I hate to the bearer of bad news but, your logs show very dangerous trojans and rootkits are residing on your PC.
They attempt to steal passwords, as well as logging key presses and open window titles to text files and periodically send the collected information to a remote user via HTTP. They download and execute additional files from a remote site. Configuration files may also be downloaded which define further behaviors.
As you can see, it not only includes a key logger, but back door functionality.
I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or it if it contains any other sensitive information, please get to a known clean computer and change all passwords where applicable and it would be wise to contact those same financial institutions to apprise them of your situation.
Though the trojans and rootkits have been identified and can be killed, because of their back door functionality your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with these types of infections, the best course of action would be a reformat and reinstall of the OS. If it were on my PC I would not hesitate for a moment to do so. Please read these for more information:
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall
Should you decide not to follow that advice, we will of course do our best to clean the computer of any infections that we can see but, as I already stated, we can in no way guarantee it to be trustworthy.
Should you have any questions, please feel free to ask.
Please let us know what you have decided to do.
If you choose to continue instead of format, follow the below instructions.
======================================================
Please read through the instructions to familiarize yourself with what to expect when the tool runs.
Please download
Combofix from either of the links below, and save it to your desktop.
You
must rename it before saving it. Save it as
iexplore.exe.
[external image: Posted Image]
Link 1
Link 2
The images above say how to save it as Combo-fix.exe, but in this case it is crucial that it is saved as iexplore.exe
**Note: It is important that it is saved directly to your desktop**
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link:How to Disable your Security Programs
- Double click on iexplore.exe & follow the prompts. Close all browsers/windows first.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the
C:\ComboFix.txt in your next reply.
Notes:
1.
Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of
ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.