Quite some time ago, I had the 'Symantec Email Proxy' problem where 'Scanning Message One of One' kept on popping up, and it kept on sending random e-mails to unknown IPs and what not.
Hi Kevin,
I am not sure about the Symantec problem, but you do have a couple baddies showing in your HJT Log.FIRST -- Please DELETE your current copy of HijackThis
Download a fresh HijackThis from http://downloads.malwareremoval.com/hijackthis_sfx.exe
Save the setup file on your desktop.
Then, DoubleClick on it and by default it should install to C:\Program Files\HijackThis
Continue through the setup and allow it to create a desktop icon for you. Follow all the prompts, and click Finish .
Please Scan with HJT, and check the boxes for the following items:
O4 - HKLM\..\Run: [itunesff] C:\WINDOWS\system32\itunesff.exe -go -c48 -w
O4 - HKCU\..\Run: [WinMedia] C:\DOCUME~1\PON\LOCALS~1\Temp\2307796.exe
O16 - DPF: {33331111-1111-1111-1111-611111193423} -
O16 - DPF: {33331111-1111-1111-1111-615111193427} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB45AE83-A2C7-4543-9F30-ED0CB0B3874C}: NameServer = 202.188.0.133 202.188.1.5 ---> If this is your ISP in Kuala Lumpur then leave this entry alone
Be sure All Browser Windows are Closed and then Click Fix Checked.
NEXT:
Please Boot to Safe Mode and navigate to and DELETE C:\WINDOWS\system32\itunesff.exe
If you are unable to do so, let me know.
THEN:
Please download HOSTER and Extract it to your Desktop.
Click the Restore Original Hosts Button and then click OK and exit HOSTER.
NEXT:
Please Update your Java here ---> http://www.java.com/en
Then, look in Add/Remove Programs and Remove ALL traces of any older Java versions!
If you do not uninstall ALL older versions, you may remain at risk for a number of baddies.
-- Download ATF-Cleaner.exe by Atribune to your Desktop.
-- Click on ATF-Cleaner to run it
-- Where it says Select Files To Delete, Check the Select All Option (if you don’t want it to clean cookies, set it accordingly)
-- Click Empty Selected > OK > EXIT
This will flush TEMP files, etc... as well as clean the Java Cache.
THEN:
-- Please download and Install AVG Anti-Spyware v7.5
THEN:
RightClick the AVG Anti-Spy Icon in your system tray and do the following:
-- Uncheck Resident Shield
-- Uncheck Automatic Updates
-- Uncheck Start with Windows
* You can reset the above to their defaults AFTER your machine has been deemed “clean,” if you so desire. For now, we need them disabled.
Click Run online update and allow it to run until you see the Update Successful message. If you are unable to do this, please let me know.
NOW, run a full scan:
-- Click on the Scanner button and choose the Settings Tab.
---> Under How to act?, click on Recommended action and choose Quarantine to set default action for detected malware.
--->Under Reports make sure Automatically generate report after every scan is selected and UNCHECK the Only if threats were found box.
-- Leave everything else at their default settings and Select the Scan tab and CLICK Complete System Scan to scan your machine.
-- Upon completion of the scan, Click Apply all actions to place any detected baddies in Quarantine.
-- AFTER clicking Apply all actions, Click on Save Report and select Save the report to your Desktop where you can find it easily. Again, be sure to Apply All Actions Before saving the Log!
LASTLY: Please post a Fresh HijackThis Scanlog taken AFTER the AVG Anti-spy run and the AVG Anti-Spyware Log and we'll go from there.
Best Luck :)
PP