First of a a big word...CAUTION...you should never run Combofix unless first directed to do so by a helper. It can do severe damage to the computer if run at the wrong time.
First thing to do now is
Disable Spybot's TeaTimer as it will interfere with fixes done.
* Run Spybot-S&D in Advanced Mode
* If it is not already set to do this, go to the Mode menu
select
Advanced Mode
* On the left hand side, click on Tools
* Then click on the Resident icon in the list
* Uncheck
Resident TeaTimer
and OK any prompts.
* Restart your computer
Next do the following:
Please download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.
* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.
Reboot the computer.
Run a new HJT scan and save the log. Post back here with the MBA-M log and the HJT log.
Judy
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
Looks much better. One of the items found was MyWebSearch. You need to do the following just to be certain there are no remainders:
Go to Start, Control Panel, Add/Remove and look for any of the following:
My Web Search (Smiley Central or FWP product as applicable)
My Way Speedbar (Smiley Central or other FWP as applicable)
My Way Speedbar (AOL and Yahoo Messengers) (beta users only)
My Way Speedbar (Outlook, Outlook Express, and IncrediMail)
Search Assistant - My Way
FunWebProducts.
Uninstall Any of the above items you may find there. If you DON'T find any that is fine. We just want to be certain.
Once you have done the uninstalls then run HJT again and place a check mark next to the following entries if they remain:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
O20 - Winlogon Notify: bbfedbbfedfccdbee - C:\WINDOWS\
Once you have placed the check marks then click the Fix Checked button.
Exit HJT.
Reboot the computer and run a new HJT scan and post that log back here.
Judy
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
Your Hijackthis log looks clean, there's just one thing i found..
O20 - Winlogon Notify: bbfedbbfedfccdbee - C:\WINDOWS\
Fix it by checking the box next to the entry and clicking 'fix checked'...search for a file named bbfedbbfedfccdbee.dll inside C:/Windows/system32 if it exists and delete it, restart and run hijackthis...If you still see that file exists then download the application below and delete the file using it..
UltraShredder
The HJT log is NOT completely clean. There are three items noted by me in the previous instructions which should be fixed using HJT.
The file you noted was removed earlier when the poster ran combofix listed in a previous thread.There is NO NEED to download another program for removal. Removal of the HJT entry with HJT will be sufficient.
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
jrb, Please follow MY instructions and ignore info given by Godsp3ed.
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
Godsp3ed, you really need to do some better research before posting information
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
Hi Jill, Looks good. Couple recommendations and I think you are good to go.
First of all, keep the MBA-M program and update and run a Quick Scan with it at least weekly. Be sure to Remove items found.
If anything IS found during the Quick scan then immediately run a Full Scan with it and Remove all found.
Also a MUST have program, FREE also is SpywareBlaster . I wouldn't run a computer without it. Blocks malicious ActiveX installs by implementing a “kill bit” to prevent those ActiveX programs with known CLSIDs from being executed.
And unlike many other anti-spy apps, SpywareBlaster does not have to remain running in the background. Very highly recommended! From Javacool Software. Download, install, update and then Enable All protection, including the Restricted Sites portion. Works with both IE and Firefox. Then close the program. Just check weekly for updates and enable any new updates.
Now you should also set a new, clean Restore Point on the computer. To do this Right Click My Computer. Choose Properties. When System Properties opens click the System Restore Tab. Put a check mark in Turn Off system restore. Windows will warn you that you are turning it off. Click ok. It will then turn off. Wait a moment and then turn it back on.
Judy
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
Yes Jill, you can get rid of that backup folder. As far as the security programs, the one I would actually Uninstall would be Windows Defender. It is just not as powerful or as reliable as MBA-M or Spybot and once in awhile it interferes. As far as the TeaTimer, leave it disabled. It truly doesn't do much, as you have seen. Spybot itself is an EXCELLENT program and definitely keep that one and scan with it weekly. Same goes for MBA-M, but be sure you update both programs before doing scans. MBA-M especially actually has updates daily, sometimes more than once a day so always be sure to update before running.
Also, I noticed that there are several programs running on my log that I tried to remove through the windows add/remove programs.
Which programs are those? Rather than stop programs using HiJackThis I would recommend using this Free program Codestuff Starter . You can stop auto starting programs and also unnecessary auto starting Services using it. It also has a Processes Tab which works much like Task Manager to show you running processes on the computer but it shows much more than Task Manager shows you.
Looking at your HJT log I see the following which can easily be run manually when needed and are not required by the computer or operating system.
BCMSMMSG-this is a voice modem driver. Only required if you are on dial-up
UserFaultCheck-Used in connection with memory dumps
NvCplDaemon-System Tray icon used to change display settings, change the clock rate and memory speed for nVidia based graphics cards.
Adobe Photo Downloader-From Adobe Photoshop Album
Those are really the only ones I see that are auto starting that are not required. All of those showing in auto starting Services ARE required to run.
You asked about a Firewall, you all ready have a Firewall with your Trend Micro Internet Security. You don't need another. If you have the Windows Firewall turned on then it should be turned off. The rule is only ONE anti-virus program and ONE firewall on a system.
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
What changes did Trend Micro say had been made? Is there a log available, if so post it. Was this the anti-virus program? Are you sure it said 8000? Don't forget there were a lot of infected files on there. Plus you turned off auto starts and also removed Defender, plus turned off Windows Firewall.
DSBroker Service. It's listed under Dell Support, but it has an unknown owner...is that strange? No, you see that often.
You DON'T run a scan with SpywareBlaster, it is not a scanner program. Are you certain you downloaded the correct program? It is a protection program ONLY. Don't forget it also has 12,299 items it BLOCKS. Maybe Trend noticed some of those. Did you actually run a scan with Trend Micro...do so please.
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
Yes, Spyware blaster is set to protect all, I didn't run a scan. The trend micro changes were all in Internet explorer (5684 changes made to IE) and they were all icky website places. So, I checked them to undo the changes in trend. My system is running VERY slow. I have been trying to run a scan with trend, but it locks up...well, let me clarify...it appears to be scanning, but after over an hour, zero targets were scanned. Also, I had this trojan_NOTTY that appeared and one of the things that has happened is that there appears to be a virus on my F: drive - that's the USB port that my printer, camera card reader and iPod go into on the front of my computer. I am going to see what I can find in my trend after I post this.
Tell you what...I am somewhat confused here because SpywareBlaster BLOCKS all nasty websites, you have a firewall, why suddenly would all these sites appear in IE? Are you absolutely CERTAIN that these sites had not been ADDED to be blocked web sites in IE? OR are you certain these were not removed cookies in IE? I really would like to see the actual wording of these warnings and maybe I will better understand.
The other thing...a trojan on your F drive...it doesn't mean the USB port, it means whatever is plugged into it at the moment. What was plugged in there when this trojan was found? It would not be the printer it would have to be either the iPod or the camera card.
Whatever it is, leave it in there. Stop the Trend Micro scan and update and run a full system scan with MBA-M, INCLUDING whatever is plugged into that F drive, because with your last Full Scan with MBA-M there was no scanning done on this F drive.
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
5684 changes made to IE) and they were all icky website places.
SpywareBlaster secures your browser against potentially unwanted software and sites this is why I am wondering if these were the changes that Trend Micro saw, which would actually been GOOD changes. If so, by undoing them then SpywareBlaster has been disabled.
There shouldn't be websites LISTED in IE unless they were either listed as GOOD or BLOCKED, otherwise there aren't sites listed in IE.
With the latest updates SpywareBlaster has 4826 Restricted sites. Meaning if enabled this many sites are BLOCKED in IE.
It also has a total of 7243 activeX and Cookies BLOCKED in IE.
I really do think that it is very possible that this is what Trend Micro saw. Can you check SpywareBlaster again and be certain that it is 100% enabled and shows NO protection disabled.
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340