yes that all happened and it said it had completed but then the red icon disappeared as well a little box comes up with a green line that moves along
Is the green line still moving along?
the green line stopped moving and then the icon disappeared but now something else has happened. I tried to save combotxt to my desp top and I have a message which says illegal operation attempted on a regsitry key that has been marked for deletion so I can't get on to the internet now on my computer I am on my laptop sendingthis to you where as before I was working ont he computer with the virus.
Have you tried to reboot your computer?
ok thanks now I am back on my computer
I will try to explain what happens
I press Windo and R and put in the ComboFix "C:\Users\margaret\Documents\cfscript.txt"
Then what happens is the black screen comes up and when it is finished I get the green line movingalong at the same time as the red icon comes up on my taskbar. As soon as the green line stops - it disappears and so does the icon so i have no way of knowing where it has been saved to other than on the hard drive.
Try putting:
C:\combofix.txt
In the runbox and click OK.
Hopefully that will bring up a log file for you to post.
Here goes this is what I got
ComboFix 11-04-01.01 - margaret 02/04/2011 10:31:09.4.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.2047.1342 [GMT 1:00]
Running from: c:\users\[removed]\Documents\ComboFix.exe
Command switches used :: c:\users\margaret\Documents\cfscript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
.
.
2011-04-02 09:36 . 2011-04-02 09:36 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-04-01 20:26 . 2011-04-02 09:36 ——– d—–w- c:\users\margaret\AppData\Local\temp
2011-03-28 20:48 . 2011-03-28 20:48 ——– d—–w- c:\programdata\PC Tools
2011-03-15 22:56 . 2011-03-15 22:56 ——– d—–w- c:\users\margaret\AppData\Local\Apps
2011-03-08 22:54 . 2011-02-19 05:32 1074176 —-a-w- c:\windows\system32\DWrite.dll
2011-03-08 22:54 . 2011-02-19 05:33 802304 —-a-w- c:\windows\system32\FntCache.dll
2011-03-08 22:54 . 2011-02-19 05:32 739840 —-a-w- c:\windows\system32\d2d1.dll
2011-03-08 22:54 . 2010-12-23 05:28 850432 —-a-w- c:\windows\system32\sbe.dll
2011-03-08 22:54 . 2010-12-23 05:28 642048 —-a-w- c:\windows\system32\CPFilters.dll
2011-03-08 22:54 . 2010-12-23 05:28 534528 —-a-w- c:\windows\system32\EncDec.dll
2011-03-08 22:54 . 2010-12-23 05:24 199680 —-a-w- c:\windows\system32\mpg2splt.ax
2011-03-08 22:54 . 2010-12-18 05:30 2690560 —-a-w- c:\windows\system32\mstscax.dll
2011-03-08 22:54 . 2010-12-18 05:26 1034240 —-a-w- c:\windows\system32\mstsc.exe
2011-03-03 23:36 . 2011-03-03 23:36 ——– d—–w- c:\programdata\McAfee
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 05:45 . 2011-02-09 20:12 219008 —-a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-02-02 21:40 . 2010-10-17 21:49 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-01-07 07:31 . 2011-02-25 19:09 442880 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-07 07:31 . 2011-02-25 19:09 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-07 07:27 . 2011-02-09 20:12 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-01-07 05:33 . 2011-02-09 20:12 294400 —-a-w- c:\windows\system32\atmfd.dll
2011-01-05 05:37 . 2011-02-09 20:12 428032 —-a-w- c:\windows\system32\vbscript.dll
2011-01-05 03:37 . 2011-02-09 20:12 2329088 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}"= "c:\program files\Radio_TV_2.1\tbRadi.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}]
2010-12-09 12:51 3911776 —-a-w- c:\program files\Radio_TV_2.1\tbRadi.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85F5CF95-EC8F-49fc-BB3F-38C79455CBA2}]
2010-11-09 19:42 826880 —-a-w- c:\program files\alotappbar\bin\BHO\alotappbarBHO.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b9b97401-98e1-4942-930d-c36652dab7f2}]
2011-01-17 14:54 175912 —-a-w- c:\program files\TranslatorBar_5\prxtbTra0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b9b97401-98e1-4942-930d-c36652dab7f2}"= "c:\program files\TranslatorBar_5\prxtbTra0.dll" [2011-01-17 175912]
"{A531D99C-5A22-449b-83DA-872725C6D0ED}"= "c:\program files\alotappbar\bin\alotappbar.dll" [2010-11-09 826880]
"{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}"= "c:\program files\Radio_TV_2.1\tbRadi.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{b9b97401-98e1-4942-930d-c36652dab7f2}]
.
[HKEY_CLASSES_ROOT\clsid\{a531d99c-5a22-449b-83da-872725c6d0ed}]
.
[HKEY_CLASSES_ROOT\clsid\{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B9B97401-98E1-4942-930D-C36652DAB7F2}"= "c:\program files\TranslatorBar_5\prxtbTra0.dll" [2011-01-17 175912]
"{4ADC4B13-B4C2-4946-835E-C5F61FA9D8BF}"= "c:\program files\Radio_TV_2.1\tbRadi.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{b9b97401-98e1-4942-930d-c36652dab7f2}]
.
[HKEY_CLASSES_ROOT\clsid\{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-13 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"DT HPW"="c:\program files\Portrait Displays\HP My Display\DTHtml.exe" [2007-06-29 278528]
"HostManager"="c:\program files\Common Files\AOL\1215702661\ee\AOLSoftware.exe" [2006-11-14 50736]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-13 202256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-7-5 113664]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 135664]
R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-14 1343400]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [2009-07-13 545792]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 13:52]
.
2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 13:52]
.
2011-03-28 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]
.
2010-12-30 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2830582
mStart Page = hxxp://www.myaolbroadband.co.uk
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
Trusted Zone: edexcel.com\osca2
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game07.zylom.com/activex/zylomgamesplayer.cab
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-04-02 10:38:23
ComboFix-quarantined-files.txt 2011-04-02 09:38
ComboFix2.txt 2011-04-01 20:57
ComboFix3.txt 2011-04-01 20:26
ComboFix4.txt 2011-03-30 23:38
.
Pre-Run: 250,411,765,760 bytes free
Post-Run: 250,359,697,408 bytes free
.
- - End Of File - - B4284102C40E01669339393C826F3D45
Yes. That is what I needed.
Now we are going to do that again… but this time, when it runs…. wait for the green line to finish, and then continue to wait until the log pops up. If you've waited one hour and it still hasn't popped up, then go ahead and reboot your computer and get the file manually. I'll give better directions in order.
COMBOFIX-Script
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
If after you've waited an hour, the log doesn't appear…. then reboot your computer. Hold the windows key again and press R for the runbox. Enter
C:\combofix.txt and click OK. Post the log here.
Sorry I don't quite understand do you want me to put in COMBOFIX-Script
this time. or do exactly as before. If so what do I do with all the information from COMBOFIX-Script onwards
COMBOFIX-Script is just a heading. You don't do anything with it.
Then I need you to copy the information in the code box and save it as a file called CFScript.txt (just like you did before).
Then I want you to put ComboFix "C:\Users\margaret\Documents\cfscript.txt" in a runbox and click OK (just like you did before).
Then I want you to let ComboFix run. Don't do anything… just let it run. It will go through the stages, you'll see the little green line… just wait and eventually a log should bop up. If a log does not pop up within an hour… then restart your computer and put C:\combofix.txt in the runbox and click OK.
A text file will open. Just post that information here like you did before.
copy of what came up
ComboFix 11-04-01.01 - margaret 02/04/2011 19:41:59.5.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.2047.1348 [GMT 1:00]
Running from: c:\users\[removed]\Documents\ComboFix.exe
Command switches used :: c:\users\margaret\Documents\cfscript.txt
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\alotappbar
c:\program files\alotappbar\alotUninst.exe
c:\program files\alotappbar\bin\alotappbar.dll
c:\program files\alotappbar\bin\ALOTSettings.exe
c:\program files\alotappbar\bin\BHO\alotappbarBHO.dll
c:\programdata\McAfee
c:\programdata\McAfee\MCLOGS\Common\MsiExec\MsiExec000.log
.
.
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
.
.
2011-04-02 18:46 . 2011-04-02 18:47 ——– d—–w- c:\users\margaret\AppData\Local\temp
2011-04-02 18:46 . 2011-04-02 18:46 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-03-28 20:48 . 2011-03-28 20:48 ——– d—–w- c:\programdata\PC Tools
2011-03-15 22:56 . 2011-03-15 22:56 ——– d—–w- c:\users\margaret\AppData\Local\Apps
2011-03-08 22:54 . 2011-02-19 05:32 1074176 —-a-w- c:\windows\system32\DWrite.dll
2011-03-08 22:54 . 2011-02-19 05:33 802304 —-a-w- c:\windows\system32\FntCache.dll
2011-03-08 22:54 . 2011-02-19 05:32 739840 —-a-w- c:\windows\system32\d2d1.dll
2011-03-08 22:54 . 2010-12-23 05:28 850432 —-a-w- c:\windows\system32\sbe.dll
2011-03-08 22:54 . 2010-12-23 05:28 642048 —-a-w- c:\windows\system32\CPFilters.dll
2011-03-08 22:54 . 2010-12-23 05:28 534528 —-a-w- c:\windows\system32\EncDec.dll
2011-03-08 22:54 . 2010-12-23 05:24 199680 —-a-w- c:\windows\system32\mpg2splt.ax
2011-03-08 22:54 . 2010-12-18 05:30 2690560 —-a-w- c:\windows\system32\mstscax.dll
2011-03-08 22:54 . 2010-12-18 05:26 1034240 —-a-w- c:\windows\system32\mstsc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 05:45 . 2011-02-09 20:12 219008 —-a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-02-02 21:40 . 2010-10-17 21:49 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-01-07 07:31 . 2011-02-25 19:09 442880 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-07 07:31 . 2011-02-25 19:09 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-07 07:27 . 2011-02-09 20:12 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-01-07 05:33 . 2011-02-09 20:12 294400 —-a-w- c:\windows\system32\atmfd.dll
2011-01-05 05:37 . 2011-02-09 20:12 428032 —-a-w- c:\windows\system32\vbscript.dll
2011-01-05 03:37 . 2011-02-09 20:12 2329088 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}"= "c:\program files\Radio_TV_2.1\tbRadi.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}]
2010-12-09 12:51 3911776 —-a-w- c:\program files\Radio_TV_2.1\tbRadi.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b9b97401-98e1-4942-930d-c36652dab7f2}]
2011-01-17 14:54 175912 —-a-w- c:\program files\TranslatorBar_5\prxtbTra0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b9b97401-98e1-4942-930d-c36652dab7f2}"= "c:\program files\TranslatorBar_5\prxtbTra0.dll" [2011-01-17 175912]
"{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}"= "c:\program files\Radio_TV_2.1\tbRadi.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{b9b97401-98e1-4942-930d-c36652dab7f2}]
.
[HKEY_CLASSES_ROOT\clsid\{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B9B97401-98E1-4942-930D-C36652DAB7F2}"= "c:\program files\TranslatorBar_5\prxtbTra0.dll" [2011-01-17 175912]
"{4ADC4B13-B4C2-4946-835E-C5F61FA9D8BF}"= "c:\program files\Radio_TV_2.1\tbRadi.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{b9b97401-98e1-4942-930d-c36652dab7f2}]
.
[HKEY_CLASSES_ROOT\clsid\{4adc4b13-b4c2-4946-835e-c5f61fa9d8bf}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-13 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"DT HPW"="c:\program files\Portrait Displays\HP My Display\DTHtml.exe" [2007-06-29 278528]
"HostManager"="c:\program files\Common Files\AOL\1215702661\ee\AOLSoftware.exe" [2006-11-14 50736]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-13 202256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-7-5 113664]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 135664]
R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-14 1343400]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [2009-07-13 545792]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 13:52]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 13:52]
.
2011-04-02 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]
.
2010-12-30 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2830582
mStart Page = hxxp://www.myaolbroadband.co.uk
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
Trusted Zone: edexcel.com\osca2
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://www.gamehouse.com/games/gamehouse/ghplayer.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game07.zylom.com/activex/zylomgamesplayer.cab
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-alotAppbar - c:\program files\alotappbar\alotUninst.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-04-02 19:48:36
ComboFix-quarantined-files.txt 2011-04-02 18:48
ComboFix2.txt 2011-04-02 09:38
ComboFix3.txt 2011-04-01 20:57
ComboFix4.txt 2011-04-01 20:26
ComboFix5.txt 2011-04-02 18:41
.
Pre-Run: 250,401,779,712 bytes free
Post-Run: 250,345,902,080 bytes free
.
- - End Of File - - 4463E4AB6F2E825C55D4D9BF7E5C31BF
maggss,
Well done.
That is looking good.
Let's get an online scan. Be prepared as it take a long time to run. Do this when you don't need to use your computer for awhile.
ESET Online Scanner:
Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read
here .
Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select
Run as Administrator from the context menu.
Please go here then click on: [external image: Posted Image]
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image] When prompted allow the Add-On/Active X to install. Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked. Now click on Advanced Settings and select the following:
Scan for potentially unwanted applications Scan for potentially unsafe applications Enable Anti-Stealth Technology Now click on: [external image: Posted Image] The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection. When completed the Online Scan will begin automatically. Do no t touch either the Mouse or keyboard during the scan otherwise it may stall.When completed select Uninstall application on close if you so wish, make sure you copy the logfile first! Now click on: [external image: Posted Image] Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt . Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
When you post back… please also let me know how things seem to be running.
it does not say uninstall two files have come up and I can restore or go back
only
At the end is gives you the choice to uninstall ESET. Not to uninstall the files.
Please post the information.
Sorry all I have is a box which says
Scan results
step 4 of 4 then there are two file names
and at the bottom left it says restore and at the right it says back
then there is the eset logl