This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Service and Controller App Error- HJT logfile

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=bdcb6cb29db0524ca19dc85eecefdf85 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-02-04 02:45:14 # local_time=2011-02-03 07:45:14 (-0700, Mountain Standard Time) # country="United States" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5892 16776574 100 100 0 133374364 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=278515 # found=11 # cleaned=0 # scan_time=20677 C:\Program Files\Uniblue\RegistryBooster\Launcher.exe a variant of Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe Win32/RegistryBooster application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Windows\system32\Drivers\afd.sys.vir Win32/Olmarik.ZC trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\Owner\Desktop\powersuite.exe multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Users\Owner\Music\Autodesk Revit Architecture.iso probably a variant of Win32/Agent.EMANMCD trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\Owner\Music\Autodesk.AutoCAD.Architecture.2011.Win32-ISO\Autodesk AutoCAD Architecture v2011 x86.iso probably a variant of Win32/Agent.EMANMCD trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\Owner\Music\Google SketchUp Pro 8.0.3117 With Crack\Google SketchUp Pro 8.0.3117 With Crack.rar multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Users\Owner\Music\Informatix Piranesi 5.0\Informatix.Piranesi.v5.iSO-ENGiNE.[sharethefiles.com].iso a variant of Win32/HackTool.Patcher.A application (unable to clean) 00000000000000000000000000000000 I C:\Windows\System32\drivers\pmpqnmsxz.sys Win32/Bubnix.BK trojan (unable to clean) 00000000000000000000000000000000 I C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18005_none_d9d3bb9e5b8eea9c\afd.sys Win32/Olmarik.ZC trojan (unable to clean) 00000000000000000000000000000000 I
lehmbergj,

It appears that you have at least one pirated program on there that may be at the root of all your troubles.

Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

Odds are also fairly good that people in your address book have been receiving spam mail from you. Because part of the payload that the backdoor trojan "steals" is your address book, there is a fair chance that they will continue to receive spam mail even after we have cleaned the trojan off of your system.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Users\Owner\Desktop\powersuite.exe
    C:\Windows\System32\drivers\pmpqnmsxz.sys
    C:\Users\Owner\Music\Autodesk Revit Architecture.iso
    C:\Users\Owner\Music\Autodesk.AutoCAD.Architecture.2011.Win32-ISO\Autodesk AutoCAD Architecture v2011 x86.iso
    C:\Windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18005_none_d9d3bb9e5b8eea9c\afd.sys
    
    Folder::
    C:\Program Files\Uniblue\SpeedUpMyPC
    C:\Program Files\Uniblue\RegistryBooster
    C:\Users\Owner\Music\Google SketchUp Pro 8.0.3117 With Crack
    C:\Users\Owner\Music\Informatix Piranesi 5.0
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 11-02-05.01 - Owner 02/05/2011 13:55:50.4.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2939.1990 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Owner\Desktop\CFScript.txt SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FILE :: "c:\users\Owner\Desktop\powersuite.exe" "c:\users\Owner\Music\Autodesk Revit Architecture.iso" "c:\users\Owner\Music\Autodesk.AutoCAD.Architecture.2011.Win32-ISO\Autodesk AutoCAD Architecture v2011 x86.iso" "c:\windows\System32\drivers\pmpqnmsxz.sys" "c:\windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18005_none_d9d3bb9e5b8eea9c\afd.sys" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Uniblue\RegistryBooster c:\program files\Uniblue\RegistryBooster\cache.dll c:\program files\Uniblue\RegistryBooster\cwebpage.dll c:\program files\Uniblue\RegistryBooster\InstallerExtensions.dll c:\program files\Uniblue\RegistryBooster\intermediate_views.dat c:\program files\Uniblue\RegistryBooster\Launcher.exe c:\program files\Uniblue\RegistryBooster\library.dat c:\program files\Uniblue\RegistryBooster\locale\dk\dk.dll c:\program files\Uniblue\RegistryBooster\locale\dk\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\dk\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\dk\messages.dk.po c:\program files\Uniblue\RegistryBooster\locale\en\en.dll c:\program files\Uniblue\RegistryBooster\locale\en\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\en\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\en\messages.en.po c:\program files\Uniblue\RegistryBooster\locale\es\es.dll c:\program files\Uniblue\RegistryBooster\locale\es\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\es\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\es\messages.es.po c:\program files\Uniblue\RegistryBooster\locale\fr\fr.dll c:\program files\Uniblue\RegistryBooster\locale\fr\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\fr\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\fr\messages.fr.po c:\program files\Uniblue\RegistryBooster\locale\gr\gr.dll c:\program files\Uniblue\RegistryBooster\locale\gr\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\gr\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\gr\messages.gr.po c:\program files\Uniblue\RegistryBooster\locale\it\it.dll c:\program files\Uniblue\RegistryBooster\locale\it\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\it\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\it\messages.it.po c:\program files\Uniblue\RegistryBooster\locale\jp\jp.dll c:\program files\Uniblue\RegistryBooster\locale\jp\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\jp\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\jp\messages.jp.po c:\program files\Uniblue\RegistryBooster\locale\nl\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\nl\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\nl\messages.nl.po c:\program files\Uniblue\RegistryBooster\locale\nl\nl.dll c:\program files\Uniblue\RegistryBooster\locale\no\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\no\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\no\messages.no.po c:\program files\Uniblue\RegistryBooster\locale\no\no.dll c:\program files\Uniblue\RegistryBooster\locale\pt\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\pt\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\pt\messages.pt.po c:\program files\Uniblue\RegistryBooster\locale\pt\pt.dll c:\program files\Uniblue\RegistryBooster\locale\ru\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\ru\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\ru\messages.ru.po c:\program files\Uniblue\RegistryBooster\locale\ru\pt.dll c:\program files\Uniblue\RegistryBooster\locale\ru\ru.dll c:\program files\Uniblue\RegistryBooster\locale\se\LC_MESSAGES\messages.mo c:\program files\Uniblue\RegistryBooster\locale\se\LC_MESSAGES\rbmessages.mo c:\program files\Uniblue\RegistryBooster\locale\se\messages.se.po c:\program files\Uniblue\RegistryBooster\locale\se\se.dll c:\program files\Uniblue\RegistryBooster\Microsoft.VC90.CRT.manifest c:\program files\Uniblue\RegistryBooster\msvcp90.dll c:\program files\Uniblue\RegistryBooster\msvcr90.dll c:\program files\Uniblue\RegistryBooster\registrybooster.exe c:\program files\Uniblue\RegistryBooster\repair_transform.xsl c:\program files\Uniblue\RegistryBooster\ui_dll.dll c:\program files\Uniblue\RegistryBooster\unins000.dat c:\program files\Uniblue\RegistryBooster\unins000.exe c:\program files\Uniblue\RegistryBooster\views.dat c:\program files\Uniblue\SpeedUpMyPC c:\program files\Uniblue\SpeedUpMyPC\cache.dll c:\program files\Uniblue\SpeedUpMyPC\cwebpage.dll c:\program files\Uniblue\SpeedUpMyPC\InstallerExtensions.dll c:\program files\Uniblue\SpeedUpMyPC\intermediate_views.dat c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe c:\program files\Uniblue\SpeedUpMyPC\library.dat c:\program files\Uniblue\SpeedUpMyPC\locale\br\br.dll c:\program files\Uniblue\SpeedUpMyPC\locale\br\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\de\de.dll c:\program files\Uniblue\SpeedUpMyPC\locale\de\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\dk\dk.dll c:\program files\Uniblue\SpeedUpMyPC\locale\dk\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\en\en.dll c:\program files\Uniblue\SpeedUpMyPC\locale\en\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\en\LC_MESSAGES\sumpmessages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\es\es.dll c:\program files\Uniblue\SpeedUpMyPC\locale\es\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\fi\fi.dll c:\program files\Uniblue\SpeedUpMyPC\locale\fi\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\fr\fr.dll c:\program files\Uniblue\SpeedUpMyPC\locale\fr\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\gr\gr.dll c:\program files\Uniblue\SpeedUpMyPC\locale\gr\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\it\it.dll c:\program files\Uniblue\SpeedUpMyPC\locale\it\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\it\LC_MESSAGES\sumpmessages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\jp\jp.dll c:\program files\Uniblue\SpeedUpMyPC\locale\jp\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\nl\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\nl\nl.dll c:\program files\Uniblue\SpeedUpMyPC\locale\no\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\no\no.dll c:\program files\Uniblue\SpeedUpMyPC\locale\pl\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\pl\pl.dll c:\program files\Uniblue\SpeedUpMyPC\locale\pt\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\pt\pt.dll c:\program files\Uniblue\SpeedUpMyPC\locale\ru\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\ru\ru.dll c:\program files\Uniblue\SpeedUpMyPC\locale\se\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\se\se.dll c:\program files\Uniblue\SpeedUpMyPC\locale\tr\LC_MESSAGES\messages.mo c:\program files\Uniblue\SpeedUpMyPC\locale\tr\tr.dll c:\program files\Uniblue\SpeedUpMyPC\Microsoft.VC90.CRT.manifest c:\program files\Uniblue\SpeedUpMyPC\msvcp90.dll c:\program files\Uniblue\SpeedUpMyPC\msvcr90.dll c:\program files\Uniblue\SpeedUpMyPC\st.dat c:\program files\Uniblue\SpeedUpMyPC\sump.exe c:\program files\Uniblue\SpeedUpMyPC\unins000.dat c:\program files\Uniblue\SpeedUpMyPC\unins000.exe c:\program files\Uniblue\SpeedUpMyPC\views.dat c:\users\Owner\AppData\Local\Temp\6EF7.tmp c:\users\Owner\Desktop\powersuite.exe c:\users\Owner\Music\Autodesk Revit Architecture.iso c:\users\Owner\Music\Autodesk.AutoCAD.Architecture.2011.Win32-ISO\Autodesk AutoCAD Architecture v2011 x86.iso c:\users\Owner\Music\Google SketchUp Pro 8.0.3117 With Crack c:\users\Owner\Music\Google SketchUp Pro 8.0.3117 With Crack\Google SketchUp Pro 8.0.3117 With Crack.rar c:\users\Owner\Music\Informatix Piranesi 5.0 c:\users\Owner\Music\Informatix Piranesi 5.0\Informatix.Piranesi.v5.iSO-ENGiNE.[sharethefiles.com].iso c:\users\Owner\Music\Informatix Piranesi 5.0\Torrent downloaded from Demonoid.com.txt c:\windows\System32\drivers\pmpqnmsxz.sys c:\windows\winsxs\x86_microsoft-windows-winsock-core_31bf3856ad364e35_6.0.6002.18005_none_d9d3bb9e5b8eea9c\afd.sys . ((((((((((((((((((((((((( Files Created from 2011-01-05 to 2011-02-05 ))))))))))))))))))))))))))))))) . 2011-02-05 21:01 . 2011-02-05 21:02 ——– d—–w- c:\users\Owner\AppData\Local\temp 2011-02-05 21:01 . 2011-02-05 21:01 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-02-03 20:12 . 2011-02-03 20:12 ——– d—–w- c:\windows\Sun 2011-02-03 19:47 . 2011-02-03 19:47 ——– d—–w- c:\program files\ESET 2011-02-03 19:44 . 2011-02-03 19:44 ——– d—–w- c:\program files\Common Files\Java 2011-02-03 19:43 . 2011-02-03 19:43 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-02-03 19:43 . 2011-02-03 19:43 472808 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll 2011-02-01 09:11 . 2011-01-20 17:39 5890896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{11789360-86F4-4CA1-B47C-2AD21A40A891}\mpengine.dll 2011-02-01 04:59 . 2011-02-01 04:59 ——– d—–w- C:\8982a9c9ce2175880827 2011-01-25 23:25 . 2009-06-05 01:43 330264 —-a-w- c:\windows\system32\drivers\iaStor.sys 2011-01-24 05:49 . 2011-01-24 05:49 ——– d—–w- c:\users\Owner\AppData\Roaming\Malwarebytes 2011-01-24 05:49 . 2010-12-21 01:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-01-24 05:49 . 2011-01-24 05:49 ——– d—–w- c:\programdata\Malwarebytes 2011-01-24 05:49 . 2011-01-24 05:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-01-24 05:49 . 2010-12-21 01:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-01-24 05:21 . 2011-01-24 05:37 ——– d—–w- c:\program files\Wise Disk Cleaner 2011-01-24 05:13 . 2011-01-24 05:19 ——– d—–w- c:\program files\Wise Registry Cleaner 2011-01-24 04:55 . 2011-01-24 04:55 ——– d—–w- c:\users\Owner\AppData\Roaming\Uniblue 2011-01-24 04:55 . 2011-02-05 21:01 ——– d—–w- c:\program files\Uniblue 2011-01-16 09:37 . 2011-01-16 09:37 ——– d—–w- c:\programdata\WindowsSearch . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TWebCamera"="%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe autorun" [X] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-13 150040] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-13 154136] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-13 6965792] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-18 1451304] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe" [2009-03-24 1007616] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-13 178712] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208] "ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-04-02 1283384] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-11 421160] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ DRSpawner.lnk - c:\programdata\ASGvis\DRSpawner\DRSpawner.exe [2010-11-29 2076672] McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) R0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys [x] R0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x] R3 CFcatchme;CFcatchme;c:\users\Owner\AppData\Local\Temp\CFcatchme.sys [x] R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 Partner Service;Partner Service;c:\programdata\Partner\partner.exe [2009-06-16 110576] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504] S2 camsvc;TOSHIBA Web Camera Service;c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe [2009-04-17 20544] S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448] S2 RSELSVC;TOSHIBA Modem region select service;c:\program files\TOSHIBA\RSelect\RSelSvc.exe [2009-02-19 57344] S2 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-04-02 62776] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-04-15 176128] S2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-03-17 73728] S2 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-04-10 656752] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-03-21 12920] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168] S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [2009-03-18 22272] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache Akamai REG_MULTI_SZ Akamai . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\hc3cvsps.default\ FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . - - - - ORPHANS REMOVED - - - - AddRemove-{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1 - c:\program files\Uniblue\SpeedUpMyPC\unins000.exe AddRemove-{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1 - c:\program files\Uniblue\RegistryBooster\unins000.exe ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . ———————— Other Running Processes ———————— . c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe c:\windows\system32\WLANExt.exe c:\windows\system32\agrsmsvc.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Intel\WiFi\bin\EvtEng.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe c:\program files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe c:\windows\system32\TODDSrv.exe c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe c:\program files\Canon\CAL\CALMAIN.exe c:\windows\system32\igfxsrvc.exe c:\program files\iPod\bin\iPodService.exe c:\\?\c:\windows\system32\wbem\WMIADAP.EXE . ************************************************************************** . Completion time: 2011-02-05 14:08:36 - machine was rebooted ComboFix-quarantined-files.txt 2011-02-05 21:08 ComboFix2.txt 2011-02-02 04:51 ComboFix3.txt 2011-02-02 02:29 ComboFix4.txt 2011-01-26 23:19 Pre-Run: 143,613,288,448 bytes free Post-Run: 143,572,238,336 bytes free - - End Of File - - 13C90050EF5DDCA80EE6640A96F9FA28
DDS (Ver_10-12-12.02) - NTFSx86 Run by [removed] at 22:42:17.23 on Wed 02/09/2011 Internet Explorer: 8.0.6001.18999 BrowserJavaVersion: 1.6.0_23 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2939.1535 [GMT -7:00] SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxpers.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Windows\system32\agrsmsvc.exe C:\Windows\System32\svchost.exe -k Akamai C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe C:\Program Files\TOSHIBA\TECO\TecoService.exe C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\taskeng.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Owner\Desktop\dds (2).com C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s BHO: MRI_DISABLED - No File BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10h_Plugin.exe -update plugin mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe" mRun: [Persistence] "c:\windows\system32\igfxpers.exe" mRun: [RtHDVCpl] "c:\program files\realtek\audio\hda\RtHDVCpl.exe" mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe" mRun: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun mRun: [TosSENotify] "c:\program files\toshiba\toshiba hdd ssd alert\TosSENotify.exe" mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe" mRun: [Adobe_ID0EYTHM] "c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE" mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60 mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\drspaw~1.lnk - c:\programdata\asgvis\drspawner\DRSpawner.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\hc3cvsps.default\ FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\picasa2\npPicasa2.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} ============= SERVICES / DRIVERS =============== R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 21504] R2 camsvc;TOSHIBA Web Camera Service;c:\program files\toshiba\toshiba web camera application\TWebCameraSrv.exe [2009-6-15 20544] R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448] R2 RSELSVC;TOSHIBA Modem region select service;c:\program files\toshiba\rselect\RSelSvc.exe [2009-2-19 57344] R2 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2010-10-12 62776] R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-4-14 176128] R2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-3-17 73728] R2 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-4-9 656752] R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-3-20 12920] R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-5-3 7168] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-11-17 3668480] R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2009-6-15 22272] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);"c:\program files\google\update\googleupdate.exe" /svc –> c:\program files\google\update\GoogleUpdate.exe [?] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 Partner Service;Partner Service;c:\programdata\partner\partner.exe [2009-6-15 110576] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] =============== File Associations =============== .scr=AutoCADScriptFile =============== Created Last 30 ================ 2011-02-05 21:12:14 ——– d—–w- c:\users\owner\appdata\local\temp 2011-02-05 21:08:04 ——– d-sh–w- C:\$RECYCLE.BIN 2011-02-03 19:47:45 ——– d—–w- c:\program files\ESET 2011-02-03 19:43:54 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-02-03 19:43:54 472808 —-a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll 2011-02-02 02:05:02 98816 —-a-w- c:\windows\sed.exe 2011-02-02 02:05:02 89088 —-a-w- c:\windows\MBR.exe 2011-02-02 02:05:02 256512 —-a-w- c:\windows\PEV.exe 2011-02-02 02:05:02 161792 —-a-w- c:\windows\SWREG.exe 2011-02-01 09:11:26 5890896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{11789360-86f4-4ca1-b47c-2ad21a40a891}\mpengine.dll 2011-02-01 04:59:30 ——– d—–w- C:\8982a9c9ce2175880827 2011-01-25 23:25:50 330264 —-a-w- c:\windows\system32\drivers\iaStor.sys 2011-01-24 05:49:49 ——– d—–w- c:\users\owner\appdata\roaming\Malwarebytes 2011-01-24 05:49:45 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-01-24 05:49:44 ——– d—–w- c:\progra~2\Malwarebytes 2011-01-24 05:49:42 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-01-24 05:49:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-01-24 05:21:06 ——– d—–w- c:\program files\Wise Disk Cleaner 2011-01-24 05:13:38 ——– d—–w- c:\program files\Wise Registry Cleaner 2011-01-24 04:55:49 ——– d—–w- c:\users\owner\appdata\roaming\Uniblue 2011-01-24 04:55:20 ——– d—–w- c:\program files\Uniblue ==================== Find3M ==================== 2010-12-28 15:55:03 413696 —-a-w- c:\windows\system32\odbc32.dll 2010-12-14 14:49:23 1169408 —-a-w- c:\windows\system32\sdclt.exe ============= FINISH: 22:42:40.47 ===============

Attachments:

Things are running smoothly so far. Thank you very much for all your help/ guidance, and support in fixing my pc issues. Are there any suggestions you could give me for anti-virus/ adware and daily security? Thanks again.
lehmbergj,

Absolutely.

Time for some housekeeping
  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI