This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Phishing or spyware? password reset

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi so recently my passwords for several of my accounts have been being changing. I'm not too entirely sure what the cause is however, I believe it might be the cause of a phishing website or spyware. My gmail account password has been changed and now I can't even retrieve it because for some reason, my security question also got changed. As for my aol email, the same thing occured where the passwords would change everytime I tried to reset it and input my own password and this has been going on for the past 3 days. however just today, my aol email's security question also got changed so I can't even reset the password at this point. My facebook and other social networking accounts, the passwords keep reverting back to my old password whenever I change it. I'm not really sure what the cause is but I really need your assistance. I can't even communicate or go online now to talk to people because I can't access any of my emails or my social networking sites. Am I infected with a spyware and is someone on my account? Please help me. I know this description might sound weird but that is the case. Here's my OTL log


OTL logfile created on: 8/12/2011 12:02:59 PM - Run 5
OTL by OldTimer - Version 3.2.26.1 Folder = C:UserskennyDownloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19120)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.93 Gb Total Physical Memory | 0.58 Gb Available Physical Memory | 29.89% Memory free
4.10 Gb Paging File | 2.54 Gb Available in Paging File | 61.93% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 139.19 Gb Total Space | 70.94 Gb Free Space | 50.96% Space Free | Partition Type: NTFS
Drive D: | 9.86 Gb Total Space | 1.74 Gb Free Space | 17.70% Space Free | Partition Type: NTFS

Computer Name: KENNY-PC | User Name: kenny | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:UserskennyDownloadsOTL.exe (OldTimer Tools)
PRC - C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe (Malwarebytes Corporation)
PRC - C:Program FilesooVooooVoo.exe (ooVoo LLC)
PRC - C:Program FilesAVAST SoftwareAvastAvastUI.exe (AVAST Software)
PRC - C:Program FilesAVAST SoftwareAvastAvastSvc.exe (AVAST Software)
PRC - C:Program FilesAIM7aim.exe (AOL Inc.)
PRC - C:Windowsexplorer.exe (Microsoft Corporation)
PRC - C:Program FilesLogitechQuickCamQuickcam.exe ()
PRC - C:Program FilesCommon FilesLogiShrdLQCVFXCOCIManager.exe ()
PRC - C:Program FilesCommon FilesLogiShrdLVMVFMLVPrcSrv.exe (Logitech Inc.)
PRC - C:Program FilesYahoo!SoftwareUpdateYahooAUService.exe (Yahoo! Inc.)
PRC - C:WindowsSMINSTBLService.exe ()
PRC - C:Program FilesWindows DefenderMSASCui.exe (Microsoft Corporation)
PRC - C:Program FilesViewpointCommonViewpointService.exe (Viewpoint Corporation)


========== Modules (SafeList) ==========

MOD - C:UserskennyDownloadsOTL.exe (OldTimer Tools)
MOD - C:Program FilesAVAST SoftwareAvastsnxhk.dll (AVAST Software)
MOD - C:Windowswinsxsx86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Akamai) – c:Program FilesCommon FilesAkamainetsession_win_2da1ebd.dll ()
SRV - (MBAMService) – C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe (Malwarebytes Corporation)
SRV - (avast! Antivirus) – C:Program FilesAVAST SoftwareAvastAvastSvc.exe (AVAST Software)
SRV - (npggsvc) – C:WindowsSystem32GameMon.des (INCA Internet Co., Ltd.)
SRV - (LVPrcSrv) – C:Program FilesCommon FilesLogiShrdLVMVFMLVPrcSrv.exe (Logitech Inc.)
SRV - (OpenVPNService) – C:Program FilesOpenVPNbinopenvpnserv.exe ()
SRV - (YahooAUService) – C:Program FilesYahoo!SoftwareUpdateYahooAUService.exe (Yahoo! Inc.)
SRV - (Recovery Service for Windows) – C:WindowsSMINSTBLService.exe ()
SRV - (WinDefend) – C:Program FilesWindows DefenderMpSvc.dll (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:Program FilesViewpointCommonViewpointService.exe (Viewpoint Corporation)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) – C:WindowsSystem32driversmbam.sys (Malwarebytes Corporation)
DRV - (aswSnx) – C:WindowsSystem32driversaswSnx.sys (AVAST Software)
DRV - (aswSP) – C:WindowsSystem32driversaswSP.sys (AVAST Software)
DRV - (aswTdi) – C:WindowsSystem32driversaswTdi.sys (AVAST Software)
DRV - (aswRdr) – C:WindowsSystem32driversaswRdr.sys (AVAST Software)
DRV - (aswMonFlt) – C:WindowsSystem32driversaswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:WindowsSystem32driversaswFsBlk.sys (AVAST Software)
DRV - (Mkd2kfNt) – C:WindowsSystem32driversMkd2kfNT.sys (AhnLab, Inc.)
DRV - (hamachi) – C:WindowsSystem32drivershamachi.sys (LogMeIn, Inc.)
DRV - (TesDrvPt) – C:WindowsSystem32TesDrvPt.sys (TENCENT)
DRV - (Mkd2Nadr) – C:WindowsSystem32driversMkd2Nadr.sys (AhnLab, Inc.)
DRV - (LVUVC) QuickCam Pro for Notebooks(UVC) – C:WindowsSystem32driverslvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:WindowsSystem32driversLVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:WindowsSystem32driverslvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:WindowsSystem32driversLVPr2Mon.sys ()
DRV - (tap0901) – C:WindowsSystem32driverstap0901.sys (The OpenVPN Project)
DRV - (RTL8169) – C:WindowsSystem32driversRtlh86.sys (Realtek Corporation )
DRV - (CnxtHdAudService) – C:WindowsSystem32driversCHDRT32.sys (Conexant Systems Inc.)
DRV - (IntcHdmiAddService) Intel® – C:WindowsSystem32driversIntcHdmi.sys (Intel® Corporation)
DRV - (athr) – C:WindowsSystem32driversathr.sys (Atheros Communications, Inc.)
DRV - (msloop) – C:WindowsSystem32driversloop.sys (Microsoft Corporation)
DRV - (XAudio) – C:WindowsSystem32driversXAudio.sys (Conexant Systems, Inc.)
DRV - (lvpopflt) – C:WindowsSystem32driverslvpopflt.sys (Logitech Inc.)
DRV - (HpqKbFiltr) – C:WindowsSystem32driversHpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (NVENETFD) – C:WindowsSystem32driversnvm60x32.sys (NVIDIA Corporation)
DRV - (NPPTNT2) – C:WindowsSystem32npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf;=cnnb
IE - HKLM..URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:Program FilesAIM Toolbaraimtb.dll (AOL LLC.)

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Bar = http://www.crawler.com/search/dispatcher.a…&tbid;=60468
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.bing.com/?pc=Z015&form;=ZGAPHP
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Restore = http://www.google.com/
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,StartPageCache = 1
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:20110101
FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=Z015&form;=ZGAADF&q;="


FF - [removed]/FlashPlayer: C:Windowssystem32MacromedFlashNPSWF32.dll ()
FF - [removed]/ShockwavePlayer: C:Windowssystem32AdobeDirectornp32dsw.dll (Adobe Systems, Inc.)
FF - [removed]/asp/npaosmgr.1: C:Program FilesAhnLabASPComponentsaosmgrconflict_221npaosmgr.dll (AhnLab, Inc.)
FF - [removed]/asp/npmkd25aos: C:Program FilesAhnLabASPMyKeyDefense 2.5npmkd25aos.dll (AhnLab, Inc.)
FF - [removed]/vlc;version=0.8.6f: C:Program FilesDyynoDyyno Playernpvlc.dll (Dyyno)
FF - [removed]/JavaPlugin: C:Program FilesJavajre6binnew_pluginnpjp2.dll (Sun Microsystems, Inc.)
FF - [removed]/NpCtrl,version=1.0: c:Program FilesMicrosoft Silverlight4.0.60531.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/OfficeLive,version=1.5: C:Program FilesMicrosoftOffice LivenpOLW.dll (Microsoft Corp.)
FF - [removed]/WLPG,version=15.4.3502.0922: C:Program FilesWindows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - [removed]/WLPG,version=15.4.3508.1109: C:Program FilesWindows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - [removed]/WPF,version=3.5: c:WindowsMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation)
FF - [removed]/NxGame: C:ProgramDataNexonUSNGMnpNxGameUS.dll (Nexon)
FF - [removed]/PandoWebPlugin: C:Program FilesPando NetworksMedia BoosternpPandoWebPlugin.dll (Pando Networks)
FF - [removed]/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.65npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.65npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/VMP: C:Program FilesViewpointViewpoint Media PlayernpViewpoint.dll ()
FF - [removed]/asp/npmkd25aos: C:Program FilesAhnLabASPMyKeyDefense 2.5npmkd25aos.dll (AhnLab, Inc.)
FF - [removed]/Google Update;version=3: C:UserskennyAppDataLocalGoogleUpdate1.3.21.65npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:UserskennyAppDataLocalGoogleUpdate1.3.21.65npGoogleUpdate3.dll (Google Inc.)
FF - HKCUSoftwareMozillaPluginspandonetworks.com/PandoWebPlugin: C:Program FilesPando NetworksMedia BoosternpPandoWebPlugin.dll (Pando Networks)

FF - [removed]: C:Program FilesHPDigital ImagingSmart Web PrintingMozillaAddOn3 [2010/01/13 17:56:52 | 000,000,000 | —D | M]
FF - [removed]: C:Program FilesAVAST SoftwareAvastWebRepFF [2011/08/01 16:29:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 5.0extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2011/08/07 21:06:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 5.0extensionsPlugins: C:Program FilesMozilla Firefoxplugins [2011/08/07 21:06:52 | 000,000,000 | —D | M]
FF - [removed]: C:Program FilesHPDigital ImagingSmart Web PrintingMozillaAddOn3 [2010/01/13 17:56:52 | 000,000,000 | —D | M]

[2011/01/03 19:38:36 | 000,000,000 | —D | M] (No name found) – C:UserskennyAppDataRoamingMozillaExtensions
[2009/11/03 14:29:23 | 000,000,000 | —D | M] (No name found) – C:[removed]
[2011/05/20 16:27:08 | 000,000,000 | —D | M] (No name found) – C:UserskennyAppDataRoamingMozillaFirefoxProfilesfk1mvvth.defaultextensi
ons
[2011/04/11 20:32:24 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:UserskennyAppDataRoamingMozillaFirefoxProfilesfk1mvvth.defaultextensi
ons{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/30 00:47:07 | 000,001,919 | —- | M] () – C:UserskennyAppDataRoamingMozillaFirefoxProfilesfk1mvvth.defaultsearchp
luginsbing-zugo.xml
[2011/06/08 00:15:54 | 000,000,000 | —D | M] (No name found) – C:Program FilesMozilla Firefoxextensions
[2010/12/28 22:08:59 | 000,000,000 | —D | M] (Java Console) – C:Program FilesMozilla Firefoxextensions{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/05/30 18:56:23 | 000,000,000 | —D | M] (Java Console) – C:Program FilesMozilla Firefoxextensions{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/06/08 00:15:54 | 000,000,000 | —D | M] (Java Console) – C:Program FilesMozilla Firefoxextensions{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) –
[2011/06/25 16:23:03 | 000,142,296 | —- | M] (Mozilla Foundation) – C:Program Filesmozilla firefoxcomponentsbrowsercomps.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:Program Filesmozilla firefoxpluginsnpdeployJava1.dll
[2007/04/16 13:07:12 | 000,180,293 | —- | M] () – C:Program Filesmozilla firefoxpluginsnpViewpoint.dll
[2011/05/20 17:17:29 | 000,002,252 | —- | M] () – C:Program Filesmozilla firefoxsearchpluginsbing.xml
[2009/09/21 12:24:16 | 000,001,329 | —- | M] () – C:Program Filesmozilla firefoxsearchpluginscrawlersrch.xml

O1 HOSTS File: ([2010/07/31 18:53:39 | 000,000,027 | —- | M]) - C:WindowsSystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ooVoo Toolbar) - {59c6f12b-f004-43e5-9997-08f2123119b6} - C:Program FilesoovootoolbaroovootoolbarX.dll ()
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.7.6406.1642swg.dll (Google Inc.)
O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:UserskennyAppDataRoamingFlashGetBHOFlashGetBHO3.dll (Trend Media Group)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:Program FilesAIM Toolbaraimtb.dll (AOL LLC.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:Program FilesMSNToolbar3.0.0988.2msneshellx.dll (Microsoft Corp.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpn0YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM..Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:Program FilesMSNToolbar3.0.0988.2msneshellx.dll (Microsoft Corp.)
O3 - HKLM..Toolbar: (ooVoo Toolbar) - {59c6f12b-f004-43e5-9997-08f2123119b6} - C:Program FilesoovootoolbaroovootoolbarX.dll ()
O3 - HKLM..Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:Program FilesAIM Toolbaraimtb.dll (AOL LLC.)
O3 - HKLM..Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)
O3 - HKLM..Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll (Yahoo! Inc.)
O3 - HKCU..ToolbarWebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..Run: [] File not found
O4 - HKLM..Run: [avast] C:Program FilesAVAST SoftwareAvastavastUI.exe (AVAST Software)
O4 - HKLM..Run: [HP Health Check Scheduler] c:Program FilesHewlett-PackardHP Health CheckHPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..Run: [LogitechQuickCamRibbon] C:Program FilesLogitechQuickCamQuickcam.exe ()
O4 - HKLM..Run: [Malwarebytes' Anti-Malware] C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe (Malwarebytes Corporation)
O4 - HKLM..Run: [Windows Defender] C:Program FilesWindows DefenderMSASCui.exe (Microsoft Corporation)
O4 - HKCU..Run: [Aim] C:Program FilesAIM7aim.exe (AOL Inc.)
O4 - HKCU..Run: [ooVoo.exe] C:Program FilesooVoooovoo.exe (ooVoo LLC)
O6 - HKLMSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDrives = 0
O7 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDrives = 0
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: LogonHoursAction = 2
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Download All By FlashGet3 - C:UserskennyAppDataRoamingFlashGetBHOGetAllUrl.htm ()
O8 - Extra context menu item: Download By FlashGet3 - C:UserskennyAppDataRoamingFlashGetBHOGetUrl.htm ()
O8 - Extra context menu item: Google Sidewiki… - C:Program FilesGoogleGoogle ToolbarComponentGoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll (Google Inc.)
O10 - NameSpace_Catalog5Catalog_Entries\000000000007 [] - C:Program FilesBonjourmdnsNSP.dll (Apple Inc.)
O15 - HKCU..Trusted Domains: kuaiche.com ([software] http in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - ProtocolHandlerbwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:Program FilesLogitechDesktop Messenger8876480ProgramGAPlugProtocol-8876480.dll (Logitech Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:WindowsWebWallpaperimg29.jpg
O24 - Desktop BackupWallPaper: C:WindowsWebWallpaperimg29.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/27 14:16:34 | 000,000,074 | —- | M] () - C:autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*
O37 - HKCU…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:MapleSeal3codeca.acm File not found
Drivers32: msacm.l3codecp - C:WindowsSystem32l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:WindowsSystem32vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:WindowsSystem32vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:WindowsSystem32iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:WindowsSystem32LVCodec2.dll (Logitech Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/08/09 15:29:44 | 000,375,808 | —- | C] (Microsoft Corporation) – C:WindowsSystem32winsrv.dll
[2011/08/09 15:28:51 | 000,025,600 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jsproxy.dll
[2011/08/09 15:28:41 | 000,174,080 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ie4uinit.exe
[2011/08/09 15:28:40 | 000,105,984 | —- | C] (Microsoft Corporation) – C:WindowsSystem32url.dll
[2011/08/09 15:28:39 | 001,469,440 | —- | C] (Microsoft Corporation) – C:WindowsSystem32inetcpl.cpl
[2011/08/09 15:28:39 | 000,611,840 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mstime.dll
[2011/08/09 15:28:39 | 000,602,112 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeeds.dll
[2011/08/09 15:28:39 | 000,387,584 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iedkcs32.dll
[2011/08/09 15:28:38 | 000,385,024 | —- | C] (Microsoft Corporation) – C:WindowsSystem32html.iec
[2011/08/09 15:28:38 | 000,184,320 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iepeers.dll
[2011/08/09 15:28:38 | 000,164,352 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieui.dll
[2011/08/09 15:28:38 | 000,109,056 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iesysprep.dll
[2011/08/09 15:28:37 | 000,133,632 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieUnatt.exe
[2011/08/09 15:28:37 | 000,071,680 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iesetup.dll
[2011/08/09 15:28:37 | 000,055,808 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iernonce.dll
[2011/08/09 15:28:37 | 000,055,296 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeedsbs.dll
[2011/08/09 15:28:37 | 000,043,520 | —- | C] (Microsoft Corporation) – C:WindowsSystem32licmgr10.dll
[2011/08/09 15:28:36 | 001,638,912 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mshtml.tlb
[2011/08/09 15:28:36 | 000,013,312 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeedssync.exe
[2011/08/09 15:28:05 | 003,602,832 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ntkrnlpa.exe
[2011/08/09 15:28:04 | 003,550,096 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ntoskrnl.exe
[2011/08/07 21:06:23 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsQuickTime
[2011/08/07 21:05:52 | 000,000,000 | —D | C] – C:Program FilesQuickTime
[2010/08/25 19:59:08 | 000,004,096 | —- | C] ( ) – C:WindowsSystem32IGFXDEVLib.dll

========== Files - Modified Within 30 Days ==========

[2011/08/12 12:15:00 | 000,000,418 | -H– | M] () – C:WindowstasksUser_Feed_Synchronization-{9FAFAA7E-1051-4934-AB73-B60567FBCA4A}.job
[2011/08/12 12:05:41 | 000,000,422 | -H– | M] () – C:WindowstasksUser_Feed_Synchronization-{36BAD781-23A8-4E6D-9F8B-3F41DB49DF2D}.job
[2011/08/12 11:54:13 | 000,000,886 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineUA.job
[2011/08/12 11:49:12 | 000,000,284 | —- | M] () – C:UsersPublicDocumentshpqp.ini
[2011/08/12 11:49:10 | 000,000,436 | —- | M] () – C:WindowsSystem32driversetchosts.ics
[2011/08/12 11:48:05 | 000,000,882 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineCore.job
[2011/08/12 11:47:26 | 000,003,216 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/12 11:47:25 | 000,003,216 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/12 11:47:12 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2011/08/11 23:05:45 | 000,000,000 | —- | M] () – C:WindowsSystem32driverslvuvc.hs
[2011/08/11 22:41:16 | 000,000,908 | —- | M] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-2974057216-669283323-2720603189-1000UA.job
[2011/08/10 16:10:08 | 000,008,428 | —- | M] () – C:WindowsSystem32hpasset.xml
[2011/08/10 00:07:56 | 000,648,426 | —- | M] () – C:WindowsSystem32perfh009.dat
[2011/08/10 00:07:56 | 000,122,250 | —- | M] () – C:WindowsSystem32perfc009.dat
[2011/08/09 20:43:33 | 000,002,042 | —- | M] () – C:UserskennyDesktopGoogle Chrome.lnk
[2011/08/09 20:43:33 | 000,002,004 | —- | M] () – C:UserskennyApplication DataMicrosoftInternet ExplorerQuick LaunchGoogle Chrome.lnk
[2011/08/07 21:06:24 | 000,001,726 | —- | M] () – C:UsersPublicDesktopQuickTime Player.lnk
[2011/08/05 11:25:34 | 000,131,665 | —- | M] () – C:UserskennyDesktopschedule.jpg
[2011/08/05 01:41:02 | 000,000,856 | —- | M] () – C:WindowstasksGoogleUpdateTaskUserS-1-5-21-2974057216-669283323-2720603189-1000Core.job
[2011/08/03 16:51:11 | 000,008,428 | —- | M] () – C:WindowsSystem32hpasset.xml.bkp
[2011/08/02 21:07:07 | 000,000,930 | —- | M] () – C:UserskennyApplication DataMicrosoftInternet ExplorerQuick LaunchMalwarebytes' Anti-Malware.lnk
[2011/08/02 21:07:07 | 000,000,906 | —- | M] () – C:UsersPublicDesktopMalwarebytes' Anti-Malware.lnk
[2011/08/01 23:14:29 | 000,000,322 | —- | M] () – C:WindowstasksHPCeeScheduleForkenny.job
[2011/08/01 16:35:02 | 000,001,829 | —- | M] () – C:UsersPublicDesktopavast! Free Antivirus.lnk
[2011/08/01 16:34:53 | 000,002,577 | —- | M] () – C:WindowsSystem32config.nt
[2011/07/23 07:04:18 | 000,105,984 | —- | M] (Microsoft Corporation) – C:WindowsSystem32url.dll
[2011/07/23 07:01:07 | 000,611,840 | —- | M] (Microsoft Corporation) – C:WindowsSystem32mstime.dll
[2011/07/23 07:00:36 | 000,602,112 | —- | M] (Microsoft Corporation) – C:WindowsSystem32msfeeds.dll
[2011/07/23 07:00:36 | 000,055,296 | —- | M] (Microsoft Corporation) – C:WindowsSystem32msfeedsbs.dll
[2011/07/23 07:00:05 | 000,043,520 | —- | M] (Microsoft Corporation) – C:WindowsSystem32licmgr10.dll
[2011/07/23 06:59:57 | 000,025,600 | —- | M] (Microsoft Corporation) – C:WindowsSystem32jsproxy.dll
[2011/07/23 06:59:52 | 001,469,440 | —- | M] (Microsoft Corporation) – C:WindowsSystem32inetcpl.cpl
[2011/07/23 06:59:35 | 000,164,352 | —- | M] (Microsoft Corporation) – C:WindowsSystem32ieui.dll
[2011/07/23 06:59:34 | 000,184,320 | —- | M] (Microsoft Corporation) – C:WindowsSystem32iepeers.dll
[2011/07/23 06:59:34 | 000,109,056 | —- | M] (Microsoft Corporation) – C:WindowsSystem32iesysprep.dll
[2011/07/23 06:59:34 | 000,071,680 | —- | M] (Microsoft Corporation) – C:WindowsSystem32iesetup.dll
[2011/07/23 06:59:34 | 000,055,808 | —- | M] (Microsoft Corporation) – C:WindowsSystem32iernonce.dll
[2011/07/23 06:59:29 | 000,387,584 | —- | M] (Microsoft Corporation) – C:WindowsSystem32iedkcs32.dll
[2011/07/23 06:03:47 | 000,385,024 | —- | M] (Microsoft Corporation) – C:WindowsSystem32html.iec
[2011/07/23 05:27:04 | 000,133,632 | —- | M] (Microsoft Corporation) – C:WindowsSystem32ieUnatt.exe
[2011/07/23 05:26:52 | 000,174,080 | —- | M] (Microsoft Corporation) – C:WindowsSystem32ie4uinit.exe
[2011/07/23 05:26:12 | 000,013,312 | —- | M] (Microsoft Corporation) – C:WindowsSystem32msfeedssync.exe
[2011/07/23 05:25:38 | 001,638,912 | —- | M] (Microsoft Corporation) – C:WindowsSystem32mshtml.tlb
[2011/07/17 22:57:54 | 000,001,726 | —- | M] () – C:UsersPublicDesktopooVoo.lnk

========== Files Created - No Company Name ==========

[2011/08/07 21:06:24 | 000,001,726 | —- | C] () – C:UsersPublicDesktopQuickTime Player.lnk
[2011/08/05 11:25:34 | 000,131,665 | —- | C] () – C:UserskennyDesktopschedule.jpg
[2011/06/25 17:03:49 | 000,000,891 | —- | C] () – C:WindowsSystem32secushr.dat
[2011/06/25 17:01:03 | 000,000,025 | —- | C] () – C:Windowslibem.INI
[2010/08/25 20:30:02 | 000,439,308 | —- | C] () – C:WindowsSystem32igcompkrng500.bin
[2010/08/25 20:30:00 | 000,982,240 | —- | C] () – C:WindowsSystem32igkrng500.bin
[2010/08/25 20:30:00 | 000,092,356 | —- | C] () – C:WindowsSystem32igfcg500m.bin
[2010/08/25 19:57:00 | 000,000,151 | —- | C] () – C:WindowsSystem32GfxUI.exe.config
[2010/08/25 19:52:00 | 000,208,896 | —- | C] () – C:WindowsSystem32iglhsip32.dll
[2010/08/25 19:52:00 | 000,143,360 | —- | C] () – C:WindowsSystem32iglhcp32.dll
[2010/01/13 17:56:15 | 000,023,087 | —- | C] () – C:Windowshpqins15.dat
[2009/09/30 16:30:37 | 000,000,321 | —- | C] () – C:WindowsSystem32XMLConfig_SYSID.ini
[2009/08/29 18:17:29 | 000,018,760 | —- | C] () – C:WindowsSystem32QQVistaHelper.dll
[2009/08/18 18:16:29 | 000,107,612 | —- | C] () – C:WindowsSystem32StructuredQuerySchema.bin
[2009/08/18 18:16:28 | 000,117,248 | —- | C] () – C:WindowsSystem32EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:WindowsSystem32OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:WindowsSystem32OGAEXEC.exe
[2009/06/11 22:36:47 | 000,000,552 | —- | C] () – C:UserskennyAppDataLocald3d8caps.dat
[2009/04/22 17:38:34 | 000,081,110 | —- | C] () – C:WindowsSystem32lvcoinst.ini
[2009/02/21 23:31:05 | 000,000,056 | -H– | C] () – C:ProgramDataezsidmv.dat
[2009/01/20 20:01:51 | 000,000,132 | —- | C] () – C:UserskennyAppDataRoaming281.cmd
[2009/01/20 19:54:45 | 000,000,132 | —- | C] () – C:UserskennyAppDataRoaming888.cmd
[2009/01/20 19:51:01 | 000,000,132 | —- | C] () – C:UserskennyAppDataRoaming336.cmd
[2009/01/20 18:54:57 | 000,000,132 | —- | C] () – C:UserskennyAppDataRoaming196.cmd
[2008/12/22 20:59:19 | 000,005,972 | —- | C] () – C:UserskennyAppDataLocald3d9caps.dat
[2008/12/16 21:58:54 | 000,025,624 | —- | C] () – C:WindowsSystem32driversLVPr2Mon.sys
[2008/12/16 21:50:56 | 000,013,584 | —- | C] () – C:WindowsSystem32driversiKeyLgFT.dll
[2008/11/07 22:25:07 | 000,018,904 | —- | C] () – C:WindowsSystem32StructuredQuerySchemaTrivial.bin
[2008/11/07 20:30:25 | 000,029,696 | —- | C] () – C:UserskennyAppDataLocalDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/27 14:31:32 | 000,101,605 | —- | C] () – C:Windowshpqins13.dat
[2008/06/12 14:59:22 | 000,147,456 | —- | C] () – C:WindowsSystem32igfxCoIn_v1502.dll
[2008/06/12 14:41:18 | 000,147,172 | —- | C] () – C:WindowsSystem32igfcg550.bin
[2008/06/04 13:54:12 | 000,004,608 | —- | C] () – C:WindowsSystem32HdmiCoin.dll
[2006/11/02 08:57:28 | 000,067,584 | –S- | C] () – C:Windowsbootstat.dat
[2006/11/02 08:47:37 | 002,325,504 | —- | C] () – C:WindowsSystem32FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:WindowsSystem32sysprepMCE.dll
[2006/11/02 06:33:01 | 000,648,426 | —- | C] () – C:WindowsSystem32perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | —- | C] () – C:WindowsSystem32perfi009.dat
[2006/11/02 06:33:01 | 000,122,250 | —- | C] () – C:WindowsSystem32perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | —- | C] () – C:WindowsSystem32perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | —- | C] () – C:WindowsSystem32dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | —- | C] () – C:Windowsmib.bin
[2006/11/02 04:19:00 | 000,000,741 | —- | C] () – C:WindowsSystem32NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:WindowsSystem32pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | —- | C] () – C:WindowsSystem32mlang.dat
[2006/04/30 00:34:04 | 000,049,152 | —- | C] () – C:WindowsSystem32WbxRMenu.dll
[2006/04/13 23:18:24 | 000,196,608 | —- | C] () – C:WindowsSystem32atonres.dll
[2006/04/13 23:18:24 | 000,131,072 | —- | C] () – C:WindowsSystem32WbxMSAI.dll
[2006/04/13 23:18:24 | 000,098,304 | —- | C] () – C:WindowsSystem32atonecli.dll
[2006/03/09 05:58:00 | 001,060,424 | —- | C] () – C:WindowsSystem32WdfCoInstaller01000.dll

========== LOP Check ==========

[2009/06/02 17:24:44 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingacccore
[2011/04/24 08:32:52 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingAIM
[2011/08/05 13:04:59 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingBITS
[2009/02/03 18:53:41 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingcom.raptr.Raptr.848BBC53270CAC248E8FA0F339176201C
DEB525F.1
[2011/06/25 16:59:51 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingFlashGet
[2011/06/25 16:59:30 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingFlashGetBHO
[2009/08/04 23:41:25 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingfunkitron
[2010/05/02 16:13:07 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingGetRightToGo
[2009/04/15 14:22:22 | 000,000,000 | -H-D | M] – C:UserskennyAppDataRoamingijjigame
[2010/07/11 01:20:11 | 000,000,000 | RHSD | M] – C:UserskennyAppDataRoaminginstall
[2010/02/10 13:03:26 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingLimeWire
[2008/11/08 11:44:51 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingNexon
[2010/02/10 23:36:16 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingooVoo Details
[2010/06/13 09:30:41 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingoovooinstaller
[2011/02/05 16:24:38 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingSynthesia
[2010/01/06 19:02:07 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingTeamViewer
[2009/08/29 19:19:18 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingTencent
[2008/11/07 22:43:07 | 000,000,000 | —D | M] – C:UserskennyAppDataRoamingWildTangent
[2011/08/11 23:14:10 | 000,032,562 | —- | M] () – C:WindowsTasksSCHEDLGU.TXT
[2011/08/12 12:05:41 | 000,000,422 | -H– | M] () – C:WindowsTasksUser_Feed_Synchronization-{36BAD781-23A8-4E6D-9F8B-3F41DB49DF2D}.job
[2011/08/12 12:15:00 | 000,000,418 | -H– | M] () – C:WindowsTasksUser_Feed_Synchronization-{9FAFAA7E-1051-4934-AB73-B60567FBCA4A}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%*.* >
[2008/06/27 14:16:34 | 000,000,074 | —- | M] () – C:autoexec.bat
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:bootmgr
[2009/07/22 22:43:03 | 000,001,439 | —- | M] () – C:cmdline.txt
[2010/07/31 18:59:58 | 000,016,485 | —- | M] () – C:ComboFix.txt
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:config.sys
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:globdata.ini
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:install.res.3082.dll
[2011/04/24 08:45:07 | 000,001,117 | -H– | M] () – C:IPH.PH
[2011/08/12 11:47:07 | 2389,123,072 | -HS- | M] () – C:pagefile.sys
[2008/12/19 20:28:14 | 000,000,204 | —- | M] () – C:Plugins
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:VC_RED.MSI

< %systemroot%Fonts*.com >
[2006/11/02 08:37:12 | 000,026,040 | —- | M] () – C:WindowsFontsGlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | —- | M] () – C:WindowsFontsGlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | —- | M] () – C:WindowsFontsGlobalSerif.CompositeFont
[2009/08/19 08:04:13 | 000,037,665 | —- | M] () – C:WindowsFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >

< %systemroot%Fonts*.ini >
[2006/09/18 17:37:34 | 000,000,065 | -H– | M] () – C:WindowsFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >
[2006/11/02 08:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:Windowssystem32spoolprtprocsw32x86jnwppr.dll
[2006/10/26 22:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:Windowssystem32spoolprtprocsw32x86msonpppr.dll

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >

< %systemroot%*.png >

< %systemroot%*.scr >
[2011/05/10 08:10:59 | 000,040,112 | —- | M] (AVAST Software) – C:WindowsavastSS.scr
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:WindowsWLXPGSS.SCR

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >

< %PROGRAMFILES%*.* >
[2008/01/20 22:43:21 | 000,000,174 | -HS- | M] () – C:Program Filesdesktop.ini

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >
[2008/01/20 23:14:18 | 016,846,848 | —- | M] () – C:WindowsSystem32configCOMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | —- | M] () – C:WindowsSystem32configDEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | —- | M] () – C:WindowsSystem32configSECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:WindowsSystem32configSOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:WindowsSystem32configSYSTEM.SAV

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2010/03/06 00:52:50 | 000,000,429 | -HS- | M] () – C:UserskennyAppDataRoamingMicrosoftInternet ExplorerQuick Launchdesktop.ini

< %USERPROFILE%Desktop*.exe >
[2011/07/08 10:52:25 | 000,332,288 | —- | M] (AuraSEA) – C:UserskennyDesktopAuraSea.exe
[2010/12/31 18:25:35 | 000,602,624 | —- | M] (OldTimer Tools) – C:UserskennyDesktopOTL.exe

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstallLastSuccessTime: 2011-08-12 15:59:48

========== Alternate Data Streams ==========

@Alternate Data Stream - 127 bytes -> C:ProgramDataTEMP:430C6D84
@Alternate Data Stream - 125 bytes -> C:ProgramDataTEMP:DFC5A2B2
@Alternate Data Stream - 111 bytes -> C:ProgramDataTEMP:187F4542
@Alternate Data Stream - 109 bytes -> C:ProgramDataTEMP:A8ADE5D8

< End of report >

For some reason, I never got an Extras. Txt.even though I did the scan 2x. (Am I suppose put the setting for extras on Use Safelist? because when I downloaded it was under "none") So instead heres my HijackThis Scan as well. Thank you


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:52:32 PM, on 8/12/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19120)
Boot mode: Normal

Running processes:
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Windowssystem32taskeng.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesHPQuickPlayQPService.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesHewlett-PackardHP Quick Launch ButtonsQLBCTRL.exe
C:Windowssystem32igfxsrvc.exe
C:WindowsSystem32mobsync.exe
C:Program FilesHewlett-PackardHP Wireless AssistantHPWAMain.exe
C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe
C:Program FilesLogitechQuickCamQuickcam.exe
C:WindowsSystem32hkcmd.exe
C:WindowsSystem32igfxpers.exe
C:Program FilesAVAST SoftwareAvastAvastUI.exe
C:Program FilesHPHP Software Updatehpwuschd2.exe
C:Program FilesCommon FilesJavaJava Updatejusched.exe
C:Program FilesCommon FilesLightScribeLightScribeControlPanel.exe
C:Windowsehomeehtray.exe
C:Program FilesooVooooVoo.exe
C:Windowsehomeehmsas.exe
C:Program FilesAIM7aim.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesCommon FilesLogishrdLQCVFXCOCIManager.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesHewlett-PackardHP wireless AssistantWiFiMsg.EXE
C:Program FilesHewlett-PackardSharedHpqToaster.exe
C:Windowssystem32wbemunsecapp.exe
C:Program FilesSynapticsSynTPSynTPHelper.exe
C:UserskennyAppDataLocalGoogleChromeApplicationchrome.exe
C:Windowssystem32rundll32.exe
C:UserskennyAppDataLocalGoogleChromeApplicationchrome.exe
C:UserskennyAppDataLocalGoogleChromeApplicationchrome.exe
C:UserskennyAppDataLocalGoogleChromeApplicationchrome.exe
C:Program FilesInternet ExplorerIELowutil.exe
C:UserskennyDesktopHiJackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.crawler.com/search/dispatcher.a…&tbid;=60468
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.bing.com/?pc=Z015&form;=ZGAPHP
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf;=cnnb
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:Program FilesHPDigital ImagingSmart Web Printinghpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: ooVoo Toolbar - {59c6f12b-f004-43e5-9997-08f2123119b6} - C:Program FilesoovootoolbaroovootoolbarX.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:Program FilesMicrosoftSearch Enhancement PackSearch HelperSEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:Program FilesWindows LiveCompanioncompanioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.7.6406.1642swg.dll
O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:UserskennyAppDataRoamingFlashGetBHOFlashGetBHO3.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:Program FilesAIM Toolbaraimtb.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:Program FilesMSNToolbar3.0.0988.2msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6binjp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpn0YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:Program FilesMSNToolbar3.0.0988.2msneshellx.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:Program FilesAIM Toolbaraimtb.dll
O3 - Toolbar: ooVoo Toolbar - {59c6f12b-f004-43e5-9997-08f2123119b6} - C:Program FilesoovootoolbaroovootoolbarX.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [QPService] "C:Program FilesHPQuickPlayQPService.exe"
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [QlbCtrl.exe] C:Program FilesHewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe /Start
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [hpWirelessAssistant] C:Program FilesHewlett-PackardHP Wireless AssistantHPWAMain.exe
O4 - HKLM..Run: [HP Health Check Scheduler] c:Program FilesHewlett-PackardHP Health CheckHPHC_Scheduler.exe
O4 - HKLM..Run: [GrooveMonitor] "C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe"
O4 - HKLM..Run: [LogitechQuickCamRibbon] "C:Program FilesLogitechQuickCamQuickcam.exe" /hide
O4 - HKLM..Run: [IgfxTray] C:Windowssystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:Windowssystem32hkcmd.exe
O4 - HKLM..Run: [Persistence] C:Windowssystem32igfxpers.exe
O4 - HKLM..Run: [avast] "C:Program FilesAVAST SoftwareAvastavastUI.exe" /nogui
O4 - HKLM..Run: [HP Software Update] C:Program FilesHpHP Software UpdateHPWuSchd2.exe
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesCommon FilesJavaJava Updatejusched.exe"
O4 - HKLM..Run: [Malwarebytes' Anti-Malware] "C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe" /starttray
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeQTTask.exe" -atboottime
O4 - HKCU..Run: [LightScribe Control Panel] C:Program FilesCommon FilesLightScribeLightScribeControlPanel.exe -hidden
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [ooVoo.exe] C:Program FilesooVoooovoo.exe /minimized
O4 - HKCU..Run: [Google Update] "C:UserskennyAppDataLocalGoogleUpdateGoogleUpdate.exe" /c
O4 - HKCU..Run: [Aim] "C:Program FilesAIM7aim.exe" /d locale=en-US
O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:Program FilesLogitechDesktop Messenger8876480ProgramLogitechDesktopMessenger.exe
O4 - Global Startup: WhiteSmoke Translator.lnk = C:UserskennyDownloadsWhiteSmokeWriterGeo5002_en.exe
O8 - Extra context menu item: Download All By FlashGet3 - C:UserskennyAppDataRoamingFlashGetBHOGetAllUrl.htm
O8 - Extra context menu item: Download By FlashGet3 - C:UserskennyAppDataRoamingFlashGetBHOGetUrl.htm
O8 - Extra context menu item: Google Sidewiki… - res://C:Program FilesGoogleGoogle ToolbarComponentGoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
O9 - Extra button: @C:Program FilesWindows LiveCompanioncompanionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:Program FilesWindows LiveCompanioncompanioncore.dll
O9 - Extra button: @C:Program FilesWindows LiveWriterWindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:Program FilesWindows LiveWriterWindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~3Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~3Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3Office12REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:Program FilesHPDigital ImagingSmart Web Printinghpswp_BHO.dll
O15 - Trusted Zone: http://software.kuaiche.com
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:Program FilesLogitechDesktop Messenger8876480ProgramGAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:Program FilesMicrosoft OfficeOffice12GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:Program FilesWindows LivePhoto GalleryAlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:Windowssystem32browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:Program FilesAVAST SoftwareAvastAvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:Program FilesBonjourmDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:Program FilesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:Program FilesHP GamesMy HP Game ConsoleGameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:Program FilesHewlett-PackardHP Health Checkhphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:Program FilesHewlett-PackardSharedhpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1050Intel 32IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:Program FilesCommon FilesLightScribeLSSrvc.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:Program FilesCommon FilesLogiShrdLVMVFMLVPrcSrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:Windowssystem32GameMon.des.exe (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:Program FilesOpenVPNbinopenvpnserv.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:WindowsSMINSTBLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:Program FilesCyberLinkShared FilesRichVideo.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:Program FilesViewpointCommonViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:Windowssystem32DRIVERSxaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:Program FilesYahoo!SoftwareUpdateYahooAUService.exe

–
End of file - 13320 bytes
Posted Image


DO NOT use any TOOLS such as Combofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


Next:

Close all browsers before running ATF: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
When I open ComboFix.Exe and I double click it, it automatically ran a scan or something and then afterwards I got a message saying NIRCMD was not found, make sure you type the name correctly. Did I do something wrong? Because When I ran combofix, it automatically did it's own thing, there was no steps
Run this and lets see if you have a rootkit infection


Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.




Also please describe how your computer behaves at the moment.
It said that there was no threat found. 2011/08/14 13:55:21.0733 4196 TDSS rootkit removing tool 2.5.15.0 Aug 11 2011 16:32:13 2011/08/14 13:55:22.0199 4196 ================================================================================ 2011/08/14 13:55:22.0199 4196 SystemInfo: 2011/08/14 13:55:22.0199 4196 2011/08/14 13:55:22.0200 4196 OS Version: 6.0.6002 ServicePack: 2.0 2011/08/14 13:55:22.0200 4196 Product type: Workstation 2011/08/14 13:55:22.0200 4196 ComputerName: KENNY-PC 2011/08/14 13:55:22.0201 4196 UserName: kenny 2011/08/14 13:55:22.0201 4196 Windows directory: C:\Windows 2011/08/14 13:55:22.0201 4196 System windows directory: C:\Windows 2011/08/14 13:55:22.0201 4196 Processor architecture: Intel x86 2011/08/14 13:55:22.0201 4196 Number of processors: 2 2011/08/14 13:55:22.0201 4196 Page size: 0x1000 2011/08/14 13:55:22.0201 4196 Boot type: Normal boot 2011/08/14 13:55:22.0201 4196 ================================================================================ 2011/08/14 13:55:25.0018 4196 Initialize success 2011/08/14 13:55:32.0681 5232 ================================================================================ 2011/08/14 13:55:32.0681 5232 Scan started 2011/08/14 13:55:32.0681 5232 Mode: Manual; 2011/08/14 13:55:32.0681 5232 ================================================================================ 2011/08/14 13:55:36.0146 5232 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 2011/08/14 13:55:36.0468 5232 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 2011/08/14 13:55:36.0823 5232 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 2011/08/14 13:55:36.0944 5232 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 2011/08/14 13:55:36.0992 5232 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 2011/08/14 13:55:37.0388 5232 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 2011/08/14 13:55:37.0517 5232 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 2011/08/14 13:55:37.0614 5232 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2011/08/14 13:55:37.0893 5232 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 2011/08/14 13:55:38.0030 5232 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 2011/08/14 13:55:38.0083 5232 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 2011/08/14 13:55:38.0157 5232 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 2011/08/14 13:55:38.0494 5232 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys 2011/08/14 13:55:39.0111 5232 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 2011/08/14 13:55:39.0339 5232 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 2011/08/14 13:55:39.0528 5232 aswFsBlk (7f08d9c504b015d81a8abd75c80028c5) C:\Windows\system32\drivers\aswFsBlk.sys 2011/08/14 13:55:39.0602 5232 aswMonFlt (9bdc8e9ce17b773f69d2c6696c768c4f) C:\Windows\system32\drivers\aswMonFlt.sys 2011/08/14 13:55:40.0231 5232 aswRdr (ac48bdd4cd5d44af33087c06d6e9511c) C:\Windows\system32\drivers\aswRdr.sys 2011/08/14 13:55:40.0551 5232 aswSnx (b64134316fcd1f20e0f10ef3e65bd522) C:\Windows\system32\drivers\aswSnx.sys 2011/08/14 13:55:41.0046 5232 aswSP (d6788e3211afa9951ed7a4d617f68a4f) C:\Windows\system32\drivers\aswSP.sys 2011/08/14 13:55:41.0116 5232 aswTdi (4d100c45517809439c7b6dd98997fa00) C:\Windows\system32\drivers\aswTdi.sys 2011/08/14 13:55:41.0286 5232 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/08/14 13:55:41.0384 5232 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 2011/08/14 13:55:41.0758 5232 athr (600efe56f37adbd65a0fb076b50d1b8d) C:\Windows\system32\DRIVERS\athr.sys 2011/08/14 13:55:42.0281 5232 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys 2011/08/14 13:55:42.0550 5232 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2011/08/14 13:55:42.0645 5232 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 2011/08/14 13:55:43.0014 5232 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 2011/08/14 13:55:43.0117 5232 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2011/08/14 13:55:43.0185 5232 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2011/08/14 13:55:43.0234 5232 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2011/08/14 13:55:43.0298 5232 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2011/08/14 13:55:43.0445 5232 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2011/08/14 13:55:43.0505 5232 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2011/08/14 13:55:43.0603 5232 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2011/08/14 13:55:43.0880 5232 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/08/14 13:55:43.0995 5232 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 2011/08/14 13:55:44.0265 5232 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 2011/08/14 13:55:44.0347 5232 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 2011/08/14 13:55:44.0486 5232 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/08/14 13:55:44.0591 5232 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 2011/08/14 13:55:44.0714 5232 CnxtHdAudService (1adf6f4852e7d7e2e8ac481bdb970586) C:\Windows\system32\drivers\CHDRT32.sys 2011/08/14 13:55:44.0773 5232 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 2011/08/14 13:55:45.0096 5232 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 2011/08/14 13:55:45.0435 5232 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 2011/08/14 13:55:45.0818 5232 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 2011/08/14 13:55:45.0982 5232 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 2011/08/14 13:55:46.0383 5232 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2011/08/14 13:55:46.0721 5232 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 2011/08/14 13:55:46.0863 5232 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 2011/08/14 13:55:47.0106 5232 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 2011/08/14 13:55:47.0209 5232 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 2011/08/14 13:55:47.0332 5232 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 2011/08/14 13:55:47.0454 5232 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 2011/08/14 13:55:47.0649 5232 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 2011/08/14 13:55:47.0783 5232 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 2011/08/14 13:55:47.0997 5232 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2011/08/14 13:55:48.0086 5232 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2011/08/14 13:55:48.0137 5232 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/08/14 13:55:48.0214 5232 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 2011/08/14 13:55:48.0366 5232 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys 2011/08/14 13:55:48.0523 5232 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2011/08/14 13:55:48.0655 5232 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 2011/08/14 13:55:48.0927 5232 hamachi (833051c6c6c42117191935f734cfbd97) C:\Windows\system32\DRIVERS\hamachi.sys 2011/08/14 13:55:49.0032 5232 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 2011/08/14 13:55:49.0412 5232 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 2011/08/14 13:55:49.0904 5232 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2011/08/14 13:55:50.0147 5232 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2011/08/14 13:55:50.0436 5232 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 2011/08/14 13:55:50.0580 5232 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 2011/08/14 13:55:50.0734 5232 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 2011/08/14 13:55:50.0897 5232 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 2011/08/14 13:55:51.0055 5232 HSF_DPV (cc267848cb3508e72762be65734e764d) C:\Windows\system32\DRIVERS\HSX_DPV.sys 2011/08/14 13:55:51.0196 5232 HSXHWAZL (a2882945cc4b6e3e4e9e825590438888) C:\Windows\system32\DRIVERS\HSXHWAZL.sys 2011/08/14 13:55:51.0284 5232 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 2011/08/14 13:55:51.0380 5232 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 2011/08/14 13:55:51.0443 5232 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2011/08/14 13:55:51.0517 5232 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 2011/08/14 13:55:52.0018 5232 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys 2011/08/14 13:55:52.0363 5232 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2011/08/14 13:55:52.0502 5232 ImmunetProtectDriver (0452cbd785659bb9e86b6c849bc292f9) C:\Windows\system32\DRIVERS\ImmunetProtect.sys 2011/08/14 13:55:52.0671 5232 ImmunetSelfProtectDriver (426737322b000e3d9d7fb5b13f443b27) C:\Windows\system32\DRIVERS\ImmunetSelfProtect.sys 2011/08/14 13:55:52.0765 5232 IntcHdmiAddService (ab8b0206bcdff0ed03cec500fa03a32a) C:\Windows\system32\drivers\IntcHdmi.sys 2011/08/14 13:55:52.0928 5232 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2011/08/14 13:55:53.0026 5232 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2011/08/14 13:55:53.0140 5232 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/08/14 13:55:53.0225 5232 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 2011/08/14 13:55:53.0269 5232 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2011/08/14 13:55:53.0309 5232 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2011/08/14 13:55:53.0417 5232 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 2011/08/14 13:55:53.0496 5232 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 2011/08/14 13:55:53.0547 5232 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2011/08/14 13:55:53.0670 5232 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2011/08/14 13:55:53.0715 5232 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/08/14 13:55:53.0764 5232 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\drivers\kbdhid.sys 2011/08/14 13:55:53.0845 5232 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 2011/08/14 13:55:54.0033 5232 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2011/08/14 13:55:54.0100 5232 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 2011/08/14 13:55:54.0140 5232 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 2011/08/14 13:55:54.0175 5232 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 2011/08/14 13:55:54.0210 5232 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2011/08/14 13:55:54.0325 5232 lvpopflt (e1158b0cb852db0573922c92e6e564de) C:\Windows\system32\DRIVERS\lvpopflt.sys 2011/08/14 13:55:54.0638 5232 LVPr2Mon (f96cfb47903854f228baaf3e2d41a0a3) C:\Windows\system32\DRIVERS\LVPr2Mon.sys 2011/08/14 13:55:54.0908 5232 LVRS (e22fd7852e74f04cceb6b8a684a51f3e) C:\Windows\system32\DRIVERS\lvrs.sys 2011/08/14 13:55:55.0135 5232 LVUSBSta (5f987fc1aad215ec2c60cf07719b1cce) C:\Windows\system32\drivers\LVUSBSta.sys 2011/08/14 13:55:55.0393 5232 LVUVC (e89df2b88ee659954de79827ddf46dc9) C:\Windows\system32\DRIVERS\lvuvc.sys 2011/08/14 13:55:55.0697 5232 MBAMProtector (eca00eed9ab95489007b0ef84c7149de) C:\Windows\system32\drivers\mbam.sys 2011/08/14 13:55:55.0835 5232 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 2011/08/14 13:55:55.0933 5232 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 2011/08/14 13:55:56.0003 5232 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 2011/08/14 13:55:56.0153 5232 Mkd2kfNt (6f4d79ea861137ef2f9078e265c2aa83) C:\Windows\system32\drivers\Mkd2kfNt.sys 2011/08/14 13:55:56.0224 5232 Mkd2Nadr (fe7925784f6801e983b41ec118ef62ac) C:\Windows\system32\drivers\Mkd2Nadr.sys 2011/08/14 13:55:56.0272 5232 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2011/08/14 13:55:56.0319 5232 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2011/08/14 13:55:56.0433 5232 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2011/08/14 13:55:56.0466 5232 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2011/08/14 13:55:56.0524 5232 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2011/08/14 13:55:56.0755 5232 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 2011/08/14 13:55:56.0857 5232 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2011/08/14 13:55:56.0906 5232 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2011/08/14 13:55:56.0974 5232 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 2011/08/14 13:55:57.0089 5232 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/08/14 13:55:57.0149 5232 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/08/14 13:55:57.0207 5232 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/08/14 13:55:57.0273 5232 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys 2011/08/14 13:55:57.0370 5232 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 2011/08/14 13:55:57.0455 5232 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2011/08/14 13:55:57.0503 5232 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2011/08/14 13:55:57.0654 5232 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2011/08/14 13:55:57.0728 5232 msloop (0a562f61d84bf1988e4dd6413b76c1d4) C:\Windows\system32\DRIVERS\loop.sys 2011/08/14 13:55:57.0843 5232 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/08/14 13:55:57.0891 5232 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2011/08/14 13:55:57.0970 5232 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 2011/08/14 13:55:58.0069 5232 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2011/08/14 13:55:58.0117 5232 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2011/08/14 13:55:58.0165 5232 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 2011/08/14 13:55:58.0259 5232 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 2011/08/14 13:55:58.0562 5232 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 2011/08/14 13:55:58.0716 5232 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/08/14 13:55:58.0791 5232 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/08/14 13:55:58.0918 5232 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/08/14 13:55:59.0090 5232 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2011/08/14 13:55:59.0256 5232 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2011/08/14 13:55:59.0784 5232 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 2011/08/14 13:56:00.0359 5232 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2011/08/14 13:56:00.0793 5232 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 2011/08/14 13:56:01.0107 5232 NPPTNT2 (9131fe60adfab595c8da53ad6a06aa31) C:\Windows\system32\npptNT2.sys 2011/08/14 13:56:01.0332 5232 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2011/08/14 13:56:01.0535 5232 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 2011/08/14 13:56:01.0759 5232 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2011/08/14 13:56:02.0915 5232 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2011/08/14 13:56:03.0547 5232 NVENETFD (1657f3fbd9061526c14ff37e79306f98) C:\Windows\system32\DRIVERS\nvm60x32.sys 2011/08/14 13:56:03.0894 5232 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 2011/08/14 13:56:04.0116 5232 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 2011/08/14 13:56:04.0194 5232 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 2011/08/14 13:56:04.0523 5232 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys 2011/08/14 13:56:04.0742 5232 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2011/08/14 13:56:04.0875 5232 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 2011/08/14 13:56:05.0051 5232 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2011/08/14 13:56:05.0301 5232 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 2011/08/14 13:56:05.0683 5232 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys 2011/08/14 13:56:06.0255 5232 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2011/08/14 13:56:06.0561 5232 PCTCore (6ef125721a9f1f7dbf3229786f7decd0) C:\Windows\system32\drivers\PCTCore.sys 2011/08/14 13:56:06.0765 5232 pctDS (f820b4c61d1e591325b679d479d4eea4) C:\Windows\system32\drivers\pctDS.sys 2011/08/14 13:56:06.0952 5232 pctEFA (acc8c15f3d59f17c5d903ff1de3b43d3) C:\Windows\system32\drivers\pctEFA.sys 2011/08/14 13:56:07.0521 5232 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2011/08/14 13:56:08.0145 5232 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2011/08/14 13:56:08.0244 5232 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 2011/08/14 13:56:08.0507 5232 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 2011/08/14 13:56:08.0817 5232 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 2011/08/14 13:56:09.0016 5232 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2011/08/14 13:56:09.0097 5232 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2011/08/14 13:56:09.0185 5232 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2011/08/14 13:56:09.0269 5232 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/08/14 13:56:09.0388 5232 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/08/14 13:56:09.0491 5232 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 2011/08/14 13:56:09.0578 5232 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 2011/08/14 13:56:09.0749 5232 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/08/14 13:56:09.0964 5232 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 2011/08/14 13:56:10.0050 5232 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2011/08/14 13:56:10.0153 5232 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 2011/08/14 13:56:10.0403 5232 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2011/08/14 13:56:10.0511 5232 RTL8169 (125c504a34d0a2e152517e342e7e432c) C:\Windows\system32\DRIVERS\Rtlh86.sys 2011/08/14 13:56:10.0584 5232 RTSTOR (b0538dea03e088b80482ca939f4e8740) C:\Windows\system32\drivers\RTSTOR.SYS 2011/08/14 13:56:10.0658 5232 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2011/08/14 13:56:10.0957 5232 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2011/08/14 13:56:11.0366 5232 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2011/08/14 13:56:11.0591 5232 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2011/08/14 13:56:11.0665 5232 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2011/08/14 13:56:11.0762 5232 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 2011/08/14 13:56:11.0809 5232 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 2011/08/14 13:56:11.0860 5232 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 2011/08/14 13:56:12.0046 5232 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2011/08/14 13:56:12.0138 5232 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 2011/08/14 13:56:12.0188 5232 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 2011/08/14 13:56:12.0321 5232 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 2011/08/14 13:56:12.0435 5232 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 2011/08/14 13:56:12.0621 5232 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2011/08/14 13:56:12.0768 5232 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 2011/08/14 13:56:12.0937 5232 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 2011/08/14 13:56:13.0055 5232 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 2011/08/14 13:56:13.0243 5232 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2011/08/14 13:56:13.0320 5232 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2011/08/14 13:56:13.0565 5232 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2011/08/14 13:56:13.0712 5232 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2011/08/14 13:56:13.0906 5232 SynTP (00b19f27858f56181edb58b71a7c67a0) C:\Windows\system32\DRIVERS\SynTP.sys 2011/08/14 13:56:14.0100 5232 tap0901 (1e89de7a4fb7a854ebb241d0aa8996dd) C:\Windows\system32\DRIVERS\tap0901.sys 2011/08/14 13:56:14.0416 5232 Tcpip (2756186e287139310997090797e0182b) C:\Windows\system32\drivers\tcpip.sys 2011/08/14 13:56:14.0704 5232 Tcpip6 (2756186e287139310997090797e0182b) C:\Windows\system32\DRIVERS\tcpip.sys 2011/08/14 13:56:14.0858 5232 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 2011/08/14 13:56:14.0919 5232 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2011/08/14 13:56:14.0999 5232 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2011/08/14 13:56:15.0217 5232 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 2011/08/14 13:56:15.0876 5232 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 2011/08/14 13:56:16.0299 5232 TesDrvPt (24b566e25d32d7b2dfad2afd785de2c0) C:\Windows\system32\TesDrvPt.sys 2011/08/14 13:56:16.0545 5232 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/08/14 13:56:16.0659 5232 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2011/08/14 13:56:16.0846 5232 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 2011/08/14 13:56:16.0917 5232 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 2011/08/14 13:56:16.0990 5232 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 2011/08/14 13:56:17.0329 5232 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 2011/08/14 13:56:17.0419 5232 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 2011/08/14 13:56:17.0508 5232 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2011/08/14 13:56:18.0017 5232 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2011/08/14 13:56:18.0688 5232 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2011/08/14 13:56:19.0975 5232 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys 2011/08/14 13:56:20.0216 5232 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2011/08/14 13:56:20.0282 5232 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2011/08/14 13:56:20.0358 5232 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 2011/08/14 13:56:20.0495 5232 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 2011/08/14 13:56:20.0578 5232 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\Windows\system32\DRIVERS\usbohci.sys 2011/08/14 13:56:20.0646 5232 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\drivers\usbprint.sys 2011/08/14 13:56:20.0727 5232 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2011/08/14 13:56:20.0916 5232 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/08/14 13:56:21.0120 5232 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/08/14 13:56:21.0171 5232 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2011/08/14 13:56:21.0262 5232 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 2011/08/14 13:56:21.0362 5232 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 2011/08/14 13:56:21.0466 5232 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 2011/08/14 13:56:21.0549 5232 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2011/08/14 13:56:21.0635 5232 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 2011/08/14 13:56:21.0773 5232 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 2011/08/14 13:56:21.0909 5232 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 2011/08/14 13:56:22.0008 5232 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2011/08/14 13:56:22.0074 5232 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/08/14 13:56:22.0126 5232 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2011/08/14 13:56:22.0373 5232 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 2011/08/14 13:56:22.0530 5232 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2011/08/14 13:56:22.0771 5232 winachsf (0acd399f5db3df1b58903cf4949ab5a8) C:\Windows\system32\DRIVERS\HSX_CNXT.sys 2011/08/14 13:56:23.0180 5232 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 2011/08/14 13:56:23.0359 5232 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 2011/08/14 13:56:23.0541 5232 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2011/08/14 13:56:23.0652 5232 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/08/14 13:56:23.0769 5232 XAudio (dab33cfa9dd24251aaa389ff36b64d4b) C:\Windows\system32\DRIVERS\xaudio.sys 2011/08/14 13:56:23.0953 5232 MBR (0x1B8) (85d751f0e41b8e520aee8c07a8da777b) \Device\Harddisk0\DR0 2011/08/14 13:56:23.0999 5232 Boot (0x1200) (2a8f368ee574a5451dd930b069ce1f0d) \Device\Harddisk0\DR0\Partition0 2011/08/14 13:56:24.0031 5232 Boot (0x1200) (3424b4681fadd4a4fbc87259422a180b) \Device\Harddisk0\DR0\Partition1 2011/08/14 13:56:24.0053 5232 ================================================================================ 2011/08/14 13:56:24.0053 5232 Scan finished 2011/08/14 13:56:24.0053 5232 ================================================================================ 2011/08/14 13:56:24.0117 4432 Detected object count: 0 2011/08/14 13:56:24.0117 4432 Actual detected object count: 0
Um as for my computer, it seems to run the same as always. Nothing really changed. Sorry that my description is really vague and probably not that useful but my system right now seems to be operating the same as before.
Hi um okay just now… a blue screen popped up saying that "a problem was detected and windows was forced to shut down to prevent damage to our computer" and that it was "collecting data for crash dump, initializing disk for crash dump, and etc." This is the first time this has happened to me, and I was wondering, is this related to the combofix problem before? Because you stated that combofix can delete some of your files if done incorrectly however, before when I was following your steps, combofix ran on its own without any steps the moment I opened it and it kept giving me the no nircmd error.
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have XP SP3, use the XP SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI