This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Need help with removing a trojan.dnschanger and more

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello I'm currently struggling how to remove trojan.dnschanger, i keep doing a quick scan on MalwareBytes and it keeps showing up after i removed it from said MalwareBytes. I tried alot of things but to no avail, i didn't succeed in taking it out. I noticed that it's currently blocking me from windows update. I Have a Windows 7, my laptop manufacture is a Toshiba. I was currently trying to make a HiJackThis Log but it's not working it keeps redirecting host file or something so it doesn't let it write. All i have is a log from MalwareBytes if it helps. It's even blocking me from the MalwareBytes webpage…. Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3930 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 3/29/2010 4:31:02 PM mbam-log-2010-03-29 (16-31-02).txt Scan type: Quick scan Objects scanned: 100039 Time elapsed: 9 minute(s), 9 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] [removed] -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{33efffa5-1f9c-4866-a2bf-47329d48e2d5}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] [removed] -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Thanks for anyone willing to help, if you need more info just ask me.
Hello and :welcome:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 24 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________



You will need to right click and choose "Run as Administrator" to run the tools we will use.


OTL:
  • Download OTL to your desktop.
  • Right click on OTL.exe then choose "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Copy and paste the following bold text into the box under Custom Scan

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    /md5stop
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of the OTL.txt and post it with your next reply along with the Extras.txt log.

–Next–

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right click GMER.exe then choose "Run as Administrator" to run the tool. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


To post in your next reply:
1. OTL logs.
2. GMER log.
OTL logfile created on: 3/30/2010 5:24:39 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\ZSnake\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.00 Mb Total Physical Memory | 548.00 Mb Available Physical Memory | 61.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.59 Gb Total Space | 27.50 Gb Free Space | 49.47% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ZSNAKE-PC
Current User Name: ZSnake
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\ZSnake\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\PowerStrip\PStrip.exe (EnTech Taiwan)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\ZSnake\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (PStrip) – C:\Windows\System32\drivers\pstrip.sys (EnTech Taiwan)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FB BC DC FF 84 CF CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.57

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/29 16:10:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/29 16:10:55 | 000,000,000 | —D | M]

[2010/03/29 14:44:05 | 000,000,000 | —D | M] – C:\Users\ZSnake\AppData\Roaming\Mozilla\Extensions
[2010/03/29 19:32:03 | 000,000,000 | —D | M] – C:\Users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\extensions
[2010/03/29 19:31:58 | 000,000,000 | —D | M] (NoScript) – C:\Users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/03/29 16:00:07 | 000,000,000 | —D | M] (WOT) – C:\Users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/03/29 14:43:47 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 14:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\ZSnake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerStrip.lnk = C:\Program Files\PowerStrip\PStrip.exe (EnTech Taiwan)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/07/13 19:37:08 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

========== Files/Folders - Created Within 30 Days ==========

[2010/03/30 12:16:32 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Juce VST Host
[2010/03/30 12:16:02 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Hardcore
[2010/03/29 22:15:29 | 000,000,000 | —D | C] – C:\Program Files\BeatPack
[2010/03/29 21:16:57 | 000,000,000 | —D | C] – C:\Program Files\ASIO4ALL v2
[2010/03/29 21:16:45 | 000,225,280 | —- | C] (Propellerhead Software AB) – C:\Windows\System32\rewire.dll
[2010/03/29 21:16:21 | 001,554,944 | —- | C] (HMS http://hp.vector.co.jp/authors/VA012897/) – C:\Windows\System32\vorbis.acm
[2010/03/29 21:15:57 | 000,000,000 | —D | C] – C:\Program Files\VstPlugins
[2010/03/29 21:15:55 | 000,000,000 | —D | C] – C:\Program Files\Outsim
[2010/03/29 21:12:38 | 000,000,000 | —D | C] – C:\Program Files\Image-Line
[2010/03/29 20:39:41 | 000,000,000 | —D | C] – C:\Program Files\TrendMicro
[2010/03/29 20:10:54 | 000,000,000 | —D | C] – C:\Program Files\DVDVideoSoft
[2010/03/29 20:10:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DVDVideoSoft
[2010/03/29 19:39:53 | 000,000,000 | —D | C] – C:\Program Files\PowerStrip
[2010/03/29 16:14:48 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Malwarebytes
[2010/03/29 16:14:40 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/29 16:14:37 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/03/29 16:14:36 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/03/29 16:14:36 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/29 16:14:06 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Apple Computer
[2010/03/29 16:14:05 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Apple Computer
[2010/03/29 16:13:34 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/03/29 16:13:34 | 000,000,000 | —D | C] – C:\Windows\System32\DRVSTORE
[2010/03/29 16:12:30 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/03/29 16:12:27 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/03/29 16:12:27 | 000,000,000 | —D | C] – C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/29 16:11:07 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/03/29 16:10:11 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/03/29 16:10:11 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/03/29 16:09:56 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Apple
[2010/03/29 16:09:49 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/03/29 16:08:15 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/03/29 16:08:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/03/29 15:20:50 | 000,028,520 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\ssmdrv.sys
[2010/03/29 15:20:49 | 000,124,784 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\avipbb.sys
[2010/03/29 15:20:49 | 000,060,936 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\avgntflt.sys
[2010/03/29 15:20:49 | 000,051,992 | —- | C] (AVIRA GmbH) – C:\Windows\System32\drivers\avgntdd.sys
[2010/03/29 15:20:49 | 000,017,016 | —- | C] (AVIRA GmbH) – C:\Windows\System32\drivers\avgntmgr.sys
[2010/03/29 15:20:48 | 000,000,000 | —D | C] – C:\ProgramData\Avira
[2010/03/29 15:20:48 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2010/03/29 15:16:02 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2010/03/29 14:43:55 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Mozilla
[2010/03/29 14:43:55 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Mozilla
[2010/03/29 14:43:45 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/03/29 14:34:11 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\WinRAR
[2010/03/29 14:32:20 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2010/03/29 14:26:31 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Diagnostics
[2010/03/29 14:19:26 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Macromedia
[2010/03/29 14:19:26 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Adobe
[2010/03/29 14:19:07 | 000,000,000 | —D | C] – C:\Windows\System32\Macromed
[2010/03/29 01:43:29 | 000,000,000 | —D | C] – C:\Windows\Panther
[2010/03/29 01:19:54 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Searches
[2010/03/29 01:19:39 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Identities
[2010/03/29 01:19:34 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Contacts
[2010/03/29 01:19:17 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\VirtualStore
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\AppData\Local\Temporary Internet Files
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Templates
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Start Menu
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\SendTo
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Recent
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\PrintHood
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\NetHood
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Documents\My Videos
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Documents\My Pictures
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Documents\My Music
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\My Documents
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Local Settings
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\AppData\Local\History
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Cookies
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Application Data
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\AppData\Local\Application Data
[2010/03/29 01:19:01 | 000,000,000 | –SD | C] – C:\Users\ZSnake\AppData\Roaming\Microsoft
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Videos
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Saved Games
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Pictures
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Music
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Links
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Favorites
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Downloads
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Documents
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Desktop
[2010/03/29 01:19:01 | 000,000,000 | -H-D | C] – C:\Users\ZSnake\AppData
[2010/03/29 01:19:01 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Temp
[2010/03/29 01:19:01 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Microsoft
[2010/03/29 01:19:01 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Media Center Programs
[2010/03/29 00:48:00 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2010/03/29 00:44:52 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2010/03/23 15:30:07 | 000,000,000 | —D | C] – C:\Users\ZSnake\Documents\Samples

========== Files - Modified Within 30 Days ==========

[2010/03/30 17:27:21 | 000,786,432 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT
[2010/03/30 12:22:46 | 000,016,944 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/30 12:22:46 | 000,016,944 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/30 12:19:25 | 000,713,888 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/03/30 12:19:25 | 000,615,360 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/03/30 12:19:25 | 000,103,702 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/03/30 12:15:37 | 000,008,463 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.ini
[2010/03/30 12:15:33 | 000,008,463 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bak
[2010/03/30 12:15:11 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/03/30 12:14:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/03/30 12:14:47 | 703,156,224 | -HS- | M] () – C:\hiberfil.sys
[2010/03/29 23:05:45 | 000,008,486 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bk!
[2010/03/29 23:05:44 | 001,237,742 | -H– | M] () – C:\Users\ZSnake\AppData\Local\IconCache.db
[2010/03/29 21:16:45 | 000,001,108 | —- | M] () – C:\Users\ZSnake\Desktop\FL Studio 9.lnk
[2010/03/29 20:39:42 | 000,002,967 | —- | M] () – C:\Users\ZSnake\Desktop\HiJackThis.lnk
[2010/03/29 20:11:13 | 000,001,208 | —- | M] () – C:\Users\ZSnake\Desktop\DVDVideoSoft Free Studio.lnk
[2010/03/29 19:48:40 | 000,007,733 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bko
[2010/03/29 19:48:40 | 000,001,435 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerStrip.lnk
[2010/03/29 19:40:04 | 000,000,063 | —- | M] () – C:\Windows\wininit.ini
[2010/03/29 16:14:43 | 000,000,990 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/29 16:13:46 | 000,002,429 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/03/29 16:10:33 | 000,001,826 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/03/29 15:24:58 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/29 15:24:46 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/03/29 15:21:16 | 000,002,023 | —- | M] () – C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2010/03/29 14:46:25 | 000,057,560 | —- | M] () – C:\Users\ZSnake\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/29 14:43:49 | 000,001,896 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/03/29 14:36:21 | 000,000,020 | RHS- | M] () – C:\winx.ld
[2010/03/29 14:36:19 | 000,205,098 | RHS- | M] () – C:\GQILH
[2010/03/29 01:43:16 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2010/03/29 01:19:12 | 000,000,020 | -HS- | M] () – C:\Users\ZSnake\ntuser.ini
[2010/03/29 01:19:11 | 000,524,288 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/03/29 01:19:11 | 000,524,288 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/03/29 01:19:11 | 000,065,536 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/03/29 00:58:21 | 000,266,808 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/03/29 00:49:39 | 000,042,045 | —- | M] () – C:\Windows\System32\license.rtf
[2010/03/28 21:16:15 | 000,000,330 | —- | M] () – C:\Users\ZSnake\Documents\cc_20100328_211551.reg
[2010/03/28 21:15:31 | 000,010,702 | —- | M] () – C:\Users\ZSnake\Documents\cc_20100328_211520.reg
[2010/03/01 09:05:24 | 000,124,784 | —- | M] (Avira GmbH) – C:\Windows\System32\drivers\avipbb.sys

========== Files Created - No Company Name ==========

[2010/03/30 12:15:36 | 000,008,486 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bk!
[2010/03/30 12:15:29 | 000,007,733 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bko
[2010/03/29 21:16:45 | 000,001,108 | —- | C] () – C:\Users\ZSnake\Desktop\FL Studio 9.lnk
[2010/03/29 20:39:42 | 000,002,967 | —- | C] () – C:\Users\ZSnake\Desktop\HiJackThis.lnk
[2010/03/29 20:23:57 | 000,008,463 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bak
[2010/03/29 20:11:13 | 000,001,208 | —- | C] () – C:\Users\ZSnake\Desktop\DVDVideoSoft Free Studio.lnk
[2010/03/29 19:48:38 | 000,001,435 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerStrip.lnk
[2010/03/29 19:48:36 | 000,008,463 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.ini
[2010/03/29 19:40:04 | 000,000,063 | —- | C] () – C:\Windows\wininit.ini
[2010/03/29 16:14:43 | 000,000,990 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/29 16:13:46 | 000,002,429 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/03/29 16:10:33 | 000,001,826 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/03/29 15:21:16 | 000,002,023 | —- | C] () – C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2010/03/29 14:43:49 | 000,001,896 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/03/29 14:36:21 | 000,000,020 | RHS- | C] () – C:\winx.ld
[2010/03/29 14:36:19 | 000,205,098 | RHS- | C] () – C:\GQILH
[2010/03/29 01:19:12 | 000,000,020 | -HS- | C] () – C:\Users\ZSnake\ntuser.ini
[2010/03/29 01:19:11 | 000,524,288 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/03/29 01:19:11 | 000,524,288 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/03/29 01:19:11 | 000,065,536 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/03/29 01:19:01 | 000,786,432 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT
[2010/03/29 00:44:23 | 703,156,224 | -HS- | C] () – C:\hiberfil.sys
[2010/03/28 21:15:53 | 000,000,330 | —- | C] () – C:\Users\ZSnake\Documents\cc_20100328_211551.reg
[2010/03/28 21:15:24 | 000,010,702 | —- | C] () – C:\Users\ZSnake\Documents\cc_20100328_211520.reg
[2009/07/13 16:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll

========== LOP Check ==========

[2010/03/30 12:16:02 | 000,000,000 | —D | M] – C:\Users\ZSnake\AppData\Roaming\Hardcore
[2010/03/30 12:16:43 | 000,000,000 | —D | M] – C:\Users\ZSnake\AppData\Roaming\Juce VST Host
[2009/07/13 21:53:46 | 000,004,618 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 18:26:15 | 000,053,312 | —- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E – C:\Windows\System32\drivers\AGP440.sys
[2009/07/13 18:26:15 | 000,053,312 | —- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E – C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009/07/13 18:26:15 | 000,053,312 | —- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 18:26:15 | 000,021,584 | —- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E – C:\Windows\System32\drivers\atapi.sys
[2009/07/13 18:26:15 | 000,021,584 | —- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009/07/13 18:26:15 | 000,021,584 | —- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\System32\cngaudit.dll
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2009/07/13 18:20:36 | 000,332,352 | —- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 – C:\Windows\System32\drivers\iaStorV.sys
[2009/07/13 18:20:36 | 000,332,352 | —- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 18:20:36 | 000,332,352 | —- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\System32\netlogon.dll
[2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 18:20:44 | 000,142,416 | —- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F – C:\Windows\System32\drivers\nvstor.sys
[2009/07/13 18:20:44 | 000,142,416 | —- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 18:20:44 | 000,142,416 | —- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\System32\scecli.dll
[2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll

< End of report >


——————————————————————————————————————————————-

OTL Extras logfile created on: 3/30/2010 5:24:39 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\ZSnake\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.00 Mb Total Physical Memory | 548.00 Mb Available Physical Memory | 61.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.59 Gb Total Space | 27.50 Gb Free Space | 49.47% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ZSNAKE-PC
Current User Name: ZSnake
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{81063354-9060-42B2-A000-1EBE96778AA9}" = iTunes
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ASIO4ALL" = ASIO4ALL
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BeatPack" = BeatPack (0.9)
"FL Studio 9" = FL Studio 9
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.2
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.2
"Hardcore" = Hardcore
"IL Download Manager" = IL Download Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6.2)" = Mozilla Firefox (3.6.2)
"PoiZone" = PoiZone
"PowerStrip 3 (remove only)" = PowerStrip 3 (remove only)
"Sawer" = Sawer
"Toxic Biohazard" = Toxic Biohazard
"Uninstall_is1" = Uninstall 1.0.0.1
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/29/2010 5:37:24 PM | Computer Name = ZSnake-PC | Source = Windows 7 Loader | ID = 1000
Description =

Error - 3/29/2010 5:37:24 PM | Computer Name = ZSnake-PC | Source = Windows 7 Loader | ID = 1000
Description =

Error - 3/29/2010 5:37:24 PM | Computer Name = ZSnake-PC | Source = Windows 7 Loader | ID = 1000
Description =

Error - 3/29/2010 5:37:24 PM | Computer Name = ZSnake-PC | Source = Windows 7 Loader | ID = 1000
Description =

Error - 3/29/2010 5:37:24 PM | Computer Name = ZSnake-PC | Source = Windows 7 Loader | ID = 1000
Description =

Error - 3/29/2010 5:37:24 PM | Computer Name = ZSnake-PC | Source = Windows 7 Loader | ID = 1000
Description =

Error - 3/29/2010 5:37:24 PM | Computer Name = ZSnake-PC | Source = Windows 7 Loader | ID = 1000
Description =

Error - 3/29/2010 5:37:24 PM | Computer Name = ZSnake-PC | Source = Windows 7 Loader | ID = 1000
Description =

Error - 3/29/2010 6:15:56 PM | Computer Name = ZSnake-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Users\ZSnake\AppData\Local\Temp\RarSFX0\redist.dll".
Dependent
Assembly Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.4148"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 3/30/2010 1:22:10 AM | Computer Name = ZSnake-PC | Source = Application Hang | ID = 1002
Description = The program iTunes.exe version 9.0.3.15 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 4ac Start Time:
01cacfc8c26ddcd4 Termination Time: 69 Application Path: C:\Program Files\iTunes\iTunes.exe

Report
Id:

[ System Events ]
Error - 3/29/2010 9:25:41 PM | Computer Name = ZSnake-PC | Source = Service Control Manager | ID = 7038
Description = The WdiServiceHost service was unable to log on as NT AUTHORITY\LocalService
with the currently configured password due to the following error: %%50 To ensure
that the service is configured properly, use the Services snap-in in Microsoft
Management Console (MMC).

Error - 3/29/2010 9:25:41 PM | Computer Name = ZSnake-PC | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
error: %%1069

Error - 3/29/2010 9:25:41 PM | Computer Name = ZSnake-PC | Source = Service Control Manager | ID = 7000
Description = The Portable Device Enumerator Service service failed to start due
to the following error: %%1115

Error - 3/29/2010 9:26:56 PM | Computer Name = ZSnake-PC | Source = DCOM | ID = 10005
Description =

Error - 3/29/2010 9:26:56 PM | Computer Name = ZSnake-PC | Source = Service Control Manager | ID = 7038
Description = The netprofm service was unable to log on as NT AUTHORITY\LocalService
with the currently configured password due to the following error: %%1352 To ensure
that the service is configured properly, use the Services snap-in in Microsoft
Management Console (MMC).

Error - 3/29/2010 9:26:56 PM | Computer Name = ZSnake-PC | Source = Service Control Manager | ID = 7000
Description = The Network List Service service failed to start due to the following
error: %%1069

Error - 3/29/2010 9:26:56 PM | Computer Name = ZSnake-PC | Source = Service Control Manager | ID = 7038
Description = The WdiServiceHost service was unable to log on as NT AUTHORITY\LocalService
with the currently configured password due to the following error: %%1352 To ensure
that the service is configured properly, use the Services snap-in in Microsoft
Management Console (MMC).

Error - 3/29/2010 9:26:56 PM | Computer Name = ZSnake-PC | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
error: %%1069

Error - 3/29/2010 9:26:56 PM | Computer Name = ZSnake-PC | Source = Service Control Manager | ID = 7000
Description = The Portable Device Enumerator Service service failed to start due
to the following error: %%1115

Error - 3/29/2010 11:23:22 PM | Computer Name = ZSnake-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:20:08 PM on ?3/?29/?2010 was unexpected.


< End of report >
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-30 18:01:41
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\ZSnake\AppData\Local\Temp\uxlyypow.sys


—- System - GMER 1.0.15 —-

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82826AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82826104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 828263F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8280EFB4
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 828261DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82826958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 828266F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82826F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 828271A8

—- Devices - GMER 1.0.15 —-

Device \Driver\ACPI_HAL \Device\00000045 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi,

Right click OTL.exe then choose "Run as Administrator" to run the tool.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • Then post the result and a new OTL log in your next reply. ( don't check the boxes beside LOP Check or Purity this time )
–Next–
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform full scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

–Next–

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Right-click SystemLook.exe then choose "Run as Administrator" to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    webcheck.dll
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

To post in your next reply:
1. OTL logs.
2. Malwarebytes' log.
3. Systemlook log.
All processes killed ========== OTL ========== No active process named explorer.exe was found! HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer| /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: ZSnake ->Temp folder emptied: 7275479 bytes ->Temporary Internet Files folder emptied: 47940798 bytes ->FireFox cache emptied: 72351996 bytes ->Flash cache emptied: 2905 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2329472 bytes RecycleBin emptied: 374585 bytes Total Files Cleaned = 124.00 mb OTL by OldTimer - Version 3.1.37.3 log created on 03302010_213600 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3935 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 3/30/2010 11:05:02 PM mbam-log-2010-03-30 (23-05-02).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 165351 Time elapsed: 48 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] [removed] -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{33efffa5-1f9c-4866-a2bf-47329d48e2d5}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] [removed] -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 23:10 on 30/03/2010 by ZSnake (Administrator - Elevation successful) ========== filefind ========== Searching for "webcheck.dll" C:\Windows\System32\webcheck.dll –a— 229376 bytes [23:43 13/07/2009] [01:16 14/07/2009] 177DF28315BF4300ECB5CBEEEE961292 C:\Windows\winsxs\x86_microsoft-windows-ie-offlinefavorites_31bf3856ad364e35_8.0.7600.16385_none_7bbc80532a0f1e83\webcheck.dll –a— 229376 bytes [23:43 13/07/2009] [01:16 14/07/2009] 177DF28315BF4300ECB5CBEEEE961292 -=End Of File=-
Hi,

Download Combofix from either of the links below. You must rename it to Subsfix.exe before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

———————————————————–


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Right click and choose Run as Administrator the renamed ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

———————————————————–

ComboFix 10-03-29.04 - ZSnake 04/01/2010 14:18:11.1.1 - x86 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.894.468 [GMT -7:00] Running from: c:\users\[removed]\Desktop\Subsfix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2010-03-01 to 2010-04-01 ))))))))))))))))))))))))))))))) . 2010-04-01 21:25 . 2010-04-01 21:25 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-03-31 04:36 . 2010-03-31 04:36 ——– d—–w- C:\_OTL 2010-03-30 19:16 . 2010-03-30 19:16 ——– d—–w- c:\users\ZSnake\AppData\Roaming\Juce VST Host 2010-03-30 19:16 . 2010-03-30 19:16 ——– d—–w- c:\users\ZSnake\AppData\Roaming\Hardcore 2010-03-30 05:15 . 2010-03-30 05:15 ——– d—–w- c:\program files\BeatPack 2010-03-30 04:16 . 2010-03-30 04:16 ——– d—–w- c:\program files\ASIO4ALL v2 2010-03-30 04:16 . 2006-06-20 08:56 225280 —-a-w- c:\windows\system32\rewire.dll 2010-03-30 04:15 . 2010-03-30 04:16 ——– d—–w- c:\program files\VstPlugins 2010-03-30 04:15 . 2010-03-30 04:15 ——– d—–w- c:\program files\Outsim 2010-03-30 04:12 . 2010-03-30 04:16 ——– d—–w- c:\program files\Image-Line 2010-03-30 03:39 . 2010-03-30 03:39 388096 —-a-r- c:\users\ZSnake\AppData\Roaming\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe 2010-03-30 03:39 . 2010-03-30 03:39 ——– d—–w- c:\program files\TrendMicro 2010-03-30 03:10 . 2010-03-30 03:11 ——– d—–w- c:\program files\Common Files\DVDVideoSoft 2010-03-30 03:10 . 2010-03-30 03:11 ——– d—–w- c:\program files\DVDVideoSoft 2010-03-30 02:39 . 2010-03-30 02:40 ——– d—–w- c:\program files\PowerStrip 2010-03-29 23:14 . 2010-03-29 23:14 ——– d—–w- c:\users\ZSnake\AppData\Roaming\Malwarebytes 2010-03-29 23:14 . 2010-03-29 22:24 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-29 23:14 . 2010-03-29 23:14 ——– d—–w- c:\programdata\Malwarebytes 2010-03-29 23:14 . 2010-03-29 23:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-03-29 23:14 . 2010-03-29 22:24 20824 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-03-29 23:14 . 2010-03-31 21:31 ——– d—–w- c:\users\ZSnake\AppData\Local\Apple Computer 2010-03-29 23:14 . 2010-03-29 23:16 ——– d—–w- c:\users\ZSnake\AppData\Roaming\Apple Computer 2010-03-29 23:13 . 2010-03-29 23:13 ——– dc—-w- c:\windows\system32\DRVSTORE 2010-03-29 23:13 . 2009-05-18 21:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2010-03-29 23:13 . 2008-04-17 20:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll 2010-03-29 23:12 . 2010-03-29 23:12 ——– d—–w- c:\program files\iPod 2010-03-29 23:12 . 2010-03-29 23:13 ——– d—–w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2010-03-29 23:12 . 2010-03-29 23:13 ——– d—–w- c:\program files\iTunes 2010-03-29 23:11 . 2010-03-29 23:11 ——– d—–w- c:\program files\Bonjour 2010-03-29 23:10 . 2010-03-29 23:12 ——– d—–w- c:\programdata\Apple Computer 2010-03-29 23:10 . 2010-03-29 23:10 ——– d—–w- c:\program files\QuickTime 2010-03-29 23:09 . 2010-03-29 23:09 ——– d—–w- c:\users\ZSnake\AppData\Local\Apple 2010-03-29 23:09 . 2010-03-29 23:09 ——– d—–w- c:\program files\Apple Software Update 2010-03-29 23:08 . 2010-03-29 23:12 ——– d—–w- c:\program files\Common Files\Apple 2010-03-29 23:08 . 2010-03-29 23:08 ——– d—–w- c:\programdata\Apple 2010-03-29 22:20 . 2010-03-01 16:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys 2010-03-29 22:20 . 2010-02-16 20:24 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2010-03-29 22:20 . 2009-05-11 18:49 51992 —-a-w- c:\windows\system32\drivers\avgntdd.sys 2010-03-29 22:20 . 2009-05-11 18:49 17016 —-a-w- c:\windows\system32\drivers\avgntmgr.sys 2010-03-29 22:20 . 2010-03-29 22:20 ——– d—–w- c:\programdata\Avira 2010-03-29 22:20 . 2010-03-29 22:20 ——– d—–w- c:\program files\Avira 2010-03-29 22:16 . 2010-03-30 03:39 ——– d-sh–w- c:\windows\Installer 2010-03-29 21:46 . 2010-03-29 21:46 57560 —-a-w- c:\users\ZSnake\AppData\Local\GDIPFONTCACHEV1.DAT 2010-03-29 21:43 . 2010-03-29 21:43 ——– d—–w- c:\users\ZSnake\AppData\Local\Mozilla 2010-03-29 21:26 . 2010-03-29 21:26 ——– d—–w- c:\users\ZSnake\AppData\Local\Diagnostics 2010-03-29 21:19 . 2010-03-29 21:19 ——– d—–w- c:\windows\system32\Macromed 2010-03-29 20:56 . 2010-04-01 21:07 ——– d—–w- c:\windows\system32\wbem\Performance 2010-03-29 08:43 . 2010-03-29 08:18 ——– d—–w- c:\windows\Panther . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-31 05:23 . 2010-03-31 05:23 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf 2010-02-16 01:41 . 2010-02-16 01:41 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe 2009-06-10 21:26 . 2009-07-14 02:04 9633792 –sha-r- c:\windows\Fonts\StaticCache.dat 2009-07-14 01:14 . 2009-07-13 23:42 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-16 141608] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-03-29 1086856] c:\users\ZSnake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ PowerStrip.lnk - c:\program files\PowerStrip\PStrip.exe [2009-11-1 744992] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv S1 PStrip;PStrip;c:\windows\system32\drivers\pstrip.sys [2007-07-15 27992] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local FF - ProfilePath - c:\users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\ FF - prefs.js: browser.search.selectedEngine - Wikipedia (en) —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); . . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'Explorer.exe'(1736) c:\program files\PowerStrip\pshook.dll . Completion time: 2010-04-01 14:28:16 ComboFix-quarantined-files.txt 2010-04-01 21:28 Pre-Run: 29,089,783,808 bytes free Post-Run: 29,107,208,192 bytes free - - End Of File - - 8079C6819B072BB90EBF43402DC064B4
Hi,

Let’s try to reset the router to its default configuration.
  • This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router.
  • Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
  • If you don’t know the router's default password, you can look it up. HERE
  • You also need to reconfigure any security settings you had in place prior to the reset.
  • You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

–Next–

Do the following:
  • Click the Start logo in the bottom left corner of the screen.
  • Click All Programs.
  • Click Accessories.
  • RIGHT-click on Command Prompt.
  • Select Run As Administrator.
  • In the command window type the following or copy/paste and then hit enter: ipconfig /flushdns
    NOTE:There is a space between the letter g in ipconfig and the slash(/) in /flushdns.
  • You will see the following confirmation:

Windows IP Configuration
Successfully flushed the DNS Resolver Cache.


–Next–

Let's go for another Malwarebytes scan:
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform full scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


To post in your next reply:
1. Were you able to reset your router and flushed your DNS?
2. Malwarebytes' log.
3. How is your computer?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI