This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Antimalware Doctor and other infections

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Once again I am in need of some help. While browsing some video game websites at the Library on my Laptop I contracted a virus on m laptop. Antimalware Doctor is one. I have installed Malwarebytes and deleted 29 infections.

The fake antimalware program still runs, and I found the main .exe it uses. and its location.

C:\Users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA

The files: enemies-name.txt, local.ini, lsrslt.ini, ris700acpt.exe. Once I end the ris700acpt.exe task, virus does not seem to run, but this is not make it fixed.

Also While rooting around in my AppData, I found a few other suspisous files:
in C:\Users\James Mann\AppData\Local
imejihafew.dll
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini


Here is what Malwarebytes found and removed:
__________________________________________________________________

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6878

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

6/17/2011 11:28:15 AM
mbam-log-2011-06-17 (11-28-15).txt

Scan type: Quick scan
Objects scanned: 188014
Time elapsed: 5 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 19

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\Users\james mann\AppData\Local\ending.dll (Trojan.Hiloti.Gen) -> Delete on reboot.

Registry Keys Infected:
HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Jtewuvuw (Trojan.Hiloti.Gen) -> Value: Jtewuvuw -> Delete on reboot.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\Users\james mann\AppData\Roaming\microsoft\Windows\start menu\Programs\antimalware doctor (Rogue.AntiMalwareDoctor) -> Quarantined and deleted successfully.

Files Infected:
c:\Users\james mann\AppData\Local\ending.dll (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Local\Temp\3DF0.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Local\Temp\CF60.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Local\Temp\emwasrocxn.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Local\Temp\FE4F.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Local\Temp\setup1011892352.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Local\Temp\setup2068463744.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Local\Temp\setup3838272960.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Local\Temp\setup3847049856.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Local\Temp\setup965211712.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Local\Temp\wmxcensroa.exe (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
c:\Users\james mann\local settings\ending.dll (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
c:\Users\james mann\local settings\application data\ending.dll (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
c:\Users\james mann\Desktop\antimalware doctor.lnk (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Roaming\microsoft\internet explorer\quick launch\antimalware doctor.lnk (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Roaming\microsoft\Windows\start menu\antimalware doctor.lnk (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Roaming\microsoft\Windows\start menu\Programs\Startup\antimalware doctor.lnk (Rogue.AntiMalwareDoctor) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Roaming\microsoft\Windows\start menu\Programs\antimalware doctor\antimalware doctor.lnk (Rogue.AntiMalwareDoctor) -> Quarantined and deleted successfully.
c:\Users\james mann\AppData\Roaming\microsoft\Windows\start menu\Programs\antimalware doctor\uninstall.lnk (Rogue.AntiMalwareDoctor) -> Quarantined and deleted successfully.
__________________________________________

Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:43:37 PM, on 6/17/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16800)
Boot mode: Normal

Running processes:
C:\PROGRA~2\McAfee.com\Agent\mcagent.exe
C:\Program Files (x86)\Electronic Arts\EADM\Core.exe
C:\Program Files (x86)\Free Download Manager\fdm.exe
C:\Program Files (x86)\NetZero\exec.exe
C:\Program Files (x86)\NetZero\exec.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\NetZero\qsacc\x1exec.exe
C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe
C:\Program Files (x86)\mcafee\VirusScan\mcvsshld.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Windows Live\Toolbar\wltuser.exe
C:\Program Files (x86)\Ant.com\IE add-on\AntMaintainer.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10e.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\James Mann\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files (x86)\NetZero\SearchEnh1.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - C:\Program Files (x86)\McAfee\MSK\MskAPBho.dll
O2 - BHO: Ant.com browser helper (video detector) - {346FDE31-DFF9-418A-90C8-BA31DC9FF2EF} - C:\Program Files (x86)\Ant.com\IE add-on\Download.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files (x86)\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files (x86)\NetZero\Toolbar.dll
O3 - Toolbar: Ant.com Download Toolbar - {2E924F4F-67F0-4BD8-9560-49F468E843D2} - C:\Program Files (x86)\Ant.com\IE add-on\AntToolbar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files (x86)\Software Informer\softinfo.exe" -autorun
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files (x86)\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Google Update] "C:\Users\James Mann\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ris700acpt.exe] C:\Users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA\ris700acpt.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Display All Images with Full Quality - "res://C:\Program Files (x86)\NetZero\qsacc\appres.dll/228"
O8 - Extra context menu item: Display Image with Full Quality - "res://C:\Program Files (x86)\NetZero\qsacc\appres.dll/227"
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Download videos by Ant.com - {70AF6C9F-0818-4cf7-924A-BBDBB24211D3} - C:\Program Files (x86)\Ant.com\IE add-on\Download.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O16 - DPF: {C9D7D239-B502-48B3-BA25-9DF8C7264073} (CCAWebLogin Control) - https://ahfcas3.ahf2000.aultman.com/auth/CCALogin.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A14B778-E1F7-4A7D-9A95-176351294A1A}: NameServer = 64.136.44.74 64.136.52.74
O17 - HKLM\System\CS1\Services\Tcpip\..\{0A14B778-E1F7-4A7D-9A95-176351294A1A}: NameServer = 64.136.44.74 64.136.52.74
O18 - Protocol: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Ant Toolbar updater service (AntUpdaterService) - Ant.com - C:\Program Files (x86)\Ant.com\IE add-on\AntUpdaterService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - D:\Dragon Age- Origins\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files (x86)\Common Files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - Unknown owner - C:\Program Files (x86)\McAfee\VIRUSS~1\mcods.exe (file missing)
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\PROGRA~2\COMMON~1\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: mental ray 3.8 Satellite for Autodesk 3ds Max 2011 32-bit 32-bit (mi-raysat_3dsmax2011_32) - Unknown owner - C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files (x86)\McAfee\MSK\MskSrver.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Realtek87B - Realtek - C:\Program Files (x86)\REALTEK\RTL8187 Wireless LAN Utility\RtlService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZoneServer System Service (ZSS) - Unknown owner - C:\SERVER WOK 53\Data\rtservice\xRemoteService.exe (file missing)

–
End of file - 17899 bytes

__________________________________
Hi Severance,
:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Thank you for taking the time to help :D Here is my dds logs _____________________________________ . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 17:56:01.12 on Mon 06/20/2011 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3957.2438 [GMT -4:00] . AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: McAfee VirusScan *Disabled/Outdated* {86355677-4064-3EA7-ABB3-1B136EB04637} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: McAfee VirusScan *Disabled/Outdated* {3D54B793-665E-3129-9103-206115370C8A} FW: McAfee Personal Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe C:\Windows\system32\agr64svc.exe C:\Program Files (x86)\Ant.com\IE add-on\AntUpdaterService.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\PROGRA~2\COMMON~1\McAfee\McProxy\McProxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe C:\Program Files (x86)\McAfee\MSK\MskSrver.exe C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Program Files (x86)\REALTEK\RTL8187 Wireless LAN Utility\RtlService.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files (x86)\REALTEK\RTL8187 Wireless LAN Utility\RtWlan.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE C:\Program Files (x86)\Electronic Arts\EADM\Core.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\Dell\DellDock\DellDock.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Windows\system32\conhost.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe C:\Windows\SysWOW64\wscript.exe C:\Users\James Mann\Desktop\dds.scr C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://my.netzero.net/s/search?r=minisearch uStart Page = hxxp://www.google.com/ uSearch Bar = hxxp://my.netzero.net/s/search?r=minisearch mDefault_Search_URL = hxxp://my.netzero.net/s/search?r=minisearch mSearch Page = hxxp://my.netzero.net/s/search?r=minisearch uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch mSearchAssistant = hxxp://my.netzero.net/s/search?r=minisearch uURLSearchHooks: URLSearchHook Class: {37d2cdbf-2af4-44aa-8113-bd0d2da3c2b8} - C:\Program Files (x86)\NetZero\SearchEnh1.dll mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - C:\Program Files (x86)\McAfee\MSK\MskAPBho.dll BHO: Ant.com browser helper (video detector): {346fde31-dff9-418a-90c8-ba31dc9ff2ef} - C:\Program Files (x86)\Ant.com\IE add-on\Download.dll BHO: Pop-up Blocker: {52706ef7-d7a2-49ad-a615-e903858cf284} - C:\Program Files (x86)\NetZero\qsacc\X1IEBHO.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll TB: ZeroBar: {f0f8ecbe-d460-4b34-b007-56a92e8f84a7} - C:\Program Files (x86)\NetZero\Toolbar.dll TB: Ant.com Download Toolbar: {2e924f4f-67f0-4bd8-9560-49f468e843d2} - C:\Program Files (x86)\Ant.com\IE add-on\AntToolbar.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll uRun: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent uRun: [Free Download Manager] "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun uRun: [Software Informer] "C:\Program Files (x86)\Software Informer\softinfo.exe" -autorun uRun: [NetZero_uoltray] C:\Program Files (x86)\NetZero\exec.exe regrun uRun: [PlayNC Launcher] uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized uRun: [Google Update] "C:\Users\James Mann\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [ris700acpt.exe] C:\Users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA\ris700acpt.exe mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 mRun: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe /runkey mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui StartupFolder: C:\Users\JAMESM~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files\Dell\DellDock\DellDock.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MICROS~1.LNK - C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Display All Images with Full Quality - "C:\Program Files (x86)\NetZero\qsacc\appres.dll/228" IE: Display Image with Full Quality - "C:\Program Files (x86)\NetZero\qsacc\appres.dll/227" IE: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll IE: {70AF6C9F-0818-4cf7-924A-BBDBB24211D3} - {70AF6C9F-0818-4cf7-924A-BBDBB24211D3} - C:\Program Files (x86)\Ant.com\IE add-on\Download.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {C9D7D239-B502-48B3-BA25-9DF8C7264073} - hxxps://ahfcas3.ahf2000.aultman.com/auth/CCALogin.CAB DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\microsoft shared\Web Folders\PKMCDO.DLL Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - C:\Program Files (x86)\McAfee\MSK\mskapbho64.dll BHO-X64: McAfee Phishing Filter - No File BHO-X64: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll BHO-X64: scriptproxy - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll TB-X64: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File TB-X64: {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - No File TB-X64: {2E924F4F-67F0-4BD8-9560-49F468E843D2} - No File mRun-x64: [Apoint] C:\Program Files\DellTPad\Apoint.exe mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s mRun-x64: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe mRun-x64: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\JAMESM~1\AppData\Roaming\Mozilla\Firefox\Profiles\3zuie2a7.default\ FF - component: C:\Program Files (x86)\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npViewpoint.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npWebLaunch.dll FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Windows\system32\npmirage.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} FF - Ext: Ant Video Downloader: [removed] - %profile%\extensions\[removed] . ============= SERVICES / DRIVERS =============== . R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-4-30 55280] R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2011-6-17 600920] R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2011-6-17 287576] R1 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2010-4-30 307400] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904] R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2010-3-27 92160] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-3-27 202752] R2 AntUpdaterService;Ant Toolbar updater service;C:\Program Files (x86)\Ant.com\IE add-on\AntUpdaterService.exe [2010-12-22 515096] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2011-6-17 22360] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2011-6-17 64344] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-6-17 42184] R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648] R2 McProxy;McAfee Proxy Service;C:\PROGRA~2\COMMON~1\McAfee\McProxy\McProxy.exe [2010-4-30 359952] R2 McShield;McAfee Real-time Scanner;C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2010-4-30 155456] R2 mi-raysat_3dsmax2011_32;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 32-bit 32-bit;C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe [2010-3-10 86016] R2 Realtek87B;Realtek87B;C:\Program Files (x86)\REALTEK\RTL8187 Wireless LAN Utility\RtlService.exe [2011-3-24 40960] R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atipmdag.sys [2010-3-27 6233088] R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-3-27 161280] R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2010-4-30 172704] R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-3-27 56344] R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2010-4-30 102600] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-3-27 239616] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-2-28 136176] S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-6-17 366640] S2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-4-30 2320920] S2 ZSS;ZoneServer System Service;C:\SERVER WOK 53\Data\rtservice\xRemoteService.exe –> C:\SERVER WOK 53\Data\rtservice\xRemoteService.exe [?] S3 bcm;WiMAX Network Adapter;C:\Windows\System32\drivers\drxvi314_64.sys [2010-2-11 359040] S3 bcmbusctr;WiMAX Bus Driver;C:\Windows\System32\drivers\BcmBusCtr_64.sys [2010-2-11 62976] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;D:\Dragon Age- Origins\Dragon Age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-2-28 136176] S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-6-17 25912] S3 mfebopk;McAfee Inc. mfebopk;C:\Windows\System32\drivers\mfebopk.sys [2010-4-30 41032] S3 mferkdk;McAfee Inc. mferkdk;C:\Windows\System32\drivers\mferkdk.sys [2010-4-30 40904] S3 mfesmfk;McAfee Inc. mfesmfk;C:\Windows\System32\drivers\mfesmfk.sys [2010-4-30 49480] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-3-27 220672] S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-2-18 51712] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-8-30 1255736] S4 McSysmon;McAfee SystemGuards;C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe [2010-4-30 606736] . =============== Created Last 30 ================ . 2011-06-20 21:56:36 0 —ha-w- C:\Users\JAMESM~1\AppData\Local\BIT4477.tmp 2011-06-18 03:04:33 ——– d—–w- C:\Program Files (x86)\tamasoftware 2011-06-17 15:43:59 600920 —-a-w- C:\Windows\System32\drivers\aswSnx.sys 2011-06-17 15:43:58 64344 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2011-06-17 15:43:35 40112 —-a-w- C:\Windows\avastSS.scr 2011-06-17 15:43:24 ——– d—–w- C:\Program Files\AVAST Software 2011-06-17 15:43:24 ——– d—–w- C:\PROGRA~3\AVAST Software 2011-06-17 15:18:35 ——– d—–w- C:\Users\JAMESM~1\AppData\Roaming\Malwarebytes 2011-06-17 15:18:30 39984 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-06-17 15:18:29 ——– d—–w- C:\PROGRA~3\Malwarebytes 2011-06-17 15:18:25 25912 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-06-17 15:18:25 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-06-17 15:09:23 ——– d—–w- C:\Users\JAMESM~1\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA 2011-06-17 14:43:53 499712 —-a-w- C:\Windows\System32\drivers\afd.sys 2011-06-17 14:43:53 1896832 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2011-06-17 13:08:52 461312 —-a-w- C:\Windows\System32\drivers\srv.sys 2011-06-17 13:08:52 399872 —-a-w- C:\Windows\System32\drivers\srv2.sys 2011-06-17 13:08:51 161792 —-a-w- C:\Windows\System32\drivers\srvnet.sys 2011-06-17 12:58:55 287744 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-06-17 12:58:55 157696 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys 2011-06-17 12:58:55 126464 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2011-06-17 12:58:11 3133952 —-a-w- C:\Windows\System32\win32k.sys 2011-06-17 12:50:09 976896 —-a-w- C:\Windows\System32\inetcomm.dll 2011-06-17 12:50:09 740864 —-a-w- C:\Windows\SysWow64\inetcomm.dll 2011-06-17 11:49:25 759296 —-a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2011-06-17 11:49:25 1110528 —-a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll 2011-06-17 11:47:18 197120 —-a-w- C:\Windows\System32\d3d10_1.dll 2011-06-17 11:47:18 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll 2011-06-17 11:44:09 861184 —-a-w- C:\Windows\System32\oleaut32.dll 2011-06-17 11:44:09 571904 —-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-06-17 11:32:30 102400 —-a-w- C:\Windows\System32\drivers\dfsc.sys 2011-06-05 23:09:04 ——– d—–w- C:\Users\JAMESM~1\AppData\Local\Reb3lzrr_Programming 2011-06-04 04:31:41 ——– d—–w- C:\Users\JAMESM~1\AppData\Local\RebelsProgramming 2011-06-02 19:39:59 27008 —-a-w- C:\Windows\System32\drivers\Diskdump.sys 2011-05-23 01:40:08 ——– d—–w- C:\Program Files (x86)\Road Rash 2 . ==================== Find3M ==================== . 2011-05-28 03:25:16 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2011-05-28 03:00:02 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-04-22 20:18:28 1197056 —-a-w- C:\Windows\System32\wininet.dll 2011-04-22 20:14:08 57856 —-a-w- C:\Windows\System32\licmgr10.dll 2011-04-22 19:31:50 981504 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-04-22 19:31:26 44544 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2011-04-22 18:49:57 482816 —-a-w- C:\Windows\System32\html.iec 2011-04-22 18:23:59 386048 —-a-w- C:\Windows\SysWow64\html.iec 2011-04-09 06:58:56 142336 —-a-w- C:\Windows\System32\poqexec.exe 2011-04-09 06:45:48 5509504 —-a-w- C:\Windows\System32\ntoskrnl.exe 2011-04-09 06:13:06 3957632 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2011-04-09 06:13:06 3901824 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2011-04-09 05:56:38 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe 2011-04-06 20:26:58 96544 —-a-w- C:\Windows\System32\dnssd.dll 2011-04-06 20:26:58 69408 —-a-w- C:\Windows\System32\jdns_sd.dll 2011-04-06 20:26:58 237856 —-a-w- C:\Windows\System32\dnssdX.dll 2011-04-06 20:26:58 119584 —-a-w- C:\Windows\System32\dns-sd.exe 2011-04-06 20:20:16 91424 —-a-w- C:\Windows\SysWow64\dnssd.dll 2011-04-06 20:20:16 75040 —-a-w- C:\Windows\SysWow64\jdns_sd.dll 2011-04-06 20:20:16 197920 —-a-w- C:\Windows\SysWow64\dnssdX.dll 2011-04-06 20:20:16 107808 —-a-w- C:\Windows\SysWow64\dns-sd.exe 2011-03-29 03:32:44 343040 —-a-w- C:\Windows\System32\drivers\usbhub.sys 2011-03-29 03:32:29 99328 —-a-w- C:\Windows\System32\drivers\usbccgp.sys 2011-03-29 03:32:20 324608 —-a-w- C:\Windows\System32\drivers\usbport.sys 2011-03-29 03:32:16 52224 —-a-w- C:\Windows\System32\drivers\usbehci.sys 2011-03-29 03:32:16 25600 —-a-w- C:\Windows\System32\drivers\usbohci.sys 2011-03-29 03:32:13 30720 —-a-w- C:\Windows\System32\drivers\usbuhci.sys 2011-03-29 03:32:09 7936 —-a-w- C:\Windows\System32\drivers\usbd.sys . ============= FINISH: 17:58:29.06 ===============

Attachments:

Severance,

You've got two anti-virus programs running. Bad idea. They will conflict with each other… making each less effective than they would be on their own. McAfee is out of date so I suggest you uninstall it. McAfee is also your firewall so be sure to turn on windows firewall once McAfee is removed.

Then,

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks again for all the help, here is an included log Combofix. Also discovered a new folder after running C:\32788R22FWJFW, this is new, would this be associated with ComboFix. _________________________________ ComboFix 11-06-19.0r1 - James Mann 06/21/2011 11:55:02.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3957.2446 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\netzeroinstaller\NetZeroInstaller.exe c:\users\James Mann\AppData\Roaming\.# c:\users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA c:\users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA\enemies-names.txt c:\users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA\local.ini c:\users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA\lsrslt.ini c:\users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA\ris700acpt.exe c:\users\James Mann\AppData\Roaming\Adobe\plugs c:\users\James Mann\AppData\Roaming\Adobe\shed c:\windows\system32\jusched.exe c:\windows\SysWow64\jusched.exe D:\install.exe . . ((((((((((((((((((((((((( Files Created from 2011-05-21 to 2011-06-21 ))))))))))))))))))))))))))))))) . . 2011-06-21 16:02 . 2011-06-21 16:02 ——– d—–w- c:\users\Sharon\AppData\Local\temp 2011-06-21 16:02 . 2011-06-21 16:02 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-06-21 15:50 . 2011-06-21 15:51 ——– d—–w- C:\32788R22FWJFW 2011-06-18 03:04 . 2011-06-18 03:04 ——– d—–w- c:\program files (x86)\tamasoftware 2011-06-17 15:44 . 2011-05-10 11:59 22360 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-06-17 15:44 . 2011-05-10 12:04 287576 —-a-w- c:\windows\system32\drivers\aswSP.sys 2011-06-17 15:44 . 2011-05-10 11:59 31064 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2011-06-17 15:44 . 2011-05-10 12:02 53592 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2011-06-17 15:43 . 2011-05-10 12:04 600920 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-06-17 15:43 . 2011-05-10 12:10 253888 —-a-w- c:\windows\system32\aswBoot.exe 2011-06-17 15:43 . 2011-05-10 11:59 64344 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-06-17 15:43 . 2011-05-10 12:10 40112 —-a-w- c:\windows\avastSS.scr 2011-06-17 15:43 . 2011-05-10 12:10 199304 —-a-w- c:\windows\SysWow64\aswBoot.exe 2011-06-17 15:43 . 2011-06-17 15:43 ——– d—–w- c:\programdata\AVAST Software 2011-06-17 15:43 . 2011-06-17 15:43 ——– d—–w- c:\program files\AVAST Software 2011-06-17 15:18 . 2011-06-17 15:18 ——– d—–w- c:\users\James Mann\AppData\Roaming\Malwarebytes 2011-06-17 15:18 . 2011-05-29 13:11 39984 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-06-17 15:18 . 2011-06-17 15:18 ——– d—–w- c:\programdata\Malwarebytes 2011-06-17 15:18 . 2011-06-17 15:18 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-06-17 15:18 . 2011-05-29 13:11 25912 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-06-17 14:43 . 2011-04-25 05:32 1896832 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-06-17 14:43 . 2011-04-25 02:44 499712 —-a-w- c:\windows\system32\drivers\afd.sys 2011-06-17 13:08 . 2011-04-29 03:13 461312 —-a-w- c:\windows\system32\drivers\srv.sys 2011-06-17 13:08 . 2011-04-29 03:12 399872 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-06-17 13:08 . 2011-04-29 03:12 161792 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-06-17 12:58 . 2011-05-04 02:51 287744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-17 12:58 . 2011-05-04 02:51 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-06-17 12:58 . 2011-05-04 02:51 126464 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-06-17 12:58 . 2011-05-28 03:07 3133952 —-a-w- c:\windows\system32\win32k.sys 2011-06-17 12:50 . 2011-05-03 05:21 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-06-17 12:50 . 2011-05-03 04:50 740864 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-06-17 11:49 . 2011-04-29 05:47 1110528 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 2011-06-17 11:49 . 2011-04-29 05:08 759296 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2011-06-17 11:47 . 2011-01-17 06:17 197120 —-a-w- c:\windows\system32\d3d10_1.dll 2011-06-17 11:47 . 2011-01-17 05:38 161792 —-a-w- c:\windows\SysWow64\d3d10_1.dll 2011-06-17 11:44 . 2010-12-18 06:13 861184 —-a-w- c:\windows\system32\oleaut32.dll 2011-06-17 11:44 . 2010-12-18 05:31 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-06-17 11:32 . 2011-04-27 02:57 102400 —-a-w- c:\windows\system32\drivers\dfsc.sys 2011-06-05 23:09 . 2011-06-05 23:09 ——– d—–w- c:\users\James Mann\AppData\Local\Reb3lzrr_Programming 2011-06-04 04:31 . 2011-06-04 04:31 ——– d—–w- c:\users\James Mann\AppData\Local\RebelsProgramming 2011-06-02 19:39 . 2011-04-22 20:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-23 01:40 . 2011-05-23 01:40 ——– d—–w- c:\program files (x86)\Road Rash 2 . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-06-17 13:44 . 2010-08-30 22:58 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2011-06-17 13:42 . 2010-08-30 22:58 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2011-05-11 19:05 . 2010-08-30 23:00 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2011-05-11 19:04 . 2011-04-26 18:16 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2011-05-11 19:03 . 2011-02-14 16:26 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2011-05-11 19:03 . 2011-02-14 16:26 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2011-04-28 15:50 . 2011-02-14 16:28 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2011-04-28 15:39 . 2010-08-30 23:00 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2011-04-23 13:39 . 2011-04-23 13:39 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-5\Microsoft.MediaCenter.Sports.UI.dll 2011-04-09 06:58 . 2011-05-20 20:52 142336 —-a-w- c:\windows\system32\poqexec.exe 2011-04-09 06:45 . 2011-05-11 19:29 5509504 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-04-09 06:13 . 2011-05-11 19:29 3957632 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-04-09 06:13 . 2011-05-11 19:29 3901824 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-04-09 05:56 . 2011-05-20 20:52 123904 —-a-w- c:\windows\SysWow64\poqexec.exe 2011-04-06 20:26 . 2011-04-06 20:26 96544 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 20:26 . 2011-04-06 20:26 69408 —-a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 20:26 . 2011-04-06 20:26 237856 —-a-w- c:\windows\system32\dnssdX.dll 2011-04-06 20:26 . 2011-04-06 20:26 119584 —-a-w- c:\windows\system32\dns-sd.exe 2011-04-06 20:20 . 2011-04-06 20:20 91424 —-a-w- c:\windows\SysWow64\dnssd.dll 2011-04-06 20:20 . 2011-04-06 20:20 75040 —-a-w- c:\windows\SysWow64\jdns_sd.dll 2011-04-06 20:20 . 2011-04-06 20:20 197920 —-a-w- c:\windows\SysWow64\dnssdX.dll 2011-04-06 20:20 . 2011-04-06 20:20 107808 —-a-w- c:\windows\SysWow64\dns-sd.exe 2011-03-29 03:32 . 2011-05-11 19:11 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-03-29 03:32 . 2011-05-11 19:11 99328 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-03-29 03:32 . 2011-05-11 19:11 324608 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-03-29 03:32 . 2011-05-11 19:12 52224 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-03-29 03:32 . 2011-05-11 19:11 25600 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-03-29 03:32 . 2011-05-11 19:11 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-03-29 03:32 . 2011-05-11 19:11 7936 —-a-w- c:\windows\system32\drivers\usbd.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EA Core"="c:\program files (x86)\Electronic Arts\EADM\Core.exe" [2009-03-28 3325952] "Free Download Manager"="c:\program files (x86)\Free Download Manager\fdm.exe" [2010-04-29 3727411] "NetZero_uoltray"="c:\program files (x86)\NetZero\exec.exe" [2008-05-07 1701376] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-01-26 15026056] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-12-29 140520] "Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600] "Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-10-15 498160] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744] "DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-14 421160] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-05-10 3459712] . c:\users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384] . c:\users\James Mann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-28 136176] R2 ZSS;ZoneServer System Service;c:\server wok 53\Data\rtservice\xRemoteService.exe [x] R3 bcm;WiMAX Network Adapter;c:\windows\system32\DRIVERS\drxvi314_64.sys [x] R3 bcmbusctr;WiMAX Bus Driver;c:\windows\system32\DRIVERS\BcmBusCtr_64.sys [x] R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\dragon age- origins\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-28 136176] R3 PCTINDIS5X64;PCTINDIS5X64 NDIS Protocol Driver;c:\windows\system32\PCTINDIS5X64.SYS [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-10-09 92160] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AntUpdaterService;Ant Toolbar updater service;c:\program files (x86)\Ant.com\IE add-on\AntUpdaterService.exe [2010-12-22 515096] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640] S2 mi-raysat_3dsmax2011_32;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 32-bit 32-bit;c:\program files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe [2010-03-10 86016] S2 Realtek87B;Realtek87B;c:\program files (x86)\REALTEK\RTL8187 Wireless LAN Utility\RtlService.exe [2009-06-30 40960] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-09-30 2320920] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-06-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-28 08:35] . 2011-06-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-28 08:35] . 2011-06-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-619826061-120817133-1486808799-1000Core.job - c:\users\James Mann\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-17 14:18] . 2011-06-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-619826061-120817133-1486808799-1000UA.job - c:\users\James Mann\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-17 14:18] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-05-10 12:10 134384 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-09-16 357376] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-09 8158240] "QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2009-10-01 3189016] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch IE: Display All Images with Full Quality - "c:\program files (x86)\NetZero\qsacc\appres.dll/228" IE: Display Image with Full Quality - "c:\program files (x86)\NetZero\qsacc\appres.dll/227" IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000 IE: {{70AF6C9F-0818-4cf7-924A-BBDBB24211D3} - {70AF6C9F-0818-4cf7-924A-BBDBB24211D3} - c:\program files (x86)\Ant.com\IE add-on\Download.dll DPF: {C9D7D239-B502-48B3-BA25-9DF8C7264073} - hxxps://ahfcas3.ahf2000.aultman.com/auth/CCALogin.CAB FF - ProfilePath - c:\users\James Mann\AppData\Roaming\Mozilla\Firefox\Profiles\3zuie2a7.default\ FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} FF - Ext: Ant Video Downloader: [removed] - %profile%\extensions\[removed] . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-Software Informer - c:\program files (x86)\Software Informer\softinfo.exe Wow6432Node-HKCU-Run-PlayNC Launcher - (no file) Wow6432Node-HKCU-Run-ris700acpt.exe - c:\users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA\ris700acpt.exe SafeBoot-mcmscsvc SafeBoot-MCODS Toolbar-Locked - (no file) AddRemove-Adobe Shockwave Player - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE AddRemove-CinemaForge - c:\windows\system32\xmirage.exe AddRemove-DAZ|Studio - c:\windows\unvise32.exe AddRemove-ColladaMax - c:\program files (x86)\Feeling Software\ColladaMax\uninstallColladaMax.exe AddRemove-World Of Kung Fu client - c:\wokf\uninst.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-619826061-120817133-1486808799-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] @Allowed: (Read) (RestrictedCode) "??"=hex:c5,a2,01,83,24,5b,cb,f7,35,5e,67,b5,04,a9,9c,f1,6f,62,29,53,ef,36,f8, 5a,9a,75,04,ab,be,95,a8,57,e4,27,98,9f,47,11,86,f1,64,79,55,e9,70,ae,3c,2e,\ "??"=hex:0c,03,0e,4e,d6,13,d2,5f,c8,0f,a6,cf,f6,4e,d1,d7 . [HKEY_USERS\S-1-5-21-619826061-120817133-1486808799-1000\Software\SecuROM\License information*] "datasecu"=hex:80,38,41,ae,67,a1,29,28,69,4a,c8,6d,f3,4e,f1,de,4c,f6,8d,11,dd, a3,ca,40,20,c2,79,6d,02,70,2f,f5,b3,78,f7,78,53,4b,f9,e0,16,ff,0d,fa,68,70,\ "rkeysecu"=hex:8c,f2,c1,44,15,01,d4,87,16,e0,cc,1f,16,ce,7f,d4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files (x86)\REALTEK\RTL8187 Wireless LAN Utility\RtWlan.exe c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe . ************************************************************************** . Completion time: 2011-06-21 12:12:02 - machine was rebooted ComboFix-quarantined-files.txt 2011-06-21 16:12 . Pre-Run: 3,816,972,288 bytes free Post-Run: 6,393,413,632 bytes free . - - End Of File - - F8EDC6AF912D6BEC202F12D112D7CEE9
Severance,

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Also, please let me know how things are running.
This is what it found: __________________ C:\Qoobox\Quarantine\C\Users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA\enemies-names.txt.vir Win32/Adware.AntimalwareDoctor.AE.Gen application C:\Qoobox\Quarantine\C\Users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA\local.ini.vir Win32/Adware.AntimalwareDoctor.AE.Gen application C:\Qoobox\Quarantine\C\Users\James Mann\AppData\Roaming\4637A2867EED304013FF0DA6B2AF96AA\ris700acpt.exe.vir a variant of Win32/Kryptik.PHE trojan C:\Users\James Mann\AppData\Local\imejihafew.dll a variant of Win32/Kryptik.NCK trojan
Severance,

If ComboFix asks to update… let it.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Users\James Mann\AppData\Local\imejihafew.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Here is what the new log says: ____________________________________________________ ComboFix 11-06-19.0r1 - James Mann 06/27/2011 17:10:20.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3957.2415 [GMT -4:00] Running from: c:\users\[removed]\Desktop\Anti Virus\ComboFix.exe Command switches used :: c:\users\James Mann\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . - REDUCED FUNCTIONALITY MODE - . FILE :: "c:\users\James Mann\AppData\Local\imejihafew.dll" . . ((((((((((((((((((((((((( Files Created from 2011-05-27 to 2011-06-27 ))))))))))))))))))))))))))))))) . . 2011-06-27 21:11 . 2011-06-27 21:11 ——– d—–w- c:\users\Sharon\AppData\Local\temp 2011-06-27 21:11 . 2011-06-27 21:11 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-06-22 17:50 . 2011-06-22 19:26 ——– d—–w- c:\program files (x86)\GLIntercept0_5 2011-06-22 15:02 . 2011-06-20 12:57 8873296 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{78E3E223-4430-4FEB-878D-649705A7F36A}\mpengine.dll 2011-06-22 15:01 . 2011-05-24 23:14 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-06-22 13:35 . 2011-06-22 13:35 ——– d—–w- c:\program files (x86)\ESET 2011-06-18 03:04 . 2011-06-18 03:04 ——– d—–w- c:\program files (x86)\tamasoftware 2011-06-17 15:44 . 2011-05-10 11:59 22360 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-06-17 15:44 . 2011-05-10 12:04 287576 —-a-w- c:\windows\system32\drivers\aswSP.sys 2011-06-17 15:44 . 2011-05-10 11:59 31064 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2011-06-17 15:44 . 2011-05-10 12:02 53592 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2011-06-17 15:43 . 2011-05-10 12:04 600920 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-06-17 15:43 . 2011-05-10 12:10 253888 —-a-w- c:\windows\system32\aswBoot.exe 2011-06-17 15:43 . 2011-05-10 11:59 64344 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-06-17 15:43 . 2011-05-10 12:10 40112 —-a-w- c:\windows\avastSS.scr 2011-06-17 15:43 . 2011-05-10 12:10 199304 —-a-w- c:\windows\SysWow64\aswBoot.exe 2011-06-17 15:43 . 2011-06-17 15:43 ——– d—–w- c:\programdata\AVAST Software 2011-06-17 15:43 . 2011-06-17 15:43 ——– d—–w- c:\program files\AVAST Software 2011-06-17 15:18 . 2011-06-17 15:18 ——– d—–w- c:\users\James Mann\AppData\Roaming\Malwarebytes 2011-06-17 15:18 . 2011-05-29 13:11 39984 —-a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-06-17 15:18 . 2011-06-17 15:18 ——– d—–w- c:\programdata\Malwarebytes 2011-06-17 15:18 . 2011-06-17 15:18 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-06-17 15:18 . 2011-05-29 13:11 25912 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-06-17 14:43 . 2011-04-25 05:32 1896832 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-06-17 14:43 . 2011-04-25 02:44 499712 —-a-w- c:\windows\system32\drivers\afd.sys 2011-06-17 13:08 . 2011-04-29 03:13 461312 —-a-w- c:\windows\system32\drivers\srv.sys 2011-06-17 13:08 . 2011-04-29 03:12 399872 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-06-17 13:08 . 2011-04-29 03:12 161792 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-06-17 12:58 . 2011-05-04 02:51 287744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-17 12:58 . 2011-05-04 02:51 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-06-17 12:58 . 2011-05-04 02:51 126464 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-06-17 12:58 . 2011-05-28 03:07 3133952 —-a-w- c:\windows\system32\win32k.sys 2011-06-17 12:50 . 2011-05-03 05:21 976896 —-a-w- c:\windows\system32\inetcomm.dll 2011-06-17 12:50 . 2011-05-03 04:50 740864 —-a-w- c:\windows\SysWow64\inetcomm.dll 2011-06-17 11:49 . 2011-04-29 05:47 1110528 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll 2011-06-17 11:49 . 2011-04-29 05:08 759296 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2011-06-17 11:47 . 2011-01-17 06:17 197120 —-a-w- c:\windows\system32\d3d10_1.dll 2011-06-17 11:47 . 2011-01-17 05:38 161792 —-a-w- c:\windows\SysWow64\d3d10_1.dll 2011-06-17 11:44 . 2010-12-18 06:13 861184 —-a-w- c:\windows\system32\oleaut32.dll 2011-06-17 11:44 . 2010-12-18 05:31 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-06-17 11:32 . 2011-04-27 02:57 102400 —-a-w- c:\windows\system32\drivers\dfsc.sys 2011-06-05 23:09 . 2011-06-05 23:09 ——– d—–w- c:\users\James Mann\AppData\Local\Reb3lzrr_Programming 2011-06-04 04:31 . 2011-06-04 04:31 ——– d—–w- c:\users\James Mann\AppData\Local\RebelsProgramming 2011-06-02 19:39 . 2011-04-22 20:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-06-22 13:33 . 2011-02-14 16:28 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2011-06-22 13:31 . 2010-08-30 23:00 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2011-06-22 13:14 . 2011-02-14 16:26 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2011-06-22 13:14 . 2011-02-14 16:26 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2011-06-17 13:44 . 2010-08-30 22:58 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2011-06-17 13:42 . 2010-08-30 22:58 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2011-05-11 19:05 . 2010-08-30 23:00 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2011-05-11 19:04 . 2011-04-26 18:16 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2011-04-23 13:39 . 2011-04-23 13:39 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-5\Microsoft.MediaCenter.Sports.UI.dll 2011-04-09 06:58 . 2011-05-20 20:52 142336 —-a-w- c:\windows\system32\poqexec.exe 2011-04-09 06:45 . 2011-05-11 19:29 5509504 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-04-09 06:13 . 2011-05-11 19:29 3957632 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-04-09 06:13 . 2011-05-11 19:29 3901824 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-04-09 05:56 . 2011-05-20 20:52 123904 —-a-w- c:\windows\SysWow64\poqexec.exe 2011-04-06 20:26 . 2011-04-06 20:26 96544 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 20:26 . 2011-04-06 20:26 69408 —-a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 20:26 . 2011-04-06 20:26 237856 —-a-w- c:\windows\system32\dnssdX.dll 2011-04-06 20:26 . 2011-04-06 20:26 119584 —-a-w- c:\windows\system32\dns-sd.exe 2011-04-06 20:20 . 2011-04-06 20:20 91424 —-a-w- c:\windows\SysWow64\dnssd.dll 2011-04-06 20:20 . 2011-04-06 20:20 75040 —-a-w- c:\windows\SysWow64\jdns_sd.dll 2011-04-06 20:20 . 2011-04-06 20:20 197920 —-a-w- c:\windows\SysWow64\dnssdX.dll 2011-04-06 20:20 . 2011-04-06 20:20 107808 —-a-w- c:\windows\SysWow64\dns-sd.exe . . ((((((((((((((((((((((((((((( SnapShot@2011-06-21_16.05.31 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 04:54 . 2011-06-27 21:15 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-06-21 16:05 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-06-21 16:05 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2011-06-27 21:15 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-06-21 16:05 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-06-27 21:15 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-04-30 14:07 . 2011-06-27 21:24 58766 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2011-06-27 21:24 29908 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-05-05 22:36 . 2011-06-27 21:24 16070 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-619826061-120817133-1486808799-1000_UserData.bin + 2010-05-05 19:45 . 2011-06-22 13:34 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-05-05 19:45 . 2011-06-20 22:38 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-05-05 19:45 . 2011-06-20 22:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2010-05-05 19:45 . 2011-06-22 13:34 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-06-20 22:38 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-06-22 13:34 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-05-05 21:19 . 2011-06-27 21:15 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-05-05 21:19 . 2011-06-21 15:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:46 . 2011-06-22 16:08 80672 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2010-05-05 21:19 . 2011-06-27 21:15 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2010-05-05 21:19 . 2011-06-21 15:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2010-05-05 21:19 . 2011-06-21 15:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-05-05 21:19 . 2011-06-27 21:15 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-05-05 20:55 . 2011-06-27 21:15 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-05-05 20:55 . 2011-06-21 15:48 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-05-05 20:55 . 2011-06-21 15:48 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-05-05 20:55 . 2011-06-27 21:15 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-06-27 21:12 . 2011-06-27 21:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-06-21 16:03 . 2011-06-21 16:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-06-21 16:03 . 2011-06-21 16:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-06-27 21:12 . 2011-06-27 21:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2010-06-02 20:55 . 2011-06-23 15:54 246358 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin + 2010-05-07 17:40 . 2011-06-24 05:29 285932 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin + 2009-07-14 02:36 . 2011-06-24 21:22 670886 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2011-06-21 15:53 670886 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2011-06-21 15:53 124164 c:\windows\system32\perfc009.dat + 2009-07-14 02:36 . 2011-06-24 21:22 124164 c:\windows\system32\perfc009.dat - 2009-07-14 05:01 . 2011-06-21 16:02 389260 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2011-06-27 21:12 389260 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 02:34 . 2011-06-21 15:59 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat + 2009-07-14 02:34 . 2011-06-27 21:11 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EA Core"="c:\program files (x86)\Electronic Arts\EADM\Core.exe" [2009-03-28 3325952] "Free Download Manager"="c:\program files (x86)\Free Download Manager\fdm.exe" [2010-04-29 3727411] "NetZero_uoltray"="c:\program files (x86)\NetZero\exec.exe" [2008-05-07 1701376] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-01-26 15026056] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-12-29 140520] "Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600] "Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-10-15 498160] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744] "DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-14 421160] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-05-10 3459712] . c:\users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384] . c:\users\James Mann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-28 136176] R2 ZSS;ZoneServer System Service;c:\server wok 53\Data\rtservice\xRemoteService.exe [x] R3 bcm;WiMAX Network Adapter;c:\windows\system32\DRIVERS\drxvi314_64.sys [x] R3 bcmbusctr;WiMAX Bus Driver;c:\windows\system32\DRIVERS\BcmBusCtr_64.sys [x] R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\dragon age- origins\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-28 136176] R3 PCTINDIS5X64;PCTINDIS5X64 NDIS Protocol Driver;c:\windows\system32\PCTINDIS5X64.SYS [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-10-09 92160] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 AntUpdaterService;Ant Toolbar updater service;c:\program files (x86)\Ant.com\IE add-on\AntUpdaterService.exe [2010-12-22 515096] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640] S2 mi-raysat_3dsmax2011_32;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 32-bit 32-bit;c:\program files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe [2010-03-10 86016] S2 Realtek87B;Realtek87B;c:\program files (x86)\REALTEK\RTL8187 Wireless LAN Utility\RtlService.exe [2009-06-30 40960] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-09-30 2320920] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-28 08:35] . 2011-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-28 08:35] . 2011-06-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-619826061-120817133-1486808799-1000Core.job - c:\users\James Mann\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-17 14:18] . 2011-06-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-619826061-120817133-1486808799-1000UA.job - c:\users\James Mann\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-17 14:18] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-05-10 12:10 134384 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-09-16 357376] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-09 8158240] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch IE: Display All Images with Full Quality - "c:\program files (x86)\NetZero\qsacc\appres.dll/228" IE: Display Image with Full Quality - "c:\program files (x86)\NetZero\qsacc\appres.dll/227" IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000 IE: {{70AF6C9F-0818-4cf7-924A-BBDBB24211D3} - {70AF6C9F-0818-4cf7-924A-BBDBB24211D3} - c:\program files (x86)\Ant.com\IE add-on\Download.dll TCP: DhcpNameServer = 192.168.1.40 DPF: {C9D7D239-B502-48B3-BA25-9DF8C7264073} - hxxps://ahfcas3.ahf2000.aultman.com/auth/CCALogin.CAB FF - ProfilePath - c:\users\James Mann\AppData\Roaming\Mozilla\Firefox\Profiles\3zuie2a7.default\ FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} FF - Ext: Ant Video Downloader: [removed] - %profile%\extensions\[removed] FF - Ext: avast! WebRep: [removed] - c:\program files\AVAST Software\Avast\WebRep\FF . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) AddRemove-DAZ|Studio - c:\windows\unvise32.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-619826061-120817133-1486808799-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] @Allowed: (Read) (RestrictedCode) "??"=hex:c5,a2,01,83,24,5b,cb,f7,35,5e,67,b5,04,a9,9c,f1,6f,62,29,53,ef,36,f8, 5a,9a,75,04,ab,be,95,a8,57,e4,27,98,9f,47,11,86,f1,64,79,55,e9,70,ae,3c,2e,\ "??"=hex:0c,03,0e,4e,d6,13,d2,5f,c8,0f,a6,cf,f6,4e,d1,d7 . [HKEY_USERS\S-1-5-21-619826061-120817133-1486808799-1000\Software\SecuROM\License information*] "datasecu"=hex:80,38,41,ae,67,a1,29,28,69,4a,c8,6d,f3,4e,f1,de,4c,f6,8d,11,dd, a3,ca,40,20,c2,79,6d,02,70,2f,f5,b3,78,f7,78,53,4b,f9,e0,16,ff,0d,fa,68,70,\ "rkeysecu"=hex:8c,f2,c1,44,15,01,d4,87,16,e0,cc,1f,16,ce,7f,d4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files (x86)\REALTEK\RTL8187 Wireless LAN Utility\RtWlan.exe c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe c:\program files (x86)\Roxio\Roxio Burn\Roxio Burn.exe c:\program files (x86)\NetZero\qsacc\x1exec.exe c:\program files (x86)\Skype\Plugin Manager\skypePM.exe . ************************************************************************** . Completion time: 2011-06-27 17:38:15 - machine was rebooted ComboFix-quarantined-files.txt 2011-06-27 21:38 ComboFix2.txt 2011-06-21 16:12 . Pre-Run: 5,481,652,224 bytes free Post-Run: 5,926,699,008 bytes free . - - End Of File - - C09A70291F9B81C0F05F1FC2AA33E46C
Severance,

Looks good.

Let's cleanup.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /Uninstall in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI