This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE /Browser Hijack

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

………………………START…………………….
problem description:

internet explorer
web pages are hijacked and replaced with a red banner screen saying "Attention! Your web page request has been cancelled" in order to activate your security software, please press Fix Now(recommended)

option boxes: Resend request and Fix Now
……………………………………………..
sysinfo:
Windows 7 - (winNT 6.00.3504)
internet explorer v8.00 (8.00.7600.16385)
Toshiba Laptop
………………………………………………


1) have searched for antivirus7 on system; not found.

2) run McAfee stinger(10.1.0.995 built aug 5 2010)

c:\program files\toshiba\TosApin\Comps1\TC\10033000\TC10033000C.exe\wtsetup.exe\11.nsis\6.nsis\7.nsis
found the Artemis!BB03AF6402B Trojan!!!
c:\ProgramData\WildTangent\951226E3-26FC-40BC-8085-3677B1128F95-extr.exe\7.niss
found the Artemis!BB03AF6402B Trojan!!!
c:\ProgramData\WildTangent\951226E3-26FC-40BC-8085-3677B1128F95-extr.exe\7.niss has been deleted.

clean files 20563
number of trojans 2
number of files deleted 1


3) run McAfee stinger(10.1.0.995 built aug 5 2010)

c:\program files\toshiba\TosApin\Comps1\TC\10033000\TC10033000C.exe\wtsetup.exe\11.nsis\6.nsis\7.nsis
found the Artemis!BB03AF6402B Trojan!!!

clean files 20560
number of trojans 1

4) run malwazrebytes(current update) full scan… found none
………………………………………
Hijackthis post below
……………………….
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:26:58 PM, on 8/25/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskhost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn1.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.3.60.33\facemoods.dll
O2 - BHO: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn1.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client\YontooIEClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyn1.dll
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.3.60.33\facemoodsTlbr.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [NortonOnlineBackupReminder] "C:\Program Files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" UNATTENDED
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\ARO.exe -rem
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MemTurbo.lnk = C:\Program Files\MemTurbo 4\MemTurbo.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AMD External Events Utility - AMD - C:\windows\system32\atiesrxx.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe

–
End of file - 8874 bytes
…………………………………….END…………………………….
……….
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
=========================================
start of post
=====================================

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: TOSHIBA
BIOS Manufacturer: Insyde Corp.
System Manufacturer: TOSHIBA
System Product Name: Satellite L505D
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 195):
0x82C10000 \SystemRoot\system32\ntkrnlpa.exe
0x83020000 \SystemRoot\system32\halmacpi.dll
0x867C7000 \SystemRoot\system32\kdcom.dll
0x83232000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
0x8323D000 \SystemRoot\system32\PSHED.dll
0x8324E000 \SystemRoot\system32\BOOTVID.dll
0x83256000 \SystemRoot\system32\CLFS.SYS
0x83298000 \SystemRoot\system32\CI.dll
0x83343000 \SystemRoot\system32\drivers\Wdf01000.sys
0x833B4000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8342A000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x83472000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x8347B000 \SystemRoot\system32\drivers\fltmgr.sys
0x834AF000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x834B7000 \SystemRoot\system32\DRIVERS\pci.sys
0x834E1000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x834EC000 \SystemRoot\System32\drivers\partmgr.sys
0x834FD000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x83505000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x83510000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x83520000 \SystemRoot\System32\drivers\volmgrx.sys
0x8356B000 \SystemRoot\system32\DRIVERS\pciide.sys
0x83572000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x83580000 \SystemRoot\System32\drivers\mountmgr.sys
0x83596000 \SystemRoot\system32\DRIVERS\atapi.sys
0x8359F000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x835C2000 \SystemRoot\system32\DRIVERS\msahci.sys
0x835CC000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x835D5000 \SystemRoot\system32\drivers\fileinfo.sys
0x833C2000 \SystemRoot\system32\drivers\PCTCore.sys
0x8362F000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8375E000 \SystemRoot\System32\Drivers\msrpc.sys
0x83789000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8379C000 \SystemRoot\System32\Drivers\cng.sys
0x83600000 \SystemRoot\System32\drivers\pcw.sys
0x8360E000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x8AA05000 \SystemRoot\system32\drivers\ndis.sys
0x8AABC000 \SystemRoot\system32\drivers\NETIO.SYS
0x8AAFA000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8AC38000 \SystemRoot\System32\drivers\tcpip.sys
0x8AD81000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8ADB2000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x8ADF1000 \SystemRoot\system32\DRIVERS\TVALZ_O.SYS
0x8AB1F000 \SystemRoot\system32\DRIVERS\tos_sps32.sys
0x8ADF6000 \SystemRoot\System32\Drivers\spldr.sys
0x8AC00000 \SystemRoot\System32\drivers\rdyboost.sys
0x8AB66000 \SystemRoot\System32\Drivers\mup.sys
0x8AC2D000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8AB76000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x8ABA8000 \SystemRoot\system32\DRIVERS\disk.sys
0x8ABB9000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8ABDE000 \SystemRoot\system32\DRIVERS\AtiPcie.sys
0x83400000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x83621000 \SystemRoot\System32\Drivers\Null.SYS
0x83628000 \SystemRoot\System32\Drivers\Beep.SYS
0x83200000 \SystemRoot\System32\drivers\vga.sys
0x8320C000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8FE14000 \SystemRoot\System32\drivers\watchdog.sys
0x8FE21000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8FE29000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8FE31000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8FE39000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8FE44000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8FE52000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8FE69000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8FE74000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8FEA6000 \SystemRoot\system32\drivers\afd.sys
0x8FF00000 \SystemRoot\system32\drivers\ws2ifsl.sys
0x8FF09000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x8FF10000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8FF2F000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x8FF40000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8FF4E000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8FF61000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8FF71000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x8FF77000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8FFB8000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8FFC2000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8FFCC000 \SystemRoot\System32\drivers\discache.sys
0x8FFD8000 \SystemRoot\System32\Drivers\dfsc.sys
0x8FFF0000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x8F008000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x8F024000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0x8F026000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8F047000 \SystemRoot\system32\DRIVERS\TVALZFL.sys
0x8F04E000 \SystemRoot\system32\DRIVERS\FwLnk.sys
0x8F056000 \SystemRoot\system32\DRIVERS\amdppm.sys
0x8F067000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x90C0F000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x91124000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8F06B000 \SystemRoot\System32\drivers\dxgmms1.sys
0x8F0A4000 \SystemRoot\system32\DRIVERS\RTL8187Se.sys
0x911DB000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x8F107000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x911E5000 \SystemRoot\system32\DRIVERS\tdcmdpst.sys
0x911EF000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x911F5000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x8F138000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x90C00000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8F183000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8F1A2000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8F1BA000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8F1C7000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8F1FA000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8FE00000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x94C29000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x94C36000 \SystemRoot\system32\DRIVERS\serscan.sys
0x94C3E000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x94C50000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x94C68000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x94C73000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x94C95000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x94CAD000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x94CC4000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x94CDB000 \SystemRoot\system32\DRIVERS\swenum.sys
0x94CDD000 \SystemRoot\system32\DRIVERS\ks.sys
0x94D11000 \SystemRoot\system32\DRIVERS\umbus.sys
0x94D1F000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x94D63000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x96025000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x962C1000 \SystemRoot\system32\drivers\portcls.sys
0x962F0000 \SystemRoot\system32\drivers\drmk.sys
0x96EF0000 \SystemRoot\System32\win32k.sys
0x96309000 \SystemRoot\System32\drivers\Dxapi.sys
0x96313000 \SystemRoot\System32\Drivers\crashdmp.sys
0x96320000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x9632B000 \SystemRoot\System32\Drivers\dump_msahci.sys
0x96335000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x96346000 \SystemRoot\system32\DRIVERS\monitor.sys
0x97150000 \SystemRoot\System32\TSDDD.dll
0x97180000 \SystemRoot\System32\cdd.dll
0x96351000 \SystemRoot\system32\drivers\luafv.sys
0x9636C000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x96380000 \SystemRoot\system32\drivers\WudfPf.sys
0x9639A000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x963AA000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x963F0000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x96000000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x94D74000 \SystemRoot\system32\drivers\HTTP.sys
0x94C00000 \SystemRoot\system32\DRIVERS\bowser.sys
0x96013000 \SystemRoot\System32\drivers\mpsdrv.sys
0x9C214000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x9C237000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x9C272000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x9C2A5000 \SystemRoot\system32\drivers\AVRec.sys
0x9C2AD000 \SystemRoot\system32\drivers\peauth.sys
0x9C344000 \SystemRoot\System32\Drivers\secdrv.SYS
0x9C34E000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x9C36F000 \SystemRoot\System32\drivers\tcpipreg.sys
0x9C37C000 \SystemRoot\system32\drivers\AVHook.sys
0x9C386000 \SystemRoot\System32\DRIVERS\srv2.sys
0x9C3D5000 \SystemRoot\system32\drivers\AVFilter.sys
0xA061C000 \SystemRoot\System32\DRIVERS\srv.sys
0xA066D000 \SystemRoot\System32\Drivers\RtsUStor.sys
0xA069A000 \SystemRoot\System32\Drivers\fastfat.SYS
0xA06E5000 \SystemRoot\system32\drivers\spsys.sys
0x76ED0000 \Windows\System32\ntdll.dll
0x47D40000 \Windows\System32\smss.exe
0x77110000 \Windows\System32\apisetschema.dll
0x000D0000 \Windows\System32\autochk.exe
0x770E0000 \Windows\System32\imm32.dll
0x77090000 \Windows\System32\gdi32.dll
0x76E40000 \Windows\System32\oleaut32.dll
0x761F0000 \Windows\System32\shell32.dll
0x76160000 \Windows\System32\clbcatq.dll
0x760C0000 \Windows\System32\advapi32.dll
0x77080000 \Windows\System32\psapi.dll
0x76010000 \Windows\System32\msvcrt.dll
0x75F70000 \Windows\System32\usp10.dll
0x77070000 \Windows\System32\nsi.dll
0x75EF0000 \Windows\System32\comdlg32.dll
0x75CF0000 \Windows\System32\iertutil.dll
0x77020000 \Windows\System32\Wldap32.dll
0x75BB0000 \Windows\System32\urlmon.dll
0x75A50000 \Windows\System32\ole32.dll
0x77010000 \Windows\System32\normaliz.dll
0x758B0000 \Windows\System32\setupapi.dll
0x757E0000 \Windows\System32\user32.dll
0x757B0000 \Windows\System32\imagehlp.dll
0x756B0000 \Windows\System32\wininet.dll
0x75690000 \Windows\System32\sechost.dll
0x755E0000 \Windows\System32\rpcrt4.dll
0x755D0000 \Windows\System32\lpk.dll
0x75590000 \Windows\System32\ws2_32.dll
0x75530000 \Windows\System32\difxapi.dll
0x754D0000 \Windows\System32\shlwapi.dll
0x75400000 \Windows\System32\msctf.dll
0x75320000 \Windows\System32\kernel32.dll
0x752F0000 \Windows\System32\wintrust.dll
0x75260000 \Windows\System32\comctl32.dll
0x75210000 \Windows\System32\KernelBase.dll
0x750F0000 \Windows\System32\crypt32.dll
0x750C0000 \Windows\System32\cfgmgr32.dll
0x750A0000 \Windows\System32\devobj.dll
0x75090000 \Windows\System32\msasn1.dll

Processes (total 65):
0 System Idle Process
4 System
272 C:\Windows\System32\smss.exe
412 csrss.exe
488 csrss.exe
496 C:\Windows\System32\wininit.exe
536 C:\Windows\System32\winlogon.exe
596 C:\Windows\System32\services.exe
604 C:\Windows\System32\lsass.exe
612 C:\Windows\System32\lsm.exe
724 C:\Windows\System32\svchost.exe
824 C:\Windows\System32\svchost.exe
872 C:\Windows\System32\atiesrxx.exe
952 C:\Windows\System32\svchost.exe
1004 C:\Windows\System32\svchost.exe
1060 C:\Windows\System32\svchost.exe
1124 C:\Windows\System32\audiodg.exe
1180 C:\Windows\System32\svchost.exe
1196 C:\Windows\System32\atieclxx.exe
1332 C:\Windows\System32\svchost.exe
1516 C:\Windows\System32\spoolsv.exe
1544 C:\Windows\System32\dwm.exe
1608 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1620 C:\Windows\explorer.exe
1640 C:\Windows\System32\taskhost.exe
1680 C:\Windows\System32\svchost.exe
1744 C:\Windows\System32\taskeng.exe
1992 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
432 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
408 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
480 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
1164 C:\Program Files\Bonjour\mDNSResponder.exe
1284 C:\Program Files\iTunes\iTunesHelper.exe
1552 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
1580 C:\Program Files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe
1832 C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
308 C:\Windows\System32\svchost.exe
2132 C:\Windows\System32\svchost.exe
2240 C:\Windows\System32\TODDSrv.exe
2348 C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
2448 C:\Program Files\TOSHIBA\TECO\TecoService.exe
2524 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
2612 C:\Windows\System32\SearchIndexer.exe
2824 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
3160 C:\Windows\System32\SearchProtocolHost.exe
3260 C:\Program Files\iPod\bin\iPodService.exe
3308 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
3860 C:\Program Files\Windows Media Player\wmpnetwk.exe
4024 C:\Windows\System32\svchost.exe
2008 WmiPrvSE.exe
3656 C:\Windows\System32\taskeng.exe
4004 C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
2952 C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
1488 dllhost.exe
208 C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
1820 C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
2876 C:\Windows\System32\sppsvc.exe
3460 C:\Windows\System32\svchost.exe
3912 taskhost.exe
908 C:\Windows\System32\SearchFilterHost.exe
2908 C:\Program Files\Internet Explorer\ielowutil.exe
2164 C:\Windows\System32\wermgr.exe
976 C:\Users\Mia\Desktop\reply1\MBRCheck.exe
2896 C:\Windows\System32\conhost.exe
2196 C:\Windows\System32\dllhost.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`5dd00000 (NTFS)

PhysicalDrive0 Model Number: TOSHIBAMK3263GSX, Rev: FG020M

Size Device Name MBR Status
——————————————–
298 GB \\.\PhysicalDrive0 MBR Code Faked!
SHA1: CCF356FEC6D9BBB29EF3EF1E4270A2B799955EA4


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.

Enter your choice:

Done!
================================================================================
=============
dds.txt

DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 18:33:08.22 on Sun 08/29/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1766 [GMT -4:00]

SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

============== Running Processes ===============

C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\atieclxx.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskhost.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\windows\system32\DllHost.exe
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\system32\svchost.exe -k SDRSVC
C:\Users\Mia\Desktop\Ducky\reply1\dds.com
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/?ilc=1
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\tbZyn1.dll
mURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\tbZyn1.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: CescrtHlpr Object: {64182481-4f71-486b-a045-b233bd0da8fc} - c:\program files\facemoods.com\facemoods\1.3.60.33\facemoods.dll
BHO: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\tbZyn1.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers client\YontooIEClient.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\tbZyn1.dll
TB: facemoods Toolbar: {db4e9724-f518-4dfd-9c7c-78b52103cab9} - c:\program files\facemoods.com\facemoods\1.3.60.33\facemoodsTlbr.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TobuActivation.exe" UNATTENDED
uRun: [AROReminder] c:\program files\advanced registry optimizer\ARO.exe -rem
mRun: []
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\mia\appdata\roaming\micros~1\windows\startm~1\programs\startup\memturbo.lnk - c:\program files\memturbo 4\MemTurbo.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
AppInit_DLLs: avgrsstx.dll
mASetup: {01250B8F-D947-4F8A-9408-FE8E3EE2EC92} - c:\program files\toshiba\my toshiba\MyToshiba.exe /SETUP

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-11-27 206256]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-3-10 11608]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-11-16 176128]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-3-10 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-3-10 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-3-10 56816]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-8-10 185712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-3-10 1153368]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-11 185712]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
R3 AVHook;AVHook;c:\windows\system32\drivers\AVHook.sys [2009-11-27 28560]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-11-16 7680]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-11-16 171520]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-11-16 187392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-6 135664]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-11-16 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
S3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-31 1343400]

=============== Created Last 30 ================

2010-08-26 02:14:59 0 d—–w- c:\program files\Trend Micro
2010-08-25 01:36:06 0 d–h–w- C:\kleaner.tmp
2010-08-25 01:31:46 0 d—–w- c:\programdata\Kaspersky Lab Setup Files
2010-08-22 12:06:50 0 d—–w- C:\perflogs
2010-08-11 18:52:31 0 d—–w- c:\programdata\Office Genuine Advantage
2010-08-07 12:44:54 0 d—–w- c:\program files\iPod
2010-08-07 12:44:53 0 d—–w- c:\program files\iTunes

==================== Find3M ====================

2010-07-29 06:30:49 197632 —-a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 —-a-w- c:\windows\system32\iccvid.dll
2010-06-30 06:25:31 978432 —-a-w- c:\windows\system32\wininet.dll
2010-06-19 06:33:29 3955080 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23:50 37376 —-a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07:18 2326016 —-a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48:35 224256 —-a-w- c:\windows\system32\schannel.dll
2010-06-08 06:02:06 1233920 —-a-w- c:\windows\system32\msxml3.dll
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 –sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2009-11-26 02:38:34 14 –sh–r- c:\windows\system32\drivers\fbd.sys
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 18:34:14.86 ===============
================================================================================
======

withheld attach.txt per file instructions….will attach as zip

============================================================================
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-29 20:01:44
Windows 6.1.7600
Running: lzth4ct2.exe; Driver: C:\Users\Mia\AppData\Local\Temp\kwrdypow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x833CB9A6]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x833CBB98]
SSDT 9431089C ZwCreateThread
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x833CBDA0]
SSDT 94310888 ZwOpenProcess
SSDT 9431088D ZwOpenThread
SSDT 94310897 ZwTerminateProcess

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8303AAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8303A104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8303A3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83022634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83022898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8303A1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8303A958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8303A6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8303AF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8303B1A8

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82C53599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C77F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 32C 82C7F83C 8 Bytes [A6, B9, 3C, 83, 98, BB, 3C, …] {CMPSB ; MOV ECX, 0xbb98833c; CMP AL, 0x83}
.text ntkrnlpa.exe!RtlSidHashLookup + 34C 82C7F85C 4 Bytes [9C, 08, 31, 94] {PUSHF ; OR [ECX], DH; XCHG ESP, EAX}
.text ntkrnlpa.exe!RtlSidHashLookup + 364 82C7F874 4 Bytes [A0, BD, 3C, 83]
.text ntkrnlpa.exe!RtlSidHashLookup + 4E8 82C7F9F8 4 Bytes [88, 08, 31, 94]
.text ntkrnlpa.exe!RtlSidHashLookup + 508 82C7FA18 4 Bytes CALL B3D0879F
.text …
.text C:\windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x8AB20000, 0x3C849, 0xE8000020]
.dsrt C:\windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x8AB65000, 0x3DC, 0x48000040]
.text C:\windows\system32\DRIVERS\atikmdag.sys section is writeable [0x90C10000, 0x2D5526, 0xE8000020]
.text peauth.sys 9C2B2C9D 28 Bytes [84, AD, 6F, C0, C0, 95, 8F, …]
.text peauth.sys 9C2B2CC1 28 Bytes [84, AD, 6F, C0, C0, 95, 8F, …]
PAGE peauth.sys 9C2B8E20 101 Bytes [89, AC, D3, 50, 00, E7, E7, …]
PAGE peauth.sys 9C2B902C 102 Bytes [10, F1, 59, EB, D7, F4, 14, …]

—- User code sections - GMER 1.0.15 —-

.text C:\windows\system32\svchost.exe[1060] ntdll.dll!NtProtectVirtualMemory 76F15380 5 Bytes JMP 002E000A
.text C:\windows\system32\svchost.exe[1060] ntdll.dll!NtWriteVirtualMemory 76F15F00 5 Bytes JMP 002F000A
.text C:\windows\system32\svchost.exe[1060] ntdll.dll!KiUserExceptionDispatcher 76F16448 5 Bytes JMP 001F000A
.text C:\windows\system32\svchost.exe[1060] ole32.dll!CoCreateInstance 75AA57FC 5 Bytes JMP 0092000A
.text C:\windows\system32\svchost.exe[1060] USER32.dll!GetCursorPos 757EC198 5 Bytes JMP 0116000A
.text C:\windows\Explorer.EXE[1620] ntdll.dll!NtProtectVirtualMemory 76F15380 5 Bytes JMP 003E000A
.text C:\windows\Explorer.EXE[1620] ntdll.dll!NtWriteVirtualMemory 76F15F00 5 Bytes JMP 003F000A
.text C:\windows\Explorer.EXE[1620] ntdll.dll!KiUserExceptionDispatcher 76F16448 5 Bytes JMP 003D000A

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs AVHook.sys (PC Tools Filter Driver for Windows 2000/XP/PC Tools Research Pty Ltd.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device \Driver\ACPI_HAL \Device\0000004d halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat AVHook.sys (PC Tools Filter Driver for Windows 2000/XP/PC Tools Research Pty Ltd.)

—- EOF - GMER 1.0.15 —-
==================================================================

end of post

===================================================================

Attachments:

Hi

Please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 10-08-30.02 - Mia 08/31/2010 0:32.4.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.2216 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common Files\Uninstall
c:\program files\facemoods.com
c:\program files\facemoods.com\facemoods\1.3.60.33\facemoods.dll
c:\program files\facemoods.com\facemoods\1.3.60.33\facemoods.png
c:\program files\facemoods.com\facemoods\1.3.60.33\facemoodsApp.dll
c:\program files\facemoods.com\facemoods\1.3.60.33\facemoodsEng.dll
c:\program files\facemoods.com\facemoods\1.3.60.33\facemoodsTlbr.dll
c:\program files\facemoods.com\facemoods\1.3.60.33\uninstall.exe
c:\program files\Mozilla Firefox\extensions\[removed]
c:\program files\Mozilla Firefox\extensions\[removed]\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\[removed]\.svn\entries
c:\program files\Mozilla Firefox\extensions\[removed]\.svn\prop-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\.svn\text-base\chrome.manifest.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\.svn\text-base\install.rdf.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\.svn\text-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\chrome.manifest
c:\program files\Mozilla Firefox\extensions\[removed]\chrome\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\[removed]\chrome\.svn\entries
c:\program files\Mozilla Firefox\extensions\[removed]\components\FFHst.dll
c:\program files\Mozilla Firefox\extensions\[removed]\components\FFHst.xpt
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\entries
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\prop-base\facemoods.png.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\prop-base\Thumbs.db.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\prop-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\facemoods.css.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\facemoods.png.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\facemoods.xul.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\fcmdDef.js.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\Loader.js.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\newTabLgc.js.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\prefman.js.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\script-compiler.js.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\Thumbs.db.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\utils.js.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\xmlhttprequester.js.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\.svn\text-base\xpiInstallLgc.js.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\facemoods.css
c:\program files\Mozilla Firefox\extensions\[removed]\content\facemoods.png
c:\program files\Mozilla Firefox\extensions\[removed]\content\facemoods.xul
c:\program files\Mozilla Firefox\extensions\[removed]\content\fcmdDef.js
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\entries
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\facemoods.png.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\fb.gif.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\help_16.gif.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\home.gif.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\logo.png.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\moodsIcon.png.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\pref.jpg.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\privecy_16_hot.gif.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\stripicons.png.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\tellafriend.gif.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\Thumbs.db.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\prop-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\facemoods.png.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\fb.gif.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\help_16.gif.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\home.gif.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\logo.png.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\moodsIcon.png.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\pref.jpg.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\privecy_16_hot.gif.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\stripicons.png.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\tellafriend.gif.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\Thumbs.db.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\.svn\text-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\facemoods.png
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\fb.gif
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\help_16.gif
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\home.gif
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\logo.png
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\moodsIcon.png
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\pref.jpg
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\privecy_16_hot.gif
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\stripicons.png
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\tellafriend.gif
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\Thumbs.db
c:\program files\Mozilla Firefox\extensions\[removed]\content\images\vssver.scc
c:\program files\Mozilla Firefox\extensions\[removed]\content\instlgc.js
c:\program files\Mozilla Firefox\extensions\[removed]\content\Loader.js
c:\program files\Mozilla Firefox\extensions\[removed]\content\newTabLgc.js
c:\program files\Mozilla Firefox\extensions\[removed]\content\preferences\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\[removed]\content\preferences\.svn\entries
c:\program files\Mozilla Firefox\extensions\[removed]\content\preferences\.svn\prop-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\preferences\.svn\text-base\preferences.js.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\preferences\.svn\text-base\preferences.xul.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\preferences\.svn\text-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\content\preferences\preferences.js
c:\program files\Mozilla Firefox\extensions\[removed]\content\preferences\preferences.xul
c:\program files\Mozilla Firefox\extensions\[removed]\content\preferences\vssver.scc
c:\program files\Mozilla Firefox\extensions\[removed]\content\prefman.js
c:\program files\Mozilla Firefox\extensions\[removed]\content\script-compiler.js
c:\program files\Mozilla Firefox\extensions\[removed]\content\Thumbs.db
c:\program files\Mozilla Firefox\extensions\[removed]\content\utils.js
c:\program files\Mozilla Firefox\extensions\[removed]\content\vssver.scc
c:\program files\Mozilla Firefox\extensions\[removed]\content\xmlhttprequester.js
c:\program files\Mozilla Firefox\extensions\[removed]\content\xpiInstallLgc.js
c:\program files\Mozilla Firefox\extensions\[removed]\defaults\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\[removed]\defaults\.svn\entries
c:\program files\Mozilla Firefox\extensions\[removed]\defaults\preferences\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\[removed]\defaults\preferences\.svn\entries
c:\program files\Mozilla Firefox\extensions\[removed]\defaults\preferences\.svn\prop-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\defaults\preferences\.svn\text-base\instlPref.js.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\defaults\preferences\.svn\text-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\[removed]\defaults\preferences\instlPref.js
c:\program files\Mozilla Firefox\extensions\[removed]\defaults\preferences\vssver.scc
c:\program files\Mozilla Firefox\extensions\[removed]\install.rdf
c:\program files\Mozilla Firefox\extensions\[removed]\vssver.scc
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\users\Mia\AppData\Local\Microsoft\Windows\Temporary Internet Files\-kI1Euv10-l_VMa
c:\users\Mia\AppData\Local\Microsoft\Windows\Temporary Internet Files\PI5y-G4c
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((( Files Created from 2010-07-28 to 2010-08-31 )))))))))))))))))))))))))))))))
.

2010-08-31 04:45 . 2010-08-31 04:45 ——– d—–w- c:\users\Mia\AppData\Local\temp
2010-08-31 04:45 . 2010-08-31 04:45 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-08-31 04:24 . 2010-08-31 04:25 ——– d—–w- C:\32788R22FWJFW
2010-08-26 02:14 . 2010-08-26 02:14 388096 —-a-r- c:\users\Mia\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-26 02:14 . 2010-08-26 02:14 ——– d—–w- c:\program files\Trend Micro
2010-08-25 01:36 . 2010-08-25 01:36 ——– d—–w- C:\kleaner.tmp
2010-08-25 01:31 . 2010-08-25 01:31 ——– d—–w- c:\programdata\Kaspersky Lab Setup Files
2010-08-22 12:06 . 2010-08-22 12:06 ——– d—–w- C:\perflogs
2010-08-11 18:52 . 2010-08-11 18:52 ——– d—–w- c:\programdata\Office Genuine Advantage
2010-08-07 12:44 . 2010-08-07 12:44 ——– d—–w- c:\program files\iPod
2010-08-07 12:44 . 2010-08-07 12:45 ——– d—–w- c:\program files\iTunes
2010-08-07 12:41 . 2010-08-07 12:41 73000 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-08-07 12:39 . 2010-08-07 12:39 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe
2010-08-04 20:24 . 2010-08-04 20:24 ——– d—–w- c:\users\Default\AppData\Local\Microsoft Help

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-26 00:26 . 2009-09-02 05:34 ——– d—–w- c:\programdata\WildTangent
2010-08-25 01:36 . 2010-03-10 21:38 ——– d—–w- c:\program files\AVG
2010-08-24 22:54 . 2010-03-10 19:26 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-20 11:38 . 2010-04-07 12:13 ——– d—–w- c:\programdata\DriverCure
2010-08-18 19:19 . 2009-12-06 16:09 ——– d—–w- c:\users\Mia\AppData\Roaming\FUJIFILM
2010-08-13 12:14 . 2009-11-16 07:17 ——– d—–w- c:\program files\Microsoft Works
2010-08-13 12:10 . 2009-11-16 07:26 ——– d—–w- c:\programdata\Microsoft Help
2010-08-11 18:52 . 2009-09-02 05:46 ——– d—–w- c:\program files\Microsoft Silverlight
2010-08-07 19:00 . 2010-02-16 23:37 ——– d—–w- c:\program files\Zynga
2010-08-07 12:44 . 2010-03-20 02:21 ——– d—–w- c:\program files\Common Files\Apple
2010-08-07 12:41 . 2010-05-21 13:14 ——– d—–w- c:\program files\Safari
2010-07-29 06:30 . 2010-08-12 12:51 197632 —-a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-12 12:51 82944 —-a-w- c:\windows\system32\iccvid.dll
2010-07-07 08:46 . 2010-07-07 08:46 92816 —-a-w- c:\programdata\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2011 11.0.1.400\english\setup.exe
2010-07-05 21:06 . 2010-04-07 12:13 ——– d—–w- c:\programdata\ParetoLogic
2010-07-05 21:06 . 2010-04-07 12:13 ——– d—–w- c:\program files\Common Files\ParetoLogic
2010-07-05 21:06 . 2010-07-05 21:05 3248400 —-a-w- c:\programdata\ParetoLogic\UUS2\DriverCure\Temp\Update.exe
2010-06-30 06:25 . 2010-08-12 12:51 978432 —-a-w- c:\windows\system32\wininet.dll
2010-06-22 02:47 . 2010-08-12 12:51 310784 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-22 02:47 . 2010-08-12 12:51 307200 —-a-w- c:\windows\system32\drivers\srv2.sys
2010-06-22 02:47 . 2010-08-12 12:51 113664 —-a-w- c:\windows\system32\drivers\srvnet.sys
2010-06-19 12:54 . 2010-06-19 12:54 71992 —-a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-19 06:33 . 2010-08-12 12:51 3955080 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33 . 2010-08-12 12:51 3899784 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23 . 2010-08-12 12:51 37376 —-a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07 . 2010-08-12 12:51 2326016 —-a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48 . 2010-08-12 12:51 224256 —-a-w- c:\windows\system32\schannel.dll
2010-06-14 11:35 . 2010-06-14 11:36 53632 —-a-w- c:\users\Mia\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-14 11:35 . 2010-04-11 00:51 53632 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-14 06:12 . 2010-08-12 12:51 1286016 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-08 06:02 . 2010-08-12 12:51 1233920 —-a-w- c:\windows\system32\msxml3.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 –sha-r- c:\windows\Fonts\StaticCache.dat
2009-11-26 02:38 . 2009-11-26 02:38 14 –sh–r- c:\windows\System32\drivers\fbd.sys
2009-07-14 01:14 . 2009-07-13 23:42 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyn1.dll" [2010-08-07 2734688]

[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
2010-08-07 19:00 2734688 —-a-w- c:\program files\Zynga\tbZyn1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2010-05-25 01:52 194912 ——w- c:\program files\Yontoo Layers Client\YontooIEClient.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyn1.dll" [2010-08-07 2734688]

[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{7B13EC3E-999A-4B70-B9CB-2617B8323822}"= "c:\program files\Zynga\tbZyn1.dll" [2010-08-07 2734688]

[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-02 39408]
"NortonOnlineBackupReminder"="c:\program files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" [2009-07-16 529256]
"AROReminder"="c:\program files\Advanced Registry Optimizer\ARO.exe" [2009-12-28 2137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

c:\users\Mia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MemTurbo.lnk - c:\program files\MemTurbo 4\MemTurbo.exe [2010-3-27 3121760]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCTAVSvc]
@=""

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Exif Launcher S.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Exif Launcher S.lnk
backup=c:\windows\pss\Exif Launcher S.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Mia^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ZooskMessenger.lnk]
path=c:\users\Mia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ZooskMessenger.lnk
backup=c:\windows\pss\ZooskMessenger.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00TCrdMain]
2009-08-05 22:04 738616 —-a-w- c:\program files\TOSHIBA\FlashCards\TCrdMain.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
2009-05-26 21:46 1159168 ——w- c:\program files\Brother\Brmfcmon\BrMfcWnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
2008-12-24 15:26 114688 ——w- c:\program files\Brother\ControlCenter3\BrCtrCen.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverCure]
2009-08-07 19:36 3993368 —-a-w- c:\program files\ParetoLogic\DriverCure\DriverCure.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 19:39 1090952 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 20:39 5244216 —-a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyTOSHIBA]
2009-08-06 16:15 264048 —-a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackupReminder]
2009-07-16 19:04 529256 —-a-w- c:\program files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp]
2009-04-16 16:27 1505168 —-a-w- c:\program files\PC Tools AntiVirus\PCTAV.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
2008-07-03 16:37 812952 —-a-w- c:\program files\Registry Mechanic\RMTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2009-07-29 05:12 7625248 ——w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
2009-02-23 13:05 111856 —-a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
2009-07-28 22:00 460088 —-a-w- c:\program files\TOSHIBA\SmoothView\SmoothView.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2009-07-30 06:32 98304 —-a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-09-02 05:47 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2009-07-21 01:46 1545512 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Teco]
2009-08-12 00:09 1324384 —-a-w- c:\program files\TOSHIBA\TECO\TEco.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToshibaServiceStation]
2009-08-17 18:48 1294136 —-a-w- c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosSENotify]
2009-08-04 01:17 611672 —-a-w- c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TosWaitSrv]
2009-08-07 01:05 611672 —-a-w- c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain]
2009-08-21 17:29 476512 —-a-w- c:\program files\TOSHIBA\Power Saver\TPwrMain.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
2009-02-23 13:05 111856 —-a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 135664]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 111960]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-07 685424]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-31 1343400]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-08-24 206256]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-30 176128]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-08-11 185712]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-12 185712]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 12920]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2009-07-07 7680]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-08-06 171520]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-31 187392]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}]
2009-08-06 16:15 264048 —-a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe
.
Contents of the 'Scheduled Tasks' folder

2010-08-20 c:\windows\Tasks\DriverCure.job
- c:\program files\ParetoLogic\DriverCure\DriverCure.exe [2009-08-07 19:36]

2010-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 15:25]

2010-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 15:25]

2010-08-22 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]

2010-08-16 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
- - - - ORPHANS REMOVED - - - -

BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - c:\program files\facemoods.com\facemoods\1.3.60.33\facemoods.dll
Toolbar-Locked - (no file)
Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - c:\program files\facemoods.com\facemoods\1.3.60.33\facemoodsTlbr.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-AV - c:\program files\AV\Antivir.exe
MSConfigStartUp-AVGT - c:\program files\AVGT\antivirusGT.exe
MSConfigStartUp-CyberDefender Early Detection Center - c:\users\Mia\AppData\Local\CyberDefender Internet Security\AntiSpyware\cdas1e69.exe
AddRemove-facemoods - c:\program files\facemoods.com\facemoods\1.3.60.33\uninstall.exe
AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe



**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x86725ACE]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
IoDeviceObjectType -> DumpProcedure -> 0xd46a624f
user & kernel MBR OK

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-08-31 00:49:34
ComboFix-quarantined-files.txt 2010-08-31 04:49

Pre-Run: 272,800,149,504 bytes free
Post-Run: 272,917,913,600 bytes free

- - End Of File - - 3364B0CE855E16BDE3E4A87A2594DC06
Hi,

Please do the following


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
Hello, Thank you for the help……………….. ============================================================ 2010/08/31 22:00:45.0835 TDSS rootkit removing tool 2.4.1.4 Aug 31 2010 16:55:25 2010/08/31 22:00:45.0835 ================================================================================ 2010/08/31 22:00:45.0835 SystemInfo: 2010/08/31 22:00:45.0835 2010/08/31 22:00:45.0835 OS Version: 6.1.7600 ServicePack: 0.0 2010/08/31 22:00:45.0835 Product type: Workstation 2010/08/31 22:00:45.0835 ComputerName: MIA-PC 2010/08/31 22:00:45.0835 UserName: Mia 2010/08/31 22:00:45.0835 Windows directory: C:\windows 2010/08/31 22:00:45.0835 System windows directory: C:\windows 2010/08/31 22:00:45.0835 Processor architecture: Intel x86 2010/08/31 22:00:45.0835 Number of processors: 2 2010/08/31 22:00:45.0835 Page size: 0x1000 2010/08/31 22:00:45.0835 Boot type: Normal boot 2010/08/31 22:00:45.0835 ================================================================================ 2010/08/31 22:00:46.0069 Initialize success 2010/08/31 22:00:54.0321 ================================================================================ 2010/08/31 22:00:54.0321 Scan started 2010/08/31 22:00:54.0321 Mode: Manual; 2010/08/31 22:00:54.0321 ================================================================================ 2010/08/31 22:00:57.0426 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys 2010/08/31 22:00:57.0597 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys 2010/08/31 22:00:57.0738 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys 2010/08/31 22:00:57.0878 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys 2010/08/31 22:00:58.0003 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys 2010/08/31 22:00:58.0143 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys 2010/08/31 22:00:58.0330 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\windows\system32\drivers\afd.sys 2010/08/31 22:00:58.0455 AgereSoftModem (7e10e3bb9b258ad8a9300f91214d67b9) C:\windows\system32\DRIVERS\AGRSM.sys 2010/08/31 22:00:58.0580 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys 2010/08/31 22:00:58.0705 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys 2010/08/31 22:00:58.0845 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys 2010/08/31 22:00:58.0986 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys 2010/08/31 22:00:59.0095 amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys 2010/08/31 22:00:59.0220 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys 2010/08/31 22:00:59.0344 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys 2010/08/31 22:00:59.0469 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\windows\system32\DRIVERS\amdsata.sys 2010/08/31 22:00:59.0594 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys 2010/08/31 22:00:59.0719 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\windows\system32\DRIVERS\amdxata.sys 2010/08/31 22:00:59.0844 AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys 2010/08/31 22:01:00.0015 arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys 2010/08/31 22:01:00.0124 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys 2010/08/31 22:01:00.0249 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys 2010/08/31 22:01:00.0390 atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys 2010/08/31 22:01:00.0530 athr (76bab0c824e2d05b940c4dd40a9b08bf) C:\windows\system32\DRIVERS\athr.sys 2010/08/31 22:01:00.0764 atikmdag (c97be8350fbcb1960b22fad2e6c2b514) C:\windows\system32\DRIVERS\atikmdag.sys 2010/08/31 22:01:00.0967 AtiPcie (b73c832088dd54b55e04ff6f9646ad8c) C:\windows\system32\DRIVERS\AtiPcie.sys 2010/08/31 22:01:01.0092 AVFilter (a7f31519efda39d9c4669aaa5475d38f) C:\windows\system32\drivers\AVFilter.sys 2010/08/31 22:01:01.0154 avgio (6a646c46b9415e13095aa9b352040a7a) C:\Program Files\Avira\AntiVir Desktop\avgio.sys 2010/08/31 22:01:01.0248 avgntflt (14fe36d8f2c6a2435275338d061a0b66) C:\windows\system32\DRIVERS\avgntflt.sys 2010/08/31 22:01:01.0341 AVHook (8ff38af73a478a01fd3065adbbef401c) C:\windows\system32\drivers\AVHook.sys 2010/08/31 22:01:01.0404 avipbb (452e382340bb0c5e694ed9d3625356d0) C:\windows\system32\DRIVERS\avipbb.sys 2010/08/31 22:01:01.0528 AVRec (e7510743a3d54e96eea34dbf5255fd5e) C:\windows\system32\drivers\AVRec.sys 2010/08/31 22:01:01.0669 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys 2010/08/31 22:01:01.0809 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys 2010/08/31 22:01:01.0934 Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys 2010/08/31 22:01:02.0074 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys 2010/08/31 22:01:02.0215 bowser (fcafaef6798d7b51ff029f99a9898961) C:\windows\system32\DRIVERS\bowser.sys 2010/08/31 22:01:02.0340 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys 2010/08/31 22:01:02.0449 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys 2010/08/31 22:01:02.0589 Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys 2010/08/31 22:01:02.0714 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys 2010/08/31 22:01:02.0823 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys 2010/08/31 22:01:02.0932 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys 2010/08/31 22:01:03.0042 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys 2010/08/31 22:01:03.0432 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys 2010/08/31 22:01:03.0588 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys 2010/08/31 22:01:03.0728 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys 2010/08/31 22:01:03.0822 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys 2010/08/31 22:01:03.0962 CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys 2010/08/31 22:01:04.0071 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys 2010/08/31 22:01:04.0227 CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys 2010/08/31 22:01:04.0352 Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys 2010/08/31 22:01:04.0477 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys 2010/08/31 22:01:04.0617 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys 2010/08/31 22:01:04.0789 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\windows\system32\Drivers\dfsc.sys 2010/08/31 22:01:04.0929 discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys 2010/08/31 22:01:05.0070 Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys 2010/08/31 22:01:05.0210 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys 2010/08/31 22:01:05.0335 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\windows\System32\drivers\dxgkrnl.sys 2010/08/31 22:01:05.0522 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys 2010/08/31 22:01:05.0694 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys 2010/08/31 22:01:05.0803 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys 2010/08/31 22:01:05.0943 exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys 2010/08/31 22:01:06.0053 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys 2010/08/31 22:01:06.0193 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys 2010/08/31 22:01:06.0333 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys 2010/08/31 22:01:06.0443 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys 2010/08/31 22:01:06.0567 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys 2010/08/31 22:01:06.0739 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys 2010/08/31 22:01:06.0879 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys 2010/08/31 22:01:06.0989 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys 2010/08/31 22:01:07.0145 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\windows\system32\DRIVERS\fvevol.sys 2010/08/31 22:01:07.0254 FwLnk (0f76e205bdc60364f08a5949082771ca) C:\windows\system32\DRIVERS\FwLnk.sys 2010/08/31 22:01:07.0394 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys 2010/08/31 22:01:07.0535 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys 2010/08/31 22:01:07.0691 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys 2010/08/31 22:01:07.0800 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys 2010/08/31 22:01:07.0909 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys 2010/08/31 22:01:08.0018 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys 2010/08/31 22:01:08.0112 HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys 2010/08/31 22:01:08.0221 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys 2010/08/31 22:01:08.0346 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys 2010/08/31 22:01:08.0486 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys 2010/08/31 22:01:08.0611 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys 2010/08/31 22:01:08.0720 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys 2010/08/31 22:01:08.0829 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys 2010/08/31 22:01:08.0939 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\windows\system32\DRIVERS\iaStorV.sys 2010/08/31 22:01:09.0048 iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys 2010/08/31 22:01:09.0251 IntcAzAudAddService (e4a2e810cb2607c9c159c0dfb0bd4c88) C:\windows\system32\drivers\RTKVHDA.sys 2010/08/31 22:01:09.0375 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys 2010/08/31 22:01:09.0500 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys 2010/08/31 22:01:09.0609 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys 2010/08/31 22:01:09.0734 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys 2010/08/31 22:01:09.0843 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys 2010/08/31 22:01:09.0968 IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys 2010/08/31 22:01:10.0062 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys 2010/08/31 22:01:10.0187 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys 2010/08/31 22:01:10.0311 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys 2010/08/31 22:01:10.0405 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys 2010/08/31 22:01:10.0545 KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys 2010/08/31 22:01:10.0701 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\windows\system32\Drivers\ksecpkg.sys 2010/08/31 22:01:10.0842 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys 2010/08/31 22:01:10.0982 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys 2010/08/31 22:01:11.0091 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys 2010/08/31 22:01:11.0216 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys 2010/08/31 22:01:11.0310 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys 2010/08/31 22:01:11.0435 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys 2010/08/31 22:01:11.0559 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys 2010/08/31 22:01:11.0684 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys 2010/08/31 22:01:11.0793 Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys 2010/08/31 22:01:11.0887 monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys 2010/08/31 22:01:12.0012 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys 2010/08/31 22:01:12.0137 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys 2010/08/31 22:01:12.0261 mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys 2010/08/31 22:01:12.0371 mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys 2010/08/31 22:01:12.0495 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys 2010/08/31 22:01:12.0605 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys 2010/08/31 22:01:12.0729 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\windows\system32\DRIVERS\mrxsmb.sys 2010/08/31 22:01:12.0839 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\windows\system32\DRIVERS\mrxsmb10.sys 2010/08/31 22:01:12.0963 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\windows\system32\DRIVERS\mrxsmb20.sys 2010/08/31 22:01:13.0073 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys 2010/08/31 22:01:13.0182 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys 2010/08/31 22:01:13.0322 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys 2010/08/31 22:01:13.0431 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys 2010/08/31 22:01:13.0541 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys 2010/08/31 22:01:13.0665 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys 2010/08/31 22:01:13.0697 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys 2010/08/31 22:01:13.0806 MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys 2010/08/31 22:01:13.0899 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys 2010/08/31 22:01:14.0009 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys 2010/08/31 22:01:14.0118 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys 2010/08/31 22:01:14.0211 MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys 2010/08/31 22:01:14.0336 Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys 2010/08/31 22:01:14.0445 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys 2010/08/31 22:01:14.0617 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys 2010/08/31 22:01:14.0742 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys 2010/08/31 22:01:14.0851 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys 2010/08/31 22:01:14.0976 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys 2010/08/31 22:01:15.0069 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys 2010/08/31 22:01:15.0163 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys 2010/08/31 22:01:15.0303 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys 2010/08/31 22:01:15.0459 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\windows\system32\DRIVERS\netbt.sys 2010/08/31 22:01:15.0615 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys 2010/08/31 22:01:15.0756 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys 2010/08/31 22:01:15.0896 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys 2010/08/31 22:01:16.0037 Ntfs (3795dcd21f740ee799fb7223234215af) C:\windows\system32\drivers\Ntfs.sys 2010/08/31 22:01:16.0161 Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys 2010/08/31 22:01:16.0271 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\windows\system32\DRIVERS\nvraid.sys 2010/08/31 22:01:16.0380 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\windows\system32\DRIVERS\nvstor.sys 2010/08/31 22:01:16.0489 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys 2010/08/31 22:01:16.0598 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys 2010/08/31 22:01:16.0739 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys 2010/08/31 22:01:16.0879 partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys 2010/08/31 22:01:16.0988 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys 2010/08/31 22:01:17.0129 pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys 2010/08/31 22:01:17.0253 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys 2010/08/31 22:01:17.0363 pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys 2010/08/31 22:01:17.0581 PCTCore (d302a59e6d1842a201930928a5bad68b) C:\windows\system32\drivers\PCTCore.sys 2010/08/31 22:01:17.0706 pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys 2010/08/31 22:01:17.0815 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys 2010/08/31 22:01:18.0002 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys 2010/08/31 22:01:18.0111 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys 2010/08/31 22:01:18.0267 Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys 2010/08/31 22:01:18.0392 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys 2010/08/31 22:01:18.0517 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys 2010/08/31 22:01:18.0642 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys 2010/08/31 22:01:18.0735 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys 2010/08/31 22:01:18.0845 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys 2010/08/31 22:01:18.0969 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys 2010/08/31 22:01:19.0094 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys 2010/08/31 22:01:19.0219 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys 2010/08/31 22:01:19.0359 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys 2010/08/31 22:01:19.0453 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys 2010/08/31 22:01:19.0593 RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys 2010/08/31 22:01:19.0734 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys 2010/08/31 22:01:19.0843 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys 2010/08/31 22:01:19.0952 RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys 2010/08/31 22:01:20.0108 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\windows\system32\drivers\rdyboost.sys 2010/08/31 22:01:20.0249 rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys 2010/08/31 22:01:20.0358 RSUSBSTOR (ef8b2afc3c0751c5e5a59983c8893260) C:\windows\system32\Drivers\RtsUStor.sys 2010/08/31 22:01:20.0483 RTL8167 (6465166dd9b2f841dabad16abdadbe98) C:\windows\system32\DRIVERS\Rt86win7.sys 2010/08/31 22:01:20.0607 RTL8187Se (5bd298bdf62e6a8a0fc69f73a82a52bb) C:\windows\system32\DRIVERS\RTL8187Se.sys 2010/08/31 22:01:20.0826 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys 2010/08/31 22:01:20.0966 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys 2010/08/31 22:01:21.0091 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys 2010/08/31 22:01:21.0231 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys 2010/08/31 22:01:21.0341 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys 2010/08/31 22:01:21.0450 sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys 2010/08/31 22:01:21.0575 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys 2010/08/31 22:01:21.0699 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys 2010/08/31 22:01:21.0793 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\windows\system32\DRIVERS\sffp_sd.sys 2010/08/31 22:01:21.0902 sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys 2010/08/31 22:01:22.0027 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys 2010/08/31 22:01:22.0167 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys 2010/08/31 22:01:22.0261 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys 2010/08/31 22:01:22.0401 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys 2010/08/31 22:01:22.0542 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys 2010/08/31 22:01:22.0682 srv (dd0dd124d95390fdffa7fb6283923ed4) C:\windows\system32\DRIVERS\srv.sys 2010/08/31 22:01:22.0791 srv2 (59ef6d9c690e89d51b0692ccb13a06fc) C:\windows\system32\DRIVERS\srv2.sys 2010/08/31 22:01:22.0901 srvnet (08f28676802b58138e48a2b40caf6204) C:\windows\system32\DRIVERS\srvnet.sys 2010/08/31 22:01:23.0041 ssmdrv (654dfea96bc82b4acda4f37e5e4a3bbf) C:\windows\system32\DRIVERS\ssmdrv.sys 2010/08/31 22:01:23.0150 stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys 2010/08/31 22:01:23.0259 StillCam (edb05bd63148796f23ea78506404a538) C:\windows\system32\DRIVERS\serscan.sys 2010/08/31 22:01:23.0369 swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys 2010/08/31 22:01:23.0509 SynTP (8bd10dc8809dc69a1c5a795cb10add76) C:\windows\system32\DRIVERS\SynTP.sys 2010/08/31 22:01:23.0743 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\windows\system32\drivers\tcpip.sys 2010/08/31 22:01:23.0993 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\windows\system32\DRIVERS\tcpip.sys 2010/08/31 22:01:24.0133 tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys 2010/08/31 22:01:24.0258 tdcmdpst (4084ea00d50c858d6f9038f86ae2e2d0) C:\windows\system32\DRIVERS\tdcmdpst.sys 2010/08/31 22:01:24.0351 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys 2010/08/31 22:01:24.0461 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys 2010/08/31 22:01:24.0585 tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys 2010/08/31 22:01:24.0695 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys 2010/08/31 22:01:24.0960 tos_sps32 (969377943fe7284609babbab4e06b93c) C:\windows\system32\DRIVERS\tos_sps32.sys 2010/08/31 22:01:25.0085 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys 2010/08/31 22:01:25.0209 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys 2010/08/31 22:01:25.0334 TVALZ (fc24015b4052600c324c43e3a79c0664) C:\windows\system32\DRIVERS\TVALZ_O.SYS 2010/08/31 22:01:25.0443 TVALZFL (866462f5ae3f375ef83ef9dce436031c) C:\windows\system32\DRIVERS\TVALZFL.sys 2010/08/31 22:01:25.0553 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys 2010/08/31 22:01:25.0677 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\windows\system32\DRIVERS\udfs.sys 2010/08/31 22:01:25.0802 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys 2010/08/31 22:01:25.0927 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys 2010/08/31 22:01:26.0036 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys 2010/08/31 22:01:26.0145 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\windows\system32\Drivers\usbaapl.sys 2010/08/31 22:01:26.0255 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\windows\system32\DRIVERS\usbccgp.sys 2010/08/31 22:01:26.0457 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys 2010/08/31 22:01:26.0551 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\windows\system32\DRIVERS\usbehci.sys 2010/08/31 22:01:26.0676 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\windows\system32\DRIVERS\usbhub.sys 2010/08/31 22:01:26.0769 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\windows\system32\DRIVERS\usbohci.sys 2010/08/31 22:01:26.0879 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys 2010/08/31 22:01:26.0988 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\windows\system32\DRIVERS\USBSTOR.SYS 2010/08/31 22:01:27.0097 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\windows\system32\DRIVERS\usbuhci.sys 2010/08/31 22:01:27.0206 usbvideo (f642a7e4bf78cfa359cca0a3557c28d7) C:\windows\system32\Drivers\usbvideo.sys 2010/08/31 22:01:27.0347 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys 2010/08/31 22:01:27.0471 vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys 2010/08/31 22:01:27.0612 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys 2010/08/31 22:01:27.0721 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys 2010/08/31 22:01:27.0846 viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys 2010/08/31 22:01:27.0955 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys 2010/08/31 22:01:28.0064 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys 2010/08/31 22:01:28.0189 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys 2010/08/31 22:01:28.0329 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys 2010/08/31 22:01:28.0470 volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys 2010/08/31 22:01:28.0610 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys 2010/08/31 22:01:28.0719 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys 2010/08/31 22:01:28.0844 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys 2010/08/31 22:01:28.0953 WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys 2010/08/31 22:01:29.0094 WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys 2010/08/31 22:01:29.0109 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys 2010/08/31 22:01:29.0265 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys 2010/08/31 22:01:29.0406 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys 2010/08/31 22:01:29.0562 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys 2010/08/31 22:01:29.0671 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys 2010/08/31 22:01:29.0843 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\windows\system32\DRIVERS\WinUsb.sys 2010/08/31 22:01:29.0999 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys 2010/08/31 22:01:30.0139 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys 2010/08/31 22:01:30.0279 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys 2010/08/31 22:01:30.0373 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys 2010/08/31 22:01:30.0467 \HardDisk0\MBR - detected Rootkit.Win32.TDSS.tdl4 (0) 2010/08/31 22:01:30.0482 ================================================================================ 2010/08/31 22:01:30.0482 Scan finished 2010/08/31 22:01:30.0482 ================================================================================ 2010/08/31 22:01:30.0498 Detected object count: 1 2010/08/31 22:03:12.0241 \HardDisk0\MBR - will be cured after reboot 2010/08/31 22:03:12.0241 Rootkit.Win32.TDSS.tdl4(\HardDisk0\MBR) - User select action: Cure 2010/08/31 22:03:17.0498 Deinitialize success ================================================================================ Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4518 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 8/31/2010 10:14:41 PM mbam-log-2010-08-31 (22-14-41).txt Scan type: Quick scan Objects scanned: 139480 Time elapsed: 5 minute(s), 17 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ===================================================================== end post =====================================================================
**Vista users - right click on the IE icon and run as administrator

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
——————-start of post————————————————– Ran eset /scan as requested….produced the following log: ————————————————– ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK ————————————————– However, found the following threats: (exported to txt file) C:\Program Files\Windows Live\Messenger\msimg32.dll Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\facemoods.com\facemoods\1.3.60.33\facemoodsApp.dll.vir a variant of Win32/Adware.Lifze.A application C:\Qoobox\Quarantine\C\Program Files\facemoods.com\facemoods\1.3.60.33\uninstall.exe.vir Win32/Adware.Lifze.H application ————————————————– attached copy of screen print of eset finish NOTE: Remove found threats was unticked thanks for the help ———————-end of post—————————————————

Attachments:

Hi,

navigate to this file > right click and delete it

C:\Program Files\Windows Live\Messenger\msimg32.dll


NEXT


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and Save it to your Desktop.
  • Scroll down to where it says Java Runtime Environment (JRE) 6 Update 21 The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the Download button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement
  • Click Continue The page will refresh.
  • Click on the link to download Windows Offline Installation and Save the file to your Desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start(or My Computer) > Control Panel and double-click on Add or Remove Programs and remove all older versions of Java.
  • Click (highlight) any item with Java Runtime Environment (JRE, J2SE, Java™ SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.
  • After the install is complete, go back to your Control Panel(using Classic View) and click the Java icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button.
    • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
    • Trace and Log Files
  • Click OK on Delete Temporary Files Window. Note: This deletes ALL the Downloaded Applications and Applets from the CACHE
  • Click OK to leave the Temporary Files Window.
  • Click OK to leave the Java Control Panel.
  • Delete jre-6u21-windows-i586-p.exe from your desktop.


NEXT

Please advise how the computer is running now and if there are any outstanding issues.
java re 6/21 task completed successfully. the original problem of red banner screen saying "Attention! Your web page request has been cancelled" has been corrected. the computer is running fine again. thank you very much. (i will be making a donation!)
Great, thank-you,

just some housekeeping to do now,

please do the following:

You can delete the MBRCheck, DDS and GMER logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI