This post is more than 5 years old


June 22nd, 2010 16:00

Thank you in advance for taking the time to help me (as well as others)--I really appreciate it.  Besides redirected searches (in google as well as the tool bar) I have had adware windows opening and a spotty internet connection (sometimes it says it is not available, not configured, but I know it is).  Sometimes none of my bookmarks will work--the browser won't go there.  I figured I had a virus and I downloaded and ran "Search and Destroy".  The first time it worked and found lots of virtumonde including the .dll file.  I told it to remove it, but I think the computer froze then and I was never sure it really did it.  Then it never could find it after that and neither could any of the other spyware removal programs.  (We have had some issues with our computer which I think are not related (but I am not sure)--it seems that it gets really hot and then just shuts down--we have it elevated from the counter where we keep it (Dell Inspiron laptop) for increased air circulation, but sometimes it will suddenly just go black and be shut down.  I assumed it was because it got too hot).

(I don't think anything has changed on this machine as I have shut it down and not used it since I originally posted this...)

Here is my HJT logfile:

June 22nd, 2010 16:00

Hi NCfan,

Welcome to Dell Community Malware Removal Forums,

I'm K27 and i will be reviewing your log for you.

Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.

Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.

Please DO NOT use this system for anything apart from visiting this forum and other sites I direct you too, as this will only make the cleanup process all the more diffecult.

The first thing we need to do is to remove prevX from the system, please go to add/remove programs in control panel and uninstall the PrevX program.

Then Please Disable Ad-Aware and Spybot's Teatimer function as they will interfere with our tools. You can re-enable them once we are finished. (instructions via links below)


1) Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2

MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.

MBAM will automatically start and you will be asked to update the program before performing a scan.

  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.

On the Scanner tab:

  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.

Back at the main Scanner screen:

  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.

Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.


2) I need to see some additional information about what is happening in your machine.
Please perform the following scan:

  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool.
  • When done, DDS will open two (2) logs
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop.
  • The instructions here ask you to attach the Attach.txt.
  • Instead of attaching, please copy/past both logs into your next reply.



  • Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control here



Next, download this Antirootkit Program to a folder that you create such as C:\ARK, by choosing the "Download EXE" button on the webpage.

Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)


Next, please perform a rootkit scan:

  • Double-click the randomly name EXE located in the C:\ARK folder that you just downloaded to launch it
  • When the program opens, it will automatically initiate a very fast scan of common rootkit hiding places.
  • When the "quick" scan is finished (a few seconds), click the Rootkit/Malware tab,and then select the Scan button.
  • Leave your system completely idle while this longer scan is in progress.
  • When the scan is done, save the scan log to the Windows clipboard
  • Open Notepad or a similar text editor
  • Paste the clipboard contents into a text file by clicking Edit | Paste or Ctl V
  • Exit the Program
  • Save the Scan log as ARK.txt and post it in your next reply.
  • Now, re-enable the active protection component of any antivirus/antimalware programs you disabled before performing the scan.

If the ARK tool crashes your machine or causes a Blue Screen error, please post the log results from the first inital quick scan,this can be saved in the same way as the full scan in the above instructions.


Please COPY/PASTE the MBAM log, BOTH DDS logs and the ARK log back to this thread,

12 Posts

June 22nd, 2010 23:00

Thanks so much again for helping me...
I disabled Spybot's Teatimer.  As far as Ad Aware is concerned, there wasn't an icon for it in the system tray and I couldn't get it to launch/run so I uninstalled it.  I already had MBAM installed on my machine, but I uninstalled it and then down loaded it again, installed it and ran a scan.  Here is the (scan) log file:

Log from DDS:


And the other one: (attach notepad):

Rootkit scan 2010-06-23 00:54:28
Windows 5.1.2600 Service Pack 3
Running: buxbern3.exe; Driver: C:\DOCUME~1\ANDREW~1\LOCALS~1\Temp\pxtdapoc.sys

---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwClose [0xAA313C7A]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwCreateKey [0xAA313B36]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwDeleteKey [0xAA3140EA]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwDeleteValueKey [0xAA314014]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwDuplicateObject [0xAA31370C]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwOpenKey [0xAA313C10]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwOpenProcess [0xAA31364C]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwOpenThread [0xAA3136B0]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwQueryValueKey [0xAA313D30]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwRenameKey [0xAA3141B8]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwRestoreKey [0xAA313CF0]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwSetValueKey [0xAA313E70]

Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwCreateProcessEx [0xAA320AC6]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwCreateSection [0xAA3208EA]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ZwLoadDriver [0xAA320A24]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         NtCreateSection
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ObInsertObject
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)                         ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

.text           ntkrnlpa.exe!ZwCallbackReturn + 2468                                                                          80501CA0 4 Bytes  JMP DAAA3140
PAGE            ntkrnlpa.exe!ZwLoadDriver                                                                                     805795FA 7 Bytes  JMP AA320A28 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!NtCreateSection                                                                                  805A075C 7 Bytes  JMP AA3208EE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!ObMakeTemporaryObject                                                                            805B1CE0 5 Bytes  JMP AA31C536 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!ObInsertObject                                                                                   805B8B58 5 Bytes  JMP AA31DEC2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE            ntkrnlpa.exe!ZwCreateProcessEx                                                                                805C73EA 7 Bytes  JMP AA320ACA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)

---- User code sections - GMER 1.0.15 ----

.text           C:\WINDOWS\System32\svchost.exe[1120] ntdll.dll!NtProtectVirtualMemory                                        7C90D6EE 5 Bytes  JMP 0092000A
.text           C:\WINDOWS\System32\svchost.exe[1120] ntdll.dll!NtWriteVirtualMemory                                          7C90DFAE 5 Bytes  JMP 0093000A
.text           C:\WINDOWS\System32\svchost.exe[1120] ntdll.dll!KiUserExceptionDispatcher                                     7C90E47C 5 Bytes  JMP 0091000C
.text           C:\WINDOWS\System32\svchost.exe[1120] USER32.dll!GetCursorPos                                                 7E42974E 5 Bytes  JMP 0262000A
.text           C:\WINDOWS\System32\svchost.exe[1120] ole32.dll!CoCreateInstance                                              7750057E 5 Bytes  JMP 0097000A
.text           C:\WINDOWS\Explorer.EXE[1584] ntdll.dll!NtProtectVirtualMemory                                                7C90D6EE 5 Bytes  JMP 00B7000A
.text           C:\WINDOWS\Explorer.EXE[1584] ntdll.dll!NtWriteVirtualMemory                                                  7C90DFAE 5 Bytes  JMP 00BD000A
.text           C:\WINDOWS\Explorer.EXE[1584] ntdll.dll!KiUserExceptionDispatcher                                             7C90E47C 5 Bytes  JMP 00B6000C
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3672] ntdll.dll!NtProtectVirtualMemory                           7C90D6EE 5 Bytes  JMP 011D000A
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3672] ntdll.dll!NtWriteVirtualMemory                             7C90DFAE 5 Bytes  JMP 011E000A
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3672] ntdll.dll!KiUserExceptionDispatcher                        7C90E47C 5 Bytes  JMP 011C000C
.text           C:\WINDOWS\system32\wuauclt.exe[3944] ntdll.dll!NtProtectVirtualMemory                                        7C90D6EE 5 Bytes  JMP 00BA000A
.text           C:\WINDOWS\system32\wuauclt.exe[3944] ntdll.dll!NtWriteVirtualMemory                                          7C90DFAE 5 Bytes  JMP 00BB000A
.text           C:\WINDOWS\system32\wuauclt.exe[3944] ntdll.dll!KiUserExceptionDispatcher                                     7C90E47C 5 Bytes  JMP 00B9000C

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\WINDOWS\system32\services.exe[832] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW]  003C0002
IAT             C:\WINDOWS\system32\services.exe[832] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW]        003C0000

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                        aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                        aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                      aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass0                                                                       SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice  \Driver\Kbdclass \Device\KeyboardClass1                                                                       SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                     aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                     aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                   aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device          \FileSystem\Fastfat \Fat                                                                                      A91F2D20
Device          \FileSystem\Fastfat \Fat                                                                                      A9202428

AttachedDevice  \FileSystem\Fastfat \Fat                                                                                      fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice  \FileSystem\Fastfat \Fat                                                                                      aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device          \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer                                                            tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device          \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer                                                             tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device          \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer                                                                 tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device          \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer                                                              tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device          \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer                                                             tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device          \FileSystem\Cdfs \Cdfs                                                                                        tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

---- EOF - GMER 1.0.15 ----

June 24th, 2010 14:00


Sorry for the Delay in replying.



Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)


Please download ComboFix.exe. Please visit THIS webpage for download links, and instructions for running the tool:

Combo-fix MUST be save to your desktop before running the tool

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

When prompted to install the recovery console please make sure to do so as the is a VERY IMPORTANT backup of Combo-fix XP only

You will need to be conected to the net to install the recovery console, if you can not install it DO NOT run Combo-Fix,
Post back and we will install it manually.

DO NOT mouse click when Combo-Fix is running as this will cause Combo-Fix to Stall and it will not work as it should

Please include the C:\ComboFix.txt in your next reply for further review.


12 Posts

June 26th, 2010 14:00


So I think I disabled all my antispyware/antivirus (I don't have a system tray icon for spybot search and destroy or MBAM, but I looked in them and can't find anywhere to disable anything that runs all the time).  I don't have any third party firewalls installed.  I downloaded ComboFix (Firefox automatically saved it to my downloaded files folder, but I moved it to the desktop so I could run it from there).  ComboFix didn't find the system recovery console on my computer and wanted to download it from Microsoft.  I followed along with that, but there was an error trying to extract it.  It said, "Windows XP Home Edition SP2 CD Boot Floppies.  Extracting file failed.  It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file".  I think at one point I disabled the microsoft system recovery point (before I started on this forum)--perhaps this is related?  I also have a sysrestore folder on my desktop but I think that is something else (not from Microsoft).  Oh, and when I clicked ok on the extracting files failed error message another message popped up and I was going to write it down, but it went away really fast.  It said something like (I can't really remember it exactly) Error: cmode(?) files not in orfer; please disable (something, maybe some more?).


1.5K Posts

June 27th, 2010 11:00


There seems to have been a problem installing the recovery console, You  have over 8GB of free space on the harddrive, that should be plenty to install the Recovery Console.

Lets try this manually. Please delete the copy of combofix you have by right clicking the CF file that is saved to the desktop and then please click delete.

Please proceed as follows:



Download ComboFix from one of these locations:

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**


With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before doing any malware removal.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Go to Microsoft's website =>

Scroll down to Step 1, and select the download that's appropriate for your Operating System. Download the file & save it as it's originally named.

Note: If you have SP3, use the SP2 package.

Save the Recovery Console file to the desktop.


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools



  • Drag the setup package onto ComboFix.exe and drop it.



  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.




  • At the next prompt, click 'Yes' to run the full ComboFix scan.



  • When the tool is finished, it will produce a report for you.

Please post the C:\ComboFix.txt in your next reply.



12 Posts

June 28th, 2010 12:00

Okay, it went better this time.  Here is the ComboFix report from the notepad:

1.5K Posts

June 28th, 2010 13:00


Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)


Next we are going to run Combo-Fix in a slightly different way

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quote box below into it:

c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb95.tmp.exe
c:\program files\13367661067-anonymous-02-06-2008-12-26-.wav



Save this as CFScript.txt, in the same location as ComboFix.exe


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


Please leave all active protection switched off while running the next scan

I'd like us to scan your machine with ESET OnlineScan

  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the esetOnline.png button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the esetSmartInstallDesktopIcon.png icon on your desktop.
  4. Check esetAcceptTerms.png
  5. Click the esetStart.png button.
  6. Accept any security warnings from your browser.
  7. Check esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push esetListThreats.png
  11. Push esetExport.png, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the esetBack.png button.
  13. Push esetFinish.png


Then please run a FULL scan with MBAM.

  • Double click your Malwarebytes desktop icon
  • Click the UPDATE tab at the top
  • Scan for and install any updates it finds
  • Then choose the SCANNER tab and run a FULL SCAN
  • Once finished if MBAM found anything please click Show Results
  • Make sure EVERYTHING has a check in the box next to it and then click Remove Selected
  • Post the MBAM log results back to this thread


NOTE: If MBAM encounters a file that is hard to remove it will prompt for a delete on reboot, answer yes to this and once rebooted please run another scan and post that scan's log results along with the log results from before reboot which can be found under the LOGS tab of Malwarebytes.


Please post the fresh Combofix log, the ESET log and the fresh MBAM log.


12 Posts

June 29th, 2010 20:00

Here are the files...
1.5K Posts

June 30th, 2010 14:00


Looking good.


I'd like us to scan your machine with ESET OnlineScan

  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the esetOnline.png button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the esetSmartInstallDesktopIcon.png icon on your desktop.
  4. Check esetAcceptTerms.png
  5. Click the esetStart.png button.
  6. Accept any security warnings from your browser.
  7. Check esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push esetListThreats.png
  11. Push esetExport.png, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the esetBack.png button.
  13. Push esetFinish.png

Please post the ESET log back to me along with an update on how the system is running.


12 Posts

July 1st, 2010 08:00

The computer is working a lot better since that first ESET scan when that trojan was found and removed.  When I ran the ESET scan yesterday no threats were found.  When doing searches yesterday and this morning, no pop-ups came up and the searches went to where they were directed without any problems.  Hurray!  Thank you so much for your help!

1.5K Posts

July 1st, 2010 13:00

OK, now we need to get you updated,


The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall
Note the space between Combofix and /

Please uninstall the other programs we used as without proper guidance they can seriously harm the workings of Windows and your PC

  • DDS and the two(2) logs you saved from it by right clicking there Desktop icons and clicking delete
  • The ARK tool we used by right clicking the folder you created to run the ARK tool from and then clicking delete


.Download and scan with CCleaner
1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free or Slim versions instead of the Standard Build.
2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:

  • Clean all entries in the "Internet Explorer" section except Cookies if you want to keep those.
  • Clean all the entries in the "Windows Explorer" section.
  • Clean all entries in the "System" section.
  • Clean all entries in the "Advanced" section.
  • Clean any others that you choose

In the Applications Tab:

  • Clean all except cookies in the Firefox/Mozilla section if you use it.
  • Clean all in the Opera section if you use it.
  • Clean Sun Java in the Internet Section.
  • Clean any others that you choose.

4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.

Now that your system is clean you should SET A NEW RESTORE POINT to prevent future reinfection from the old restore point AFTER cleaning your system of any malware infection. Any trojans or spyware you picked up could have been saved in System Restore and are waiting to re-infect you. Since System Restore is a protected directory, your tools can not access it to delete files, trapping viruses inside. Setting a new restore point should be done to prevent any future reinfection from the old restore point and enable your computer to "roll-back" in case there is a future problem.

1. Go to Start > Programs > Accessories > System Tools and click "System Restore".
2. Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
3. Then go to Start > Run and type: Cleanmgr
4. Click "OK".
5. Click the "More Options" Tab.
6. Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

Graphics for doing this are in the following links if you need them.
How to Create a Restore Point.
How to use Cleanmgr.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:

  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to "JDK 6 Update 20 (JDK or JRE).
  • Click the Download JRE button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.

Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.

  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u20-windows-i586-p.exe to install the newest version.

-- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
-- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
-- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.

Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it:

  • Go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
  • Click Ok and reboot your computer.


.Adobe Acrobat/Reader is out of date please update to the latest version from HERE

Then please go to Windows Update by clicking Start (Windows icon bottom left of screen) > All Programs > Windows Updates > then please install all the updates that are found and then please keep going back until there are no updates showing. This may take a few goes as there are updates for updates of updates.


After all the above is completed please post me a fresh HJT log.


1.5K Posts

July 4th, 2010 16:00


Please post the fresh HJT log so I can check that everything we according to plan.

We may then close the thread after some prevention advice for the future.


12 Posts

July 4th, 2010 21:00

Hi, I've done everything but the windows update which I am now working on.  I don't see that in the start menu, but I clicked the one in the system tray.  Will post the HJT log soon...

12 Posts

July 5th, 2010 15:00

Hi, here is the HJT log.  I didn't update IE because I don't use it, but I decided I should just update it anyway.  It looks like that is a loophole, not being updated on things... (so I am updating that and just checking again that it can't find anything else to update). 

1.5K Posts

July 6th, 2010 13:00


Even though you do not use IE it still need's to be updated as it poses a security risk if its left outdated.

Once all the Windows updates are done (including IE8) please post a fresh HJT log.


No Events found!
