jeff matthews
Topic Starter
Hi this is my sisters computer that i am working on. It has some maleware and virus related issues how ever some of the issues i managed to solve. When i first tried to service this computer and work on it, i noticed that mostly everything was not working, firefox was not launching at all. Download rates were usually slow. Just tried to reinstall firefox and dl a new version. It was downloading at 20kb/s. Normally my DL rate is around 150 kb/s for a single file. To proove that this was not a network issue, i tried the same thing on my computer. Absolutely no issues with DL rates or browsers not loading. IE was the only browser that i managed to load on this computer. How ever, any other site or links for that matter would not link to the appropriate URLS. It would siply come up with an error code, i forgot the code, but it cancled out the net and said something like "termination". I couldn't even launch ms configuration. I could not even boot the computer into safe mode. Programs were not even installing so i was completely limited to what i can do to fix this issue.
So i used the windows install disk and i executed a recover repair console. It indicating that your boot options have been changed and the repair feature will repair those boot options. I was then able to press F8 like normal and boot into safe mode with networking. Before this was not working. I have a few logs for you to go over so you can see. Based on my research on looking over these logs i can clearly see some infections are coming from this site called "Mp3tube" and something called "shopper reports" MP3tube was the first page that popped up when launching IE. I realized that both firefox and IE both were redirecting to this URL. Which is probably the cause of most of the infections.
How ever my sister some times goes to sites to get music downloads alot of times, so im not sure which source she is getting these infections from. I want to not only make sure the computer is clean but to also find the "source" of where these infections are eminatating from. This is extremely important as i can't always watch over what she browses though. So if you find any website, any applications that are the cause of these maleware intrusions. I can then relay this message to her and let her know not to go there or better yet, even block the URLS on the internet so she can't access them. So maybe you can help me limit access to the account for these URLS. She can still have admistrative rights to the computer, i just want to block these harmful websites, for future use, so she does not access them again.
First of off, here is my DDS log
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 13:26:12 on 2011-06-29
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.998 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\SearchIndexer.exe
C:\Users\Ashley\Desktop\Virus Removal Tool\setup_9.0.0.722_29.06.2011_21-06\setup_9.0.0.722_29.06.2011_21-06.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://mp3tubetoolbar.com/?tmp=toolbar_Mp3Tube_homepage&prt=pinballtbfour04ie&clid=23573e425387458fb5c2b1f9b76dd344
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\ashley\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\users\ashley\appdata\roaming\micros~1\windows\startm~1\programs\startup\setup_~1.lnk - c:\users\ashley\desktop\virus removal tool\setup_9.0.0.722_29.06.2011_21-06\startup.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{B2774F38-E956-4A48-8A89-372D806B599C} : DhcpNameServer = 192.168.0.1 [removed]
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\ashley\appdata\roaming\mozilla\firefox\profiles\7em8o8q5.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo-Mp3Tube
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/?r0=1309377316
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
.
—- FIREFOX POLICIES —-
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
============= SERVICES / DRIVERS ===============
.
R0 72481612;72481612 Boot Guard Driver;c:\windows\system32\drivers\72481612.sys [2011-6-29 37392]
R1 72481611;72481611;c:\windows\system32\drivers\72481611.sys [2011-6-29 128016]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsla61df759;MpKsla61df759;c:\programdata\microsoft\microsoft antimalware\definition updates\{f31d551c-2899-4f13-b7a7-4229baa4a5ad}\MpKsla61df759.sys [2011-6-29 28752]
R1 setup_9.0.0.722_29.06.2011_21-06drv;setup_9.0.0.722_29.06.2011_21-06drv;c:\windows\system32\drivers\7248161.sys [2011-6-29 311312]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-6-29 39984]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-6-20 15872]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-20 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-4-29 1343400]
.
=============== Created Last 30 ================
.
2011-06-29 20:01:26 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f31d551c-2899-4f13-b7a7-4229baa4a5ad}\MpKsla61df759.sys
2011-06-29 20:01:01 7074640 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f31d551c-2899-4f13-b7a7-4229baa4a5ad}\mpengine.dll
2011-06-29 18:58:30 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-29 18:58:27 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-29 18:57:25 ——– d—–w- c:\programdata\Kaspersky Lab
2011-06-29 18:57:03 37392 —-a-w- c:\windows\system32\drivers\72481612.sys
2011-06-29 18:57:03 311312 —-a-w- c:\windows\system32\drivers\7248161.sys
2011-06-29 18:57:03 128016 —-a-w- c:\windows\system32\drivers\72481611.sys
2011-06-29 00:30:32 293376 —-a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 00:30:28 427520 —-a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 00:30:28 337408 —-a-w- c:\windows\system32\mssph.dll
2011-06-29 00:30:28 164352 —-a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 00:30:28 1549312 —-a-w- c:\windows\system32\tquery.dll
2011-06-29 00:30:28 1401344 —-a-w- c:\windows\system32\mssrch.dll
2011-06-29 00:30:27 86528 —-a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-29 00:30:27 666624 —-a-w- c:\windows\system32\mssvp.dll
2011-06-29 00:30:27 59392 —-a-w- c:\windows\system32\msscntrs.dll
2011-06-29 00:30:27 197120 —-a-w- c:\windows\system32\mssphtb.dll
2011-06-22 21:45:36 ——– d—–w- c:\windows\system32\SPReview
2011-06-22 21:44:47 ——– d—–w- c:\windows\system32\EventProviders
2011-06-20 21:05:02 1130824 —-a-w- c:\windows\system32\dfshim.dll
2011-06-20 21:03:59 673040 —-a-w- c:\program files\internet explorer\iexplore.exe
2011-06-20 21:02:53 780288 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-20 21:02:53 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll
2011-06-20 21:02:53 363008 —-a-w- c:\windows\system32\wbemcomn.dll
2011-06-20 21:02:53 351232 —-a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-20 21:02:45 697344 —-a-w- c:\windows\system32\SmiEngine.dll
2011-06-20 21:02:41 209920 —-a-w- c:\windows\system32\PkgMgr.exe
2011-06-20 21:02:41 189952 —-a-w- c:\windows\system32\wdscore.dll
2011-06-20 21:02:24 323072 —-a-w- c:\windows\system32\drvstore.dll
2011-06-20 21:02:24 257024 —-a-w- c:\windows\system32\dpx.dll
2011-06-19 18:51:34 737072 —-a-w- c:\programdata\microsoft\ehome\packages\sportsv2\sportstemplatecore\Microsoft.MediaCenter.Sports.UI.dll
2011-06-19 18:51:05 4283672 —-a-w- c:\programdata\microsoft\ehome\packages\mceclientux\updateablemarkup\markup.dll
2011-06-19 18:31:42 42776 —-a-w- c:\programdata\microsoft\ehome\packages\mceclientux\dsm\StartResources.dll
2011-06-19 18:31:37 539968 —-a-w- c:\programdata\microsoft\ehome\packages\mcespotlight\mcespotlight\SpotlightResources.dll
2011-06-17 22:04:58 ——– d—–w- c:\programdata\KingsIsle Entertainment
2011-06-13 03:50:27 ——– d—–w- c:\program files\QuestScan
2011-06-12 06:43:14 65602 —-a-w- c:\windows\system32\cook3260.dll
2011-06-12 06:43:14 626688 —-a-w- c:\windows\system32\vp7vfw.dll
2011-06-12 06:43:14 217127 —-a-w- c:\windows\system32\drv43260.dll
2011-06-12 06:43:14 208935 —-a-w- c:\windows\system32\drv33260.dll
2011-06-12 06:43:14 176165 —-a-w- c:\windows\system32\drv23260.dll
2011-06-12 06:43:14 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll
2011-06-12 06:43:14 102439 —-a-w- c:\windows\system32\sipr3260.dll
2011-06-12 06:43:12 ——– d—–w- c:\program files\VSO
2011-06-07 19:35:34 103864 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2011-06-01 06:31:06 ——– d—–w- c:\programdata\vsosdk
2011-06-01 04:43:35 ——– d—–w- c:\users\ashley\appdata\roaming\DVDFab
2011-06-01 04:32:03 ——– d—–w- c:\program files\DVDFab 8 Qt
.
==================== Find3M ====================
.
2011-06-22 21:50:48 152576 —-a-w- c:\windows\system32\msclmd.dll
2011-05-30 05:27:23 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-28 02:53:58 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-05-03 04:30:02 741376 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 02:46:33 311808 —-a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 02:46:15 310272 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 02:46:10 114688 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:17:36 223744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:17:28 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-27 02:17:22 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 04:31:30 1290624 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:18:03 338944 —-a-w- c:\windows\system32\drivers\afd.sys
2011-04-22 19:14:16 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-22 19:10:01 981504 —-a-w- c:\windows\system32\wininet.dll
2011-04-13 22:02:36 40984 —-a-w- c:\windows\system32\drivers\point32.sys
2011-04-13 22:02:36 1461992 —-a-w- c:\windows\system32\wdfcoinstaller01009.dll
2011-04-09 06:02:25 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02:25 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:02:04 390656 —-a-w- c:\windows\system32\ipcoin815.dll
2011-04-09 05:56:38 123904 —-a-w- c:\windows\system32\poqexec.exe
.
============= FINISH: 13:26:58.46 ===============
Next here is my MBAM Log file
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6978
Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 8.0.7601.17514
6/29/2011 12:48:18 PM
mbam-log-2011-06-29 (12-48-10).txt
Scan type: Full scan (C:\|E:\|F:\|G:\|)
Objects scanned: 406033
Time elapsed: 41 minute(s), 20 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 73
Registry Values Infected: 6
Registry Data Items Infected: 0
Folders Infected: 21
Files Infected: 26
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{0D82ACD6-A652-4496-A298-2BDE705F4227} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{7025E484-D4B0-441a-9F0B-69063BD679CE} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{396CFC12-932D-496b-A0A8-5D7201E105E1} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{573F4ABB-A1A2-44ED-9BA9-A8DAD40AAC46} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{71E02280-5212-45C3-B174-4D5A35DA254F} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaNvgtnTrpr.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaNvgtnTrpr (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4D1EC4CA-4B92-4324-B8F8-C9A6ED06A8AE} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{6F098504-CDB1-420F-A2E6-DDC0B835FEDF} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.Info.1 (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.Info (Adware.Hotbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4D1EC4CA-4B92-4324-B8F8-C9A6ED06A8AE} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4E674574-3F0B-491d-8AE3-F90B43A34FD6} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.UserProfiles.1 (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.UserProfiles (Adware.Hotbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4E674574-3F0B-491D-8AE3-F90B43A34FD6} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{74C22317-5B90-471f-9AD2-FEC049870A16} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Scopes.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Scopes (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{ACC62306-9A63-4864-BD2F-C8825D2D7EA6} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{21BA420E-161C-413A-B21E-4E42AE1F4226} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF} (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89F88394-3828-4d03-A0CF-8203604C3DA6} (Adware.Hotbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4233F04-1789-483c-A137-731E8F113DD5} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.AsyncReporter (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.AsyncReporter.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Dwnldr (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Dwnldr.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbAx (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbAx.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbGuru (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbGuru.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbInfoBand (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbInfoBand.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButton (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButton.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButtonA (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButtonA.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaPSExecuter (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaPSExecuter.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.ReportData (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.ReportData.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Reporter (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Reporter.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.RprtCtrl (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.RprtCtrl.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Stock (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Stock.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiate (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiate.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiateOrRandomTS (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiateOrRandomTS.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerOnceInDay (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerOnceInDay.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\AppID\BRNstIE.DLL (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\CmndFF.DLL (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\mozillaps.dll (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\Pltfrm.DLL (Adware.ClickPotato) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\Software\hblitesa (Adware.HotBar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\HBLite (Adware.HotBar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QuestScan Service (Adware.QuestScan) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> Value: {46897C77-E7A6-4C33-BFFB-E9C2E2718942} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> Value: {46897C77-E7A6-4C33-BFFB-E9C2E2718942} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\ShopperReports 3.1.69.0 (Adware.HotBar) -> Value: ShopperReports 3.1.69.0 -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\SRS_IT_E8790677B2765D563EA094 (Malware.Trace) -> Value: SRS_IT_E8790677B2765D563EA094 -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\[removed] (ShopperReports) -> Value: [removed] -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\[removed] (Adware.HotBar) -> Value: [removed] -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\programdata\2aca5cc3-0f83-453d-a079-1076fe1a8b65 (Adware.Seekmo) -> No action taken.
c:\Users\Ashley\AppData\Roaming\HBLite (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA (Adware.Hotbar) -> No action taken.
c:\Users\Ashley\AppData\Roaming\shopperreports3 (Adware.ShopperReports) -> No action taken.
c:\program files\HBLite (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0 (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions\plugins (Adware.Hotbar) -> No action taken.
c:\program files\shopperreports3 (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0 (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports (Adware.ShopperReports) -> No action taken.
Files Infected:
c:\program files\shopperreports3\bin\3.1.69.0\CmndFF.dll (Adware.ShopperReports) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\hblitesaax.dll (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions\plugins\npclntax_hblitesa.dll (Adware.Hotbar) -> No action taken.
c:\program files\mozilla firefox\plugins\npclntax_hblitesa.dll (Adware.Hotbar) -> No action taken.
c:\program files\questscan\questscan.dll (Adware.Agent.ZGen) -> No action taken.
c:\program files\questscan\questscan.exe (Adware.Agent.ZGen) -> No action taken.
c:\program files\mozilla firefox\searchplugins\Mp3Tube.xml (Adware.Mp3Tube) -> No action taken.
c:\programdata\HBLiteSA\HBLiteSA.dat (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesaabout.mht (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesaau.dat (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesaeula.mht (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesa_kyf_update.dat (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions\install.rdf (Adware.Hotbar) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\link.ico (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome.manifest (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\install.rdf (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content\infopane.js (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content\InfoPane.xul (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components\browserextensionff.dll (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components\browserextensionff.xpt (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar\about hotbar.lnk (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar\hotbar customer support center.lnk (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar\hotbar uninstall instructions.lnk (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\About Us.lnk (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\customer support.lnk (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\shopperreports uninstall instructions.lnk (Adware.ShopperReports) -> No action taken.
That is all the information i have for right now. I am currently scanning the computer with "Kaspersky Virus removal tool" it was a download that i got from the official site. But the scan is taken quite a long time to finish, so ill post that log when ever its done. I know you do no want me to run any programs that can interfer with your tools, so if you want me to stop the scan, just say so and ill follow your instructions on the removal of these maleware infections.
Thanks!
So i used the windows install disk and i executed a recover repair console. It indicating that your boot options have been changed and the repair feature will repair those boot options. I was then able to press F8 like normal and boot into safe mode with networking. Before this was not working. I have a few logs for you to go over so you can see. Based on my research on looking over these logs i can clearly see some infections are coming from this site called "Mp3tube" and something called "shopper reports" MP3tube was the first page that popped up when launching IE. I realized that both firefox and IE both were redirecting to this URL. Which is probably the cause of most of the infections.
How ever my sister some times goes to sites to get music downloads alot of times, so im not sure which source she is getting these infections from. I want to not only make sure the computer is clean but to also find the "source" of where these infections are eminatating from. This is extremely important as i can't always watch over what she browses though. So if you find any website, any applications that are the cause of these maleware intrusions. I can then relay this message to her and let her know not to go there or better yet, even block the URLS on the internet so she can't access them. So maybe you can help me limit access to the account for these URLS. She can still have admistrative rights to the computer, i just want to block these harmful websites, for future use, so she does not access them again.
First of off, here is my DDS log
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 13:26:12 on 2011-06-29
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.998 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\SearchIndexer.exe
C:\Users\Ashley\Desktop\Virus Removal Tool\setup_9.0.0.722_29.06.2011_21-06\setup_9.0.0.722_29.06.2011_21-06.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://mp3tubetoolbar.com/?tmp=toolbar_Mp3Tube_homepage&prt=pinballtbfour04ie&clid=23573e425387458fb5c2b1f9b76dd344
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\ashley\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\users\ashley\appdata\roaming\micros~1\windows\startm~1\programs\startup\setup_~1.lnk - c:\users\ashley\desktop\virus removal tool\setup_9.0.0.722_29.06.2011_21-06\startup.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{B2774F38-E956-4A48-8A89-372D806B599C} : DhcpNameServer = 192.168.0.1 [removed]
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\ashley\appdata\roaming\mozilla\firefox\profiles\7em8o8q5.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo-Mp3Tube
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/?r0=1309377316
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
.
—- FIREFOX POLICIES —-
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
============= SERVICES / DRIVERS ===============
.
R0 72481612;72481612 Boot Guard Driver;c:\windows\system32\drivers\72481612.sys [2011-6-29 37392]
R1 72481611;72481611;c:\windows\system32\drivers\72481611.sys [2011-6-29 128016]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsla61df759;MpKsla61df759;c:\programdata\microsoft\microsoft antimalware\definition updates\{f31d551c-2899-4f13-b7a7-4229baa4a5ad}\MpKsla61df759.sys [2011-6-29 28752]
R1 setup_9.0.0.722_29.06.2011_21-06drv;setup_9.0.0.722_29.06.2011_21-06drv;c:\windows\system32\drivers\7248161.sys [2011-6-29 311312]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-6-29 39984]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-6-20 15872]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-20 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-4-29 1343400]
.
=============== Created Last 30 ================
.
2011-06-29 20:01:26 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f31d551c-2899-4f13-b7a7-4229baa4a5ad}\MpKsla61df759.sys
2011-06-29 20:01:01 7074640 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f31d551c-2899-4f13-b7a7-4229baa4a5ad}\mpengine.dll
2011-06-29 18:58:30 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-29 18:58:27 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-29 18:57:25 ——– d—–w- c:\programdata\Kaspersky Lab
2011-06-29 18:57:03 37392 —-a-w- c:\windows\system32\drivers\72481612.sys
2011-06-29 18:57:03 311312 —-a-w- c:\windows\system32\drivers\7248161.sys
2011-06-29 18:57:03 128016 —-a-w- c:\windows\system32\drivers\72481611.sys
2011-06-29 00:30:32 293376 —-a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 00:30:28 427520 —-a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 00:30:28 337408 —-a-w- c:\windows\system32\mssph.dll
2011-06-29 00:30:28 164352 —-a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 00:30:28 1549312 —-a-w- c:\windows\system32\tquery.dll
2011-06-29 00:30:28 1401344 —-a-w- c:\windows\system32\mssrch.dll
2011-06-29 00:30:27 86528 —-a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-29 00:30:27 666624 —-a-w- c:\windows\system32\mssvp.dll
2011-06-29 00:30:27 59392 —-a-w- c:\windows\system32\msscntrs.dll
2011-06-29 00:30:27 197120 —-a-w- c:\windows\system32\mssphtb.dll
2011-06-22 21:45:36 ——– d—–w- c:\windows\system32\SPReview
2011-06-22 21:44:47 ——– d—–w- c:\windows\system32\EventProviders
2011-06-20 21:05:02 1130824 —-a-w- c:\windows\system32\dfshim.dll
2011-06-20 21:03:59 673040 —-a-w- c:\program files\internet explorer\iexplore.exe
2011-06-20 21:02:53 780288 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-20 21:02:53 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll
2011-06-20 21:02:53 363008 —-a-w- c:\windows\system32\wbemcomn.dll
2011-06-20 21:02:53 351232 —-a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-20 21:02:45 697344 —-a-w- c:\windows\system32\SmiEngine.dll
2011-06-20 21:02:41 209920 —-a-w- c:\windows\system32\PkgMgr.exe
2011-06-20 21:02:41 189952 —-a-w- c:\windows\system32\wdscore.dll
2011-06-20 21:02:24 323072 —-a-w- c:\windows\system32\drvstore.dll
2011-06-20 21:02:24 257024 —-a-w- c:\windows\system32\dpx.dll
2011-06-19 18:51:34 737072 —-a-w- c:\programdata\microsoft\ehome\packages\sportsv2\sportstemplatecore\Microsoft.MediaCenter.Sports.UI.dll
2011-06-19 18:51:05 4283672 —-a-w- c:\programdata\microsoft\ehome\packages\mceclientux\updateablemarkup\markup.dll
2011-06-19 18:31:42 42776 —-a-w- c:\programdata\microsoft\ehome\packages\mceclientux\dsm\StartResources.dll
2011-06-19 18:31:37 539968 —-a-w- c:\programdata\microsoft\ehome\packages\mcespotlight\mcespotlight\SpotlightResources.dll
2011-06-17 22:04:58 ——– d—–w- c:\programdata\KingsIsle Entertainment
2011-06-13 03:50:27 ——– d—–w- c:\program files\QuestScan
2011-06-12 06:43:14 65602 —-a-w- c:\windows\system32\cook3260.dll
2011-06-12 06:43:14 626688 —-a-w- c:\windows\system32\vp7vfw.dll
2011-06-12 06:43:14 217127 —-a-w- c:\windows\system32\drv43260.dll
2011-06-12 06:43:14 208935 —-a-w- c:\windows\system32\drv33260.dll
2011-06-12 06:43:14 176165 —-a-w- c:\windows\system32\drv23260.dll
2011-06-12 06:43:14 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll
2011-06-12 06:43:14 102439 —-a-w- c:\windows\system32\sipr3260.dll
2011-06-12 06:43:12 ——– d—–w- c:\program files\VSO
2011-06-07 19:35:34 103864 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2011-06-01 06:31:06 ——– d—–w- c:\programdata\vsosdk
2011-06-01 04:43:35 ——– d—–w- c:\users\ashley\appdata\roaming\DVDFab
2011-06-01 04:32:03 ——– d—–w- c:\program files\DVDFab 8 Qt
.
==================== Find3M ====================
.
2011-06-22 21:50:48 152576 —-a-w- c:\windows\system32\msclmd.dll
2011-05-30 05:27:23 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-28 02:53:58 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-05-03 04:30:02 741376 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 02:46:33 311808 —-a-w- c:\windows\system32\drivers\srv.sys
2011-04-29 02:46:15 310272 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 02:46:10 114688 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-27 02:17:36 223744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-27 02:17:28 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-27 02:17:22 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 04:31:30 1290624 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-04-25 02:18:03 338944 —-a-w- c:\windows\system32\drivers\afd.sys
2011-04-22 19:14:16 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-22 19:10:01 981504 —-a-w- c:\windows\system32\wininet.dll
2011-04-13 22:02:36 40984 —-a-w- c:\windows\system32\drivers\point32.sys
2011-04-13 22:02:36 1461992 —-a-w- c:\windows\system32\wdfcoinstaller01009.dll
2011-04-09 06:02:25 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02:25 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 06:02:04 390656 —-a-w- c:\windows\system32\ipcoin815.dll
2011-04-09 05:56:38 123904 —-a-w- c:\windows\system32\poqexec.exe
.
============= FINISH: 13:26:58.46 ===============
Next here is my MBAM Log file
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6978
Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 8.0.7601.17514
6/29/2011 12:48:18 PM
mbam-log-2011-06-29 (12-48-10).txt
Scan type: Full scan (C:\|E:\|F:\|G:\|)
Objects scanned: 406033
Time elapsed: 41 minute(s), 20 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 73
Registry Values Infected: 6
Registry Data Items Infected: 0
Folders Infected: 21
Files Infected: 26
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{0D82ACD6-A652-4496-A298-2BDE705F4227} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{7025E484-D4B0-441a-9F0B-69063BD679CE} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{396CFC12-932D-496b-A0A8-5D7201E105E1} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{573F4ABB-A1A2-44ED-9BA9-A8DAD40AAC46} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{71E02280-5212-45C3-B174-4D5A35DA254F} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaNvgtnTrpr.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaNvgtnTrpr (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4D1EC4CA-4B92-4324-B8F8-C9A6ED06A8AE} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{6F098504-CDB1-420F-A2E6-DDC0B835FEDF} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.Info.1 (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.Info (Adware.Hotbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4D1EC4CA-4B92-4324-B8F8-C9A6ED06A8AE} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4E674574-3F0B-491d-8AE3-F90B43A34FD6} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.UserProfiles.1 (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\HBLiteAX.UserProfiles (Adware.Hotbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4E674574-3F0B-491D-8AE3-F90B43A34FD6} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{74C22317-5B90-471f-9AD2-FEC049870A16} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Scopes.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Scopes (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{ACC62306-9A63-4864-BD2F-C8825D2D7EA6} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{21BA420E-161C-413A-B21E-4E42AE1F4226} (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{CDCA70D8-C6A6-49EE-9BED-7429D6C477A2} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{8AD9AD05-36BE-4E40-BA62-5422EB0D02FB} (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{D136987F-E1C4-4CCC-A220-893DF03EC5DF} (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89F88394-3828-4d03-A0CF-8203604C3DA6} (Adware.Hotbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4233F04-1789-483c-A137-731E8F113DD5} (Adware.Hotbar) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.AsyncReporter (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.AsyncReporter.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Dwnldr (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Dwnldr.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbAx (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbAx.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbGuru (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbGuru.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbInfoBand (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.HbInfoBand.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButton (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButton.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButtonA (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.IEButtonA.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaPSExecuter (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.MozillaPSExecuter.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.ReportData (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.ReportData.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Reporter (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Reporter.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.RprtCtrl (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.RprtCtrl.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Stock (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.Stock.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiate (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiate.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiateOrRandomTS (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerImmidiateOrRandomTS.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerOnceInDay (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\ShopperReports.TriggerOnceInDay.1 (Adware.ShopperReports) -> No action taken.
HKEY_CLASSES_ROOT\AppID\BRNstIE.DLL (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\CmndFF.DLL (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\mozillaps.dll (Adware.ClickPotato) -> No action taken.
HKEY_CLASSES_ROOT\AppID\Pltfrm.DLL (Adware.ClickPotato) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> No action taken.
HKEY_CURRENT_USER\Software\hblitesa (Adware.HotBar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\HBLite (Adware.HotBar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QuestScan Service (Adware.QuestScan) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> Value: {46897C77-E7A6-4C33-BFFB-E9C2E2718942} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{46897C77-E7A6-4C33-BFFB-E9C2E2718942} (Adware.Mp3Tube) -> Value: {46897C77-E7A6-4C33-BFFB-E9C2E2718942} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\ShopperReports 3.1.69.0 (Adware.HotBar) -> Value: ShopperReports 3.1.69.0 -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\SRS_IT_E8790677B2765D563EA094 (Malware.Trace) -> Value: SRS_IT_E8790677B2765D563EA094 -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\[removed] (ShopperReports) -> Value: [removed] -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\[removed] (Adware.HotBar) -> Value: [removed] -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\programdata\2aca5cc3-0f83-453d-a079-1076fe1a8b65 (Adware.Seekmo) -> No action taken.
c:\Users\Ashley\AppData\Roaming\HBLite (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA (Adware.Hotbar) -> No action taken.
c:\Users\Ashley\AppData\Roaming\shopperreports3 (Adware.ShopperReports) -> No action taken.
c:\program files\HBLite (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0 (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions\plugins (Adware.Hotbar) -> No action taken.
c:\program files\shopperreports3 (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0 (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports (Adware.ShopperReports) -> No action taken.
Files Infected:
c:\program files\shopperreports3\bin\3.1.69.0\CmndFF.dll (Adware.ShopperReports) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\hblitesaax.dll (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions\plugins\npclntax_hblitesa.dll (Adware.Hotbar) -> No action taken.
c:\program files\mozilla firefox\plugins\npclntax_hblitesa.dll (Adware.Hotbar) -> No action taken.
c:\program files\questscan\questscan.dll (Adware.Agent.ZGen) -> No action taken.
c:\program files\questscan\questscan.exe (Adware.Agent.ZGen) -> No action taken.
c:\program files\mozilla firefox\searchplugins\Mp3Tube.xml (Adware.Mp3Tube) -> No action taken.
c:\programdata\HBLiteSA\HBLiteSA.dat (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesaabout.mht (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesaau.dat (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesaeula.mht (Adware.Hotbar) -> No action taken.
c:\programdata\HBLiteSA\hblitesa_kyf_update.dat (Adware.Hotbar) -> No action taken.
c:\program files\HBLite\bin\11.0.363.0\firefox\extensions\install.rdf (Adware.Hotbar) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\link.ico (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome.manifest (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\install.rdf (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content\infopane.js (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\chrome\content\InfoPane.xul (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components\browserextensionff.dll (Adware.ShopperReports) -> No action taken.
c:\program files\shopperreports3\bin\3.1.69.0\firefox\firefoxtoolbar\extensions\components\browserextensionff.xpt (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar\about hotbar.lnk (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar\hotbar customer support center.lnk (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\Hotbar\hotbar uninstall instructions.lnk (Adware.Hotbar) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\About Us.lnk (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\customer support.lnk (Adware.ShopperReports) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\shopperreports\shopperreports uninstall instructions.lnk (Adware.ShopperReports) -> No action taken.
That is all the information i have for right now. I am currently scanning the computer with "Kaspersky Virus removal tool" it was a download that i got from the official site. But the scan is taken quite a long time to finish, so ill post that log when ever its done. I know you do no want me to run any programs that can interfer with your tools, so if you want me to stop the scan, just say so and ill follow your instructions on the removal of these maleware infections.
Thanks!