Sorrow,
Looks like we got it. As you can see from the AVG report the only signs of the infection are in your last restore point and in combofix's quarantine.
--------------------------------------------------------------------------------------------------------------------------------------------------------
Launch Hijackthis -> Do a system Scan only -> Check the following:
O2 - BHO: (no name) - {4CADD537-FFDC-48AE-ACCD-B9A4D8CFD524} - C:\WINDOWS\system32\gebya.dll (file missing)
O2 - BHO: (no name) - {4D0A2AF5-0A7C-4928-BD04-D7A749CCBE3E} - C:\WINDOWS\system32\geedc.dll (file missing)
O2 - BHO: (no name) - {5E1484DE-8F62-44BC-9B0F-583AFA8282CC} - C:\WINDOWS\system32\vtstu.dll (file missing)
O20 - Winlogon Notify: jkkhiif - jkkhiif.dll (file missing)
The next entries are sometimes reported as malware. I would recommend you remove them but it is not mandatory.
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
After checking the above, please select
Fix Checked and close Hijackthis
Show hidden files through windows explorer
- Access Windows Explorer by clicking Start, point to All Programs, Accesories, and then click Windows Explorer. Or hold the windows key and press E
- On the Tools menu in Windows Explorer, click Folder Options.
- Click the View tab.
- Under Hidden files and folders, click Show hidden files and folders and Turn Hide protected operating system files off.
Use Windows Explorer to navigate to and delete the following files:
Files:
C:\
Program Files\free-downloads.net\tbfree.dll <-This file only
-------------------------------------------------------------------------------------------------------
Go to start -> Run -> type in
combofix /u
*note the space between
*This will uninstall combofix
*It will remove vundofix backups
*It will remove quarentine files
*It creates a fresh clean restore point
Remove Hijackthis from Start-> control panel -> add/remove programs
Remove the 3 tools from step 10 (smitfraud, vundofix,virtumondobegone) by dragging to the recycle bin
I recommend you keep
1 anti virus program (AVG not anti spyware)
1 firewall
Spybot S&D, Adaware 2007, AVG Anti Spyware if you want but the version we downloaded is a 30 day trial
keep them updated.
You can also turn on tea timer in Spybot:
- Click on Mode at the top and make sure that Advanced is checked
- Expand the Tools tab in the left pane
- Single click on the Resident Icon also in the left pane
- check Resident "TeaTimer" (Protection of over-all system settings) Active
- Close spybot
Also under Tools you can double-click
System Startup in the right pane and disable programs from running at startup. This will free up system resources. For example if you don't use MSN Messenger everytime you run your computer you can disable it, then when you want to use it you can launch it through Start -> all programs, or make a shortcut on the desktop for it. That way it doesn't use resources when you aren't using it.
Don't disable any entries in green though.
-------------------------------------------------------------------------------------------------------------------------------------------------------------------
Just to be sure please run
AVG AntiSpyware
- Launch AVG AntiSpyware
- Click on the Update Icon at the top, then click Start Update in the left pane
- After the update click on the Scanner Icon at the top, then select the settings tab, in the first section "How to act?" click on recommended actions and change it to delete.In the reports section make sure it is set to Automatically generate report after every scan
- Click back to the Scan tab and select Complete System Scan
- Finally, after the scan, select the Infections Icon at the top, click Select All at the bottom then Remove finally also at the bottom