b95-133e2086   multiple threats (deleted - quarantined)   00000000000000000000000000000000   C
        C:\Users\Erv\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\2c251572-31933403   probably a variant of Win32/Agent.NXHSWPF trojan (deleted - quarantined)   00000000000000000000000000000000   C
        C:\Windows\System32\config\systemprofile\AppData\Local\{EA00507A-6916-48EA-82E2-E9D0DF33CBFE}\chrome\content\overlay.xul   probably a variant of Win32/Agent.NVQFFQI trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C

        This is the ESET list of threats.  It looks to be a subset of the log, but your post mentioned both, so here it is for completeness.
        Quote
        C:\Qoobox\Quarantine\C\Users\Erv\AppData\Local\{871FEE34-44DD-4678-B482-1FDC3A8ACC0F}\chrome\content\overlay.xul.vir   probably a variant of Win32/Agent.NVQFFQI trojan   cleaned by deleting - quarantined
        C:\Users\Erv\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\386b5b95-133e2086   multiple threats   deleted - quarantined
        C:\Users\Erv\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\2c251572-31933403   probably a variant of Win32/Agent.NXHSWPF trojan   deleted - quarantined
        C:\Windows\System32\config\systemprofile\AppData\Local\{EA00507A-6916-48EA-82E2-E9D0DF33CBFE}\chrome\content\overlay.xul   probably a variant of Win32/Agent.NVQFFQI trojan   cleaned by deleting - quarantined

        Thank you

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Need expert to confirm that a computer has been cleaned
        « Reply #5 on: August 10, 2010, 04:37:16 PM »
        Well, that looks good. If there are no other issues, let's do some cleanup.

        * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
        * Now type Combofix /uninstall in the runbox
        * Make sure there's a space between Combofix and /Uninstall
        * Then hit Enter

        * The above procedure will:
        * Delete the following:
        * ComboFix and its associated files and folders.
        * Reset the clock settings.
        * Hide file extensions, if required.
        * Hide System/Hidden files, if required.
        * Set a new, clean Restore Point.

        ==============================

        Download OTC by OldTimer and save it to your desktop.

        1. Double-click OTC to run it.
        2. Click the CleanUp! button.
        3. Select Yes when the "Begin cleanup Process?" prompt appears.
        4. If you are prompted to Reboot during the cleanup, select Yes
        5. OTC should delete itself once it finishes, if not delete it yourself.

        =============================

        Clean out your temporary internet files and temp files.

        Download TFC by OldTimer to your desktop.

        Double-click TFC.exe to run it.

        Note: If you are running on Vista, right-click on the file and choose Run As Administrator

        TFC will close all programs when run, so make sure you have saved all your work before you begin.

        * Click the Start button to begin the cleaning process.
        * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
        * Please let TFC run uninterrupted until it is finished.

        Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

        ===============================

        Looking over your log it seems you don't have any evidence of a third party firewall.

        Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

        Remember only install ONE firewall

        1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
        2) Online Armor
        3) Agnitum Outpost
        4) PC Tools Firewall Plus

        If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

        =================================

        Use the Secunia Software Inspector to check for out of date software.

        •Click Start Now

        •Check the box next to Enable thorough system inspection.

        •Click Start

        •Allow the scan to finish and scroll down to see if any updates are needed.
        •Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

        SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
        Safe Surfing!
        Windows 8 and Windows 10 dual boot with two SSD's

        mrpants

          Topic Starter


          Starter

          Re: Need expert to confirm that a computer has been cleaned
          « Reply #6 on: August 16, 2010, 06:37:42 PM »
          Everything appears to be running smoothly now.  Thank you very much for your help, it is greatly appreciated!