This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Suspected Malware

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a comcast cable modem and use windows home vista. I also have a netgear wireless router. I am in the middle of a 30 day free trial for Kaspersky Internet Security. When I try to search from yahoo or google and find the link I'm looking for… When I click on it, it re-directs me to some spam/search engine. Also, whenever I try to burn a movie or run my Kaspersky scan, my cpu shuts down. I've had a few ongoing hardware problems that I haven't figured out yet, maybe they're related.

When I ran Hijack This, it gave me an error message: “For some reason your system denied access to the host file. For Vista users, simply run as administrator.” And I tried, but it did not give me that option. So I ran it anyway and here is the log:

Thanks in advance for your help


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:17:35 AM, on 9/23/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\taskeng.exe
C:\WINDOWS\system32\Dwm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\RtHDVCpl.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\WINDOWS\ehome\ehTray.exe
O4 - HKLM\..\Policies\Explorer\Run: [tiopmun] rundll32 "C:\Users\Kevin Taylor\AppData\Roaming\KBDMLT47R.dll",QVIAM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvvsvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 7547 bytes
Hello k7t7. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
🖼Click to load external image (Posted Image) Please download Rootkit Unhooker and save it on your desktop.
  • Disable your security programs
  • Double click RKUnhookerLE.exe to run it
  • Click the Report tab, then click Scan
  • Check Drivers, Stealth Code, Files, and Code Hooks
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • Copy the entire contents of the report and paste it in your next reply.
Note - You may get this warning it is ok, just ignore it:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"

Please include the following in your next post:
  • DDS and Attach.txt logs
  • Rootkit Unhooker log
Thank you, RPMcMurphy, for your help! DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 14:55:33.32 on Wed 09/29/2010 Internet Explorer: 8.0.6001.18928 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3454.2260 [GMT -5:00] ============== Running Processes =============== C:\WINDOWS\system32\wininit.exe C:\WINDOWS\system32\lsm.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\nvvsvc.exe C:\WINDOWS\system32\svchost.exe -k rpcss C:\WINDOWS\System32\svchost.exe -k secsvcs C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k GPSvcGroup C:\WINDOWS\system32\SLsvc.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\System32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork C:\WINDOWS\system32\taskeng.exe C:\Windows\system32\agrsmsvc.exe C:\WINDOWS\System32\svchost.exe -k Akamai C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\WUDFHost.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\taskeng.exe C:\WINDOWS\system32\Dwm.exe C:\WINDOWS\Explorer.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\RtHDVCpl.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe C:\Program Files\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe C:\WINDOWS\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\DllHost.exe C:\WINDOWS\system32\DllHost.exe C:\Users\Kevin Taylor\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ mStart Page = hxxp://www.comcast.net/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html mWindow Title = Windows Internet Explorer provided by Comcast uInternet Settings,ProxyOverride = cdn;*.local uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100 uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2011\ievkbd.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\google\BAE.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\5.0.1423.0\npwinext.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll TB: @c:\program files\msn toolbar\platform\5.0.1423.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\5.0.1423.0\npwinext.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2011\avp.exe" mRun: [Bing Bar] "c:\program files\msn toolbar\platform\5.0.1423.0\mswinext.exe" mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mPolicies-system: HideFastUserSwitching = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2011\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\windows\downloaded program files\mimectl.dll Notify: klogon - c:\windows\system32\klogon.dll AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" ============= SERVICES / DRIVERS =============== R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2010-4-22 22104] R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2010-6-4 21504] R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 2011\avp.exe [2010-7-1 352976] R3 AVer88xHD;AVerMedia 23888 AvStream Video Capture;c:\windows\system32\drivers\AVer88xHD.sys [2007-10-11 401408] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19984] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-24 135664] S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2006-11-2 9216] S2 SBSDWSCService;SBSD Security Center Service; [x] S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184] S3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM106.sys [2008-12-31 1373696] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] =============== Created Last 30 ================ 2010-09-27 23:02:15 0 d—–w- c:\program files\MSN Toolbar 2010-09-26 17:16:43 0 d—–w- c:\program files\Veetle 2010-09-22 03:51:18 97549 —-a-w- c:\windows\system32\drivers\klick.dat 2010-09-22 03:51:18 113933 —-a-w- c:\windows\system32\drivers\klin.dat 2010-09-22 03:49:40 0 d—–w- c:\programdata\Kaspersky Lab 2010-09-14 20:12:53 49904 —-a-r- c:\windows\system32\drivers\BVRPMPR5.SYS 2010-09-14 20:11:41 0 dc—-w- C:\Netgear 2010-09-12 04:18:03 0 d—–w- c:\program files\DVDVideoSoft 2010-09-12 04:18:03 0 d—–w- c:\program files\common files\DVDVideoSoft 2010-09-12 04:10:01 0 d—–w- c:\users\kevint~1\appdata\roaming\AnvSoft 2010-09-12 04:09:59 0 d—–w- c:\program files\AnvSoft 2010-09-12 03:11:47 40960 —-a-w- c:\windows\system32\ssubtmr6.dll 2010-09-12 03:11:47 36864 —-a-w- c:\windows\system32\trayicon_handler.ocx 2010-09-12 03:11:47 28672 —-a-w- c:\windows\system32\mousewheel.ocx 2010-09-11 01:41:07 28 —-a-w- c:\windows\v2d.INI ==================== Find3M ==================== 2010-09-22 03:50:34 86016 —-a-w- c:\windows\inf\infstor.dat 2010-09-22 03:50:34 51200 —-a-w- c:\windows\inf\infpub.dat 2010-09-22 03:50:33 143360 —-a-w- c:\windows\inf\infstrng.dat 2010-07-27 23:44:10 91424 —-a-w- c:\windows\system32\dnssd.dll 2010-07-27 23:44:10 107808 —-a-w- c:\windows\system32\dns-sd.exe 2010-07-23 08:47:49 311583992 —-a-w- c:\windows\DUMP583c.tmp 2010-07-06 19:50:49 166659099 —-a-w- c:\windows\DUMP46ee.tmp 2010-07-06 19:48:16 166159387 —-a-w- c:\windows\DUMP446e.tmp 2010-07-06 19:45:46 165626907 —-a-w- c:\windows\DUMP43d3.tmp 2010-07-06 19:43:16 165184539 —-a-w- c:\windows\DUMP43d2.tmp 2010-07-06 19:40:14 164422683 —-a-w- c:\windows\DUMP46c0.tmp 2010-07-06 19:37:10 165471259 —-a-w- c:\windows\DUMP477a.tmp 2010-07-06 19:34:39 165684251 —-a-w- c:\windows\DUMP46bf.tmp 2010-07-06 19:32:07 163812379 —-a-w- c:\windows\DUMP423d.tmp 2010-07-06 19:29:38 297120492 —-a-w- c:\windows\DUMP48b2.tmp 2010-07-02 02:35:12 228024 —-a-w- c:\windows\system32\klogon.dll 2010-06-04 23:41:14 174 –sha-w- c:\program files\desktop.ini 2010-06-04 23:31:33 665600 —-a-w- c:\windows\inf\drvindex.dat 2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2010-06-25 22:05:43 16384 –sha-w- c:\windows\system32\%appdata%\microsoft\windows\ietldcache\index.dat 2008-01-07 09:12:22 397312 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6000.16480_none_ef1b6bb652cf8744\WinMail.exe ============= FINISH: 14:56:34.83 ===============

Attachments:

k7t7:

I got the log, thanks!

🖼Click to load external image (Posted Image) P2P - I see you have P2P software (Vuze & StreamTorrent) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to malware infections. Please see this post for more information. I recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at WTT are complete.

🖼Click to load external image (Posted Image) Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • If you have trouble, stop and post back. Do not try to repeatedly run comboFix!
  • When finished, it will produce a report for you.
.
Please include the following in your next post:
  • ComboFix log
streamtorrent and vuze removed.

ComboFix 10-09-29.03 - Kevin Taylor 09/30/2010 0:29.7.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3454.1906 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Kevin Taylor\AppData\Local\Windows Server
c:\users\Kevin Taylor\AppData\Local\Windows Server\flags.ini

.
((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-30 )))))))))))))))))))))))))))))))
.

2010-09-30 05:36 . 2010-09-30 05:36 ——– d—–w- c:\users\Kevin Taylor\AppData\Local\temp
2010-09-30 05:36 . 2010-09-30 05:36 ——– d—–w- c:\users\Under 14\AppData\Local\temp
2010-09-30 05:36 . 2010-09-30 05:36 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-09-29 20:00 . 2010-09-29 20:00 6656 —-a-w- c:\windows\system32\4E924A7C.exe
2010-09-27 23:04 . 2010-09-27 23:04 310208 —-a-w- c:\users\Kevin Taylor\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe
2010-09-27 08:49 . 2010-09-27 08:49 1049936 —-a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\bases\sw2\klavasyswatch.dll
2010-09-23 19:55 . 2010-09-23 19:55 ——– d—–w- c:\users\Below 14\AppData\Roaming\WildTangent
2010-09-22 04:12 . 2010-09-22 04:12 288080 —-a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\bases\av\kdb\i386\win\avengine.dll
2010-09-22 04:11 . 2010-09-22 04:11 ——– d—–w- c:\users\Default\AppData\Roaming\Apple Computer
2010-09-22 04:11 . 2010-09-22 04:11 ——– d—–w- c:\users\Default\AppData\Local\Apple Computer
2010-09-22 03:51 . 2010-09-22 03:51 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-09-22 03:51 . 2010-09-22 03:51 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-09-22 03:49 . 2010-09-30 04:21 ——– d—–w- c:\programdata\Kaspersky Lab
2010-09-20 18:47 . 2010-09-20 18:47 ——– d—–w- c:\program files\QuickTime
2010-09-14 20:12 . 2009-08-19 21:49 49904 —-a-r- c:\windows\system32\drivers\BVRPMPR5.SYS
2010-09-14 20:11 . 2010-09-14 21:44 ——– dc—-w- C:\Netgear
2010-09-12 04:18 . 2010-09-12 04:18 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2010-09-12 04:18 . 2010-09-12 04:18 ——– d—–w- c:\program files\DVDVideoSoft
2010-09-12 04:10 . 2010-09-12 04:10 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\AnvSoft
2010-09-12 04:09 . 2010-09-12 04:09 ——– d—–w- c:\program files\AnvSoft
2010-09-12 03:11 . 2003-01-26 18:41 40960 —-a-w- c:\windows\system32\ssubtmr6.dll
2010-09-09 20:58 . 2010-09-09 21:01 ——– d—–w- c:\users\Below 14\AppData\Roaming\Canon
2010-09-05 21:28 . 2010-09-05 21:28 118264 —-a-w- c:\users\Below 14\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-05 21:24 . 2010-09-05 21:24 ——– d—–w- c:\users\Below 14\AppData\Local\Last.fm
2010-09-01 19:19 . 2010-09-01 19:19 ——– d—–w- c:\users\Under 14\AppData\Local\Apple Computer
2010-09-01 19:19 . 2010-09-01 19:19 ——– d—–w- c:\users\Under 14\AppData\Roaming\Apple Computer
2010-09-01 19:19 . 2010-09-01 19:19 ——– d—–w- c:\users\Under 14\AppData\Local\VirtualStore
2010-09-01 19:19 . 2010-09-02 17:11 ——– d—–w- c:\users\Under 14
2010-09-01 19:19 . 2010-09-01 19:19 ——– d—–w- c:\users\Under 14\AppData\Local\Microsoft
2010-09-01 19:19 . 2008-02-13 15:43 ——– d—–w- c:\users\Under 14\AppData\Local\Microsoft Help
2010-09-01 19:19 . 2006-11-02 12:37 ——– d—–w- c:\users\Under 14\AppData\Roaming\Media Center Programs

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-30 05:24 . 2009-08-17 20:32 ——– d—–w- c:\program files\Vuze
2010-09-30 05:22 . 2010-04-20 17:38 ——– d—–w- c:\program files\Nick Jr. Arcade
2010-09-30 05:22 . 2010-04-20 17:39 ——– d—–w- c:\program files\Microsoft
2010-09-30 05:15 . 2010-03-18 00:16 ——– d—–w- c:\program files\Common Files\Akamai
2010-09-28 20:23 . 2009-08-17 20:32 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\Azureus
2010-09-28 00:50 . 2008-01-12 04:02 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\Canon
2010-09-27 23:03 . 2009-09-29 14:58 182 —-a-w- c:\users\Kevin Taylor\AppData\Roaming\Azureus\restart.bat
2010-09-27 08:49 . 2010-06-30 23:43 1049936 —-a-w- c:\programdata\Kaspersky Lab\AVP11\Bases\klavasyswatch.dll
2010-09-22 03:50 . 2006-11-02 10:25 86016 —-a-w- c:\windows\Inf\infstor.dat
2010-09-22 03:50 . 2006-11-02 10:25 51200 —-a-w- c:\windows\Inf\infpub.dat
2010-09-22 03:50 . 2006-11-02 10:25 143360 —-a-w- c:\windows\Inf\infstrng.dat
2010-09-22 03:50 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2010-09-22 03:49 . 2008-02-10 08:58 ——– d—–w- c:\program files\Kaspersky Lab
2010-09-22 03:47 . 2008-02-10 08:57 ——– d—–w- c:\programdata\Kaspersky Lab Setup Files
2010-09-22 03:46 . 2010-07-06 22:16 ——– d—–w- c:\programdata\avg9
2010-09-20 18:44 . 2010-04-28 18:02 ——– d—–w- c:\program files\Bonjour
2010-09-12 03:12 . 2008-02-12 18:45 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\DVD Flick
2010-09-12 03:11 . 2010-07-10 06:26 ——– d—–w- c:\program files\DVD Flick
2010-09-05 17:36 . 2010-09-05 17:36 ——– d—–w- c:\users\Below 14\AppData\Roaming\Apple Computer
2010-09-05 17:36 . 2010-09-05 17:36 ——– d—–w- c:\users\Below 14\AppData\Roaming\Malwarebytes
2010-09-02 17:09 . 2010-05-08 01:45 ——– d—–w- c:\programdata\FLEXnet
2010-09-02 17:09 . 2009-02-13 03:46 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-08-27 12:02 . 2010-08-27 12:02 68256 —-a-w- c:\programdata\Kaspersky Lab Setup Files\Kaspersky Internet Security 2011 11.0.1.400\English\setup.exe
2010-08-26 14:22 . 2010-08-26 14:20 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\my_app_files
2010-08-26 14:20 . 2010-08-26 14:20 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\BirthdayAdventurec6
2010-08-26 14:05 . 2010-08-26 14:05 ——– d—–w- c:\program files\Shockwave.com
2010-08-24 00:46 . 2010-08-24 00:46 ——– d—–w- c:\program files\Audacity
2010-08-18 19:16 . 2010-08-18 19:16 271696 —-a-w- c:\programdata\Kaspersky Lab\AVP11\Bases\sys_critical_obj.dll
2010-08-14 18:51 . 2007-10-11 20:07 ——– d—–w- c:\programdata\WildTangent
2010-08-07 18:34 . 2007-10-11 20:05 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-07 18:30 . 2010-08-07 18:30 ——– d—–w- c:\program files\Disney Interactive
2010-08-07 18:29 . 2010-08-07 18:29 ——– d—–w- c:\programdata\Disney Interactive
2010-07-27 23:44 . 2010-07-27 23:44 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-07-27 23:44 . 2010-07-27 23:44 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-07-23 08:47 . 2007-10-11 19:53 311583992 —-a-w- c:\windows\DUMP583c.tmp
2010-07-11 22:17 . 2008-01-05 08:17 118264 —-a-w- c:\users\Kevin Taylor\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-06 19:50 . 2007-10-11 19:53 166659099 —-a-w- c:\windows\DUMP46ee.tmp
2010-07-06 19:48 . 2007-10-11 19:53 166159387 —-a-w- c:\windows\DUMP446e.tmp
2010-07-06 19:45 . 2007-10-11 19:53 165626907 —-a-w- c:\windows\DUMP43d3.tmp
2010-07-06 19:43 . 2007-10-11 19:53 165184539 —-a-w- c:\windows\DUMP43d2.tmp
2010-07-06 19:40 . 2007-10-11 19:53 164422683 —-a-w- c:\windows\DUMP46c0.tmp
2010-07-06 19:37 . 2007-10-11 19:53 165471259 —-a-w- c:\windows\DUMP477a.tmp
2010-07-06 19:34 . 2007-10-11 19:53 165684251 —-a-w- c:\windows\DUMP46bf.tmp
2010-07-06 19:32 . 2007-10-11 19:53 163812379 —-a-w- c:\windows\DUMP423d.tmp
2010-07-06 19:29 . 2007-10-11 19:53 297120492 —-a-w- c:\windows\DUMP48b2.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"RtHDVCpl"="RtHDVCpl.exe" [2007-01-18 4349952]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-09-22 352976]

c:\users\Below 14\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigFix]
2006-11-16 23:04 2348584 —-a-w- c:\program files\BigFix\bigfix.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTCheck]
2007-11-06 17:08 397312 ——w- c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ddoctorv2]
2008-04-24 18:25 202560 —-a-w- c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2008-11-06 03:59 4347120 —-a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-08-10 10:15 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 22:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-01-21 16:55 185872 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"ShowWnd"=ShowWnd.exe
"ModPS2"=ModPS2Key.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2908862468-2916969662-1638312087-1000]
"EnableNotificationsRef"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2908862468-2916969662-1638312087-1005]
"EnableNotificationsRef"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 135664]
R2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2006-11-02 9216]
R3 4E924A7C;4E924A7C;c:\windows\system32\4E924A7C.exe [2010-09-29 6656]
R3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-06-09 11352]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-23 22104]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
S3 AVer88xHD;AVerMedia 23888 AvStream Video Capture;c:\windows\system32\drivers\AVer88xHD.sys [2007-04-09 401408]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-03 19984]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 19:24 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-09-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 02:30]

2010-09-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 02:30]

2010-09-30 c:\windows\Tasks\User_Feed_Synchronization-{2C79498B-CB54-43C6-ABAD-63633AAFA567}.job
- c:\windows\system32\msfeedssync.exe [2010-06-25 04:30]

2010-09-30 c:\windows\Tasks\User_Feed_Synchronization-{ED4E2BAB-F02A-4EFA-9AB3-B5B4BBD2A292}.job
- c:\windows\system32\msfeedssync.exe [2010-06-25 04:30]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.comcast.net/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Settings,ProxyOverride = cdn;*.local
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-30 00:36
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,77,65,6e,af,5b,59,a8,43,ba,6a,f7,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,77,65,6e,af,5b,59,a8,43,ba,6a,f7,\

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-09-30 00:40:09
ComboFix-quarantined-files.txt 2010-09-30 05:39

Pre-Run: 74,136,616,960 bytes free
Post-Run: 74,533,326,848 bytes free

- - End Of File - - 0AD84DBBE024674C3A950474381E897E
k7t7:

🖼Click to load external image (Posted Image) Go to the Control Panel
  • In the search bar enter Show hidden
  • In the main window click on Folder Options > Show hidden files and folders
  • Change the setting under Hidden files and folders to Show hidden files, folders, or drives
  • Click OK. (Remember to Hide files and folders once done)
Please go to one of the below sites to scan the following files:
virscan.org
Virus Total

Click on Browse, and upload the following file for analysis:
c:\windows\system32\4E924A7C.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

Please include the following in your next post:
  • File analysis results
File information File Name : 4E924A7C.exe File Size : 6656 byte File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit MD5 : 2f5b3d5bcab8eaec43263edf7a45a918 SHA1 : 377b704b6a99f784ff2e2f24e8789ee5d1ba019f Scanner results Scanner results : 3% Scanner(s) (1/35) found malware! Time : 2010/09/30 11:56:40 (CDT) Scanner Engine Ver Sig Ver Sig Date Scan result Time a-squared 5.0.0.20 20100930220801 2010-09-30 - 2.261 AhnLab V3 2010.10.01.00 2010.10.01 2010-10-01 - 21.040 AntiVir 8.2.4.66 7.10.12.91 2010-09-30 - 0.290 Antiy 2.0.18 20100930.5260568 2010-09-30 - 0.124 Authentium 5.1.1 201009300512 2010-09-30 - 1.297 AVAST! 4.7.4 100930-0 2010-09-30 - 0.003 AVG 8.5.850 271.1.1/3168 2010-09-30 - 0.260 BitDefender 7.90123.6211259 7.34092 2010-09-30 - 4.602 ClamAV 0.96.1 12051 2010-09-30 - 0.008 Comodo 4.0 6224 2010-09-28 - 3.161 CP Secure 1.3.0.5 2010.09.30 2010-09-30 - 0.033 Dr.Web 5.0.2.3300 2010.09.30 2010-09-30 - 9.612 F-Prot 4.4.4.56 20100929 2010-09-29 - 1.445 F-Secure 7.02.73807 2010.09.30.06 2010-09-30 - 0.146 Fortinet 4.1.143 12.406 2010-09-30 - 0.856 GData 21.924/21.371 20100930 2010-09-30 - 40.110 Ikarus T3.1.32.15.0 2010.09.30.76847 2010-09-30 - 4.770 JiangMin 13.0.900 2010.09.29 2010-09-29 - 40.086 Kaspersky 5.5.10 2010.09.28 2010-09-28 - 0.083 KingSoft 2009.2.5.15 2010.9.30.18 2010-09-30 - 40.087 McAfee 5400.1158 6121 2010-09-29 - 18.917 Microsoft 1.6201 2010.09.30 2010-09-30 - 40.086 Norman 6.05.11 6.05.00 2010-09-02 - 8.013 nProtect 20100927.03 9236033 2010-09-27 - 40.085 Panda 9.05.01 2010.09.29 2010-09-29 Suspicious file 13.769 Quick Heal 11.00 2010.09.30 2010-09-30 - 32.988 Rising 20.0 22.67.02.07 2010-09-29 - 40.085 Sophos 3.12.1 4.58 2010-09-30 - 3.925 Sunbelt 3.9.2453.2 6949 2010-09-30 - 40.085 Symantec 1.3.0.24 20100929.002 2010-09-29 - 0.049 The Hacker 6.7.0.1 v00040 2010-09-29 - 40.087 Trend Micro 9.120-1004 7.504.09 2010-09-30 - 0.027 VBA32 3.12.14.1 20100929.1020 2010-09-29 - 3.263 ViRobot 20100930 2010.09.30 2010-09-30 - 40.122 VirusBuster 4.5.11.10 10.129.3/1948945 2010-09-30 - 2.304 ■Heuristic/Suspicious ■Exact
k7t7:

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Accessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Driver::

Driver::
NOD32FiXTemDono
KillAll::

Save this as CFScript to your desktop.

Then disable your security programs and drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

Please include the following in your next post:
  • ComboFix log
  • MBAM log
ComboFix 10-09-30.01 - Kevin Taylor 09/30/2010 15:08:38.8.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3454.2065 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Kevin Taylor\Desktop\CFScript.txt . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Service_NOD32FiXTemDono ((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-30 ))))))))))))))))))))))))))))))) . 2010-09-30 20:14 . 2010-09-30 20:19 ——– d—–w- c:\users\Kevin Taylor\AppData\Local\temp 2010-09-30 20:14 . 2010-09-30 20:14 ——– d—–w- c:\users\Under 14\AppData\Local\temp 2010-09-30 20:14 . 2010-09-30 20:14 ——– d—–w- c:\users\Public\AppData\Local\temp 2010-09-30 20:14 . 2010-09-30 20:14 ——– d—–w- c:\users\Mcx2\AppData\Local\temp 2010-09-30 20:14 . 2010-09-30 20:14 ——– d—–w- c:\users\Mcx1\AppData\Local\temp 2010-09-30 20:14 . 2010-09-30 20:14 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-09-30 20:14 . 2010-09-30 20:14 ——– d—–w- c:\users\Below 14\AppData\Local\temp 2010-09-29 20:00 . 2010-09-29 20:00 6656 —-a-w- c:\windows\system32\4E924A7C.exe 2010-09-27 23:04 . 2010-09-27 23:04 310208 —-a-w- c:\users\Kevin Taylor\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe 2010-09-27 08:49 . 2010-09-27 08:49 1049936 —-a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\bases\sw2\klavasyswatch.dll 2010-09-23 19:55 . 2010-09-23 19:55 ——– d—–w- c:\users\Below 14\AppData\Roaming\WildTangent 2010-09-22 04:12 . 2010-09-22 04:12 288080 —-a-w- c:\programdata\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\bases\av\kdb\i386\win\avengine.dll 2010-09-22 04:11 . 2010-09-22 04:11 ——– d—–w- c:\users\Default\AppData\Roaming\Apple Computer 2010-09-22 04:11 . 2010-09-22 04:11 ——– d—–w- c:\users\Default\AppData\Local\Apple Computer 2010-09-22 03:51 . 2010-09-22 03:51 97549 —-a-w- c:\windows\system32\drivers\klick.dat 2010-09-22 03:51 . 2010-09-22 03:51 113933 —-a-w- c:\windows\system32\drivers\klin.dat 2010-09-22 03:49 . 2010-09-30 20:16 ——– d—–w- c:\programdata\Kaspersky Lab 2010-09-20 18:47 . 2010-09-20 18:47 ——– d—–w- c:\program files\QuickTime 2010-09-14 20:12 . 2009-08-19 21:49 49904 —-a-r- c:\windows\system32\drivers\BVRPMPR5.SYS 2010-09-14 20:11 . 2010-09-14 21:44 ——– dc—-w- C:\Netgear 2010-09-12 04:18 . 2010-09-12 04:18 ——– d—–w- c:\program files\Common Files\DVDVideoSoft 2010-09-12 04:18 . 2010-09-12 04:18 ——– d—–w- c:\program files\DVDVideoSoft 2010-09-12 04:10 . 2010-09-12 04:10 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\AnvSoft 2010-09-12 04:09 . 2010-09-12 04:09 ——– d—–w- c:\program files\AnvSoft 2010-09-12 03:11 . 2003-01-26 18:41 40960 —-a-w- c:\windows\system32\ssubtmr6.dll 2010-09-09 20:58 . 2010-09-09 21:01 ——– d—–w- c:\users\Below 14\AppData\Roaming\Canon 2010-09-05 21:28 . 2010-09-05 21:28 118264 —-a-w- c:\users\Below 14\AppData\Local\GDIPFONTCACHEV1.DAT 2010-09-05 21:24 . 2010-09-05 21:24 ——– d—–w- c:\users\Below 14\AppData\Local\Last.fm 2010-09-01 19:19 . 2010-09-01 19:19 ——– d—–w- c:\users\Under 14\AppData\Local\Apple Computer 2010-09-01 19:19 . 2010-09-01 19:19 ——– d—–w- c:\users\Under 14\AppData\Roaming\Apple Computer 2010-09-01 19:19 . 2010-09-01 19:19 ——– d—–w- c:\users\Under 14\AppData\Local\VirtualStore 2010-09-01 19:19 . 2010-09-02 17:11 ——– d—–w- c:\users\Under 14 2010-09-01 19:19 . 2010-09-01 19:19 ——– d—–w- c:\users\Under 14\AppData\Local\Microsoft 2010-09-01 19:19 . 2008-02-13 15:43 ——– d—–w- c:\users\Under 14\AppData\Local\Microsoft Help 2010-09-01 19:19 . 2006-11-02 12:37 ——– d—–w- c:\users\Under 14\AppData\Roaming\Media Center Programs . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-09-30 20:17 . 2010-03-18 00:16 ——– d—–w- c:\program files\Common Files\Akamai 2010-09-30 05:24 . 2009-08-17 20:32 ——– d—–w- c:\program files\Vuze 2010-09-30 05:22 . 2010-04-20 17:38 ——– d—–w- c:\program files\Nick Jr. Arcade 2010-09-30 05:22 . 2010-04-20 17:39 ——– d—–w- c:\program files\Microsoft 2010-09-28 20:23 . 2009-08-17 20:32 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\Azureus 2010-09-28 00:50 . 2008-01-12 04:02 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\Canon 2010-09-27 23:03 . 2009-09-29 14:58 182 —-a-w- c:\users\Kevin Taylor\AppData\Roaming\Azureus\restart.bat 2010-09-27 08:49 . 2010-06-30 23:43 1049936 —-a-w- c:\programdata\Kaspersky Lab\AVP11\Bases\klavasyswatch.dll 2010-09-22 03:50 . 2006-11-02 10:25 86016 —-a-w- c:\windows\Inf\infstor.dat 2010-09-22 03:50 . 2006-11-02 10:25 51200 —-a-w- c:\windows\Inf\infpub.dat 2010-09-22 03:50 . 2006-11-02 10:25 143360 —-a-w- c:\windows\Inf\infstrng.dat 2010-09-22 03:50 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar 2010-09-22 03:49 . 2008-02-10 08:58 ——– d—–w- c:\program files\Kaspersky Lab 2010-09-22 03:47 . 2008-02-10 08:57 ——– d—–w- c:\programdata\Kaspersky Lab Setup Files 2010-09-22 03:46 . 2010-07-06 22:16 ——– d—–w- c:\programdata\avg9 2010-09-20 18:44 . 2010-04-28 18:02 ——– d—–w- c:\program files\Bonjour 2010-09-12 03:12 . 2008-02-12 18:45 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\DVD Flick 2010-09-12 03:11 . 2010-07-10 06:26 ——– d—–w- c:\program files\DVD Flick 2010-09-05 17:36 . 2010-09-05 17:36 ——– d—–w- c:\users\Below 14\AppData\Roaming\Apple Computer 2010-09-05 17:36 . 2010-09-05 17:36 ——– d—–w- c:\users\Below 14\AppData\Roaming\Malwarebytes 2010-09-02 17:09 . 2010-05-08 01:45 ——– d—–w- c:\programdata\FLEXnet 2010-09-02 17:09 . 2009-02-13 03:46 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2010-08-27 12:02 . 2010-08-27 12:02 68256 —-a-w- c:\programdata\Kaspersky Lab Setup Files\Kaspersky Internet Security 2011 11.0.1.400\English\setup.exe 2010-08-26 14:22 . 2010-08-26 14:20 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\my_app_files 2010-08-26 14:20 . 2010-08-26 14:20 ——– d—–w- c:\users\Kevin Taylor\AppData\Roaming\BirthdayAdventurec6 2010-08-26 14:05 . 2010-08-26 14:05 ——– d—–w- c:\program files\Shockwave.com 2010-08-24 00:46 . 2010-08-24 00:46 ——– d—–w- c:\program files\Audacity 2010-08-18 19:16 . 2010-08-18 19:16 271696 —-a-w- c:\programdata\Kaspersky Lab\AVP11\Bases\sys_critical_obj.dll 2010-08-14 18:51 . 2007-10-11 20:07 ——– d—–w- c:\programdata\WildTangent 2010-08-07 18:34 . 2007-10-11 20:05 ——– d–h–w- c:\program files\InstallShield Installation Information 2010-08-07 18:30 . 2010-08-07 18:30 ——– d—–w- c:\program files\Disney Interactive 2010-08-07 18:29 . 2010-08-07 18:29 ——– d—–w- c:\programdata\Disney Interactive 2010-07-27 23:44 . 2010-07-27 23:44 91424 —-a-w- c:\windows\system32\dnssd.dll 2010-07-27 23:44 . 2010-07-27 23:44 107808 —-a-w- c:\windows\system32\dns-sd.exe 2010-07-23 08:47 . 2007-10-11 19:53 311583992 —-a-w- c:\windows\DUMP583c.tmp 2010-07-11 22:17 . 2008-01-05 08:17 118264 —-a-w- c:\users\Kevin Taylor\AppData\Local\GDIPFONTCACHEV1.DAT 2010-07-06 19:50 . 2007-10-11 19:53 166659099 —-a-w- c:\windows\DUMP46ee.tmp 2010-07-06 19:48 . 2007-10-11 19:53 166159387 —-a-w- c:\windows\DUMP446e.tmp 2010-07-06 19:45 . 2007-10-11 19:53 165626907 —-a-w- c:\windows\DUMP43d3.tmp 2010-07-06 19:43 . 2007-10-11 19:53 165184539 —-a-w- c:\windows\DUMP43d2.tmp 2010-07-06 19:40 . 2007-10-11 19:53 164422683 —-a-w- c:\windows\DUMP46c0.tmp 2010-07-06 19:37 . 2007-10-11 19:53 165471259 —-a-w- c:\windows\DUMP477a.tmp 2010-07-06 19:34 . 2007-10-11 19:53 165684251 —-a-w- c:\windows\DUMP46bf.tmp 2010-07-06 19:32 . 2007-10-11 19:53 163812379 —-a-w- c:\windows\DUMP423d.tmp 2010-07-06 19:29 . 2007-10-11 19:53 297120492 —-a-w- c:\windows\DUMP48b2.tmp . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120] "RtHDVCpl"="RtHDVCpl.exe" [2007-01-18 4349952] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-09-22 352976] c:\users\Below 14\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "HideFastUserSwitching"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] backupExtension=.CommonStartup [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk] backupExtension=.CommonStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigFix] 2006-11-16 23:04 2348584 —-a-w- c:\program files\BigFix\bigfix.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTCheck] 2007-11-06 17:08 397312 ——w- c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ddoctorv2] 2008-04-24 18:25 202560 —-a-w- c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)] 2008-11-06 03:59 4347120 —-a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2010-08-10 10:15 421888 —-a-w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] 2009-03-05 22:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2009-01-21 16:55 185872 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime "PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE "ShowWnd"=ShowWnd.exe "ModPS2"=ModPS2Key.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2908862468-2916969662-1638312087-1000] "EnableNotificationsRef"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2908862468-2916969662-1638312087-1005] "EnableNotificationsRef"=dword:00000001 R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 135664] R2 SBSDWSCService;SBSD Security Center Service; [x] R3 4E924A7C;4E924A7C;c:\windows\system32\4E924A7C.exe [2010-09-29 6656] R3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184] R3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM106.sys [2007-12-14 1373696] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-01-27 717296] S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-06-09 11352] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-23 22104] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504] S3 AVer88xHD;AVerMedia 23888 AvStream Video Capture;c:\windows\system32\drivers\AVer88xHD.sys [2007-04-09 401408] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-03 19984] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-08-20 19:24 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder 2010-09-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 02:30] 2010-09-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 02:30] 2010-09-30 c:\windows\Tasks\User_Feed_Synchronization-{2C79498B-CB54-43C6-ABAD-63633AAFA567}.job - c:\windows\system32\msfeedssync.exe [2010-06-25 04:30] 2010-09-30 c:\windows\Tasks\User_Feed_Synchronization-{ED4E2BAB-F02A-4EFA-9AB3-B5B4BBD2A292}.job - c:\windows\system32\msfeedssync.exe [2010-06-25 04:30] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ mStart Page = hxxp://www.comcast.net/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html mWindow Title = Windows Internet Explorer provided by Comcast uInternet Settings,ProxyOverride = cdn;*.local uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100 uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,77,65,6e,af,5b,59,a8,43,ba,6a,f7,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,77,65,6e,af,5b,59,a8,43,ba,6a,f7,\ [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\windows\system32\rundll32.exe c:\windows\system32\agrsmsvc.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Common Files\Motive\McciCMService.exe c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\windows\system32\WUDFHost.exe c:\program files\Canon\CAL\CALMAIN.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\\?\c:\windows\system32\wbem\WMIADAP.EXE c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2010-09-30 15:23:14 - machine was rebooted ComboFix-quarantined-files.txt 2010-09-30 20:23 ComboFix2.txt 2010-09-30 05:40 Pre-Run: 74,504,736,768 bytes free Post-Run: 74,274,852,864 bytes free - - End Of File - - B5BCE1053D1FC5286A2693DCD34F117F Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4724 Windows 6.0.6001 Service Pack 1 Internet Explorer 8.0.6001.18928 9/30/2010 3:32:16 PM mbam-log-2010-09-30 (15-32-16).txt Scan type: Quick scan Objects scanned: 183430 Time elapsed: 5 minute(s), 26 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
k7t7:

Are you still being redirected? This next scan will require that you install the latest version of Java. Click this link and press the "Free Java Download" button near the center of the page to be directed to the download. Once you have it installed, please run this:

🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.
  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • Kaspersky log
  • How is your computer running?
Sorry, I forgot you have KAV installed. Go ahead and run a full scan with it (it will likely take several hours). Let me know the results.
Every time I try to run any virus scan it shuts down my cpu at somepoint during the scan. It started when I had AVG free. I thought it was AVG so I'm trying Kaspersky. Now it's doing the same thing.
k7t7:

See if you can get this to run. Is this an older PC?

🖼Click to load external image (Posted Image) Please run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Please include the following in your next post:
  • ESET log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI