Regarding this"
We suggest Avira or Avast as free, good antivirus programs IF there is no antivirus program on the system. That is not meant to indicate that you should uninstall a current, updating antivirus program.
Please read through the directions given with any program I ask you to run. The Eset scan says :Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is checked.
I ask questions to clarify any point or get more information. It's better if you just give me the answer and wait for me to tell you the best way to proceed. I did not expect you to do anything about the IP, nor the startup page in Firefox. I anticipated the answers to both and had written script to handle them.
I can write script to handle any of the following. I want you to be aware of these matters because they all threaten the security of your system. You do not need to do anything- just read and decide:
- All accounts on the system have a firewall port open for BitTorrent
- The following programs have shared access through the firewall:
[o]BitTornado, the BitTorrent Download Manager
[o]Azureus
[o]Serv-U
[o]WS_FTP Pro
[o]InterVideo
#1 & #2 are file sharing programs, putting your system at risk for malware
#3 & #4 are File Transfer Protocol programs for advanced users.
#5 is for various aspects of multimedia.
The malware has set: Internet Settings,ProxyServer = 213.39.234.155:80
And you have likely set:Internet Settings,ProxyOverride = *.local
==================================
Custom CFScript
[1]. Close any open browsers.
[2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
[3]. Open notepad and copy/paste the text in the code below into it:
Code:
File::
c:\program files\viewpoint\common\ViewpointService.exe
c:\windows\system32\drivers\nsdriver.sys
c:\windows\system32\drivers\awrtpd.sys
c:\windows\system32\drivers\AWRTPD.sys
Folder::c:\documents and settings\Meghan.MEGHANSCOMPUTER\Application Data\Azureus
c:\program files\Azureus
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
DDS::
uInternet Settings,ProxyServer = 213.39.234.155:80
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} - hxxp://qp.wnyric.org/qp2.cab
DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} - hxxp://support.f-secure.com/ols/fscax.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scan8/oscan8.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_02-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"= -
Driver::
Viewpoint Manager Service
F-Secure Standalone Minifilter
Ad-Watch Connect Filter
Ad-Watch Real-Time Scanner
Ad-Watch Registry Filter
Save this as CFScript.txt, in the same location as ComboFix.exe
Referring to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at C:\ComboFix.txt . Please attach to your next reply.
====================