This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please help remove: Win32:Rootkit-gen [Rtk]

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Crystal,

🖼Click to load external image (Posted Image) Open OTL again
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2010/02/25 10:37:24 | 000,000,120 | —- | M] () – C:\WINDOWS\Ydicejukoze.dat
    [2010/02/25 10:36:10 | 000,000,000 | —- | M] () – C:\WINDOWS\Obapezupewada.bin
    [2002/01/27 05:02:00 | 000,792,064 | —- | C] () – C:\WINDOWS\System32\drivers\btxbar.sys.bak
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local;*.local
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = localhost:2323
    FF - prefs.js..network.proxy.ftp: "localhost"
    FF - prefs.js..network.proxy.ftp_port: 2323
    FF - prefs.js..network.proxy.gopher: "localhost"
    FF - prefs.js..network.proxy.gopher_port: 2323
    FF - prefs.js..network.proxy.http: "localhost"
    FF - prefs.js..network.proxy.http_port: 2323
    FF - prefs.js..network.proxy.no_proxies_on: "local,*.local"
    FF - prefs.js..network.proxy.share_proxy_settings: true
    FF - prefs.js..network.proxy.socks: "localhost"
    FF - prefs.js..network.proxy.socks_port: 2323
    FF - prefs.js..network.proxy.ssl: "localhost"
    FF - prefs.js..network.proxy.ssl_port: 2323
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} http://awbeta.net-nucleus.com/FIX/WinATS.cab   (Mirar_Dummy_ATS1 Class)
    
    :Services
    SRV - (NMIndexingService) – File not found
    
    :Files
    c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
    c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\cqfyto.dat
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
Please include the following in your next post:
  • OTL Fix log
  • How is your computer running?
All processes killed ========== OTL ========== C:\WINDOWS\Ydicejukoze.dat moved successfully. C:\WINDOWS\Obapezupewada.bin moved successfully. File C:\WINDOWS\System32\drivers\btxbar.sys.bak not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! Prefs.js: "localhost" removed from network.proxy.ftp Prefs.js: 2323 removed from network.proxy.ftp_port Prefs.js: "localhost" removed from network.proxy.gopher Prefs.js: 2323 removed from network.proxy.gopher_port Prefs.js: "localhost" removed from network.proxy.http Prefs.js: 2323 removed from network.proxy.http_port Prefs.js: "local,*.local" removed from network.proxy.no_proxies_on Prefs.js: true removed from network.proxy.share_proxy_settings Prefs.js: "localhost" removed from network.proxy.socks Prefs.js: 2323 removed from network.proxy.socks_port Prefs.js: "localhost" removed from network.proxy.ssl Prefs.js: 2323 removed from network.proxy.ssl_port Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Starting removal of ActiveX control {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} C:\WINDOWS\Downloaded Program Files\WinATS.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}\ not found. ========== SERVICES/DRIVERS ========== Error: No service named SRV - (NMIndexingService) – File not found was found to stop! Service\Driver key SRV - (NMIndexingService) – File not found not found. ========== FILES ========== c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat moved successfully. c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\cqfyto.dat moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users.WINDOWS User: Crystal & Addz.HOME-8B021C13CE ->Temp folder emptied: 106661 bytes ->Temporary Internet Files folder emptied: 7320917 bytes ->Java cache emptied: 55520770 bytes ->FireFox cache emptied: 92063444 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService.NT AUTHORITY.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: NetworkService.NT AUTHORITY.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 55808 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 84172 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 483 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 148.00 mb OTL by OldTimer - Version 3.1.30.3 log created on 03012010_063949 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Hi So sorry…you will get a message from devonrexcatz saying I cant reply to your message. I am fixing 2 computers here and forgot to answer Crystal's post on Crystal's computer…to answer your question though, there is a Malwarebytes icon on the desktop which I ran but it was still not complete after 7 hours; that is when I reported that I thought it had not installed properly. Sorry for the post confusion. Crystal
Crystal,

I got your message, thanks. Here are your next instructions:

🖼Click to load external image (Posted Image) Download the Malwarebytes Removal Tool
  • Save it to your desktop, then double click it to run the utility.
  • It will ask you to restart your computer. Please allow it to.
🖼Click to load external image (Posted Image) Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]
  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • MBAM log
  • Kaspersky log
  • A new DDS.txt log
Hi RPMcMurphy (One Flew Over the Cuckoo's Nest, yes?)…very clever! 'Access is Denied' to both my Malwarebytes Log and Kaspersky Log; Avira kept popping up during the Malwarebytes scan whereby I had to OK "Access Denied" about 12 times. The Kaspersky scan is in notebook form on my desktop but I cannot open it' there is a red cross saying "access denied". What will the Malwarebytes Log on my desktop be called (not that I can open it!)? Thankyou Crystal =============== Created Last 30 ================ 2010-02-28 22:00:03 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-28 21:59:59 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-02-28 21:59:59 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-02-28 20:39:49 0 d—–w- C:\_OTL 2010-02-28 03:42:33 0 d-sh–w- c:\documents and settings\crystal & addz.home-8b021c13ce\PrivacIE 2010-02-28 03:16:06 0 d—–w- C:\ComboFix 2010-02-28 02:15:52 0 d—–w- c:\windows\SxsCaPendDel 2010-02-28 02:02:43 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-02-28 01:56:58 0 d—–w- c:\program files\Lavasoft 2010-02-28 01:18:25 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2010-02-28 01:18:20 0 d—–w- c:\program files\Avira 2010-02-28 01:18:20 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Avira 2010-02-26 22:53:27 0 d-sha-r- C:\cmdcons 2010-02-26 22:51:42 98816 —-a-w- c:\windows\sed.exe 2010-02-26 22:51:42 77312 —-a-w- c:\windows\MBR.exe 2010-02-26 22:51:42 261632 —-a-w- c:\windows\PEV.exe 2010-02-26 22:51:42 161792 —-a-w- c:\windows\SWREG.exe 2010-02-23 17:03:11 0 d—–w- c:\docume~1\crysta~1.hom\applic~1\Malwarebytes 2010-02-23 17:03:03 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes 2010-02-08 23:53:24 0 d—–w- c:\docume~1\crysta~1.hom\applic~1\Office Genuine Advantage 2010-02-07 10:18:48 0 d–h–w- c:\windows\system32\GroupPolicy 2010-02-06 14:47:03 0 d—–w- c:\documents and settings\crystal & addz.home-8b021c13ce\Shared 2010-02-06 14:46:56 0 d—–w- c:\documents and settings\crystal & addz.home-8b021c13ce\Incomplete 2010-02-01 11:08:53 0 d—–w- c:\documents and settings\crystal & addz.home-8b021c13ce\Tracing 2010-02-01 11:07:29 0 d—–w- c:\program files\Microsoft 2010-02-01 11:07:10 0 d—–w- c:\program files\Windows Live SkyDrive 2010-02-01 10:57:30 0 d—–w- c:\program files\common files\Windows Live 2010-02-01 10:37:26 0 d-sh–w- c:\documents and settings\crystal & addz.home-8b021c13ce\IETldCache 2010-02-01 10:28:58 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll 2010-02-01 10:28:19 0 d—–w- c:\windows\ie8updates 2010-02-01 10:27:31 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll 2010-02-01 10:27:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll 2010-02-01 10:22:08 0 dc-h–w- c:\windows\ie8 2010-02-01 09:52:11 0 d—–w- c:\docume~1\alluse~1.win\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2010-02-01 09:16:59 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Sony Corporation 2010-02-01 09:00:18 294912 -c—-w- c:\windows\system32\dllcache\msctf.dll ==================== Find3M ==================== 2009-12-31 16:14:12 352640 —-a-w- c:\windows\system32\drivers\srv.sys 2009-12-21 19:14:05 916480 ——w- c:\windows\system32\wininet.dll 2009-12-16 12:58:04 343040 —-a-w- c:\windows\system32\mspaint.exe 2009-12-14 19:15:14 2146304 —-a-w- c:\windows\system32\GPhotos.scr 2009-12-14 07:35:35 33280 —-a-w- c:\windows\system32\csrsrv.dll 2009-12-08 18:53:08 2136064 ——w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:19:32 2015744 ——w- c:\windows\system32\ntkrnlpa.exe ============= FINISH: 16:01:21.43 ===============

Attachments:

Crystal,

Do me a favor and from now on add a new reply instead of editing your posts. I don't get notified when you do an edit and I don't want to miss anything.

Try right clicking on the log and select "Open With…" from the menu. Make sure Notepad is selected as the program to use and click the "Always use the selected program to open this kind of file" box.

If that doesn't work for you open Notepad first then click on File > Open then find and select the log files.

The MBAM log should be in this folder: C:\Documents and Settings\(Your Profile Name)\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs

The DDS log you posted is incomplete. Please try that again also.

Thanks!
Sorry RP…I didn't know whether to reply or edit… …getting the files was easy: what a shame I didn't know how to do that many times in the past, haha. Big problem…I cannot find the Malwarebytes Log Report…it has not been saved so I will run it again. Should take about 2 hours. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, March 1, 2010 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, February 28, 2010 23:27:02 Records in database: 3672401 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Objects scanned: 47997 Threats found: 4 Infected objects found: 6 Suspicious objects found: 0 Scan duration: 01:55:14 File name / Threat / Threats count C:\Qoobox\Quarantine\C\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Start Menu\Programs\Startup\_monnid32_.exe.zip Infected: Trojan-PSW.Win32.Papras.vs 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\ieffse32.dll.vir Infected: Trojan-Downloader.Win32.VB.bla 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\veptlh.dll.vir Infected: Trojan-Downloader.Win32.Agent.dtg 1 C:\System Volume Information\_restore{4B720040-D412-436C-8B8F-F9D42F11973F}\RP1\A0000018.dll Infected: Trojan-Downloader.Win32.VB.bla 1 C:\System Volume Information\_restore{4B720040-D412-436C-8B8F-F9D42F11973F}\RP1\A0000019.dll Infected: Trojan-Downloader.Win32.Agent.dtg 1 C:\WINDOWS\system32\regmod.exe Infected: Trojan.Win32.BHO.he 1 Selected area has been scanned. DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 8:55:14.42 on Tue 02/03/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.2.1252.61.1033.18.511.107 [GMT 10:00] AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\vVX1000.exe C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\My Documents\My Pictures\aaBangin Hawtt EMOs\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com.au/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms} uSearchAssistant = hxxp://www.google.com/ie BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: BigPond Wireless Broadband 2.0 Auto Dial: {db92ec3f-697d-4c3b-9a3b-3abbd23d4a85} - c:\program files\telstra\bigpond wireless broadband 2.0\bpwbb2ad.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe" mRun: [VX1000] c:\windows\vVX1000.exe mRun: [BigPondWirelessBroadbandCM] "c:\program files\telstra\bigpond wireless broadband 2.0\BigPond_CM.exe" -tsr mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000 IE: Transfer by Image Converter 2 - c:\program files\sony\image converter 2\menu.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189190842093 DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} - hxxp://support.packardbell.com/files/activex/InfosFinder2.CAB SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\crysta~1.hom\applic~1\mozilla\firefox\profiles\mppc2bn9.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-2-28 11608] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-2-28 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-2-28 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-2-28 56816] R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [2009-8-17 235648] S2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\bt848.sys [2002-5-13 261696] S2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [2002-1-27 22016] S3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\drivers\cmusbnet.sys [2006-11-23 87424] S3 cmusbser;%CMUSBSER%;c:\windows\system32\drivers\cmusbser.sys [2006-12-13 87040] S3 SNCT511;PC Camera (6005 CIF);c:\windows\system32\drivers\snct511.sys [2007-8-24 219264] =============== Created Last 30 ================ 2010-02-28 22:00:03 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-28 21:59:59 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-02-28 21:59:59 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-02-28 20:39:49 0 d—–w- C:\_OTL 2010-02-28 03:42:33 0 d-sh–w- c:\documents and settings\crystal & addz.home-8b021c13ce\PrivacIE 2010-02-28 03:16:06 0 d—–w- C:\ComboFix 2010-02-28 02:15:52 0 d—–w- c:\windows\SxsCaPendDel 2010-02-28 02:02:43 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-02-28 01:56:58 0 d—–w- c:\program files\Lavasoft 2010-02-28 01:18:25 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2010-02-28 01:18:20 0 d—–w- c:\program files\Avira 2010-02-28 01:18:20 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Avira 2010-02-26 22:53:27 0 d-sha-r- C:\cmdcons 2010-02-26 22:51:42 98816 —-a-w- c:\windows\sed.exe 2010-02-26 22:51:42 77312 —-a-w- c:\windows\MBR.exe 2010-02-26 22:51:42 261632 —-a-w- c:\windows\PEV.exe 2010-02-26 22:51:42 161792 —-a-w- c:\windows\SWREG.exe 2010-02-23 17:03:11 0 d—–w- c:\docume~1\crysta~1.hom\applic~1\Malwarebytes 2010-02-23 17:03:03 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes 2010-02-08 23:53:24 0 d—–w- c:\docume~1\crysta~1.hom\applic~1\Office Genuine Advantage 2010-02-07 10:18:48 0 d–h–w- c:\windows\system32\GroupPolicy 2010-02-06 14:47:03 0 d—–w- c:\documents and settings\crystal & addz.home-8b021c13ce\Shared 2010-02-06 14:46:56 0 d—–w- c:\documents and settings\crystal & addz.home-8b021c13ce\Incomplete 2010-02-01 11:08:53 0 d—–w- c:\documents and settings\crystal & addz.home-8b021c13ce\Tracing 2010-02-01 11:07:29 0 d—–w- c:\program files\Microsoft 2010-02-01 11:07:10 0 d—–w- c:\program files\Windows Live SkyDrive 2010-02-01 10:57:30 0 d—–w- c:\program files\common files\Windows Live 2010-02-01 10:37:26 0 d-sh–w- c:\documents and settings\crystal & addz.home-8b021c13ce\IETldCache 2010-02-01 10:28:58 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll 2010-02-01 10:28:19 0 d—–w- c:\windows\ie8updates 2010-02-01 10:27:31 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll 2010-02-01 10:27:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll 2010-02-01 10:22:08 0 dc-h–w- c:\windows\ie8 2010-02-01 09:52:11 0 d—–w- c:\docume~1\alluse~1.win\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2010-02-01 09:16:59 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Sony Corporation 2010-02-01 09:00:18 294912 -c—-w- c:\windows\system32\dllcache\msctf.dll ==================== Find3M ==================== 2009-12-21 19:14:05 916480 ——w- c:\windows\system32\wininet.dll 2009-12-16 12:58:04 343040 —-a-w- c:\windows\system32\mspaint.exe 2009-12-14 19:15:14 2146304 —-a-w- c:\windows\system32\GPhotos.scr 2009-12-14 07:35:35 33280 —-a-w- c:\windows\system32\csrsrv.dll 2009-12-08 18:53:08 2136064 ——w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:19:32 2015744 ——w- c:\windows\system32\ntkrnlpa.exe ============= FINISH: 8:55:36.78 ===============

Attachments:

Hello RP There is a previous post. Malwarebytes will not let me open or save the log. That is why I could not find the last one I guess. There is a red crossed box when I double click to try to open it in Malwarebytes saying 'access denied' and I cannot right click this one. Belinda :)
Crystal,

Did MBAM at least run? If so, do you know if it removed anything?

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\WINDOWS\system32\regmod.exe
    
    :Commands
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
🖼Click to load external image (Posted Image) Uninstall MBAM via Add/Remove Programs, then Download the Malwarebytes Removal Tool
  • Save it to your desktop, then double click it to run the utility.
  • It will ask you to restart your computer. Please allow it to.
🖼Click to load external image (Posted Image) Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Please include the following in your next post:
  • OTL Fix log
  • MBAM log
  • How is your computer running?
Hi I ran Malwarebytes again…same problem…cannot access the log report. There was no 'OK' and no 'Show Results' to click. It did indicate though that there were no malicious objects found; same as last report. ========== FILES ========== File\Folder C:\WINDOWS\system32\regmod.exe not found. ========== COMMANDS ========== OTL by OldTimer - Version 3.1.30.3 log created on 03022010_130741
Hi There is a previous post… I know what the problem is with Malwarebytes…it does not uninstall the previous version. Regardless I whether I try to to rid it through your link or Control Panel, when I try to install a new one it asks if I want to replace the previous version. Belinda :)
Girls,

Let's try once more to get MBAM running properly for you. I only need a quick scan this time, not a full scan.

🖼Click to load external image (Posted Image) Download and install the Revo Uninstaller
  • Double click the new Revo Uninstaller icon on your desktop to start the program
  • Scroll through the listed programs and Right Click on the program you wish to uninstall (MBAM)
  • From the pop out menu choose Uninstall
  • Click Yes to the confirmation dialogue
  • In the next window select the Advanced mode
  • Click Next to start uninstalling the program
  • Answer Yes to confirm the uninstall
  • When the program has completed the four steps, click Next to allow the program to search for leftovers
  • Once complete, click Next, then Finish
  • Repeat the above steps for any other programs you wish to remove.
🖼Click to load external image (Posted Image) Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Hi I installed Revo and there was no MBAM in the list so I shut out of it. There are still Malwarebytes icons on the desktop though. So I tried to open up Revo again and it says Access Denied. So I tried to override the program with another install and it still doesn't work :( Crystal

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI