I have been getting notices of my e-mail account sending out messages to all of my contacts. Twice I've run malwarebytes and had it clean out the pup.casino virus but it keeps re-establishing itself. I also cannot access the internet through I.E, I have to use google chrome to get access.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
You might want to print these instructions out.
Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.
Please download ATF Cleaner by Atribune.
Download - ATF Cleanerยป
Double-click ATF-Cleaner.exe to run the program.
Under
Main choose:
Select All
Click the
Empty Selected button.
If you use Firefox browser
Click
Firefox at the top and choose:
Select All
Click the
Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click
No at the prompt.
If you use Opera browser Click
Opera at the top and choose:
Select All
Click the
Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click
No at the prompt.
Click
Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Next:
Please download
GooredFix from one of the locations below and
save it to your Desktop
Download Mirror #1
Download Mirror #2
Ensure all Firefox windows are closed. To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista). When prompted to run the scan, click Yes . It doesn't take long to run, once it is finished move onto the next step
Next:
Note: if the Cure option is not there, please select 'Skip'.
Please read carefully and follow these steps.
Also please describe how your computer behaves at the moment.
I did as you asked, the tds skiller didn't detect anything and it also didn't produce a log. Neither program requested a reboot. Here is the log from Goored Fix GooredFix by jpshortstuff (03.07.10.1)
Log created at 16:44 on 01/03/2011 (Bryan)
Firefox version 3.6.13 (en-US)
========== GooredScan ==========
========== GooredLog ==========
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [05:37 14/12/2010]
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [00:51 23/02/2011]
C:\Users\Bryan\Application Data\Mozilla\Firefox\Profiles\qci6f7wd.default\extensions\
{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} [05:04 24/08/2010]
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
(Key not found)
-=E.O.F=-
I will go ahead and do a reboot and check to see if the infections still come up on the scan from Online Armor++. Is there another scanning tool that might find the same things as Online Armor did? I don't know how to capture the screen shot of the scan results from Online Arm or++. If you need to see the results of the scan I will have to do it again, but please tell me how to post that scan result to this thread.
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")
Download ComboFix from one of these locations:
Link 1
Link 2 If using this link, Right Click and select Save As.
* IMPORTANT !!! Save ComboFix.exe to your Desktop
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note : If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
Double click on ComboFix.exe & follow the prompts.
Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.
Note: If you have XP SP3, use the XP SP2 package.
If Vista or Windows 7, skip the Recovery Console part
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the
C:\ComboFix.txt using Copy / Paste in your next reply.
Notes:
1.
Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of
ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you โ please tell your helper.
4.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely , the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
Please do not attach the scan results from Combofx. Use copy/paste.
Also please describe how your computer behaves at the moment.
I don't know whats going on here. I ran combofix but when it got to the finish and rebooted it didn't produce a log. When the computer did reboot and the command prompt came back up it showed unable to access three times then went off and didn't make a log. Before the tool finished though an error box came up that said "Unable to enable VBScript". One good thing is that I can now enable and use Internet Explorer once again. Please let me know what I should do next. Thank You for all your help.
I don't know whats going on here. I ran combofix but when it got to the finish and rebooted it didn't produce a log. When the computer did reboot and the command prompt came back up it showed unable to access three times then went off and didn't make a log. Before the tool finished though an error box came up that said "Unable to enable VBScript". One good thing is that I can now enable and use Internet Explorer once again. Please let me know what I should do next. Thank You for all your help.
Try running combofix scan again
If you still get this error: "Unable to enable VBScript".
If you're using Vista or Win7
Open an elevated Command Prompt to register the module vbscript.dll. To open an elevated Command Prompt, click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator.
Type the following in the Command Prompt window:
regsvr32 vbscript.dll
Press ENTER
If XP:
Open Command Prompt to register the module vbscript.dll. To open a Command Prompt, click Start, Run, type in CMD and Press ENTER
Type the following in the Command Prompt window:
regsvr32 vbscript.dll <โNote any spaces
Press ENTER
Alright, I ran Combofix once again, even though it took an exceptionally long time to run and I kept getting prompts to approve certain programs related to combofix to run even after the reboot it finally produced a log. Yes it still showed denied access and the vbscript error. I have done as you asked and enabled the vbscripting engine. Heres the log file:
ComboFix 11-02-28.07 - Bryan 03/01/2011 18:27:24.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3839.2323 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
AV: Online Armor ++ *Disabled/Updated* {607A6E45-BE50-AFD5-4F70-7EAAEC5B715D}
AV: Returnil System Safe 2011 *Disabled/Updated* {B1F99400-BE58-E5B3-88CF-FB21D431A392}
FW: Online Armor Firewall *Disabled* {5841EF60-F43F-AE8D-642F-D79F12883626}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Online Armor ++ *Disabled/Updated* {DB1B8FA1-986A-A05B-75C0-45D897DC3BE0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
โ- Previous Run โโ-
.
c:\users\Ashanthe\Desktop\Internet Explorer.lnk
c:\windows\system32\drivers\etc\lmhosts
.
((((((((((((((((((((((((( Files Created from 2011-02-02 to 2011-03-02 )))))))))))))))))))))))))))))))
.
2011-03-02 02:35 . 2011-03-02 02:35 โโโ dโโw- c:\users\Zanthia\AppData\Local\temp
2011-03-02 02:35 . 2011-03-02 02:35 โโโ dโโw- c:\users\Zanthia.Family\AppData\Local\temp
2011-03-02 02:35 . 2011-03-02 02:35 โโโ dโโw- c:\users\Default\AppData\Local\temp
2011-03-02 02:35 . 2011-03-02 02:35 โโโ dโโw- c:\users\Daniel\AppData\Local\temp
2011-03-02 02:35 . 2011-03-02 02:35 โโโ dโโw- c:\users\Daniel.Family\AppData\Local\temp
2011-03-02 02:35 . 2011-03-02 02:35 โโโ dโโw- c:\users\Betty\AppData\Local\temp
2011-03-02 02:35 . 2011-03-02 02:35 โโโ dโโw- c:\users\Ashanthe\AppData\Local\temp
2011-03-02 01:56 . 2011-02-11 07:30 7947600 โ-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{44879CA6-8641-46E2-A631-B9D1B4DBBC44}\mpengine.dll
2011-03-02 00:48 . 2011-03-02 00:48 92248 โ-a-w- c:\windows\system32\drivers\klmd.sys
2011-03-01 19:20 . 2011-03-01 19:20 โโโ dโโw- c:\users\Zanthia.Family\AppData\Local\Mozilla
2011-02-25 22:21 . 2011-02-25 22:21 โโโ dโโw- c:\programdata\launcher
2011-02-25 22:04 . 2011-01-21 22:52 37456 โ-a-w- c:\windows\system32\drivers\hotcore3.sys
2011-02-25 01:43 . 2011-02-25 01:45 โโโ dโโw- c:\program files (x86)\MasqueGames
2011-02-24 20:06 . 2011-01-17 06:12 320512 โ-a-w- c:\windows\system32\d3d10_1core.dll
2011-02-24 20:06 . 2011-01-17 06:12 197120 โ-a-w- c:\windows\system32\d3d10_1.dll
2011-02-24 20:06 . 2011-01-17 05:30 218624 โ-a-w- c:\windows\SysWow64\d3d10_1core.dll
2011-02-24 20:06 . 2011-01-17 05:30 161792 โ-a-w- c:\windows\SysWow64\d3d10_1.dll
2011-02-24 03:59 . 2011-02-24 03:59 388096 โ-a-r- c:\users\Bryan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-24 02:34 . 2011-02-24 02:34 โโโ dโโw- c:\program files\Prevx
2011-02-24 02:32 . 2011-02-24 02:37 โโโ dโโw- c:\programdata\PrevxCSI
2011-02-24 01:05 . 2010-05-26 18:39 6144 โโw- c:\windows\system32\7114.tmp
2011-02-24 01:04 . 2010-05-26 18:39 6144 โโw- c:\windows\system32\8178.tmp
2011-02-23 22:58 . 2011-02-23 22:58 โโโ dโโw- c:\users\Bryan\AppData\Roaming\SUPERAntiSpyware.com
2011-02-23 22:58 . 2011-02-23 22:58 โโโ dโโw- c:\programdata\!SASCORE
2011-02-23 00:51 . 2011-02-23 00:51 โโโ dโโw- c:\program files (x86)\Common Files\Java
2011-02-23 00:51 . 2011-02-23 00:51 472808 โ-a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-02-23 00:51 . 2011-02-23 00:51 โโโ dโโw- c:\program files (x86)\Java
2011-02-23 00:47 . 2011-02-23 00:47 โโโ dโโw- c:\program files\Java
2011-02-21 06:56 . 2011-02-21 06:56 โโโ dโโw- c:\users\Zanthia.Family\AppData\Local\JollyBear
2011-02-21 06:56 . 2011-02-21 06:56 โโโ dโโw- c:\programdata\JollyBear
2011-02-21 05:18 . 2011-02-21 05:35 โโโ dโโw- c:\users\Zanthia.Family\AppData\Roaming\Flood Light Games
2011-02-21 05:18 . 2011-02-21 05:35 โโโ dโโw- c:\programdata\Flood Light Games
2011-02-21 04:21 . 2011-02-21 04:22 โโโ dโโw- c:\users\Zanthia.Family\AppData\Roaming\Mystery of Mortlake Mansion
2011-02-17 21:14 . 2010-12-21 06:13 2003968 โ-a-w- c:\windows\system32\msxml6.dll
2011-02-12 20:52 . 2011-02-12 20:52 โโโ dโโw- c:\program files (x86)\Common Files\CA Shared
2011-02-12 01:09 . 2010-12-21 06:16 214016 โ-a-w- c:\windows\system32\winsrv.dll
2011-02-12 01:09 . 2011-01-26 06:53 982912 โ-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-02-12 01:09 . 2011-01-26 06:53 265088 โ-a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-02-12 01:09 . 2011-01-26 06:31 144384 โ-a-w- c:\windows\system32\cdd.dll
2011-02-12 01:09 . 2010-12-18 06:11 714752 โ-a-w- c:\windows\system32\kerberos.dll
2011-02-12 01:09 . 2010-12-18 05:29 541184 โ-a-w- c:\windows\SysWow64\kerberos.dll
2011-02-12 01:09 . 2011-01-05 04:00 3127808 โ-a-w- c:\windows\system32\win32k.sys
2011-02-12 01:08 . 2010-10-27 05:18 5510528 โ-a-w- c:\windows\system32\ntoskrnl.exe
2011-02-12 01:08 . 2010-10-27 05:16 1739176 โ-a-w- c:\windows\system32\ntdll.dll
2011-02-12 01:08 . 2010-10-27 04:43 3901824 โ-a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-02-12 01:08 . 2010-10-27 04:43 3957120 โ-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-02-12 01:08 . 2010-10-27 04:40 1293120 โ-a-w- c:\windows\SysWow64\ntdll.dll
2011-02-12 01:08 . 2011-01-07 08:06 46080 โ-a-w- c:\windows\system32\atmlib.dll
2011-02-12 01:08 . 2011-01-07 07:27 34304 โ-a-w- c:\windows\SysWow64\atmlib.dll
2011-02-12 01:08 . 2011-01-07 05:49 366080 โ-a-w- c:\windows\system32\atmfd.dll
2011-02-12 01:08 . 2011-01-07 05:33 294400 โ-a-w- c:\windows\SysWow64\atmfd.dll
2011-02-10 10:28 . 2011-02-10 10:28 โโโ dโโw- c:\programdata\GameHouse
2011-02-10 10:26 . 2011-02-10 10:26 โโโ dโโw- c:\programdata\Trymedia
2011-02-10 10:26 . 2011-02-10 10:26 โโโ dโโw- C:\GameHouse Games
2011-02-10 10:26 . 2011-02-10 10:26 โโโ dโโw- c:\programdata\Zylom
2011-02-10 10:24 . 2011-02-10 10:24 โโโ dโโw- c:\program files (x86)\RealArcade
2011-02-01 08:59 . 2011-02-22 06:59 โโโ dโโw- c:\users\Bryan\AppData\Roaming\Absolute Poker
2011-02-01 08:58 . 2011-02-01 08:59 โโโ dโโw- C:\Poker Application
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-24 02:34 . 2010-06-18 04:39 62976 โ-a-w- c:\windows\SysWow64\PxSecure.dll
2011-02-24 02:34 . 2010-06-18 04:39 36384 โ-a-w- c:\windows\system32\drivers\pxscan.sys
2011-02-24 02:34 . 2010-06-18 04:39 65736 โ-a-w- c:\windows\system32\drivers\pxrts.sys
2011-02-24 02:34 . 2010-06-18 04:39 24024 โ-a-w- c:\windows\system32\drivers\pxkbf.sys
2011-02-23 00:51 . 2010-05-02 22:10 472808 โ-a-w- c:\windows\SysWow64\deployJava1.dll
2011-02-23 00:47 . 2010-07-26 21:02 521448 โ-a-w- c:\windows\system32\deployJava1.dll
2011-02-11 07:30 . 2010-09-12 02:02 7947600 โ-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-01-21 22:52 . 2011-01-21 22:52 249936 โ-a-w- c:\windows\SysWow64\prgiso.dll
2011-01-21 22:52 . 2011-01-21 22:52 53840 โ-a-w- c:\windows\system32\drivers\uimx64.sys
2011-01-21 22:52 . 2011-01-21 22:52 528464 โ-a-w- c:\windows\system32\drivers\Uim_IMx64.sys
2011-01-21 22:52 . 2011-01-21 22:52 404048 โ-a-w- c:\windows\system32\drivers\UimFIO.sys
2011-01-03 14:19 . 2011-01-03 14:20 601424 โโw- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EFE444C6-3F7A-4D27-8AB5-D53B758E61FE}\gapaengine.dll
2010-12-25 21:18 . 2010-12-25 21:18 61072 โ-a-w- c:\windows\system32\drivers\rvsystem.sys
2010-12-21 02:09 . 2010-05-09 20:26 38224 โ-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2010-12-21 02:08 . 2010-05-09 20:26 24152 โ-a-w- c:\windows\system32\drivers\mbam.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fe337d7b-1447-4780-9a52-48bdac438235}"= "c:\program files (x86)\Maps_Bar\tbMaps.dll" [2010-11-29 3908192]
[HKEY_CLASSES_ROOT\clsid\{fe337d7b-1447-4780-9a52-48bdac438235}]
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{fe337d7b-1447-4780-9a52-48bdac438235}]
2010-11-29 23:26 3908192 โ-a-w- c:\program files (x86)\Maps_Bar\tbMaps.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{fe337d7b-1447-4780-9a52-48bdac438235}"= "c:\program files (x86)\Maps_Bar\tbMaps.dll" [2010-11-29 3908192]
[HKEY_CLASSES_ROOT\clsid\{fe337d7b-1447-4780-9a52-48bdac438235}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2010-05-07 0]
"OpenDNS Updater"="c:\program files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
"HostsServer"="c:\program files (x86)\HostsMan\hostssrv.exe" [2010-02-06 1930240]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-15 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" [2010-05-28 30192]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2010-12-21 291896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~2\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 CSIScanner;CSIScanner;c:\users\Bryan\prevx.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 136176]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2010-05-28 30192]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\7114.tmp [2010-05-26 6144]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 40832]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 72064]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
R3 nosGetPlusHelper;getPlusยฎ Helper 3004;c:\windows\System32\svchost.exe [2009-07-14 27136]
R3 PCGenFam;PCGenFam;c:\windows\system32\DRIVERS\PCGenFAM.sys [2010-11-02 198088]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-04-09 19936]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-04-09 13280]
R3 SaiKF622;SaiKF622;c:\windows\system32\DRIVERS\SaiKF622.sys [2009-06-02 140800]
R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-17 30336]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-03 1255736]
R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-01-21 37456]
S0 pxscan;pxscan;c:\windows\System32\drivers\pxscan.sys [2011-02-24 36384]
S0 RVSystem;RVSystem;c:\windows\system32\Drivers\RVSystem.sys [2010-12-25 61072]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
S1 OADevice;OADriver;c:\windows\SysWow64\Drivers\OADriver.sys [2010-10-27 54864]
S1 oahlpXX;Online Armor helper driver;c:\windows\syswow64\drivers\oahlp64.sys [2010-11-22 54896]
S1 OAmon;OAmon;c:\windows\SysWOW64\Drivers\OAmon.sys [2010-11-22 37872]
S1 rvsmon;rvsmon;c:\windows\system32\DRIVERS\rvsmon.sys [2010-10-18 165664]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208]
S2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2011-02-24 65736]
S2 RVSMONBL;Returnil System Safe Core Service;c:\program files (x86)\Returnil\RVS3\rvsmon.exe [2010-10-23 1714696]
S2 rvsmonf;rvsmonf;c:\windows\system32\DRIVERS\rvsmonf.sys [2010-10-18 1436136]
S2 rvsmonn;rvsmonn;c:\windows\system32\DRIVERS\rvsmonn2.sys [2010-10-18 21920]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2010-12-21 987704]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2010-12-21 399416]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2009-06-26 83488]
S3 OAnet;OnlineArmor Service;c:\windows\system32\DRIVERS\oanet.sys [2010-11-22 32728]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]
S3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2011-02-24 24024]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
โโโ x86-64 โโโโ
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288]
"PLD_FrameworkRun"="c:\windows\system32\oem\_NowIntoDT.vbs" [2009-10-11 490]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
โโ- Supplementary Scan โโ-
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewikiโฆ - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
LSP: %SYSTEMROOT%\system32\nvLsp.dll
Trusted Zone: absolutebanking.com
Trusted Zone: absolutepoker.com\www
Trusted Zone: google.com\mail
Trusted Zone: google.com\www
TCP: {473F86ED-FB55-42E5-8A1F-9FC700C929D6} = 208.67.222.222,208.67.220.220
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath - c:\users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\qci6f7wd.default\
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: CoolPreviews : {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} - %profile%\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
SafeBoot-SolutoService
ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_heroes.exe
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\7114.tmp"
.
โโโโโโโ LOCKED REGISTRY KEYS โโโโโโโ
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
โโโโโโโโ Other Running Processes โโโโโโโโ
.
c:\program files (x86)\Online Armor\OAcat.exe
c:\program files (x86)\Online Armor\oasrv.exe
c:\program files (x86)\Online Armor\a2\AVGate.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Online Armor\oaui.exe
c:\program files (x86)\Online Armor\OAhlp.exe
.
**************************************************************************
.
Completion time: 2011-03-01 18:56:02 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-02 02:56
Pre-Run: 645,347,987,456 bytes free
Post-Run: 644,964,769,792 bytes free
- - End Of File - - 3CEE775B12E0E7B049BC9DA86EA357CA
The first issue you have is having 3 anti-virus programs active:
AV: Microsoft Security Essentials *Disabled/Updated*
AV: Online Armor ++ *Disabled/Updated*
AV: Returnil System Safe 2011 *Disabled/Updated*
Never install more than one Antivirus and Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously!
The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time.
Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown.
Please do not delete anything unless instructed to.
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove 2 of the 3:
Reboot:
After the above:
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click
Start >
Run type
Notepad click OK.
This will open an empty
notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the
left mouse button , while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text,
right click the mouse for options, and select 'copy'. Now over the empty Notepad box,
right click your mouse again, and select 'paste' and you will have copied and pasted the text.
KillAll::
File::
c:\windows\system32\7114.tmp
c:\windows\system32\8178.tmp
Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fe337d7b-1447-4780-9a52-48bdac438235}"=-
[-HKEY_CLASSES_ROOT\clsid\{fe337d7b-1447-4780-9a52-48bdac438235}]
[-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{fe337d7b-1447-4780-9a52-48bdac438235}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{fe337d7b-1447-4780-9a52-48bdac438235}"=-
[-HKEY_CLASSES_ROOT\clsid\{fe337d7b-1447-4780-9a52-48bdac438235}]
Save this file to your desktop,
Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save Asโฆ Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save โฆ
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log using Copy / Paste
Also please describe how your computer behaves at the moment.
Even though I got the VBScript enabled just as you showed me when the combofix ran it still came up with the same error about vbscript being unavailable. Everything else went fine and heres the log you wanted to see.
ComboFix 11-02-28.07 - Bryan 03/02/2011 9:26.3.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3839.2599 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Bryan\Desktop\CFScript.txt
AV: Online Armor ++ *Enabled/Updated* {607A6E45-BE50-AFD5-4F70-7EAAEC5B715D}
FW: Online Armor Firewall *Enabled* {5841EF60-F43F-AE8D-642F-D79F12883626}
SP: Online Armor ++ *Enabled/Updated* {DB1B8FA1-986A-A05B-75C0-45D897DC3BE0}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FILE ::
"c:\windows\system32\7114.tmp"
"c:\windows\system32\8178.tmp"
.
((((((((((((((((((((((((( Files Created from 2011-02-02 to 2011-03-02 )))))))))))))))))))))))))))))))
.
2011-03-02 17:31 . 2011-03-02 17:31 โโโ dโโw- c:\users\Zanthia\AppData\Local\temp
2011-03-02 17:31 . 2011-03-02 17:31 โโโ dโโw- c:\users\Zanthia.Family\AppData\Local\temp
2011-03-02 17:31 . 2011-03-02 17:31 โโโ dโโw- c:\users\Default\AppData\Local\temp
2011-03-02 17:31 . 2011-03-02 17:31 โโโ dโโw- c:\users\Daniel\AppData\Local\temp
2011-03-02 17:31 . 2011-03-02 17:31 โโโ dโโw- c:\users\Daniel.Family\AppData\Local\temp
2011-03-02 17:31 . 2011-03-02 17:31 โโโ dโโw- c:\users\Betty\AppData\Local\temp
2011-03-02 17:31 . 2011-03-02 17:31 โโโ dโโw- c:\users\Ashanthe\AppData\Local\temp
2011-03-02 17:31 . 2011-03-02 17:31 โโโ dโโw- c:\users\Administrator\AppData\Local\temp
2011-03-02 03:11 . 2010-09-14 06:45 367104 โ-a-w- c:\windows\system32\wcncsvc.dll
2011-03-02 03:11 . 2010-09-14 06:07 276992 โ-a-w- c:\windows\SysWow64\wcncsvc.dll
2011-03-02 03:10 . 2011-01-07 08:07 662528 โ-a-w- c:\windows\system32\XpsPrint.dll
2011-03-02 03:10 . 2011-01-07 08:07 475648 โ-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-02 03:10 . 2011-01-07 07:31 442880 โ-a-w- c:\windows\SysWow64\XpsPrint.dll
2011-03-02 03:10 . 2011-01-07 07:31 288256 โ-a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2011-03-02 02:56 . 2011-03-02 18:18 โโโ dโโw- c:\users\Bryan\AppData\Local\temp
2011-03-02 00:48 . 2011-03-02 00:48 92248 โ-a-w- c:\windows\system32\drivers\klmd.sys
2011-03-01 19:20 . 2011-03-01 19:20 โโโ dโโw- c:\users\Zanthia.Family\AppData\Local\Mozilla
2011-02-25 22:21 . 2011-02-25 22:21 โโโ dโโw- c:\programdata\launcher
2011-02-25 22:04 . 2011-01-21 22:52 37456 โ-a-w- c:\windows\system32\drivers\hotcore3.sys
2011-02-25 01:43 . 2011-02-25 01:45 โโโ dโโw- c:\program files (x86)\MasqueGames
2011-02-24 20:06 . 2011-01-17 06:12 320512 โ-a-w- c:\windows\system32\d3d10_1core.dll
2011-02-24 20:06 . 2011-01-17 06:12 197120 โ-a-w- c:\windows\system32\d3d10_1.dll
2011-02-24 20:06 . 2011-01-17 05:30 218624 โ-a-w- c:\windows\SysWow64\d3d10_1core.dll
2011-02-24 20:06 . 2011-01-17 05:30 161792 โ-a-w- c:\windows\SysWow64\d3d10_1.dll
2011-02-24 03:59 . 2011-02-24 03:59 388096 โ-a-r- c:\users\Bryan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-24 02:34 . 2011-02-24 02:34 โโโ dโโw- c:\program files\Prevx
2011-02-24 02:32 . 2011-02-24 02:37 โโโ dโโw- c:\programdata\PrevxCSI
2011-02-24 01:05 . 2010-05-26 18:39 6144 โโw- c:\windows\system32\7114.tmp
2011-02-24 01:04 . 2010-05-26 18:39 6144 โโw- c:\windows\system32\8178.tmp
2011-02-23 22:58 . 2011-02-23 22:58 โโโ dโโw- c:\users\Bryan\AppData\Roaming\SUPERAntiSpyware.com
2011-02-23 22:58 . 2011-02-23 22:58 โโโ dโโw- c:\programdata\!SASCORE
2011-02-23 00:51 . 2011-02-23 00:51 โโโ dโโw- c:\program files (x86)\Common Files\Java
2011-02-23 00:51 . 2011-02-23 00:51 472808 โ-a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-02-23 00:51 . 2011-02-23 00:51 โโโ dโโw- c:\program files (x86)\Java
2011-02-23 00:47 . 2011-02-23 00:47 โโโ dโโw- c:\program files\Java
2011-02-21 06:56 . 2011-02-21 06:56 โโโ dโโw- c:\users\Zanthia.Family\AppData\Local\JollyBear
2011-02-21 06:56 . 2011-02-21 06:56 โโโ dโโw- c:\programdata\JollyBear
2011-02-21 05:18 . 2011-02-21 05:35 โโโ dโโw- c:\users\Zanthia.Family\AppData\Roaming\Flood Light Games
2011-02-21 05:18 . 2011-02-21 05:35 โโโ dโโw- c:\programdata\Flood Light Games
2011-02-21 04:21 . 2011-02-21 04:22 โโโ dโโw- c:\users\Zanthia.Family\AppData\Roaming\Mystery of Mortlake Mansion
2011-02-17 21:14 . 2010-12-21 06:13 2003968 โ-a-w- c:\windows\system32\msxml6.dll
2011-02-12 20:52 . 2011-02-12 20:52 โโโ dโโw- c:\program files (x86)\Common Files\CA Shared
2011-02-12 01:09 . 2010-12-21 06:16 214016 โ-a-w- c:\windows\system32\winsrv.dll
2011-02-12 01:09 . 2011-01-26 06:53 982912 โ-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-02-12 01:09 . 2011-01-26 06:53 265088 โ-a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-02-12 01:09 . 2011-01-26 06:31 144384 โ-a-w- c:\windows\system32\cdd.dll
2011-02-12 01:09 . 2010-12-18 06:11 714752 โ-a-w- c:\windows\system32\kerberos.dll
2011-02-12 01:09 . 2010-12-18 05:29 541184 โ-a-w- c:\windows\SysWow64\kerberos.dll
2011-02-12 01:09 . 2011-01-05 04:00 3127808 โ-a-w- c:\windows\system32\win32k.sys
2011-02-12 01:08 . 2010-10-27 05:18 5510528 โ-a-w- c:\windows\system32\ntoskrnl.exe
2011-02-12 01:08 . 2010-10-27 05:16 1739176 โ-a-w- c:\windows\system32\ntdll.dll
2011-02-12 01:08 . 2010-10-27 04:43 3901824 โ-a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-02-12 01:08 . 2010-10-27 04:43 3957120 โ-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-02-12 01:08 . 2010-10-27 04:40 1293120 โ-a-w- c:\windows\SysWow64\ntdll.dll
2011-02-12 01:08 . 2011-01-07 08:06 46080 โ-a-w- c:\windows\system32\atmlib.dll
2011-02-12 01:08 . 2011-01-07 07:27 34304 โ-a-w- c:\windows\SysWow64\atmlib.dll
2011-02-12 01:08 . 2011-01-07 05:49 366080 โ-a-w- c:\windows\system32\atmfd.dll
2011-02-12 01:08 . 2011-01-07 05:33 294400 โ-a-w- c:\windows\SysWow64\atmfd.dll
2011-02-10 10:28 . 2011-02-10 10:28 โโโ dโโw- c:\programdata\GameHouse
2011-02-10 10:26 . 2011-02-10 10:26 โโโ dโโw- c:\programdata\Trymedia
2011-02-10 10:26 . 2011-02-10 10:26 โโโ dโโw- C:\GameHouse Games
2011-02-10 10:26 . 2011-02-10 10:26 โโโ dโโw- c:\programdata\Zylom
2011-02-10 10:24 . 2011-02-10 10:24 โโโ dโโw- c:\program files (x86)\RealArcade
2011-02-01 08:59 . 2011-02-22 06:59 โโโ dโโw- c:\users\Bryan\AppData\Roaming\Absolute Poker
2011-02-01 08:58 . 2011-02-01 08:59 โโโ dโโw- C:\Poker Application
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-24 02:34 . 2010-06-18 04:39 62976 โ-a-w- c:\windows\SysWow64\PxSecure.dll
2011-02-24 02:34 . 2010-06-18 04:39 36384 โ-a-w- c:\windows\system32\drivers\pxscan.sys
2011-02-24 02:34 . 2010-06-18 04:39 65736 โ-a-w- c:\windows\system32\drivers\pxrts.sys
2011-02-24 02:34 . 2010-06-18 04:39 24024 โ-a-w- c:\windows\system32\drivers\pxkbf.sys
2011-02-23 00:51 . 2010-05-02 22:10 472808 โ-a-w- c:\windows\SysWow64\deployJava1.dll
2011-02-23 00:47 . 2010-07-26 21:02 521448 โ-a-w- c:\windows\system32\deployJava1.dll
2011-01-21 22:52 . 2011-01-21 22:52 249936 โ-a-w- c:\windows\SysWow64\prgiso.dll
2011-01-21 22:52 . 2011-01-21 22:52 53840 โ-a-w- c:\windows\system32\drivers\uimx64.sys
2011-01-21 22:52 . 2011-01-21 22:52 528464 โ-a-w- c:\windows\system32\drivers\Uim_IMx64.sys
2011-01-21 22:52 . 2011-01-21 22:52 404048 โ-a-w- c:\windows\system32\drivers\UimFIO.sys
2010-12-21 02:09 . 2010-05-09 20:26 38224 โ-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2010-12-21 02:08 . 2010-05-09 20:26 24152 โ-a-w- c:\windows\system32\drivers\mbam.sys
.
((((((((((((((((((((((((((((( SnapShot@2011-03-02_02.38.20 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-03-02 02:36 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-03-02 17:33 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2011-03-02 02:36 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-03-02 17:33 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-03-02 02:36 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-03-02 17:33 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-28 05:40 . 2011-03-02 17:23 81112 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-03-02 02:38 56616 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-03-02 17:23 56616 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2010-05-02 05:52 . 2011-03-02 02:38 21620 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3488347447-2488368954-518346416-1000_UserData.bin
+ 2010-05-02 05:52 . 2011-03-02 17:23 21620 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3488347447-2488368954-518346416-1000_UserData.bin
- 2006-10-11 03:00 . 2011-03-02 02:38 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-10-11 03:00 . 2011-03-02 17:35 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-11-10 23:56 . 2011-03-02 02:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-11-10 23:56 . 2011-03-02 17:35 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2011-03-02 02:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2011-03-02 17:35 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:46 . 2011-03-02 17:20 71344 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2010-05-02 05:34 . 2011-03-02 02:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-05-02 05:34 . 2011-03-02 17:33 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-03-02 17:32 . 2011-03-02 17:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-03-02 02:36 . 2011-03-02 02:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-03-02 02:36 . 2011-03-02 02:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-03-02 17:32 . 2011-03-02 17:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-05-02 18:13 . 2011-03-02 18:17 365986 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2009-07-14 02:36 . 2011-03-02 17:11 623940 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-03-02 17:11 106316 c:\windows\system32\perfc009.dat
+ 2009-07-14 05:01 . 2011-03-02 17:31 305844 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2011-03-02 02:35 305844 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 04:45 . 2011-02-25 22:53 3801083 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2011-03-02 17:01 3801083 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2010-05-03 10:38 . 2011-03-02 02:35 2776444 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-8192.dat
+ 2010-05-03 10:38 . 2011-03-02 17:31 2776444 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-8192.dat
- 2010-05-03 10:38 . 2011-03-02 01:07 3267396 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-12288.dat
+ 2010-05-03 10:38 . 2011-03-02 17:12 3267396 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-12288.dat
- 2009-07-14 02:34 . 2011-03-02 01:53 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:34 . 2011-03-02 17:46 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2010-09-28 22:59 . 2011-03-02 17:20 17280574 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-4096.dat
- 2010-09-28 22:59 . 2011-03-02 02:35 17280574 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488347447-2488368954-518346416-1000-4096.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2010-05-07 0]
"OpenDNS Updater"="c:\program files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
"HostsServer"="c:\program files (x86)\HostsMan\hostssrv.exe" [2010-02-06 1930240]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-15 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" [2010-05-28 30192]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2010-12-21 291896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~2\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 CSIScanner;CSIScanner;c:\users\Bryan\prevx.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 136176]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [2010-05-28 30192]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\7114.tmp [2010-05-26 6144]
R3 nosGetPlusHelper;getPlusยฎ Helper 3004;c:\windows\System32\svchost.exe [2009-07-14 27136]
R3 PCGenFam;PCGenFam;c:\windows\system32\DRIVERS\PCGenFAM.sys [2010-11-02 198088]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-04-09 19936]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-04-09 13280]
R3 SaiKF622;SaiKF622;c:\windows\system32\DRIVERS\SaiKF622.sys [2009-06-02 140800]
R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-17 30336]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-03 1255736]
R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-01-21 37456]
S0 pxscan;pxscan;c:\windows\System32\drivers\pxscan.sys [2011-02-24 36384]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
S1 OADevice;OADriver;c:\windows\SysWow64\Drivers\OADriver.sys [2010-10-27 54864]
S1 oahlpXX;Online Armor helper driver;c:\windows\syswow64\drivers\oahlp64.sys [2010-11-22 54896]
S1 OAmon;OAmon;c:\windows\SysWOW64\Drivers\OAmon.sys [2010-11-22 37872]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208]
S2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2011-02-24 65736]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2010-12-21 987704]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2010-12-21 399416]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2009-06-26 83488]
S3 OAnet;OnlineArmor Service;c:\windows\system32\DRIVERS\oanet.sys [2010-11-22 32728]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]
S3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2011-02-24 24024]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
โโโ x86-64 โโโโ
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288]
"PLD_FrameworkRun"="c:\windows\system32\oem\_NowIntoDT.vbs" [2009-10-11 490]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952]
.
โโ- Supplementary Scan โโ-
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewikiโฆ - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
LSP: %SYSTEMROOT%\system32\nvLsp.dll
Trusted Zone: absolutebanking.com
Trusted Zone: absolutepoker.com\www
Trusted Zone: google.com\mail
Trusted Zone: google.com\www
TCP: {473F86ED-FB55-42E5-8A1F-9FC700C929D6} = 208.67.222.222,208.67.220.220
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath - c:\users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\qci6f7wd.default\
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: CoolPreviews : {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} - %profile%\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\7114.tmp"
.
โโโโโโโ LOCKED REGISTRY KEYS โโโโโโโ
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
โโโโโโโโ Other Running Processes โโโโโโโโ
.
c:\program files (x86)\Online Armor\OAcat.exe
c:\program files (x86)\Online Armor\oasrv.exe
c:\program files (x86)\Online Armor\a2\AVGate.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Online Armor\oaui.exe
c:\program files (x86)\Online Armor\OAhlp.exe
.
**************************************************************************
.
Completion time: 2011-03-02 10:25:48 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-02 18:25
ComboFix2.txt 2011-03-02 02:56
Pre-Run: 644,640,186,368 bytes free
Post-Run: 644,588,093,440 bytes free
- - End Of File - - CFC03CA21D640282B687D501F22E242F
Hey, I just got back from running some errands. I can't give an assessment just yet but I can now access I.E. and it looks like things are moving quicker than before. If any problems or glitches come up I'll send a request in. I just want to thank you very much for all your help.
I'll keep this open for 3 more days
I just checked my mail again and it is still showing that my e-mail is still sending out messages. This last one has the time as 3:20pm pst. Which is after we completed running the combofix tool. What else do you need from me to help with this?