Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Packed.Generic.307 or Trojan.Usuge!gen3 infection?


  • Please log in to reply

#16
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
See if you can get ESET to run:

Use IE and go to http://eset.com/onlinescan and click on ESET online Scanner. Accept the terms then press Start (If you get a warning from your browser tell it you want to run it).

# Check Scan Archives
# Push the Start button.
# ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
# When the scan completes, push LIST OF THREATS FOUND
# Push EXPORT TO TEXT FILE , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
# Push the BACK button.
# Push Finish
# Once the scan is completed, you may close the window.
# Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
# Copy and paste that log as a reply.


Let's also try the bitdefender quickscan.

http://quickscan.bitdefender.com/

When it finishes there is a report option. Click on it and copy and paste the report (even if it says nothing found).
  • 0

Advertisements


#17
assetmgr

assetmgr

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Here's the bitdefender log, can't tie up my pc right now so I'll run the Eset scan a little later.



QuickScan 32-bit v0.9.9.103
---------------------------
Scan date: Tue Jan 24 15:53:05 2012
Machine ID: F7B254C9



No infection found.
-------------------



Processes
---------
avast! Antivirus 1196 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
avast! Antivirus 2600 C:\Program Files\AVAST Software\Avast\AvastUI.exe
Bonjour 1776 C:\Program Files\Bonjour\mDNSResponder.exe
Folder Size for Windows 1868 C:\Program Files\FolderSize\FolderSizeSvc.exe
Google Update 324 C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
hp digital imaging - hp all-in-one seri 3028 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
Intel® Common User Interface 3072 C:\WINDOWS\System32\HKCMD.EXE
Internet Information Services 532 C:\WINDOWS\System32\inetsrv\inetinfo.exe
Java™ Platform SE 6 U29 900 C:\Program Files\Java\jre6\bin\jqs.exe
Java™ Platform SE Auto Updater 2 0 2748 C:\Program Files\Common Files\Java\Java Update\jusched.exe
LMIGuardianSvc 1400 C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
LogMeIn 1896 C:\Program Files\LogMeIn\x86\LogMeIn.exe
LogMeIn 1860 C:\Program Files\LogMeIn\x86\RaMaint.exe
Microsoft® Windows® Operating System 1564 C:\WINDOWS\System32\spoolsv.exe
Realtek Sound Manager 2820 C:\WINDOWS\SOUNDMAN.EXE
Sphericall 2796 C:\Program Files\Sphere\Clientupdater.exe
Sphericall 3380 C:\Program Files\Sphere\phone.exe
Thunderbird 3340 C:\Program Files\Mozilla Thunderbird\thunderbird.exe
UnlockerAssistant.exe 2652 C:\Program Files\Unlocker\UnlockerAssistant.exe
(verified) LogMeIn 2960 C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
(verified) Microsoft® Windows® Operating System 892 C:\WINDOWS\Explorer.EXE
(verified) Microsoft® Windows® Operating System 4068 C:\WINDOWS\System32\ALG.EXE
(verified) Microsoft® Windows® Operating System 544 C:\WINDOWS\System32\csrss.exe
(verified) Microsoft® Windows® Operating System 3168 C:\WINDOWS\System32\CTFMON.EXE
(verified) Microsoft® Windows® Operating System 628 C:\WINDOWS\System32\lsass.exe
(verified) Microsoft® Windows® Operating System 616 C:\WINDOWS\System32\services.exe
(verified) Microsoft® Windows® Operating System 488 C:\WINDOWS\System32\smss.exe
(verified) Microsoft® Windows® Operating System 844 C:\WINDOWS\System32\svchost.exe
(verified) Microsoft® Windows® Operating System 784 C:\WINDOWS\System32\svchost.exe
(verified) Microsoft® Windows® Operating System 1108 C:\WINDOWS\System32\svchost.exe
(verified) Microsoft® Windows® Operating System 1012 C:\WINDOWS\System32\svchost.exe
(verified) Microsoft® Windows® Operating System 2728 C:\WINDOWS\System32\svchost.exe
(verified) Microsoft® Windows® Operating System 928 C:\WINDOWS\System32\svchost.exe
(verified) Microsoft® Windows® Operating System 1700 C:\WINDOWS\System32\svchost.exe
(verified) Microsoft® Windows® Operating System 568 C:\WINDOWS\System32\winlogon.exe
(verified) Windows® Internet Explorer 2764 C:\Program Files\Internet Explorer\iexplore.exe
(verified) Windows® Internet Explorer 2916 C:\Program Files\Internet Explorer\iexplore.exe
(verified) Windows® Internet Explorer 1632 C:\Program Files\Internet Explorer\iexplore.exe


Network activity
----------------
Process AvastSvc.exe (1196) connected on port 993 (IMAP4 over SSL) --> 74.125.65.16
Process AvastSvc.exe (1196) connected on port 993 (IMAP4 over SSL) --> 74.125.65.16
Process AvastSvc.exe (1196) connected on port 80 (HTTP) --> 74.125.225.11
Process AvastSvc.exe (1196) connected on port 80 (HTTP) --> 69.171.228.12
Process AvastSvc.exe (1196) connected on port 80 (HTTP) --> 131.103.137.72
Process AvastSvc.exe (1196) connected on port 993 (IMAP4 over SSL) --> 74.125.65.16
Process AvastSvc.exe (1196) connected on port 80 (HTTP) --> 66.235.142.3
Process AvastSvc.exe (1196) connected on port 80 (HTTP) --> 131.103.137.51
Process AvastSvc.exe (1196) connected on port 993 (IMAP4 over SSL) --> 74.125.115.16
Process AvastSvc.exe (1196) connected on port 993 (IMAP4 over SSL) --> 74.125.65.16
Process LogMeIn.exe (1896) connected on port 443 (HTTP over SSL) --> 64.74.103.155
Process iexplore.exe (2916) connected on port 443 (HTTP over SSL) --> 209.85.145.95
Process phone.exe (3380) connected on port 2683 --> 10.32.1.11

Process inetinfo.exe (532) listens on ports: 21 (FTP), 80 (HTTP), 443 (HTTP over SSL), 1038
Process svchost.exe (844) listens on ports: 135 (RPC)
Process LogMeIn.exe (1896) listens on ports: 2002 (Cisco ACS)
Process Clientupdater.exe (2796) listens on ports: 3051
Process phone.exe (3380) listens on ports: 5070


Autoruns and critical files
---------------------------
AUTOBACK.EXE C:\Program Files\ERUNT\AUTOBACK.EXE
avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastUI.exe
Google Updater C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
hp digital imaging - hp all-in-one seri C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
Intel® Common User Interface C:\WINDOWS\System32\HKCMD.EXE
Intel® Common User Interface C:\WINDOWS\System32\igfxsrvc.dll
Intel® Common User Interface C:\WINDOWS\System32\igfxtray.exe
Java™ Platform SE Auto Updater 2 0 C:\Program Files\Common Files\Java\Java Update\jusched.exe
LogMeIn C:\WINDOWS\system32\LMIinit.dll
Microsoft Synchronization Manager C:\WINDOWS\system32\mobsync.exe
Microsoft® Windows® Operating System C:\WINDOWS\system32\CRYPT32.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\cryptnet.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\cscdll.dll
Microsoft® Windows® Operating System C:\WINDOWS\System32\dimsntfy.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\SHELL32.dll
Microsoft® Windows® Operating System C:\WINDOWS\System32\ssmypics.scr
Microsoft® Windows® Operating System C:\WINDOWS\system32\upnpui.dll
Microsoft® Windows® Operating System c:\windows\system32\userinit.exe
Microsoft® Windows® Operating System C:\WINDOWS\system32\WlNotify.dll
QuickTime C:\Program Files\QuickTime\qttask.exe
Realtek Sound Manager C:\WINDOWS\SOUNDMAN.EXE
Sphericall C:\Program Files\Sphere\phone.exe
UnlockerAssistant.exe C:\Program Files\Unlocker\UnlockerAssistant.exe
(verified) Google Update C:\Documents and Settings\jsiragusa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
(verified) Google Update C:\Program Files\Google\Update\GoogleUpdate.exe
(verified) LogMeIn C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
(verified) Microsoft Genuine Advantage C:\WINDOWS\system32\WgaLogon.dll
(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\BROWSEUI.dll
(verified) Microsoft® Windows® Operating System C:\WINDOWS\System32\CTFMON.EXE
(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\logonui.exe
(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll
(verified) Microsoft® Windows® Operating System C:\WINDOWS\System32\stobject.dll
(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\WPDShServiceObj.dll
(verified) Windows® Internet Explorer C:\WINDOWS\system32\webcheck.dll


Browser plugins
---------------
AlternaTIFF ActiveX control C:\WINDOWS\Downloaded Program Files\alttiff.ocx
atcliun C:\WINDOWS\Downloaded Program Files\atcliun.exe
AtMgr Module C:\WINDOWS\Downloaded Program Files\atmgr.exe
avast! WebRep C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BitDefender QuickScan C:\WINDOWS\Downloaded Program Files\qsax.dll
Bonjour C:\Program Files\Bonjour\mdnsNSP.dll
Google Gears 0.5.36.0 C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
Google Update C:\Documents and Settings\jsiragusa\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll
Google Update C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
Google Updater C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
GoogleToolbarNotifier C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
InterTrust Redemption Wizard C:\Program Files\Internet Explorer\plugins\NPDocBox.dll
Java™ Platform SE 6 U29 C:\Program Files\Java\jre6\bin\jp2ssv.dll
Java™ Platform SE 6 U29 C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
Java™ Platform SE 6 U29 C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
LMIProxyHelper.exe C:\WINDOWS\Downloaded Program Files\LMIProxyHelper.exe
Messenger C:\Program Files\Messenger\msmsgs.exe
Microsoft ® Windows ® 95, Windows ( C:\WINDOWS\Downloaded Program Files\unicows.dll
Microsoft® Windows® Operating System C:\WINDOWS\Downloaded Program Files\msrdp.ocx
Microsoft® Windows® Operating System C:\WINDOWS\system32\mswsock.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\rsvpsp.dll
Microsoft® Windows® Operating System C:\WINDOWS\System32\winrnr.dll
NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
QuickTime Plug-in 7.1 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll
QuickTime Plug-in 7.1 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll
QuickTime Plug-in 7.1 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll
QuickTime Plug-in 7.1 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll
QuickTime Plug-in 7.1 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll
QuickTime Plug-in 7.1 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll
QuickTime Plug-in 7.1 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll
RACtrl.dll C:\WINDOWS\Downloaded Program Files\RACtrl.dll
Silverlight Plug-In C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
VatDecoder C:\WINDOWS\Downloaded Program Files\VATDecoder.dll
WebEx Download Module C:\WINDOWS\Downloaded Program Files\atgpcdec.dll
WebEx Download Module C:\WINDOWS\Downloaded Program Files\atgpcext.dll
WebEx Download Module C:\WINDOWS\Downloaded Program Files\ieatgpc.dll
Windows® Internet Explorer C:\WINDOWS\system32\ieframe.dll
(verified) AcroIEHelperShim Library C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
(verified) Adobe Acrobat C:\Program Files\Internet Explorer\plugins\nppdf32.dll
(verified) Microsoft® Windows® Operating System C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


Scan
----
MD5: 2e682d1b8e1b393975b56c1520f29724 C:\Documents and Settings\jsiragusa\Application Data\Thunderbird\Profiles\5ccumgdp.default\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}\components\calbasecomps.dll
MD5: 8c2044169be2224c8a7cb8e81e7581af C:\Documents and Settings\jsiragusa\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll
MD5: f042ee4c8d66248d9b86dcf52abae416 C:\george\pev.3XE
MD5: ffaa62e671f4604f729063640befd039 C:\Program Files\AVAST Software\Avast\1033\Base.dll
MD5: cd76996b881fb8e96b4ec2210e6934b8 C:\Program Files\AVAST Software\Avast\1033\UILangRes.dll
MD5: 9e9898d12608f8fbbd3ab3b9cde010c6 C:\Program Files\AVAST Software\Avast\Aavm4h.dll
MD5: b0e0b1b2f651e3c3917d4bec88be57f4 C:\Program Files\AVAST Software\Avast\AavmRpch.dll
MD5: 921d0df0b5a6b22fae44d1cde09c4330 C:\Program Files\AVAST Software\Avast\AhAScr.dll
MD5: 082901e36e49bdd5ebe1aceaccfcabae C:\Program Files\AVAST Software\Avast\AhResBhv.dll
MD5: 7748d2c035541cc6119cbd0676065555 C:\Program Files\AVAST Software\Avast\AhResJs.dll
MD5: e656b9bb3650fdc261110b5791e15ac9 C:\Program Files\AVAST Software\Avast\AhResMai.dll
MD5: 9f91b0d0f39c087de9b0eadde33f49ec C:\Program Files\AVAST Software\Avast\AhResMes.dll
MD5: c58756a546c564f0758fc13bae56fcbf C:\Program Files\AVAST Software\Avast\AhResNS.dll
MD5: ea1cfd8098399e7ffebc5014c130729b C:\Program Files\AVAST Software\Avast\AhResP2P.dll
MD5: 3a5e076cbff22e52e5bc29222437e6f2 C:\Program Files\AVAST Software\Avast\AhResStd.dll
MD5: 852369f350aa2563938ab02f0eb8b431 C:\Program Files\AVAST Software\Avast\AhResWS.dll
MD5: ca4ddb5cb61b905a4407c5fb76527437 C:\Program Files\AVAST Software\Avast\ashBase.dll
MD5: 12ccfcb4bfb998647439adc8dd58a8c1 C:\Program Files\AVAST Software\Avast\ashMaiSv.dll
MD5: a958d494cbbce0dfa989d8bb3d1b1841 C:\Program Files\AVAST Software\Avast\ashServ.dll
MD5: 7a4a6056b53f36db50bcb8a334bad2b6 C:\Program Files\AVAST Software\Avast\ashShell.dll
MD5: b821ced9f11f12f5dff8e983fc32aea2 C:\Program Files\AVAST Software\Avast\ashTask.dll
MD5: bef4f20a11c0fe612d2d521a502cca52 C:\Program Files\AVAST Software\Avast\ashTaskEx.dll
MD5: cd8e2ba308973659b224631349a2f039 C:\Program Files\AVAST Software\Avast\ashWebSv.dll
MD5: db542d64f17ce2a804581ad6ae207db6 C:\Program Files\AVAST Software\Avast\ashWsFtr.dll
MD5: 1d352baff5a4b2e5e163bb6e652daf49 C:\Program Files\AVAST Software\Avast\aswAux.dll
MD5: 5a996ce86bda5ff1b628b21b9871287a C:\Program Files\AVAST Software\Avast\aswCmnBS.dll
MD5: 85e7f7d95de30a2008c75726cfc3ad61 C:\Program Files\AVAST Software\Avast\aswCmnIS.dll
MD5: 928f0fc896d10b099588a1d5aa46b1bf C:\Program Files\AVAST Software\Avast\aswCmnOS.dll
MD5: bdf5080dc5de21a5f662e45d57926233 C:\Program Files\AVAST Software\Avast\aswData.dll
MD5: 58bc0980941cb7ad218345adf24261d4 C:\Program Files\AVAST Software\Avast\aswDld.dll
MD5: 09cb9ae8bbc2512d9818987e721abe32 C:\Program Files\AVAST Software\Avast\aswEngLdr.dll
MD5: c3f2f11d2db6436b638ffb3befe97009 C:\Program Files\AVAST Software\Avast\aswIdle.dll
MD5: 4f91c0b574919537defdb406ffd94430 C:\Program Files\AVAST Software\Avast\aswLog.dll
MD5: aee62a34b70cbea34ebe384d529312cb C:\Program Files\AVAST Software\Avast\aswProperty.dll
MD5: 388d8dd599c04577edff52e79c451bd7 C:\Program Files\AVAST Software\Avast\aswSqLt.dll
MD5: f9446590f30e954f9ada62dda89dc321 C:\Program Files\AVAST Software\Avast\aswStrm.dll
MD5: 99d5d540f154f29896c2f570938c6ceb C:\Program Files\AVAST Software\Avast\aswUtil.dll
MD5: 328bc79bc53ba7a284c818dde88945d7 C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
MD5: 996e6d052438e8d8dfd501f31560b2e0 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
MD5: f7226aa410954185160067d5fa82f3f2 C:\Program Files\AVAST Software\Avast\AvastUI.exe
MD5: c4b742a1bac5f35d9223619f94acb45f C:\Program Files\AVAST Software\Avast\CommonRes.dll
MD5: 9def0f13079db36f97a40c7b703120aa C:\Program Files\AVAST Software\Avast\defs\12012400\algo.dll
MD5: ad70d42b7b993b65c3880918d6d7a89e C:\Program Files\AVAST Software\Avast\defs\12012400\arPot.dll
MD5: 74e2fb99d9310fb73f77905e39c3a60c C:\Program Files\AVAST Software\Avast\defs\12012400\aswCmnBS.dll
MD5: 1c08931655dd2aaa4e566a9cd07d5447 C:\Program Files\AVAST Software\Avast\defs\12012400\aswCmnIS.dll
MD5: d43118da873c97716c7d7f279d77f340 C:\Program Files\AVAST Software\Avast\defs\12012400\aswCmnOS.dll
MD5: f78ee794da26d7947c0d24a8d3e10641 C:\Program Files\AVAST Software\Avast\defs\12012400\aswEngin.dll
MD5: 28501ee17a2e6e49f5d6b91d465b610e C:\Program Files\AVAST Software\Avast\defs\12012400\aswFiDb.dll
MD5: 89e83eaa3cac9ddfed7d0289e0fb2564 C:\Program Files\AVAST Software\Avast\defs\12012400\aswRep.dll
MD5: 10c0d997dc421bb7ec27841d2d10a503 C:\Program Files\AVAST Software\Avast\defs\12012400\aswScan.dll
MD5: 707e5bf1e3f53ea4c17cd44f9b602a1a C:\Program Files\AVAST Software\Avast\defs\12012400\uiExt.dll
MD5: 1f5a570ad942dfcfe4500326abdd72b2 C:\Program Files\Bonjour\mdnsNSP.dll
MD5: 73686fe0b2e0469f89fd2075be724704 C:\Program Files\Bonjour\mDNSResponder.exe
MD5: 6e3245df783e58375b3465f03274743e C:\Program Files\Common Files\Java\Java Update\jusched.exe
MD5: e00de20f0f6bed5cd2160247ddc9443b C:\Program Files\ERUNT\AUTOBACK.EXE
MD5: 7a7f1d1c598c5c8b21ceaaab892b9fb8 C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
MD5: 21a380a47e965b435544416ac2779ac4 C:\Program Files\FolderSize\FolderSizeColumn.dll
MD5: 1dd663028daac888273c8d8fed94ca19 C:\Program Files\FolderSize\FolderSizeSvc.exe
MD5: 408ddd80eede47175f6844817b90213e C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
MD5: 432226e3e9c09a73f389a65dec49bb2f C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
MD5: 358878e398ab0fb8b1ee176c2e3edf48 C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
MD5: de35c2310aa5c7cba03e454cdc5a6ea2 C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
MD5: ebb3c5714874cdf1a4fa98f9b99bb834 C:\Program Files\Google\Update\1.3.21.79\goopdate.dll
MD5: 8c2044169be2224c8a7cb8e81e7581af C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
MD5: 821f73b833c4daebc33c1a9a4b16bb5a C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
MD5: 69a3f07fad1fed82fb70b561593bbf54 C:\Program Files\Internet Explorer\ieproxy.dll
MD5: 0cbe3e4166a08fc379eabf532b4efe18 C:\Program Files\Internet Explorer\plugins\NPDocBox.dll
MD5: 7b5e8d4df30f391a29099f7927bb4938 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll
MD5: 7b5e8d4df30f391a29099f7927bb4938 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll
MD5: 7b5e8d4df30f391a29099f7927bb4938 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll
MD5: 7b5e8d4df30f391a29099f7927bb4938 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll
MD5: 7b5e8d4df30f391a29099f7927bb4938 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll
MD5: 7b5e8d4df30f391a29099f7927bb4938 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll
MD5: 7b5e8d4df30f391a29099f7927bb4938 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll
MD5: 89b42ab664ddd9d69f1a7cb94f0d5985 C:\Program Files\Internet Explorer\xpshims.dll
MD5: dc365b6e595683f67bc21a203432e336 C:\Program Files\Java\jre6\bin\jp2ssv.dll
MD5: 381b25dc8e958d905b33130d500bbf29 C:\Program Files\Java\jre6\bin\jqs.exe
MD5: 1e96525ae85d402f9f8047f8caef5f06 C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
MD5: e3a7850421a4ab8b15fc174eb587bc6b C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
MD5: a5df77a31af7c4352185e8a409ce3976 C:\Program Files\LogMeIn\x86\avutil-51.dll
MD5: 5c94533a8d2fd6e490174e30ccc69719 C:\Program Files\LogMeIn\x86\LMIGuardianDll.dll
MD5: beda81549fce5fe29fae11dd9a616541 C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
MD5: 30280763ea4a2a0e8972740d0d40ed65 C:\Program Files\LogMeIn\x86\LogMeIn.dll
MD5: 432618fa75b61059d2c57d6a7e55147a C:\Program Files\LogMeIn\x86\LogMeIn.exe
MD5: d29c6ebaad07f972a0527aeaade8a478 C:\Program Files\LogMeIn\x86\LogMeInSystray.dll
MD5: 47d56618afcdf08c4f154b57bd70bc61 C:\Program Files\LogMeIn\x86\RaMaint.exe
MD5: 3dc4c5d385a713629b56ab58ddd98fb7 C:\Program Files\LogMeIn\x86\rntfywnd.dll
MD5: 8268d9e3184aadc8d96a1dd0e41e51cf C:\Program Files\LogMeIn\x86\swscale-2.dll
MD5: 3e930c641079443d4de036167a69caa2 C:\Program Files\Messenger\msmsgs.exe
MD5: ce6db25ffa35fd051c503f11db745862 C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
MD5: ea0917252a8ef2a5f792a3ad1b807f3f C:\Program Files\Mozilla Thunderbird\freebl3.dll
MD5: 3bd0c9f5055dff4dd25d85ebf24b606d C:\Program Files\Mozilla Thunderbird\mozalloc.dll
MD5: 9826c68cfbd78b2826c58e4f271d0658 C:\Program Files\Mozilla Thunderbird\mozjs.dll
MD5: 9d35239596fc05b22d2d75ab979573f4 C:\Program Files\Mozilla Thunderbird\mozsqlite3.dll
MD5: d0c80bbf7b720dba38c8642c506f4c86 C:\Program Files\Mozilla Thunderbird\mozutils.dll
MD5: de7a2a57085e0262136cd7af4404d81b C:\Program Files\Mozilla Thunderbird\NSLDAP32V60.dll
MD5: 964053f8a3a7cafa13a4a03884650a87 C:\Program Files\Mozilla Thunderbird\NSLDAPPR32V60.dll
MD5: b0386e29f427422d9a3b056feda487d3 C:\Program Files\Mozilla Thunderbird\nspr4.dll
MD5: 0f4dc11dbc9487b726309c47f785578b C:\Program Files\Mozilla Thunderbird\nss3.dll
MD5: 6743b900bbd9d4c73c68390c840b6bb4 C:\Program Files\Mozilla Thunderbird\nssckbi.dll
MD5: 7f12d33226a0913318a7c608f48dac13 C:\Program Files\Mozilla Thunderbird\nssdbm3.dll
MD5: f01a7c1b191e92035f98df2f0d38d564 C:\Program Files\Mozilla Thunderbird\nssutil3.dll
MD5: bb53e9c721e0d060b606e72b299f6876 C:\Program Files\Mozilla Thunderbird\plc4.dll
MD5: a1e50d716f13de7f549b216f3a266b6f C:\Program Files\Mozilla Thunderbird\plds4.dll
MD5: c8b20fad2e9d9a605ff1a2971ae9db44 C:\Program Files\Mozilla Thunderbird\smime3.dll
MD5: 32d284ec52c0626f83278ac95c48bd31 C:\Program Files\Mozilla Thunderbird\softokn3.dll
MD5: 6dd2f86d4ea601aabf983ccaeb5e7091 C:\Program Files\Mozilla Thunderbird\ssl3.dll
MD5: b7b930c51b095c88880afe3f297422e2 C:\Program Files\Mozilla Thunderbird\thunderbird.exe
MD5: 2e94aaa30ac94d3d3bac1c12bec3da3d C:\Program Files\Mozilla Thunderbird\xpcom.dll
MD5: da78734229c98b9040a10700cb3506bb C:\Program Files\Mozilla Thunderbird\xul.dll
MD5: 3f12bdfc669499dae6b0fba152c94390 C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
MD5: aa59c4c6b7cc91479deb47a40bee96e7 C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\stlport_vc7145.dll
MD5: 383145864f6543c97a7e1b78505d2f1c C:\Program Files\QuickTime\qttask.exe
MD5: 40e5f26b9f83157520aa73b0e28efde8 C:\Program Files\Sphere\avcodec.dll
MD5: 5a6a36f52578e6b0375935d33e75191d C:\Program Files\Sphere\Clientupdater.exe
MD5: 24e1808753e95ca233c3acfa3ceda593 C:\Program Files\Sphere\phone.exe
MD5: 403e928ba217e38485009636c793f3c9 C:\Program Files\Unlocker\UnlockerAssistant.exe
MD5: 78d62115f51b641a9f12afdf50a352fc C:\Program Files\Unlocker\UnlockerHook.dll
MD5: 310c15fd8358b2c4cd7a5b98a112883f C:\WINDOWS\AppPatch\AcGenral.DLL
MD5: 0cbd9f765b8454338decdb3dab55ae46 C:\WINDOWS\Downloaded Program Files\alttiff.ocx
MD5: 628b7a928a88d73a9da8823737c9ceb7 C:\WINDOWS\Downloaded Program Files\atcliun.exe
MD5: c6208bdf5da4e4d5ce960dce7167007f C:\WINDOWS\Downloaded Program Files\atgpcdec.dll
MD5: 84a4baeffb2a07b737815e0b002eafc3 C:\WINDOWS\Downloaded Program Files\atgpcext.dll
MD5: 41e77b75c03a25e755d996a9794125ca C:\WINDOWS\Downloaded Program Files\atmgr.exe
MD5: cd6a2096ea1ec09e8bfaf154faaff881 C:\WINDOWS\Downloaded Program Files\ieatgpc.dll
MD5: 5dcd085ad9edd8b0bd097e3d5748b532 C:\WINDOWS\Downloaded Program Files\LMIProxyHelper.exe
MD5: 84bdd594488db17884b8e826768d5759 C:\WINDOWS\Downloaded Program Files\msrdp.ocx
MD5: b8f613ac24cc3c706029e602e2d5ddbf C:\WINDOWS\Downloaded Program Files\qsax.dll
MD5: 7e66721241ee1a09d03d49cba349050a C:\WINDOWS\Downloaded Program Files\RACtrl.dll
MD5: e1102cedf0c818984c2aca2a666d4c5f C:\WINDOWS\Downloaded Program Files\unicows.dll
MD5: 516e31eada7007d302cd9fd4e2b1bd3a C:\WINDOWS\Downloaded Program Files\VATDecoder.dll
MD5: e1a1206a4fb19b675e947b29ccd25fba C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
MD5: 45b69639043f9a9cd05a83c1f2c86a5f C:\WINDOWS\SOUNDMAN.EXE
MD5: 11848e7ebaf7d9624fa99b05226db027 C:\WINDOWS\system32\ADMWPROX.dll
MD5: 93afb83fbc1f9443cac722fca63d73bf C:\WINDOWS\system32\comctl32.dll
MD5: ed0c0df222209e43ad9afbf3fe87dde0 C:\WINDOWS\system32\comsvcs.dll
MD5: 8fcf03e4d7be9b5587ccf11719959006 C:\WINDOWS\system32\corpol.dll
MD5: ca8d087228f291a3ed7983755cfa6f70 C:\WINDOWS\system32\cpwmon2k.dll
MD5: a90e118f12d355f9946dfb30a8f94609 C:\WINDOWS\system32\CRYPT32.dll
MD5: c14350fc0d47d806699c4f907fc6785b C:\WINDOWS\system32\cryptnet.dll
MD5: 515a7fae2070c2b0242b2353443e2f11 C:\WINDOWS\system32\cscdll.dll
MD5: dd40363abad230a84c5e2178b11efa88 C:\WINDOWS\system32\CSRSRV.dll
MD5: 56adb11f7d4d0816c0be1e701c1b5e52 C:\WINDOWS\system32\D3DIM700.DLL
MD5: e2092f0a1d7abc243f9c2362483d150d C:\WINDOWS\System32\dimsntfy.dll
MD5: bc87db4759083525f96a159861670c5e C:\WINDOWS\system32\DINPUT.dll
MD5: 389496118b3b03c2328024af320132ac C:\WINDOWS\system32\DNSAPI.dll
MD5: 5f7e24fa9eab896051ffb87f840730d2 c:\windows\system32\dnsrslvr.dll
MD5: 1e44bc1e83d8fd2305f8d452db109cf9 C:\WINDOWS\System32\drivers\afd.sys
MD5: 65200a479381b5aa80b527f962574d92 C:\WINDOWS\system32\drivers\ALCXWDM.SYS
MD5: b8c99f314372be1425468d844ce45cee C:\WINDOWS\system32\drivers\ialmkchw.sys
MD5: ba8a1050e0df758b02cdfbd11f6b4464 C:\WINDOWS\System32\DRIVERS\ialmnt5.sys
MD5: 7829319b296adc8a3bd99f4824effda9 C:\WINDOWS\system32\drivers\ialmsbw.sys
MD5: 7d304a5eb4344ebeeab53a2fe3ffb9f0 C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
MD5: ca3e22598f411199adc2dfee76cd0ae0 C:\WINDOWS\system32\drivers\msmpu401.sys
MD5: 0109c4f3850dfbab279542515386ae22 C:\WINDOWS\System32\DRIVERS\ndistapi.sys
MD5: 2ef9c0dc26b30b2318b1fc3faa1f0ae7 C:\WINDOWS\System32\DRIVERS\R8139n51.SYS
MD5: a9573045baa16eab9b1085205b82f1ed C:\WINDOWS\System32\DRIVERS\serscan.sys
MD5: 47ddfc2f003f7f9f0592c6874962a2e7 C:\WINDOWS\System32\DRIVERS\srv.sys
MD5: f5b754cdea20bbb3a31e16a776ede6d6 c:\windows\system32\ESENT.dll
MD5: bcbb9c8c3b96e82d50a4bec4a9abd717 C:\WINDOWS\system32\EUSBControl.dll
MD5: 154208cada61affe5982b590aa94843e C:\WINDOWS\system32\EusbEvent.dll
MD5: 36a45e10c6f0e110c2515fbd44f34248 C:\WINDOWS\system32\EUSBi2cHook.dll
MD5: 303a63f4b913aa5d8998161cb77a8ce7 C:\WINDOWS\system32\feclient.dll
MD5: 55eb9368c2bd96cc9e0084d0b0c8326a C:\WINDOWS\System32\hccutils.DLL
MD5: 57a789dc4984ad1f5ce49f52104f2e87 C:\WINDOWS\System32\HKCMD.EXE
MD5: 0b8fb29cda02015448c9f5260a013f19 C:\WINDOWS\system32\ieframe.dll
MD5: 515aaa9c87d5c475b06dfeba3706d74f C:\WINDOWS\system32\iepeers.dll
MD5: 1ab894fa897e26b23ca53beed72f61f4 C:\WINDOWS\system32\iertutil.dll
MD5: 135d798ac1395ffc33305288343b29f5 C:\WINDOWS\System32\igfxdev.dll
MD5: b40f584e2fe671435c1da166c7e3061f C:\WINDOWS\System32\igfxhk.dll
MD5: 04969717c47cceaa514a1f0f98907b1b C:\WINDOWS\System32\igfxres.dll
MD5: 61f0a42d45d401a5d3fef374d03f5179 C:\WINDOWS\System32\igfxsrvc.dll
MD5: 7c6bbd191f9a1fa98f499c78b6d5b8c0 C:\WINDOWS\System32\igfxtray.exe
MD5: cd2dcba9155d7f03001e5b6ee5963638 C:\WINDOWS\system32\IISMAP.dll
MD5: ea77db688f86723ef710f41e56777734 C:\WINDOWS\system32\IisRTL.DLL
MD5: 63e8d944afbeebb243f25c4ed07e74c5 C:\WINDOWS\system32\inetmib1.dll
MD5: 8b1520068b9c6bfb58ba63abf8dbe25e C:\WINDOWS\system32\inetsrv\admexs.dll
MD5: 0e9106a49b72ff5e6c7eed93373a401a C:\WINDOWS\system32\inetsrv\COADMIN.dll
MD5: f005dfd204c96c94d4f1ed32377ef256 C:\WINDOWS\system32\inetsrv\compfilt.dll
MD5: 8e0b45f79bac2bfd204f172dd602d674 C:\WINDOWS\system32\inetsrv\ftpsvc2.dll
MD5: eca78193ab6f44f5b3ddec6c4e069186 C:\WINDOWS\system32\inetsrv\gzip.dll
MD5: c8b87fea6bc1428b1a4a2c5964dc3dc5 C:\WINDOWS\system32\inetsrv\httpext.dll
MD5: 173531318f4a58593cf5c2f06426c3b6 C:\WINDOWS\system32\inetsrv\iisadmin.dll
MD5: 0e64ed5eb846635639b3c658e7711a5e C:\WINDOWS\system32\inetsrv\IISFECNV.dll
MD5: 45ae139a4b7cb1951a37bca3dc6ca372 C:\WINDOWS\system32\inetsrv\iislog.dll
MD5: db3c22745c0da4666f3be31f1af36b2f C:\WINDOWS\System32\inetsrv\inetinfo.exe
MD5: 087c6340b03d82a1ab69d6317e50434b C:\WINDOWS\system32\inetsrv\INFOCOMM.dll
MD5: 415009d769f1651b83f59ad6625fcdd6 C:\WINDOWS\system32\inetsrv\ISATQ.dll
MD5: 1052a30843a752429ab223779d678ab2 C:\WINDOWS\system32\inetsrv\iscomlog.dll
MD5: aa146beca421b20e3319eda983dc17c1 C:\WINDOWS\system32\inetsrv\lonsint.dll
MD5: f0f848ef2fe9107d07422f704eb549e7 C:\WINDOWS\system32\inetsrv\md5filt.dll
MD5: 4b9e117cb68e8486792176c10337e11d C:\WINDOWS\system32\inetsrv\metadata.dll
MD5: d4f0113c084930ef51d37c156a0e3589 C:\WINDOWS\system32\inetsrv\nsepm.dll
MD5: 5a1055abbd8909b62ab70ee63ac9ca90 C:\WINDOWS\system32\inetsrv\pwsdata.dll
MD5: c42adc86ac5ef0803de8b92d5ad1a4ad C:\WINDOWS\system32\inetsrv\rpcref.dll
MD5: 0161c94dbbf5b7f478d97235f95040a1 C:\WINDOWS\system32\inetsrv\sspifilt.dll
MD5: 15922de9a8aed8afd48c229673c83938 C:\WINDOWS\system32\inetsrv\svcext.dll
MD5: ab22cad443e9693c59e82d9ec3df1b14 C:\WINDOWS\system32\inetsrv\w3svc.dll
MD5: 1ee883222c4ddc84b4c9a71438e56673 C:\WINDOWS\system32\inetsrv\wamreg.dll
MD5: 0689622e6484934eb6e5f4d3a96311f9 C:\WINDOWS\System32\jscript.dll
MD5: a525c96c51d55111fdf3bea9ffffc7ae C:\WINDOWS\system32\kerberos.dll
MD5: 619e608ee2b7f13c8f83b6a4487c98f0 C:\WINDOWS\System32\kousd.dll
MD5: 20fa028cb6506591a99c51432a3c0174 C:\WINDOWS\system32\LangWrbk.dll
MD5: 2b852a6e68d0e9d062120a83875b1435 C:\WINDOWS\system32\LMIinit.dll
MD5: 7c7c94ded2e9b3796ee260e9395e932c C:\WINDOWS\system32\LMIport.dll
MD5: 07e304fb0faeb32d59e1eab85d73a8a7 C:\WINDOWS\system32\LMIRfsClientNP.dll
MD5: bd31dc6dbe9333c4fbd4bdf0899f2160 C:\WINDOWS\system32\LSASRV.dll
MD5: 634ec15828d7f93c10721bd972c50456 C:\WINDOWS\system32\Macromed\Flash\Flash10s.ocx
MD5: de3745a51b7ac7fedc356a83f76c8023 C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MD5: 95786e866a54c7782e60855d2bae5410 C:\WINDOWS\system32\mobsync.exe
MD5: dd8d655e1881b70a5259a23a6018a6c2 C:\WINDOWS\system32\mshtml.dll
MD5: d3f72d50de53f9f1f55240115af4d42e C:\WINDOWS\system32\msi.dll
MD5: 943337d786a56729263071623bbb9de5 C:\WINDOWS\system32\mswsock.dll
MD5: 062f837c1fbdb6a0a75f82efc2ee8e74 C:\WINDOWS\system32\NETSHELL.dll
MD5: f8f0d25ca553e39dde485d8fc7fcce89 C:\WINDOWS\system32\ntdll.dll
MD5: 40b0f98bad16ad5def894e88c3ef8014 C:\WINDOWS\system32\ODBC32.dll
MD5: 6bad1bed9872e62049e487fb91ae2f3a C:\WINDOWS\system32\ole32.dll
MD5: 20200ee3cfe10e9f0c028d8653be11c6 C:\WINDOWS\system32\oleacc.dll
MD5: 1b2be5777f69a71778f52ffee1c798d6 C:\WINDOWS\system32\OLEAUT32.dll
MD5: 9b9bb6b64e074f92c2b5dbc6ad7d1f2e C:\WINDOWS\System32\pbxsp.tsp
MD5: 4bc1271244cc040ea63227459e110c2a C:\WINDOWS\system32\PlantronicsDeviceEventSink.dll
MD5: b2cf9f1f606dec23f70a40b01df3c396 C:\WINDOWS\system32\printui.dll
MD5: 54b0324241bbf3642159918f9a4f16fb C:\WINDOWS\System32\qcap.dll
MD5: 34ffb6aba2da398bb33422e1e9275ba9 C:\WINDOWS\System32\quartz.dll
MD5: b8ae25c09b8c26ff72820430294e4ef6 C:\WINDOWS\system32\rassapi.dll
MD5: d4502f124289a31976130cccb014c9aa C:\WINDOWS\system32\RPCRT4.dll
MD5: 72451fd61ddbb0a1fb071b7c3cde5594 C:\WINDOWS\system32\rsvpsp.dll
MD5: a645a78fcdabad67067324d7e6cd9f79 C:\WINDOWS\system32\schannel.dll
MD5: 8bcd11d38fce43a519246a91cc40de6a C:\WINDOWS\system32\Security.dll
MD5: 056ef846cbfd487a5f56f27db400bdee C:\WINDOWS\system32\SHDOCVW.dll
MD5: e86423aa9aa8c382af02b94a058dc2aa C:\WINDOWS\system32\SHELL32.dll
MD5: 99bc0b50f511924348be19c7c7313bbf C:\WINDOWS\system32\SHSVCS.dll
MD5: d4ba62b10f60e22722d6aa9c13d421d7 C:\WINDOWS\System32\spool\PRTPROCS\W32X86\LMIproc.dll
MD5: 60784f891563fb1b767f70117fc2428f C:\WINDOWS\System32\spoolsv.exe
MD5: 3a7c3cbe5d96b8ae96ce81f0b22fb527 c:\windows\system32\srvsvc.dll
MD5: 5e453cb99df0838226defc05f3484cdf C:\WINDOWS\System32\ssmypics.scr
MD5: 3caeae7608f1bd7ba873a3b02895b106 C:\WINDOWS\System32\sti.dll
MD5: d0049860b63dd87a73a5d165c829c65f C:\WINDOWS\system32\t2embed.dll
MD5: 1f3a82333046f4b97b2bb148abf38d54 C:\WINDOWS\system32\TRAFFIC.dll
MD5: 4763ce0b8cf4ca355db2fe6c74675db8 C:\WINDOWS\system32\twext.dll
MD5: 5c4adb808b54126c1ed2fba0eae06c63 C:\WINDOWS\system32\upnpui.dll
MD5: 496ce99bbbb7680323921df30b405c36 C:\WINDOWS\system32\urlmon.dll
MD5: a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\system32\userinit.exe
MD5: 9e03dc5ab51cfd0190541ce2038d819d C:\WINDOWS\system32\USP10.dll
MD5: 291778dfebaa278b451d457b03c10ac1 C:\WINDOWS\system32\win32spl.dll
MD5: 684559a03cbc1d05ba120a18b0d8ba5d C:\WINDOWS\system32\WINHTTP.dll
MD5: 552263502ea8c24d301a0c43ff90b3ed C:\WINDOWS\system32\WININET.dll
MD5: 4a953f13942867ba8fb41f141ec1b80c C:\WINDOWS\system32\WINMM.dll
MD5: d72b9ec3337b247a666f098f3d6b43de C:\WINDOWS\System32\winrnr.dll
MD5: 8c7dca4b158bf16894120786a7a5f366 C:\WINDOWS\system32\winsrv.dll
MD5: 2cc34e8bb667eef78899546e12649196 C:\WINDOWS\system32\WlNotify.dll
MD5: 16403217ab6fc5c30c14c6b12098ad4b C:\WINDOWS\system32\xpsp2res.dll
MD5: 4c39358ebdd2ffcd9132a30e1ec31e16 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\MSVCP90.dll
MD5: cdbe9690cf2b8409facad94fac9479c9 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\MSVCR90.dll
MD5: ca6ade4f7761bb15b3325356dc3b82bb C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
MD5: fbfca1a574d47ee575448b719cbbf2e4 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\MFC90ENU.DLL
MD5: 736b12b725aeb2b07f0241a9f680cb10 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MD5: 33d9b7bb7ba323bafe489df033dac824 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\gdiplus.dll


No file uploaded.

Scan finished - communication took 2 sec
Total traffic - 0.01 MB sent, 0.91 KB recvd
Scanned 667 files and modules - 35 seconds

==============================================================================
  • 0

#18
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
ESET can take several hours.
  • 0

#19
assetmgr

assetmgr

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Looks like ESET got it. I don't receive a warning anymore from Avast about attempted redirects (Chrome or IE). I restarted to see if it would come back and it hasn't. Here's the log from ESET.

C:\Program Files\cnet_wrar401_exe.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
C:\Program Files\PDFCreator-1_2_3_setup.exe Win32/Adware.Toolbar.Dealio application deleted - quarantined
C:\Program Files\PDFCreator\Toolbar\pdfforge Toolbar_setup.exe Win32/Adware.Toolbar.Dealio application deleted - quarantined
C:\System Volume Information\_restore{53918549-CB7A-4AF1-9A8B-E50623094AF6}\RP7\A0005569.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
C:\System Volume Information\_restore{53918549-CB7A-4AF1-9A8B-E50623094AF6}\RP7\A0005570.exe Win32/Adware.Toolbar.Dealio application deleted - quarantined
C:\System Volume Information\_restore{53918549-CB7A-4AF1-9A8B-E50623094AF6}\RP7\A0005571.exe Win32/Adware.Toolbar.Dealio application deleted - quarantined
  • 0

#20
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
Glad you got it.

Found a little on the first detection:
http://home.mcafee.c...key=631986#none
It does say that it attempts to contact another site.

This one is kind of interesting if a bit over the top:
http://forums.cnet.c...in32-opencandy/

Not too worried about Dealio. It's just adware.

Don't suppose DDS or Combofix decide to run?
  • 0

#21
assetmgr

assetmgr

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Same thing, they run for about a minute and freeze. That guy is a bit over the top but I've been reading that you have to be really careful when you download from CNET.

https://forums.craig...g/?ID=205089486
  • 0

#22
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
I expect if ESET is happy and you have no other problems then we can probably live without DDS or Combofix.


We need to clean up System Restore.

Copy the following:


:Commands
[CLEARALLRESTOREPOINTS]
[Reboot]

Run OTL. In the Custom Scans/Fixes box at the bottom, paste in the copied text (Ctrl + v) and then hit Run Fix.

You can uninstall or delete any tools we had you download and their logs.
To uninstall combofix, copy the next line:

"%userprofile%\Desktop\combofix.exe" /Uninstall

or if we renamed it to george.exe:

"%userprofile%\Desktop\george.exe" /Uninstall


Start, Run, cmd, OK then right click, Paste, then hit Enter.



OTL has a cleanup tab so if you run OTL again and select cleanup it will remove itself and its backup files.

To hide hidden files again (If you do not run OTL cleanup):

XP

# Close all programs so that you are at your desktop.
# Double-click on the My Computer icon.
# Select the Tools menu and click Folder Options.
# After the new window appears select the View tab.
# Uncheck the checkbox labeled Display the contents of system folders.
# Under the Hidden files and folders section select the 'Hide protected operating system files (recommended)' option.
# Check the checkbox labeled Hide protected operating system files.
# Press the Apply button and then the OK button and shutdown My Computer.

Note on Java and Firefox. For some reason Java does not remove old consoles from Firefox. Any time you update Java you should do Firefox, Add-ons, Extensions and disable any old Java Consoles

They will look like: Java Console 6.xx. The xx corresponds to the update number. When they switch to 7 update 0 then it will be Java Console 7.

Multiple Java Consoles will slow down the Firefox boot. (tho lately newer version of Firefox refuse to let the Java consoles run so this note is becoming obsolete.)

After any change to Firefox or its extension you should run Speedyfox. (Mentioned later.)



Also make sure you have the latest versions of any adobe.com products you use like Shockwave, Flash or Acrobat.

Whether you use adobe reader, acrobat or fox-it to read pdf files you need to disable Javascript in the program. There is an exploit out there now that can use it to get on your PC. For Adobe Reader: Start, All Programs, Adobe Reader, Edit, Preferences, Click on Javascript in the left column and uncheck Enable Acrobat Javascript. OK Close program. It's the same for Foxit reader except you uncheck Enable Javascript Actions.

To help keep your programs up-to-date you should download and run the UpdateChecker:
http://www.filehippo.../updatechecker/
(You don't need to download Betas and if there is a program you don't use you can just uninstall it rather than update it. You can right click on the updatechecker icon (looks like a downward green arrowhead) and select Settings and tell it no betas. If you don't use MSN Messenger I would not upgdate it. MS installs a bunch of stuff when you do. You can tell the program to not show you that update.)
If you use Firefox or Chome then get the AdBlock Plus Add-on. WOT (Web of Trust) is another you might want to try.
The equivalent to AdBlock Plus for IE is called Simple Adblock and you should install it too: Adhttp://simple-adblock.com/

If Firefox is slow loading make sure it only has the current Java add-on. Then download and run Speedy Fox.
http://www.crystalidea.com/speedyfox . Click on Speedup my Firefox. When it finishes click on Exit.

Be warned: If you use Limewire, utorrent or any of the other P2P programs you will almost certain be coming back to the Malware Removal forum. If you must use P2P then submit any files you get to http://virustotal.com before you open them.

If you have a router, log on to it today and change the default password! If using a Wireless router you really should be using encryption on the link. Use the strongest (newest) encryption method that your router and PC wireless adapter support especially if you own a business. See http://www.king5.com...-120637284.html and http://www.seattlepi...ted-1344185.php for why encryption is important. If you don't know how, visit the router maker's website. They all have detailed step by step instructions or a wizard you can download.

Ron
  • 0

#23
assetmgr

assetmgr

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Ron

Thanks for all your time and help, everything is running good now.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP