This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

MarkMcG Infected machine

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

TomK, Hi Tom, this is Doug. This is a relatively new (3+ months) Gateway i3 3.2ghz, with 8gb RAM, Running Windows 7 Home Premium x64 The owner does not have installation disks. The owner has not yet used the option to Create Recovery Disks. You asked me to Run DDS. It does not Run on this machine Command (DOS) box appears, reading: "This tool does not support your Operating System" Running Windows 7 Home Premium 64 bit Here's the Malwarebytes report: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5789 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 2/17/2011 7:11:37 PM mbam-log-2011-02-17 (19-11-30).txt Scan type: Full scan (C:\|) Objects scanned: 297117 Time elapsed: 25 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 3 Files Infected: 20 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken. Folders Infected: c:\Users\Owner\AppData\Roaming\whitesmoketoolbar (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather (PUP.WhiteSmoke) -> No action taken. c:\programdata\microsoft\Windows\start menu\Programs\whitesmoke translator (PUP.WhiteSmoke) -> No action taken. Files Infected: c:\Users\Owner\AppData\Local\Temp\dxfh.exe (Adware.Agent) -> No action taken. c:\Users\Owner\AppData\Local\Temp\uegsg.exe (Trojan.LVBP) -> No action taken. c:\Users\Owner\AppData\Local\Temp\updatecheck.dll (Trojan.FakeAlert) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\dtx.ini (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\guid.dat (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\log.txt (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\preferences.dat (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\stat.log (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\stats.dat (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\uninstallie.dat (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\uninstallstatie.dat (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\version.xml (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weatherbutton_prefs.xml (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\3f36704676aeca513c641eec506661b5 (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\6f855fed069951ec7b3b65ee86123a32 (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\forecasts_cache.xml (PUP.WhiteSmoke) -> No action taken. c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\observations_cache.xml (PUP.WhiteSmoke) -> No action taken. c:\programdata\microsoft\Windows\start menu\Programs\whitesmoke translator\registration.lnk (PUP.WhiteSmoke) -> No action taken. c:\programdata\microsoft\Windows\start menu\Programs\whitesmoke translator\uninstall.lnk (PUP.WhiteSmoke) -> No action taken. c:\programdata\microsoft\Windows\start menu\Programs\whitesmoke translator\whitesmoke translator.lnk (PUP.WhiteSmoke) -> No action taken. Note: I saved this report before allowing Malwarebytes to take action of removing all but the following: c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\3f36704676aeca513c641eec506661b5 (PUP.WhiteSmoke) -> c:\Users\Owner\AppData\Roaming\whitesmoketoolbar\weather\6f855fed069951ec7b3b65ee86123a32 (PUP.WhiteSmoke Reason: Believing that those two items may reside in Restore Points, therefore kept them. What scans do you wish me to run.
When you attempted to run DDS, did you right click and run as admin? (DDS does run on X64).

If you did that and it's a no go - run OTL.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
DDS (Ver_10-12-12.02) - NTFS_AMD64 Run by [removed] at 8:26:31.42 on Fri 02/18/2011 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8119.6110 [GMT -8:00] AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe C:\Windows\system32\WUDFHost.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Rhapsody\rhapsody.exe C:\Program Files (x86)\Rhapsody\rhaphlpr.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtblfs.exe C:\Windows\system32\notepad.exe C:\Windows\explorer.exe C:\Windows\explorer.exe C:\Windows\system32\NOTEPAD.EXE C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe C:\Windows\system32\taskhost.exe C:\Windows\explorer.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Owner\Downloads\dds(2).scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.cnn.com/ uDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW mDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW mStart Page = hxxp://www.bing.com/?pc=MAGW mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBER~1.LNK - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BELKIN~1.LNK - C:\Program Files\Belkin\F5D7050v5011\Belkinwcui.exe StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop (1).ini StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MICROS~1.LNK - C:\Program Files\Microsoft Office\Office10\OSA.EXE uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll IFEO: ehshell.exe - "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll BHO-X64: IEVkbdBHO - No File BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll BHO-X64: link filter bho - No File mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe mRun-x64: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" IE-X64: {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UB\UB.lnk IFEO-X64: ehshell.exe - "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect ================= FIREFOX =================== FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\jgkivk0p.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/ FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]\components\kavlinkfilter.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Kaspersky URL Advisor: [removed] - C:\Program Files (x86)\Mozilla Firefox\extensions\[removed] ============= SERVICES / DRIVERS =============== R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736] R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-7-1 352976] R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-12-8 373640] R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2010-9-17 15928] R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2011-2-17 72216] R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-5-6 271872] R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-9-20 346144] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 UsbFltr;WayTech USB Filter Driver;C:\Windows\System32\drivers\UsbFltr.sys [2007-4-9 12288] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-1-11 1255736] S4 GREGService;GREGService;C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe [2010-1-8 23584] S4 Updater Service;Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2010-9-20 243232] S4 USBS3S4Detection;USBS3S4Detection;C:\OEM\USBDECTION\USBS3S4Detection.exe [2009-12-13 76320] =============== Created Last 30 ================ 2011-02-18 12:01:50 7844688 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{E4CFD534-3757-4A73-9A68-28699B6E0224}\mpengine.dll 2011-02-18 02:40:57 38224 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-02-18 02:40:54 24152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-02-18 02:40:54 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-02-18 02:05:55 60800 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\LMIproc.dll 2011-02-18 02:05:55 33152 —-a-w- C:\Windows\System32\LMIport.dll 2011-02-18 02:05:53 87456 —-a-w- C:\Windows\System32\LMIRfsClientNP.dll 2011-02-18 02:05:51 72216 —-a-w- C:\Windows\System32\drivers\LMIRfsDriver.sys 2011-02-18 02:05:50 80768 —-a-w- C:\Windows\System32\LMIinit.dll 2011-02-18 02:05:43 ——– d—–w- C:\Program Files (x86)\LogMeIn 2011-02-06 04:37:18 ——– d—–w- C:\Users\Owner\AppData\Local\Diagnostics 2011-01-30 22:57:00 103864 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll 2011-01-30 22:57:00 103864 —-a-w- C:\Program Files (x86)\Internet Explorer\PLUGINS\nppdf32.dll 2011-01-30 05:44:19 ——– d—–w- C:\Users\Owner\AppData\Roaming\Uniblue ==================== Find3M ==================== 2011-01-26 06:53:10 982912 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2011-01-26 06:53:10 265088 —-a-w- C:\Windows\System32\drivers\dxgmms1.sys 2011-01-26 06:31:20 144384 —-a-w- C:\Windows\System32\cdd.dll 2011-01-07 08:06:50 46080 —-a-w- C:\Windows\System32\atmlib.dll 2011-01-07 07:27:11 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2011-01-07 05:49:20 366080 —-a-w- C:\Windows\System32\atmfd.dll 2011-01-07 05:33:11 294400 —-a-w- C:\Windows\SysWow64\atmfd.dll 2011-01-05 06:20:30 612352 —-a-w- C:\Windows\System32\vbscript.dll 2011-01-05 05:37:33 428032 —-a-w- C:\Windows\SysWow64\vbscript.dll 2011-01-05 04:00:16 3127808 —-a-w- C:\Windows\System32\win32k.sys 2010-12-21 06:16:27 97280 —-a-w- C:\Windows\System32\wscsvc.dll 2010-12-21 06:16:27 62976 —-a-w- C:\Windows\System32\wscapi.dll 2010-12-21 06:16:16 214016 —-a-w- C:\Windows\System32\winsrv.dll 2010-12-21 06:16:14 442880 —-a-w- C:\Windows\System32\winhttp.dll 2010-12-21 06:16:14 1197056 —-a-w- C:\Windows\System32\wininet.dll 2010-12-21 06:16:09 258048 —-a-w- C:\Windows\System32\WebClnt.dll 2010-12-21 06:15:55 264192 —-a-w- C:\Windows\System32\upnp.dll 2010-12-21 06:15:31 15360 —-a-w- C:\Windows\System32\slwga.dll 2010-12-21 06:13:03 2003968 —-a-w- C:\Windows\System32\msxml6.dll 2010-12-21 06:13:03 1880576 —-a-w- C:\Windows\System32\msxml3.dll 2010-12-21 06:10:22 100864 —-a-w- C:\Windows\System32\davclnt.dll 2010-12-21 05:38:24 51200 —-a-w- C:\Windows\SysWow64\wscapi.dll 2010-12-21 05:38:22 981504 —-a-w- C:\Windows\SysWow64\wininet.dll 2010-12-21 05:38:22 350720 —-a-w- C:\Windows\SysWow64\winhttp.dll 2010-12-21 05:38:21 204800 —-a-w- C:\Windows\SysWow64\WebClnt.dll 2010-12-21 05:38:19 204288 —-a-w- C:\Windows\SysWow64\upnp.dll 2010-12-21 05:38:16 14336 —-a-w- C:\Windows\SysWow64\slwga.dll 2010-12-21 05:36:17 1389568 —-a-w- C:\Windows\SysWow64\msxml6.dll 2010-12-21 05:36:16 1236992 —-a-w- C:\Windows\SysWow64\msxml3.dll 2010-12-21 05:34:12 80384 —-a-w- C:\Windows\SysWow64\davclnt.dll 2010-12-18 06:11:41 57856 —-a-w- C:\Windows\System32\licmgr10.dll 2010-12-18 06:11:34 714752 —-a-w- C:\Windows\System32\kerberos.dll 2010-12-18 05:29:40 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2010-12-18 05:29:31 541184 —-a-w- C:\Windows\SysWow64\kerberos.dll 2010-12-18 04:55:03 482816 —-a-w- C:\Windows\System32\html.iec 2010-12-18 04:20:55 386048 —-a-w- C:\Windows\SysWow64\html.iec 2010-12-18 04:13:40 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2010-12-18 03:47:59 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb ============= FINISH: 8:26:48.53 ===============
DDS (Ver_10-12-12.02) - NTFS_AMD64 Run by [removed] at 8:26:31.42 on Fri 02/18/2011 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8119.6110 [GMT -8:00] AV: Kaspersky Anti-Virus *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Kaspersky Anti-Virus *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe C:\Windows\system32\WUDFHost.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Rhapsody\rhapsody.exe C:\Program Files (x86)\Rhapsody\rhaphlpr.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtblfs.exe C:\Windows\system32\notepad.exe C:\Windows\explorer.exe C:\Windows\explorer.exe C:\Windows\system32\NOTEPAD.EXE C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe C:\Windows\system32\taskhost.exe C:\Windows\explorer.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Owner\Downloads\dds(2).scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.cnn.com/ uDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW mDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW mStart Page = hxxp://www.bing.com/?pc=MAGW mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBER~1.LNK - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BELKIN~1.LNK - C:\Program Files\Belkin\F5D7050v5011\Belkinwcui.exe StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop (1).ini StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MICROS~1.LNK - C:\Program Files\Microsoft Office\Office10\OSA.EXE uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll IFEO: ehshell.exe - "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll BHO-X64: IEVkbdBHO - No File BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll BHO-X64: link filter bho - No File mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe mRun-x64: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" IE-X64: {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UB\UB.lnk IFEO-X64: ehshell.exe - "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect ================= FIREFOX =================== FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\jgkivk0p.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/ FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]\components\kavlinkfilter.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Kaspersky URL Advisor: [removed] - C:\Program Files (x86)\Mozilla Firefox\extensions\[removed] ============= SERVICES / DRIVERS =============== R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2010-6-9 11864] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2010-4-22 27736] R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe [2010-7-1 352976] R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2010-12-8 373640] R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2010-9-17 15928] R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2011-2-17 72216] R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-5-6 271872] R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-9-20 346144] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 UsbFltr;WayTech USB Filter Driver;C:\Windows\System32\drivers\UsbFltr.sys [2007-4-9 12288] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-1-11 1255736] S4 GREGService;GREGService;C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe [2010-1-8 23584] S4 Updater Service;Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2010-9-20 243232] S4 USBS3S4Detection;USBS3S4Detection;C:\OEM\USBDECTION\USBS3S4Detection.exe [2009-12-13 76320] =============== Created Last 30 ================ 2011-02-18 12:01:50 7844688 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{E4CFD534-3757-4A73-9A68-28699B6E0224}\mpengine.dll 2011-02-18 02:40:57 38224 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-02-18 02:40:54 24152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-02-18 02:40:54 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-02-18 02:05:55 60800 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\LMIproc.dll 2011-02-18 02:05:55 33152 —-a-w- C:\Windows\System32\LMIport.dll 2011-02-18 02:05:53 87456 —-a-w- C:\Windows\System32\LMIRfsClientNP.dll 2011-02-18 02:05:51 72216 —-a-w- C:\Windows\System32\drivers\LMIRfsDriver.sys 2011-02-18 02:05:50 80768 —-a-w- C:\Windows\System32\LMIinit.dll 2011-02-18 02:05:43 ——– d—–w- C:\Program Files (x86)\LogMeIn 2011-02-06 04:37:18 ——– d—–w- C:\Users\Owner\AppData\Local\Diagnostics 2011-01-30 22:57:00 103864 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll 2011-01-30 22:57:00 103864 —-a-w- C:\Program Files (x86)\Internet Explorer\PLUGINS\nppdf32.dll 2011-01-30 05:44:19 ——– d—–w- C:\Users\Owner\AppData\Roaming\Uniblue ==================== Find3M ==================== 2011-01-26 06:53:10 982912 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2011-01-26 06:53:10 265088 —-a-w- C:\Windows\System32\drivers\dxgmms1.sys 2011-01-26 06:31:20 144384 —-a-w- C:\Windows\System32\cdd.dll 2011-01-07 08:06:50 46080 —-a-w- C:\Windows\System32\atmlib.dll 2011-01-07 07:27:11 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2011-01-07 05:49:20 366080 —-a-w- C:\Windows\System32\atmfd.dll 2011-01-07 05:33:11 294400 —-a-w- C:\Windows\SysWow64\atmfd.dll 2011-01-05 06:20:30 612352 —-a-w- C:\Windows\System32\vbscript.dll 2011-01-05 05:37:33 428032 —-a-w- C:\Windows\SysWow64\vbscript.dll 2011-01-05 04:00:16 3127808 —-a-w- C:\Windows\System32\win32k.sys 2010-12-21 06:16:27 97280 —-a-w- C:\Windows\System32\wscsvc.dll 2010-12-21 06:16:27 62976 —-a-w- C:\Windows\System32\wscapi.dll 2010-12-21 06:16:16 214016 —-a-w- C:\Windows\System32\winsrv.dll 2010-12-21 06:16:14 442880 —-a-w- C:\Windows\System32\winhttp.dll 2010-12-21 06:16:14 1197056 —-a-w- C:\Windows\System32\wininet.dll 2010-12-21 06:16:09 258048 —-a-w- C:\Windows\System32\WebClnt.dll 2010-12-21 06:15:55 264192 —-a-w- C:\Windows\System32\upnp.dll 2010-12-21 06:15:31 15360 —-a-w- C:\Windows\System32\slwga.dll 2010-12-21 06:13:03 2003968 —-a-w- C:\Windows\System32\msxml6.dll 2010-12-21 06:13:03 1880576 —-a-w- C:\Windows\System32\msxml3.dll 2010-12-21 06:10:22 100864 —-a-w- C:\Windows\System32\davclnt.dll 2010-12-21 05:38:24 51200 —-a-w- C:\Windows\SysWow64\wscapi.dll 2010-12-21 05:38:22 981504 —-a-w- C:\Windows\SysWow64\wininet.dll 2010-12-21 05:38:22 350720 —-a-w- C:\Windows\SysWow64\winhttp.dll 2010-12-21 05:38:21 204800 —-a-w- C:\Windows\SysWow64\WebClnt.dll 2010-12-21 05:38:19 204288 —-a-w- C:\Windows\SysWow64\upnp.dll 2010-12-21 05:38:16 14336 —-a-w- C:\Windows\SysWow64\slwga.dll 2010-12-21 05:36:17 1389568 —-a-w- C:\Windows\SysWow64\msxml6.dll 2010-12-21 05:36:16 1236992 —-a-w- C:\Windows\SysWow64\msxml3.dll 2010-12-21 05:34:12 80384 —-a-w- C:\Windows\SysWow64\davclnt.dll 2010-12-18 06:11:41 57856 —-a-w- C:\Windows\System32\licmgr10.dll 2010-12-18 06:11:34 714752 —-a-w- C:\Windows\System32\kerberos.dll 2010-12-18 05:29:40 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2010-12-18 05:29:31 541184 —-a-w- C:\Windows\SysWow64\kerberos.dll 2010-12-18 04:55:03 482816 —-a-w- C:\Windows\System32\html.iec 2010-12-18 04:20:55 386048 —-a-w- C:\Windows\SysWow64\html.iec 2010-12-18 04:13:40 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2010-12-18 03:47:59 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb ============= FINISH: 8:26:48.53 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-12-12.02) Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 1/11/2011 2:47:41 PM System Uptime: 2/17/2011 8:27:46 PM (12 hours ago) Motherboard: Gateway | | DX4840 Processor: Intel® Core™ i3 CPU 550 @ 3.20GHz | CPU 1 | 3200/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 916 GiB total, 826.301 GiB free. D: is Removable E: is Removable F: is CDROM () G: is Removable H: is Removable I: is Removable ==== Disabled Device Manager Items ============= Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318} Description: Microsoft PS/2 Mouse Device ID: ACPI\PNP0F03\4&DC382E&0 Manufacturer: Microsoft Name: Microsoft PS/2 Mouse PNP Device ID: ACPI\PNP0F03\4&DC382E&0 Service: i8042prt ==== System Restore Points =================== RP3: 1/11/2011 3:43:43 PM - Windows Update RP4: 1/11/2011 4:05:13 PM - Windows Update RP5: 1/14/2011 5:19:49 PM - Windows Update RP6: 1/18/2011 12:28:28 PM - Windows Update RP7: 1/21/2011 10:14:41 PM - Windows Update RP8: 1/25/2011 9:48:38 AM - Windows Update RP9: 1/29/2011 1:47:59 PM - Windows Update RP10: 2/1/2011 12:59:13 AM - Windows Update RP11: 2/5/2011 8:18:20 PM - Windows Update RP12: 2/9/2011 9:05:43 PM - Windows Update RP13: 2/9/2011 9:26:40 PM - Windows Update RP14: 2/14/2011 10:40:36 PM - Windows Update RP15: 2/17/2011 6:05:08 PM - Installed LogMeIn RP16: 2/18/2011 4:01:36 AM - Windows Update ==== Installed Programs ====================== Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.4.2 MUI Advertising Center Best Buy pc app CyberLink PowerDVD 9 Gateway InfoCentre Gateway Photo Frame [removed] Gateway Recovery Management Gateway Registration Gateway Updater Identity Card ImagXpress Intel® Control Center Intel® Graphics Media Accelerator Driver Junk Mail filter update Kaspersky Anti-Virus 2011 LogMeIn Malwarebytes' Anti-Malware Microsoft Choice Guard Microsoft Office 2010 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Mozilla Firefox (3.6.13) MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero 9 Essentials Nero ControlCenter Nero DiscSpeed Nero DiscSpeed Help Nero DriveSpeed Nero DriveSpeed Help Nero Express Help Nero InfoTool Nero InfoTool Help Nero Installer Nero Online Upgrade Nero StartSmart Nero StartSmart Help Nero StartSmart OEM NeroExpress neroxml Realtek Ethernet Controller Driver For Windows 7 Realtek High Definition Audio Driver Rhapsody Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) UB Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Welcome Center Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Live Writer ==== End Of File ===========================
MarkMcG (Doug),

That all looks good. Let's get an online scan to verify and also find things that are old enough not to show in the scan.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
ESET results: One Threat found…. C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0YVUFBQB\registrybooster[1].exe Win32/RegistryBooster application
MarkMcG (Doug),

Easy money. :thumbup:

You can run TFC to clean out your temp files.

Go ahead and delete the .txt files you saved and DDS.

Reset your restore points.

And you should be good to go. :thumbup:


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI