This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Maleware Infection. have logs ready!

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi this is my sisters computer that i am working on. It has some maleware and virus related issues how ever some of the issues i managed to solve. When i first tried to service this computer and work on it, i noticed that mostly everything was not working, firefox was not launching at all. Download rates were usually slow. Just tried to reinstall firefox and dl a new version. It was downloading at 20kb/s. Normally my DL rate is around 150 kb/s for a single file. To proove that this was not a network issue, i tried the same thing on my computer. Absolutely no issues with DL rates or browsers not loading. IE was the only browser that i managed to load on this computer. How ever, any other site or links for that matter would not link to the appropriate URLS. It would siply come up with an error code, i forgot the code, but it cancled out the net and said something like "termination". I couldn't even launch ms configuration. I could not even boot the computer into safe mode. Programs were not even installing so i was completely limited to what i can do to fix this issue.

So i used the windows install disk and i executed a recover repair console. It indicating that your boot options have been changed and the repair feature will repair those boot options. I was then able to press F8 like normal and boot into safe mode with networking. Before this was not working. I have a few logs for you to go over so you can see. Based on my research on looking over these logs i can clearly see some infections are coming from this site called "Mp3tube" and something called "shopper reports" MP3tube was the first page that popped up when launching IE. I realized that both firefox and IE both were redirecting to this URL. Which is probably the cause of most of the infections.

How ever my sister some times goes to sites to get music downloads alot of times, so im not sure which source she is getting these infections from. I want to not only make sure the computer is clean but to also find the "source" of where these infections are eminatating from. This is extremely important as i can't always watch over what she browses though. So if you find any website, any applications that are the cause of these maleware intrusions. I can then relay this message to her and let her know not to go there or better yet, even block the URLS on the internet so she can't access them. So maybe you can help me limit access to the account for these URLS. She can still have admistrative rights to the computer, i just want to block these harmful websites, for future use, so she does not access them again.


First of off, here is my DDS log



.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 13:26:12 on 2011-06-29
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.998 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\SearchIndexer.exe
C:\Users\Ashley\Desktop\Virus Removal Tool\setup_9.0.0.722_29.06.2011_21-06\setup_9.0.0.722_29.06.2011_21-06.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://mp3tubetoolbar.com/?tmp=toolbar_Mp3Tube_homepage&prt=pinballtbfour04ie&clid=23573e425387458fb5c2b1f9b76dd344
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\ashley\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\users\ashley\appdata\roaming\micros~1\windows\startm~1\programs\startup\setup_~1.lnk - c:\users\ashley\desktop\virus removal tool\setup_9.0.0.722_29.06.2011_21-06\startup.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{B2774F38-E956-4A48-8A89-372D806B599C} : DhcpNameServer = 192.168.0.1 [removed]
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\ashley\appdata\roaming\mozilla\firefox\profiles\7em8o8q5.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo-Mp3Tube
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/?r0=1309377316
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
.
—- FIREFOX POLICIES —-
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
============= SERVICES / DRIVERS ===============
.
R0 72481612;72481612 Boot Guard Driver;c:\windows\system32\drivers\72481612.sys [2011-6-29 37392]
R1 72481611;72481611;c:\windows\system32\drivers\72481611.sys [2011-6-29 128016]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsla61df759;MpKsla61df759;c:\programdata\microsoft\microsoft antimalware\definition updates\{f31d551c-2899-4f13-b7a7-4229baa4a5ad}\MpKsla61df759.sys [2011-6-29 28752]
R1 setup_9.0.0.722_29.06.2011_21-06drv;setup_9.0.0.722_29.06.2011_21-06drv;c:\windows\system32\drivers\7248161.sys [2011-6-29 311312]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-6-29 39984]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-6-20 15872]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-20 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-4-29 1343400]
.
=============== Created Last 30 ================
.
2011-06-29 20:01:26 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f31d551c-2899-4f13-b7a7-4229baa4a5ad}\MpKsla61df759.sys
2011-06-29 20:01:01 7074640 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f31d551c-2899-4f13-b7a7-4229baa4a5ad}\mpengine.dll
2011-06-29 18:58:30 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-29 18:58:27 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-29 18:57:25 ——– d—–w- c:\programdata\Kaspersky Lab
2011-06-29 18:57:03 37392 —-a-w- c:\windows\system32\drivers\72481612.sys
2011-06-29 18:57:03 311312 —-a-w- c:\windows\system32\drivers\7248161.sys
2011-06-29 18:57:03 128016 —-a-w- c:\windows\system32\drivers\72481611.sys
2011-06-29 00:30:32 293376 —-a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 00:30:28 427520 —-a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 00:30:28 337408 —-a-w- c:\windows\system32\mssph.dll
2011-06-29 00:30:28 164352 —-a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 00:30:28 1549312 —-a-w- c:\windows\system32\tquery.dll
2011-06-29 00:30:28 1401344 —-a-w- c:\windows\system32\mssrch.dll
2011-06-29 00:30:27 86528 —-a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-29 00:30:27 666624 —-a-w- c:\windows\system32\mssvp.dll
2011-06-29 00:30:27 59392 —-a-w- c:\windows\system32\msscntrs.dll
2011-06-29 00:30:27 197120 —-a-w- c:\windows\system32\mssphtb.dll
2011-06-22 21:45:36 ——– d—–w- c:\windows\system32\SPReview
2011-06-22 21:44:47 ——– d—–w- c:\windows\system32\EventProviders
2011-06-20 21:05:02 1130824 —-a-w- c:\windows\system32\dfshim.dll
2011-06-20 21:03:59 673040 —-a-w- c:\program files\internet explorer\iexplore.exe
2011-06-20 21:02:53 780288 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-20 21:02:53 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll
2011-06-20 21:02:53 363008 —-a-w- c:\windows\system32\wbemcomn.dll
2011-06-20 21:02:53 351232 —-a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-20 21:02:45 697344 —-a-w- c:\windows\system32\SmiEngine.dll
2011-06-20 21:02:41 209920 —-a-w- c:\windows\system32\PkgMgr.exe
2011-06-20 21:02:41 189952 —-a-w- c:\windows\system32\wdscore.dll
2011-06-20 21:02:24 323072 —-a-w- c:\windows\system32\drvstore.dll
2011-06-20 21:02:24 257024 —-a-w- c:\windows\system32\dpx.dll
2011-06-19 18:51:34 737072 —-a-w- c:\programdata\microsoft\ehome\packages\sportsv2\sportstemplatecore\Microsoft.MediaCenter.Sports.UI.dll
2011-06-19 18:51:05 4283672 —-a-w- c:\programdata\microsoft\ehome\packages\mceclientux\updateablemarkup\markup.dll
2011-06-19 18:31:42 42776 —-a-w- c:\programdata\microsoft\ehome\packages\mceclientux\dsm\StartResources.dll
2011-06-19 18:31:37 539968 —-a-w- c:\programdata\microsoft\ehome\packages\mcespotlight\mcespotlight\SpotlightResources.dll
2011-06-17 22:04:58 ——– d—–w- c:\programdata\KingsIsle Entertainment
2011-06-13 03:50:27 ——– d—–w- c:\program files\QuestScan
2011-06-12 06:43:14 65602 —-a-w- c:\windows\system32\cook3260.dll
2011-06-12 06:43:14 626688 —-a-w- c:\windows\system32\vp7vfw.dll
2011-06-12 06:43:14 217127 —-a-w- c:\windows\system32\drv43260.dll
2011-06-12 06:43:14 208935 —-a-w- c:\windows\system32\drv33260.dll
2011-06-12 06:43:14 176165 —-a-w- c:\windows\system32\drv23260.dll
2011-06-12 06:43:14 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll
2011-06-12 06:43:14 102439 —-a-w- c:\windows\system32\sipr3260.dll
2011-06-12 06:43:12 ——– d—–w- c:\program files\VSO
2011-06-07 19:35:34 103864 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2011-06-01 06:31:06 ——– d—–w- c:\programdata\vsosdk
2011-06-01 04:43:35 ——– d—–w- c:\users\ashley\appdata\roaming\DVDFab
2011-06-01 04:32:03 ——– d—–w- c:\program files\DVDFab 8 Qt
.
==================== Find3M ====================
.
2011-06-22 21:50:48 152576 —-a-w- c:\windows\system32\msclmd.dll
2011-05-30 05:27:23 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-28 02:53:58 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-05-03 04:30:02 741376 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 02:46:33 311808 —-a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 02:46:15 310272 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 02:46:10 114688 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:17:36 223744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:17:28 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-27 02:17:22 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 04:31:30 1290624 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:18:03 338944 —-a-w- c:\windows\system32\drivers\afd.sys
2011-04-22 19:14:16 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-22 19:10:01 981504 —-a-w- c:\windows\system32\wininet.dll
2011-04-13 22:02:36 40984 —-a-w- c:\windows\system32\drivers\point32.sys
2011-04-13 22:02:36 1461992 —-a-w- c:\windows\system32\wdfcoinstaller01009.dll
2011-04-09 06:02:25 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02:25 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:02:04 390656 —-a-w- c:\windows\system32\ipcoin815.dll
2011-04-09 05:56:38 123904 —-a-w- c:\windows\system32\poqexec.exe
.
============= FINISH: 13:26:58.46 ===============




Next here is my MBAM Log file





Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6978

Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 8.0.7601.17514

6/29/2011 12:48:18 PM
mbam-log-2011-06-29 (12-48-10).txt

Scan type: Full scan (C:\|E:\|F:\|G:\|)
Objects scanned: 406033
Time elapsed: 41 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 73
Registry Values Infected: 6
Registry Data Items Infected: 0
Folders Infected: 21
Files Infected: 26

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{0D82ACD6-A652-4496-A298-2BDE705F4227} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{7025E484-D4B0-441a-9F0B-69063BD679CE} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{396CFC12-932D-496b-A0A8-5D7201E105E1} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{573F4ABB-A1A2-44ED-9BA9-A8DAD40AAC46} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{71E02280-5212-45C3-B174-4D5A35DA254F} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaNvgtnTrpr.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaNvgtnTrpr (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4D1EC4CA-4B92-4324-B8F8-C9A6ED06A8AE} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{6F098504-CDB1-420F-A2E6-DDC0B835FEDF} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.Info.1 (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.Info (Adware.Hotbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4D1EC4CA-4B92-4324-B8F8-C9A6ED06A8AE} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4E674574-3F0B-491d-8AE3-F90B43A34FD6} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.UserProfiles.1 (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.UserProfiles (Adware.Hotbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4E674574-3F0B-491D-8AE3-F90B43A34FD6} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{74C22317-5B90-471f-9AD2-FEC049870A16} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Scopes.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Scopes (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{ACC62306-9A63-4864-BD2F-C8825D2D7EA6} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{21BA420E-161C-413A-B21E-4E42AE1F4226} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF} (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89F88394-3828-4d03-A0CF-8203604C3DA6} (Adware.Hotbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4233F04-1789-483c-A137-731E8F113DD5} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.AsyncReporter (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.AsyncReporter.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Dwnldr (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Dwnldr.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbAx (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbAx.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbGuru (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbGuru.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbInfoBand (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbInfoBand.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButton (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButton.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButtonA (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButtonA.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaPSExecuter (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaPSExecuter.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.ReportData (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.ReportData.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Reporter (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Reporter.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.RprtCtrl (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.RprtCtrl.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Stock (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Stock.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiate (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiate.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiateOrRandomTS (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiateOrRandomTS.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerOnceInDay (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerOnceInDay.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\AppID\BRNstIE.DLL (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\CmndFF.DLL (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\mozillaps.dll (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\Pltfrm.DLL (Adware.ClickPotato) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\Software\hblitesa (Adware.HotBar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\HBLite (Adware.HotBar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QuestScan Service (Adware.QuestScan) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> Value: {46897C77-E7A6-4C33-BFFB-E9C2E2718942} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> Value: {46897C77-E7A6-4C33-BFFB-E9C2E2718942} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\ShopperReports 3.1.69.0 (Adware.HotBar) -> Value: ShopperReports 3.1.69.0 -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\SRS_IT_E8790677B2765D563EA094 (Malware.Trace) -> Value: SRS_IT_E8790677B2765D563EA094 -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\[removed] (ShopperReports) -> Value: [removed] -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\[removed] (Adware.HotBar) -> Value: [removed] -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\programdata\2aca5cc3-0f83-453d-a079-1076fe1a8b65 (Adware.Seekmo) -> No action taken.
c:\Users\Ashley\AppData\Roaming\HBLite (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA (Adware.Hotbar) -> No action taken.
c:\Users\Ashley\AppData\Roaming\shopperreports3 (Adware.ShopperReports) -> No action taken.
c:\program files\HBLite (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0 (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions\plugins (Adware.Hotbar) -> No action taken.
c:\program files\shopperreports3 (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0 (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports (Adware.ShopperReports) -> No action taken.

Files Infected:
c:\program files\shopperreports3\bin\3.1.69.0\CmndFF.dll (Adware.ShopperReports) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\hblitesaax.dll (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions\plugins\npclntax_hblitesa.dll (Adware.Hotbar) -> No action taken.
c:\program files\mozilla firefox\plugins\npclntax_hblitesa.dll (Adware.Hotbar) -> No action taken.
c:\program files\questscan\questscan.dll (Adware.Agent.ZGen) -> No action taken.
c:\program files\questscan\questscan.exe (Adware.Agent.ZGen) -> No action taken.
c:\program files\mozilla firefox\searchplugins\Mp3Tube.xml (Adware.Mp3Tube) -> No action taken.
c:\programdata\HBLiteSA\HBLiteSA.dat (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesaabout.mht (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesaau.dat (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesaeula.mht (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesa_kyf_update.dat (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions\install.rdf (Adware.Hotbar) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\link.ico (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome.manifest (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\install.rdf (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content\infopane.js (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content\InfoPane.xul (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components\browserextensionff.dll (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components\browserextensionff.xpt (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar\about hotbar.lnk (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar\hotbar customer support center.lnk (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar\hotbar uninstall instructions.lnk (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\About Us.lnk (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\customer support.lnk (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\shopperreports uninstall instructions.lnk (Adware.ShopperReports) -> No action taken.



That is all the information i have for right now. I am currently scanning the computer with "Kaspersky Virus removal tool" it was a download that i got from the official site. But the scan is taken quite a long time to finish, so ill post that log when ever its done. I know you do no want me to run any programs that can interfer with your tools, so if you want me to stop the scan, just say so and ill follow your instructions on the removal of these maleware infections.

Thanks!

Attachments:

I just wanted to note, not to confuse the situation. Despite what the log says on MBAM. I did save the log file before i deleted the files, thats why it says "no action taken" how ever i successfully deleted all the entries that it found, after which i rebooted the machine and ran another scan with MBAM and it found nothing. But it originally there was 73 infected entries. I am also currently still scanning with kaspersky, its taking a long while but it did bring up a few infections with a window where it prompted me to delete the archive so i did so and its still scanning. So apparently MBAM didn't completely remove everything.
Turns out the kaspersky found 356 infections which apparently i wasn't able to move until i bought the program. There was no log file to save which is unusual. Maybe this application that i ran was a fake program and not the real kaspersky but i got the link directly from this site in one of my previous posts. OH yeah another thing is that some how the computer transferred all files that i was downloading to my hidden "app" folder on the HD. When i did a scan most of the infected files came from that hidden "app" folder. Anyways, still waiting for a reply. At this point i won't do any more work on the pc cause ive done all i can for the time being.
Hi,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
wow, the log shown up but i can't open up firefox or IE any more. It says "illegal operation performed on a registery key that may of been deleted" This never was an issue before so assuming combo fix deleted a critical registry value. In any case, i have the log file saved on the desktop. But i can't open up internet to send it to you. I am actually typing this message on my other computer.
Ok well i rebooted the computer and i guess that fixed it. The log is saying that my zone alarm was turned on, when i know for a fact i disabled it. Just right click the system tray and turn it off.

Anyways here is the log.



ComboFix 11-06-29.06 - Ashley 07/02/2011 22:57:33.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.1101 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
FW: ZoneAlarm Firewall *Enabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-06-03 to 2011-07-03 )))))))))))))))))))))))))))))))
.
.
2011-07-03 05:54 . 2011-07-03 05:54 ——– d—–w- c:\users\Chuck\AppData\Roaming\CheckPoint
2011-07-03 03:14 . 2011-07-03 03:14 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D0DA4AA5-68D2-478C-8E7B-151BACD344C7}\MpKsl6aadfddb.sys
2011-07-03 03:14 . 2011-06-07 15:55 7074640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D0DA4AA5-68D2-478C-8E7B-151BACD344C7}\mpengine.dll
2011-06-30 18:55 . 2011-06-30 18:55 ——– d—–w- c:\users\Ashley\AppData\Roaming\CheckPoint
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\program files\Conduit
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\users\Ashley\AppData\Local\Conduit
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\program files\ZoneAlarm_Security
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\program files\CheckPoint
2011-06-30 18:54 . 2011-03-18 08:24 69120 —-a-w- c:\windows\system32\zlcomm.dll
2011-06-30 18:54 . 2011-03-18 08:24 104448 —-a-w- c:\windows\system32\zlcommdb.dll
2011-06-30 18:53 . 2011-03-18 08:24 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2011-06-30 18:53 . 2011-06-30 18:55 ——– d—–w- c:\windows\system32\ZoneLabs
2011-06-30 18:53 . 2010-05-15 23:30 461400 —-a-w- c:\windows\system32\drivers\vsdatant.sys
2011-06-30 18:53 . 2011-06-30 18:53 ——– d—–w- c:\program files\Zone Labs
2011-06-30 18:53 . 2011-06-30 18:53 ——– d—–w- c:\programdata\CheckPoint
2011-06-30 18:53 . 2011-07-03 05:59 ——– d—–w- c:\windows\Internet Logs
2011-06-30 16:00 . 2011-06-30 16:01 ——– d—–w- c:\users\Ashley\AppData\Roaming\Auslogics
2011-06-30 16:00 . 2011-06-30 19:01 ——– d—–w- c:\program files\Auslogics
2011-06-30 15:59 . 2011-06-30 15:59 ——– d—–w- c:\program files\Common Files\Adobe
2011-06-30 15:57 . 2011-06-30 15:57 ——– d—–w- c:\program files\Common Files\Java
2011-06-30 15:57 . 2011-05-04 11:52 476904 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-06-30 15:48 . 2011-06-30 15:48 7168 —-a-w- c:\windows\system32\drivers\utewntc4.sys
2011-06-30 00:10 . 2011-06-30 15:51 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2011-06-30 00:10 . 2011-06-30 00:12 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-06-29 18:58 . 2011-05-29 16:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-29 18:58 . 2011-05-29 16:11 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-29 18:57 . 2011-06-30 15:52 ——– d—–w- c:\programdata\Kaspersky Lab
2011-06-29 18:57 . 2009-10-22 20:54 37392 —-a-w- c:\windows\system32\drivers\72481612.sys
2011-06-29 18:57 . 2009-10-10 06:31 311312 —-a-w- c:\windows\system32\drivers\7248161.sys
2011-06-29 18:57 . 2009-09-26 00:59 128016 —-a-w- c:\windows\system32\drivers\72481611.sys
2011-06-29 18:15 . 2011-06-29 18:15 ——– d—–w- c:\windows\Sun
2011-06-29 00:30 . 2011-05-24 10:44 293376 —-a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 00:30 . 2011-05-04 04:34 1549312 —-a-w- c:\windows\system32\tquery.dll
2011-06-29 00:30 . 2011-05-04 04:32 337408 —-a-w- c:\windows\system32\mssph.dll
2011-06-29 00:30 . 2011-05-04 04:32 1401344 —-a-w- c:\windows\system32\mssrch.dll
2011-06-29 00:30 . 2011-05-04 04:28 427520 —-a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 00:30 . 2011-05-04 04:28 164352 —-a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 00:30 . 2011-05-04 04:32 666624 —-a-w- c:\windows\system32\mssvp.dll
2011-06-29 00:30 . 2011-05-04 04:32 197120 —-a-w- c:\windows\system32\mssphtb.dll
2011-06-29 00:30 . 2011-05-04 04:32 59392 —-a-w- c:\windows\system32\msscntrs.dll
2011-06-29 00:30 . 2011-05-04 04:28 86528 —-a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-27 18:49 . 2011-06-27 18:49 ——– d—–w- c:\users\Kristi\AppData\Local\Mozilla
2011-06-22 21:45 . 2011-06-22 21:45 ——– d—–w- c:\windows\system32\SPReview
2011-06-22 21:44 . 2011-06-22 21:44 ——– d—–w- c:\windows\system32\EventProviders
2011-06-20 21:05 . 2010-11-05 01:58 1130824 —-a-w- c:\windows\system32\dfshim.dll
2011-06-20 21:03 . 2010-11-20 12:30 40704 —-a-w- c:\windows\system32\drivers\vmstorfl.sys
2011-06-20 21:02 . 2010-11-20 12:21 351232 —-a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-20 21:02 . 2010-11-20 12:21 780288 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-20 21:02 . 2010-11-20 12:21 363008 —-a-w- c:\windows\system32\wbemcomn.dll
2011-06-20 21:02 . 2010-11-20 12:19 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll
2011-06-20 21:02 . 2010-11-20 12:21 697344 —-a-w- c:\windows\system32\SmiEngine.dll
2011-06-20 21:02 . 2010-11-20 12:21 189952 —-a-w- c:\windows\system32\wdscore.dll
2011-06-20 21:02 . 2010-11-20 12:17 209920 —-a-w- c:\windows\system32\PkgMgr.exe
2011-06-20 21:02 . 2010-11-20 12:18 323072 —-a-w- c:\windows\system32\drvstore.dll
2011-06-20 21:02 . 2010-11-20 12:18 257024 —-a-w- c:\windows\system32\dpx.dll
2011-06-19 18:51 . 2011-06-19 18:51 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2011-06-19 18:51 . 2011-06-19 18:51 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-06-19 18:31 . 2011-06-19 18:31 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-06-19 18:31 . 2011-06-19 18:31 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-06-17 22:04 . 2011-06-17 22:04 ——– d—–w- c:\programdata\KingsIsle Entertainment
2011-06-17 22:04 . 2011-06-17 22:04 ——– d–h–w- c:\program files\InstallShield Installation Information
2011-06-13 03:50 . 2011-06-29 17:46 ——– d—–w- c:\program files\QuestScan
2011-06-12 06:43 . 2011-06-12 07:23 ——– d—–w- c:\users\Ashley\AppData\Roaming\Vso
2011-06-12 06:43 . 2009-09-02 20:44 65602 —-a-w- c:\windows\system32\cook3260.dll
2011-06-12 06:43 . 2009-09-02 20:44 626688 —-a-w- c:\windows\system32\vp7vfw.dll
2011-06-12 06:43 . 2009-09-02 20:44 217127 —-a-w- c:\windows\system32\drv43260.dll
2011-06-12 06:43 . 2009-09-02 20:44 208935 —-a-w- c:\windows\system32\drv33260.dll
2011-06-12 06:43 . 2009-09-02 20:44 176165 —-a-w- c:\windows\system32\drv23260.dll
2011-06-12 06:43 . 2009-09-02 20:44 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll
2011-06-12 06:43 . 2009-09-02 20:44 102439 —-a-w- c:\windows\system32\sipr3260.dll
2011-06-12 06:43 . 2011-06-12 06:43 ——– d—–w- c:\program files\VSO
2011-06-06 19:55 . 2011-06-06 19:55 183696 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-22 21:50 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll
2011-06-07 15:55 . 2011-04-29 02:31 7074640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-30 05:27 . 2011-05-19 16:38 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-04 11:52 . 2011-04-28 03:29 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-28 00:49 . 2011-05-20 16:43 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-04-28 00:49 . 2011-05-20 16:42 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3C590010-82FA-459F-80F1-BAC322905B57}\gapaengine.dll
2011-04-22 19:14 . 2011-05-24 20:21 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-13 22:02 . 2011-04-13 22:02 40984 —-a-w- c:\windows\system32\drivers\point32.sys
2011-04-13 22:02 . 2011-04-13 22:02 1461992 —-a-w- c:\windows\system32\wdfcoinstaller01009.dll
2011-04-09 06:02 . 2011-05-10 20:54 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-10 20:54 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:02 . 2011-04-09 06:02 390656 —-a-w- c:\windows\system32\ipcoin815.dll
2011-04-09 05:56 . 2011-05-19 02:44 123904 —-a-w- c:\windows\system32\poqexec.exe
2011-06-16 04:17 . 2011-06-29 16:34 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
2011-03-28 16:22 176936 —-a-w- c:\program files\ZoneAlarm_Security\prxtbZone.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 1808784]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-18 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-02-15 738808]
.
c:\users\Chuck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 MpKsla61174da;MpKsla61174da;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0382905C-9D84-4647-AF68-3C55B1C5A1A1}\MpKsla61174da.sys [x]
R1 MpKsle07eb13f;MpKsle07eb13f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D40D2A58-B1A5-4ECE-8C9C-39526D01A169}\MpKsle07eb13f.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 utewntc4;AVZ Kernel Driver;c:\windows\system32\Drivers\utewntc4.sys [2011-06-30 7168]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-29 1343400]
S0 72481612;72481612 Boot Guard Driver;c:\windows\system32\DRIVERS\72481612.sys [2009-10-22 37392]
S1 72481611;72481611;c:\windows\system32\DRIVERS\72481611.sys [2009-09-26 128016]
S1 MpKsl6aadfddb;MpKsl6aadfddb;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D0DA4AA5-68D2-478C-8E7B-151BACD344C7}\MpKsl6aadfddb.sys [2011-07-03 28752]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2011-02-15 26872]
S2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2011-02-15 488952]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL6AADFDDB
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2645238
TCP: DhcpNameServer = 192.168.0.1 [removed]
FF - ProfilePath - c:\users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\7em8o8q5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2645238&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(3948)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(516)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'Explorer.exe'(2284)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2011-07-02 23:02:16
ComboFix-quarantined-files.txt 2011-07-03 06:02
.
Pre-Run: 112,981,229,568 bytes free
Post-Run: 112,912,465,920 bytes free
.
- - End Of File - - 654C29683EAFDEEAA00537A0DBDBE662
Here is another log report, this time with everything disabled. Not sure if it will make a difference, but its best that i do it the correct way.


ComboFix 11-07-02.02 - Ashley 07/02/2011 23:21:57.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.1418 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
FW: ZoneAlarm Firewall *Disabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-06-03 to 2011-07-03 )))))))))))))))))))))))))))))))
.
.
2011-07-03 06:29 . 2011-07-03 06:29 ——– d—–w- c:\users\Kristi\AppData\Local\temp
2011-07-03 06:29 . 2011-07-03 06:29 ——– d—–w- c:\users\Guest\AppData\Local\temp
2011-07-03 06:29 . 2011-07-03 06:29 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-07-03 06:29 . 2011-07-03 06:29 ——– d—–w- c:\users\Chuck\AppData\Local\temp
2011-07-03 05:54 . 2011-07-03 05:54 ——– d—–w- c:\users\Chuck\AppData\Roaming\CheckPoint
2011-07-03 03:14 . 2011-06-07 15:55 7074640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D0DA4AA5-68D2-478C-8E7B-151BACD344C7}\mpengine.dll
2011-06-30 18:55 . 2011-06-30 18:55 ——– d—–w- c:\users\Ashley\AppData\Roaming\CheckPoint
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\program files\Conduit
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\users\Ashley\AppData\Local\Conduit
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\program files\ZoneAlarm_Security
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\program files\CheckPoint
2011-06-30 18:54 . 2011-03-18 08:24 69120 —-a-w- c:\windows\system32\zlcomm.dll
2011-06-30 18:54 . 2011-03-18 08:24 104448 —-a-w- c:\windows\system32\zlcommdb.dll
2011-06-30 18:53 . 2011-03-18 08:24 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2011-06-30 18:53 . 2011-06-30 18:55 ——– d—–w- c:\windows\system32\ZoneLabs
2011-06-30 18:53 . 2010-05-15 23:30 461400 —-a-w- c:\windows\system32\drivers\vsdatant.sys
2011-06-30 18:53 . 2011-06-30 18:53 ——– d—–w- c:\program files\Zone Labs
2011-06-30 18:53 . 2011-06-30 18:53 ——– d—–w- c:\programdata\CheckPoint
2011-06-30 18:53 . 2011-07-03 06:18 ——– d—–w- c:\windows\Internet Logs
2011-06-30 16:00 . 2011-06-30 16:01 ——– d—–w- c:\users\Ashley\AppData\Roaming\Auslogics
2011-06-30 16:00 . 2011-06-30 19:01 ——– d—–w- c:\program files\Auslogics
2011-06-30 15:59 . 2011-06-30 15:59 ——– d—–w- c:\program files\Common Files\Adobe
2011-06-30 15:57 . 2011-06-30 15:57 ——– d—–w- c:\program files\Common Files\Java
2011-06-30 15:57 . 2011-05-04 11:52 476904 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-06-30 15:48 . 2011-06-30 15:48 7168 —-a-w- c:\windows\system32\drivers\utewntc4.sys
2011-06-30 00:10 . 2011-06-30 15:51 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2011-06-30 00:10 . 2011-06-30 00:12 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-06-29 18:58 . 2011-05-29 16:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-29 18:58 . 2011-05-29 16:11 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-29 18:57 . 2011-06-30 15:52 ——– d—–w- c:\programdata\Kaspersky Lab
2011-06-29 18:57 . 2009-10-22 20:54 37392 —-a-w- c:\windows\system32\drivers\72481612.sys
2011-06-29 18:57 . 2009-10-10 06:31 311312 —-a-w- c:\windows\system32\drivers\7248161.sys
2011-06-29 18:57 . 2009-09-26 00:59 128016 —-a-w- c:\windows\system32\drivers\72481611.sys
2011-06-29 18:15 . 2011-06-29 18:15 ——– d—–w- c:\windows\Sun
2011-06-29 00:30 . 2011-05-24 10:44 293376 —-a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 00:30 . 2011-05-04 04:34 1549312 —-a-w- c:\windows\system32\tquery.dll
2011-06-29 00:30 . 2011-05-04 04:32 337408 —-a-w- c:\windows\system32\mssph.dll
2011-06-29 00:30 . 2011-05-04 04:32 1401344 —-a-w- c:\windows\system32\mssrch.dll
2011-06-29 00:30 . 2011-05-04 04:28 427520 —-a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 00:30 . 2011-05-04 04:28 164352 —-a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 00:30 . 2011-05-04 04:32 666624 —-a-w- c:\windows\system32\mssvp.dll
2011-06-29 00:30 . 2011-05-04 04:32 197120 —-a-w- c:\windows\system32\mssphtb.dll
2011-06-29 00:30 . 2011-05-04 04:32 59392 —-a-w- c:\windows\system32\msscntrs.dll
2011-06-29 00:30 . 2011-05-04 04:28 86528 —-a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-27 18:49 . 2011-06-27 18:49 ——– d—–w- c:\users\Kristi\AppData\Local\Mozilla
2011-06-22 21:45 . 2011-06-22 21:45 ——– d—–w- c:\windows\system32\SPReview
2011-06-22 21:44 . 2011-06-22 21:44 ——– d—–w- c:\windows\system32\EventProviders
2011-06-20 21:05 . 2010-11-05 01:58 1130824 —-a-w- c:\windows\system32\dfshim.dll
2011-06-20 21:03 . 2010-11-20 12:30 40704 —-a-w- c:\windows\system32\drivers\vmstorfl.sys
2011-06-20 21:02 . 2010-11-20 12:21 351232 —-a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-20 21:02 . 2010-11-20 12:21 780288 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-20 21:02 . 2010-11-20 12:21 363008 —-a-w- c:\windows\system32\wbemcomn.dll
2011-06-20 21:02 . 2010-11-20 12:19 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll
2011-06-20 21:02 . 2010-11-20 12:21 697344 —-a-w- c:\windows\system32\SmiEngine.dll
2011-06-20 21:02 . 2010-11-20 12:21 189952 —-a-w- c:\windows\system32\wdscore.dll
2011-06-20 21:02 . 2010-11-20 12:17 209920 —-a-w- c:\windows\system32\PkgMgr.exe
2011-06-20 21:02 . 2010-11-20 12:18 323072 —-a-w- c:\windows\system32\drvstore.dll
2011-06-20 21:02 . 2010-11-20 12:18 257024 —-a-w- c:\windows\system32\dpx.dll
2011-06-19 18:51 . 2011-06-19 18:51 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2011-06-19 18:51 . 2011-06-19 18:51 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-06-19 18:31 . 2011-06-19 18:31 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-06-19 18:31 . 2011-06-19 18:31 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-06-17 22:04 . 2011-06-17 22:04 ——– d—–w- c:\programdata\KingsIsle Entertainment
2011-06-17 22:04 . 2011-06-17 22:04 ——– d–h–w- c:\program files\InstallShield Installation Information
2011-06-13 03:50 . 2011-06-29 17:46 ——– d—–w- c:\program files\QuestScan
2011-06-12 06:43 . 2011-06-12 07:23 ——– d—–w- c:\users\Ashley\AppData\Roaming\Vso
2011-06-12 06:43 . 2009-09-02 20:44 65602 —-a-w- c:\windows\system32\cook3260.dll
2011-06-12 06:43 . 2009-09-02 20:44 626688 —-a-w- c:\windows\system32\vp7vfw.dll
2011-06-12 06:43 . 2009-09-02 20:44 217127 —-a-w- c:\windows\system32\drv43260.dll
2011-06-12 06:43 . 2009-09-02 20:44 208935 —-a-w- c:\windows\system32\drv33260.dll
2011-06-12 06:43 . 2009-09-02 20:44 176165 —-a-w- c:\windows\system32\drv23260.dll
2011-06-12 06:43 . 2009-09-02 20:44 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll
2011-06-12 06:43 . 2009-09-02 20:44 102439 —-a-w- c:\windows\system32\sipr3260.dll
2011-06-12 06:43 . 2011-06-12 06:43 ——– d—–w- c:\program files\VSO
2011-06-06 19:55 . 2011-06-06 19:55 183696 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-22 21:50 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll
2011-06-07 15:55 . 2011-04-29 02:31 7074640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-30 05:27 . 2011-05-19 16:38 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-04 11:52 . 2011-04-28 03:29 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-28 00:49 . 2011-05-20 16:43 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-04-28 00:49 . 2011-05-20 16:42 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3C590010-82FA-459F-80F1-BAC322905B57}\gapaengine.dll
2011-04-22 19:14 . 2011-05-24 20:21 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-13 22:02 . 2011-04-13 22:02 40984 —-a-w- c:\windows\system32\drivers\point32.sys
2011-04-13 22:02 . 2011-04-13 22:02 1461992 —-a-w- c:\windows\system32\wdfcoinstaller01009.dll
2011-04-09 06:02 . 2011-05-10 20:54 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-10 20:54 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:02 . 2011-04-09 06:02 390656 —-a-w- c:\windows\system32\ipcoin815.dll
2011-04-09 05:56 . 2011-05-19 02:44 123904 —-a-w- c:\windows\system32\poqexec.exe
2011-06-16 04:17 . 2011-06-29 16:34 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
2011-03-28 16:22 176936 —-a-w- c:\program files\ZoneAlarm_Security\prxtbZone.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 1808784]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-18 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-02-15 738808]
.
c:\users\Chuck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 MpKsla61174da;MpKsla61174da;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0382905C-9D84-4647-AF68-3C55B1C5A1A1}\MpKsla61174da.sys [x]
R1 MpKsle07eb13f;MpKsle07eb13f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D40D2A58-B1A5-4ECE-8C9C-39526D01A169}\MpKsle07eb13f.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 utewntc4;AVZ Kernel Driver;c:\windows\system32\Drivers\utewntc4.sys [2011-06-30 7168]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-29 1343400]
S0 72481612;72481612 Boot Guard Driver;c:\windows\system32\DRIVERS\72481612.sys [2009-10-22 37392]
S1 72481611;72481611;c:\windows\system32\DRIVERS\72481611.sys [2009-09-26 128016]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2011-02-15 26872]
S2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2011-02-15 488952]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2645238
TCP: DhcpNameServer = 192.168.0.1 [removed]
FF - ProfilePath - c:\users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\7em8o8q5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2645238&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(512)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'Explorer.exe'(1776)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2011-07-02 23:30:37
ComboFix-quarantined-files.txt 2011-07-03 06:30
ComboFix2.txt 2011-07-03 06:02
.
Pre-Run: 113,049,354,240 bytes free
Post-Run: 113,005,789,184 bytes free
.
- - End Of File - - BC31F53BF76B8C126C24D5FC9DB12F6A
Hi

Please do the following

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Like i mentioned before, the scan results for MBAM, didn't show anything, i scanned again just to make sure, but no infections. Here is the log report for SCET scan. C:\Users\Ashley\Desktop\avc-free.exe Win32/OpenCandy application F:\back up\Desktop\avc-free.exe Win32/OpenCandy application F:\Program Files\Search Toolbar\SearchToolbar.dll Win32/Toolbar.Zugo application F:\Users\Ashley\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\68b74c9f-26d254d4 probably a variant of Java/Agent.BR trojan F:\Users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\zs3w14vm.default\extensions\[removed]\chrome\content\overlay.js Win32/Adware.GamePlayLabs application F:\Users\Ashley\Downloads\BrowserPlugin.exe a variant of Win32/Adware.GamePlayLabs application F:\Users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\9xyi8uf9.default\extensions\[removed]\chrome\content\overlay.js Win32/Adware.GamePlayLabs application
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
F:\Program Files\Search Toolbar\SearchToolbar.dll 
F:\Users\Ashley\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\68b74c9f-26d254d4 
F:\Users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\zs3w14vm.default\extensions\[removed]\chrome\content\overlay.js 
F:\Users\Ashley\Downloads\BrowserPlugin.exe 
F:\Users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\9xyi8uf9.default\extensions\[removed]\chrome\content\overlay.js

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT


Visit ADOBEand download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 24 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Java cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT

Please advise how the computer is running now and if there are any outstanding issues
Ok here is combofix's log



ComboFix 11-07-03.04 - Ashley 07/04/2011 7:24.3.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.1102 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Ashley\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
FW: ZoneAlarm Firewall *Disabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"f:\program files\Search Toolbar\SearchToolbar.dll"
"f:\users\Ashley\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\68b74c9f-26d254d4"
"f:\users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\zs3w14vm.default\extensions\[removed]\chrome\content\overlay.js"
"f:\users\Ashley\Downloads\BrowserPlugin.exe"
"f:\users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\9xyi8uf9.default\extensions\[removed]\chrome\content\overlay.js"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
f:\program files\Search Toolbar\SearchToolbar.dll
f:\users\Ashley\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\68b74c9f-26d254d4
f:\users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\zs3w14vm.default\extensions\[removed]\chrome\content\overlay.js
f:\users\Ashley\Downloads\BrowserPlugin.exe
f:\users\Chuck\AppData\Roaming\Mozilla\Firefox\Profiles\9xyi8uf9.default\extensions\[removed]\chrome\content\overlay.js
.
.
((((((((((((((((((((((((( Files Created from 2011-06-04 to 2011-07-04 )))))))))))))))))))))))))))))))
.
.
2011-07-04 14:27 . 2011-07-04 14:27 ——– d—–w- c:\users\Kristi\AppData\Local\temp
2011-07-04 14:27 . 2011-07-04 14:27 ——– d—–w- c:\users\Guest\AppData\Local\temp
2011-07-04 14:27 . 2011-07-04 14:27 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-07-04 14:27 . 2011-07-04 14:27 ——– d—–w- c:\users\Chuck\AppData\Local\temp
2011-07-04 06:38 . 2011-06-07 15:55 7074640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4195F513-0D18-4DEA-B824-CF1A7756FA59}\mpengine.dll
2011-07-03 19:31 . 2011-07-03 19:31 ——– d—–w- c:\program files\ESET
2011-07-03 05:54 . 2011-07-03 05:54 ——– d—–w- c:\users\Chuck\AppData\Roaming\CheckPoint
2011-06-30 18:55 . 2011-06-30 18:55 ——– d—–w- c:\users\Ashley\AppData\Roaming\CheckPoint
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\program files\Conduit
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\users\Ashley\AppData\Local\Conduit
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\program files\ZoneAlarm_Security
2011-06-30 18:54 . 2011-06-30 18:54 ——– d—–w- c:\program files\CheckPoint
2011-06-30 18:54 . 2011-03-18 08:24 69120 —-a-w- c:\windows\system32\zlcomm.dll
2011-06-30 18:54 . 2011-03-18 08:24 104448 —-a-w- c:\windows\system32\zlcommdb.dll
2011-06-30 18:53 . 2011-03-18 08:24 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2011-06-30 18:53 . 2011-06-30 18:55 ——– d—–w- c:\windows\system32\ZoneLabs
2011-06-30 18:53 . 2010-05-15 23:30 461400 —-a-w- c:\windows\system32\drivers\vsdatant.sys
2011-06-30 18:53 . 2011-06-30 18:53 ——– d—–w- c:\program files\Zone Labs
2011-06-30 18:53 . 2011-06-30 18:53 ——– d—–w- c:\programdata\CheckPoint
2011-06-30 18:53 . 2011-07-03 19:31 ——– d—–w- c:\windows\Internet Logs
2011-06-30 16:00 . 2011-06-30 16:01 ——– d—–w- c:\users\Ashley\AppData\Roaming\Auslogics
2011-06-30 16:00 . 2011-06-30 19:01 ——– d—–w- c:\program files\Auslogics
2011-06-30 15:59 . 2011-06-30 15:59 ——– d—–w- c:\program files\Common Files\Adobe
2011-06-30 15:57 . 2011-06-30 15:57 ——– d—–w- c:\program files\Common Files\Java
2011-06-30 15:57 . 2011-05-04 11:52 476904 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-06-30 15:48 . 2011-06-30 15:48 7168 —-a-w- c:\windows\system32\drivers\utewntc4.sys
2011-06-30 00:10 . 2011-06-30 15:51 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2011-06-30 00:10 . 2011-06-30 00:12 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-06-29 18:58 . 2011-05-29 16:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-29 18:58 . 2011-05-29 16:11 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-29 18:57 . 2011-06-30 15:52 ——– d—–w- c:\programdata\Kaspersky Lab
2011-06-29 18:57 . 2009-10-22 20:54 37392 —-a-w- c:\windows\system32\drivers\72481612.sys
2011-06-29 18:57 . 2009-10-10 06:31 311312 —-a-w- c:\windows\system32\drivers\7248161.sys
2011-06-29 18:57 . 2009-09-26 00:59 128016 —-a-w- c:\windows\system32\drivers\72481611.sys
2011-06-29 18:15 . 2011-06-29 18:15 ——– d—–w- c:\windows\Sun
2011-06-29 00:30 . 2011-05-24 10:44 293376 —-a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 00:30 . 2011-05-04 04:34 1549312 —-a-w- c:\windows\system32\tquery.dll
2011-06-29 00:30 . 2011-05-04 04:32 337408 —-a-w- c:\windows\system32\mssph.dll
2011-06-29 00:30 . 2011-05-04 04:32 1401344 —-a-w- c:\windows\system32\mssrch.dll
2011-06-29 00:30 . 2011-05-04 04:28 427520 —-a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 00:30 . 2011-05-04 04:28 164352 —-a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 00:30 . 2011-05-04 04:32 666624 —-a-w- c:\windows\system32\mssvp.dll
2011-06-29 00:30 . 2011-05-04 04:32 197120 —-a-w- c:\windows\system32\mssphtb.dll
2011-06-29 00:30 . 2011-05-04 04:32 59392 —-a-w- c:\windows\system32\msscntrs.dll
2011-06-29 00:30 . 2011-05-04 04:28 86528 —-a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-27 18:49 . 2011-06-27 18:49 ——– d—–w- c:\users\Kristi\AppData\Local\Mozilla
2011-06-22 21:45 . 2011-06-22 21:45 ——– d—–w- c:\windows\system32\SPReview
2011-06-22 21:44 . 2011-06-22 21:44 ——– d—–w- c:\windows\system32\EventProviders
2011-06-20 21:05 . 2010-11-05 01:58 1130824 —-a-w- c:\windows\system32\dfshim.dll
2011-06-20 21:03 . 2010-11-20 12:30 40704 —-a-w- c:\windows\system32\drivers\vmstorfl.sys
2011-06-20 21:02 . 2010-11-20 12:21 351232 —-a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-20 21:02 . 2010-11-20 12:21 780288 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-20 21:02 . 2010-11-20 12:21 363008 —-a-w- c:\windows\system32\wbemcomn.dll
2011-06-20 21:02 . 2010-11-20 12:19 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll
2011-06-20 21:02 . 2010-11-20 12:21 697344 —-a-w- c:\windows\system32\SmiEngine.dll
2011-06-20 21:02 . 2010-11-20 12:21 189952 —-a-w- c:\windows\system32\wdscore.dll
2011-06-20 21:02 . 2010-11-20 12:17 209920 —-a-w- c:\windows\system32\PkgMgr.exe
2011-06-20 21:02 . 2010-11-20 12:18 323072 —-a-w- c:\windows\system32\drvstore.dll
2011-06-20 21:02 . 2010-11-20 12:18 257024 —-a-w- c:\windows\system32\dpx.dll
2011-06-19 18:51 . 2011-06-19 18:51 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2011-06-19 18:51 . 2011-06-19 18:51 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-06-19 18:31 . 2011-06-19 18:31 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-06-19 18:31 . 2011-06-19 18:31 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-06-17 22:04 . 2011-06-17 22:04 ——– d—–w- c:\programdata\KingsIsle Entertainment
2011-06-17 22:04 . 2011-06-17 22:04 ——– d–h–w- c:\program files\InstallShield Installation Information
2011-06-13 03:50 . 2011-06-29 17:46 ——– d—–w- c:\program files\QuestScan
2011-06-12 06:43 . 2011-06-12 07:23 ——– d—–w- c:\users\Ashley\AppData\Roaming\Vso
2011-06-12 06:43 . 2009-09-02 20:44 65602 —-a-w- c:\windows\system32\cook3260.dll
2011-06-12 06:43 . 2009-09-02 20:44 626688 —-a-w- c:\windows\system32\vp7vfw.dll
2011-06-12 06:43 . 2009-09-02 20:44 217127 —-a-w- c:\windows\system32\drv43260.dll
2011-06-12 06:43 . 2009-09-02 20:44 208935 —-a-w- c:\windows\system32\drv33260.dll
2011-06-12 06:43 . 2009-09-02 20:44 176165 —-a-w- c:\windows\system32\drv23260.dll
2011-06-12 06:43 . 2009-09-02 20:44 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll
2011-06-12 06:43 . 2009-09-02 20:44 102439 —-a-w- c:\windows\system32\sipr3260.dll
2011-06-12 06:43 . 2011-06-12 06:43 ——– d—–w- c:\program files\VSO
2011-06-06 19:55 . 2011-06-06 19:55 183696 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-22 21:50 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll
2011-06-07 15:55 . 2011-04-29 02:31 7074640 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-30 05:27 . 2011-05-19 16:38 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-04 11:52 . 2011-04-28 03:29 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-28 00:49 . 2011-05-20 16:43 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-04-28 00:49 . 2011-05-20 16:42 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3C590010-82FA-459F-80F1-BAC322905B57}\gapaengine.dll
2011-04-22 19:14 . 2011-05-24 20:21 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-13 22:02 . 2011-04-13 22:02 40984 —-a-w- c:\windows\system32\drivers\point32.sys
2011-04-13 22:02 . 2011-04-13 22:02 1461992 —-a-w- c:\windows\system32\wdfcoinstaller01009.dll
2011-04-09 06:02 . 2011-05-10 20:54 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02 . 2011-05-10 20:54 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:02 . 2011-04-09 06:02 390656 —-a-w- c:\windows\system32\ipcoin815.dll
2011-04-09 05:56 . 2011-05-19 02:44 123904 —-a-w- c:\windows\system32\poqexec.exe
2011-06-16 04:17 . 2011-06-29 16:34 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
2011-03-28 16:22 176936 —-a-w- c:\program files\ZoneAlarm_Security\prxtbZone.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 1808784]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-18 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-02-15 738808]
.
c:\users\Chuck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 MpKsla61174da;MpKsla61174da;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0382905C-9D84-4647-AF68-3C55B1C5A1A1}\MpKsla61174da.sys [x]
R1 MpKsle07eb13f;MpKsle07eb13f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D40D2A58-B1A5-4ECE-8C9C-39526D01A169}\MpKsle07eb13f.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 utewntc4;AVZ Kernel Driver;c:\windows\system32\Drivers\utewntc4.sys [2011-06-30 7168]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-29 1343400]
S0 72481612;72481612 Boot Guard Driver;c:\windows\system32\DRIVERS\72481612.sys [2009-10-22 37392]
S1 72481611;72481611;c:\windows\system32\DRIVERS\72481611.sys [2009-09-26 128016]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2011-02-15 26872]
S2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2011-02-15 488952]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2645238
TCP: DhcpNameServer = 192.168.0.1 [removed]
FF - ProfilePath - c:\users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\7em8o8q5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2645238&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=2&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(512)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2011-07-04 07:28:19
ComboFix-quarantined-files.txt 2011-07-04 14:28
ComboFix2.txt 2011-07-03 06:30
ComboFix3.txt 2011-07-03 06:02
.
Pre-Run: 112,618,643,456 bytes free
Post-Run: 112,569,098,240 bytes free
.
- - End Of File - - 9D7881589454D8F4AE73AE91A5A86B80


Well when i scanned it earlier with MBAM. I notice the bulk of the issues were absent after that. So i am assuming that scan got rid most of the infected files, how ever some files probably were still dorment and combo fix probably took care of the rest. As of now i don't see any outstanding issues with the machine. It seems to be running ok.

Though i would like to know exactly where the files were located, what URLS. And also how to block these URLS so my sister does not accidentally access those harmful websites again and i would like to relay this information to her and tell her to stay away from these area's on the internet. For example, a few of them i notice is "gamelabs", she has had that in the past multiple times, but what site is that. According to her she doesn't even recognize going to a site gamelabs.com. SO it must be a pop up of some sorts from a different URL address. Another one is"OPen candy application" Which was found in the folder for "ani video converter". A free harmless software that she uses to convert different file formats. Perhaps the ones that were causing the most harm was "shopper reports" and "MP3Tube". I am not sure where she got these from, but for some reason it kept redirecting the browser to its own home page called mp3tube.com and i wasn't even able to use firefox or any web browser to surf any website accept anything that was "shopper reports" related. It just redirected every URL with that domain name. Another one was "Adware.QuestScan" and there was also a "trojan agent" on the machine. I would like to know where all these files originated from so i can block certain URLS in the internet security settings.

Both Java and adobe reader are actually fully updated already.


It really is impossible to know exactly where these infections come from, adware is usually attached to free downloads of various programs etc. a lot of infections come from using torrents and peer to peer programs, I strongly suggest using the Web of Trust that I will be linking to below,

just house keeping to do now

please do the following:



You can delete the DDS and aswMBR logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Nothing is impossible as far as im concerned. When working with computers, especially in the field of internet security or removal of maleware in any given situation, there is always a solution to these things. That is what i have learned. Every virus, maleware, has a pathway from which it came from. It doesn't just appear out of thin air, thats what i think. If i could trace the source or directory, folders, etc of where this virus came from. I can then block that particular URL. I remember using a firewall before called Comodo internet security. It does a really great job of actually blocking all incoming and outgoing traffic and it traces the source and directory of where the infection comes from so you know automatically where you got it. Such as installing software, using any p2p sharing program, or browsing any internet. It also tracks each TCP and IP links so that if you download anything from a torrent file or any peer to peer sharing software, it will tell you which protocol to locate so you can then look on your program and find out which one it came from. Each p2p sharing software always details what TCP location your downloading from and if your able to track that through a file wall you can stop alot of these threats. The problem i have with comodo is for 1, it uses up a ton of CPU resources and 2. Its not very user friendly, it restricts alot of things you can do on the computer and that is kind of why i got rid of it. But in any case, im using the free zone alarm now so hopefully that will keep the computer clean and free of infections. As for p2p programs, there hasn't been any source of p2p file sharing on this computer in a very long time. So i don't think that is where the infections came from. Yes i have used web of trust, its a very reliable tool for surfing the web. I also used addblock+ for firefox, which is a VERY nice addon for firefox that disables alot of pop up adds. I also use killbox, if zone alarm detects anything, i use killbox and complete eradicate the file on the spot including the registry value. I used TFC to clean up my computer, cause it usually cleans all my cookies and internet files. It is a better application to use then just dumping temp files. I got it from this site and ive used it ever since to clean my computer of cookies every month or so. Thanks for your help!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI