This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Persistent Popup on desktop related to Mshta.exe

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I am having some problems with my laptop. There has been this one popup that only has a "close" box on the top right and nothing else. It is linked to mshta.exe when i checked it under Task Manager. Also, i had previously been able to disable it by deleting certain unknown tasks in the Task Scheduler. However, it comes back out within a day or two. I'm not sure if it is creating new tasks or what but it just manages to survive anything i throw at it.. The interesting thing is that it does not appear after i end the mshta.exe process, but pops right back up during the after-login process after restarting the com. I would like to remove this program permanently if possible as it is rather irritating. Please give me some help as to which programs to use to remove this. Thank you hotshot
To add on, it may have caused my computer to run much slower, though this has yet to be proven. I recently had a few laggy periods when my laptop is usually working fine. Not sure if it's correlated, but all the same…. And i should clarify, sometimes the program pops up again even after ending the mshta.exe process. Need some way to deal with it. Thank you
Hi hotshot,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I can't tell anything about your computer without a log to look at.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Hi, thanks for responding. The following is the DDS Report: . DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26 Run by [removed] at 22:40:00 on 2011-08-21 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.65.1033.18.3037.1791 [GMT 8:00] . AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\windows\system32\wininit.exe C:\windows\system32\lsm.exe C:\windows\system32\svchost.exe -k DcomLaunch C:\windows\system32\nvvsvc.exe C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\windows\system32\svchost.exe -k RPCSS C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\windows\system32\svchost.exe -k netsvcs C:\windows\system32\svchost.exe -k LocalService C:\windows\system32\svchost.exe -k NetworkService C:\windows\system32\svchost.exe -k LocalServiceNoNetwork C:\windows\System32\spoolsv.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\windows\system32\nvvsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe C:\windows\system32\PnkBstrA.exe C:\windows\System32\IgrsSvcs.exe C:\Program Files\Cyberlink\Shared files\RichVideo.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\windows\system32\wbem\wmiprvse.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\windows\system32\svchost.exe -k bthsvcs C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\windows\system32\taskhost.exe C:\windows\system32\taskeng.exe C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Lenovo\Energy Management\utility.exe C:\Program Files\Lenovo\Energy Management\Energy Management.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Pando Networks\Media Booster\PMB.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\windows\System32\svchost.exe -k LocalServicePeerNet C:\windows\system32\mshta.exe C:\Users\lenovo\AppData\Local\Google\Chrome\Application\chrome.exe C:\windows\system32\DllHost.exe C:\Users\lenovo\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\lenovo\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\lenovo\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\lenovo\AppData\Local\Google\Chrome\Application\chrome.exe C:\windows\system32\rundll32.exe C:\Users\lenovo\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe C:\windows\servicing\TrustedInstaller.exe C:\windows\system32\DllHost.exe C:\windows\system32\DllHost.exe C:\windows\system32\conhost.exe C:\windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://msn.com/ uInternet Settings,ProxyServer = proxy4.hci.edu.sg:8080 uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [cereal_9e1e131bd184c0c6b4e0cbfc53fa5867d8b767c1] c:\users\lenovo\documents\cereal_9e1e131bd184c0c6b4e0cbfc53fa5867d8b767c1.vbs uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun: [EnergyUtility] c:\program files\lenovo\energy management\utility.exe mRun: [Energy Management] c:\program files\lenovo\energy management\Energy Management.exe mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" uPolicies-explorer: NoSMHelp = 1 (0x1) uPolicies-explorer: GreyMSIAds = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Evernote 4.0 - c:\program files\evernote\evernote\EvernoteIE.dll/204 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\evernote\evernote\EvernoteIE.dll/204 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{314728E9-AB3B-4ACB-B74A-7BA8907BC378} : NameServer = 203.116.1.94 203.116.254.150 TCP: Interfaces\{A6FBD4A1-6B92-4253-8A1F-A0496BADEDF8} : NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{A6FBD4A1-6B92-4253-8A1F-A0496BADEDF8} : DhcpNameServer = 192.168.1.254 TCP: Interfaces\{A6FBD4A1-6B92-4253-8A1F-A0496BADEDF8}\2427164666F6274602C4F6862E08993702960586F6E656 : NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{A6FBD4A1-6B92-4253-8A1F-A0496BADEDF8}\2427164666F6274602C4F6862E08993702960586F6E656 : DhcpNameServer = [removed] [removed] TCP: Interfaces\{A6FBD4A1-6B92-4253-8A1F-A0496BADEDF8}\C696E6B6379737 : DhcpNameServer = [removed] [removed] [removed] Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\users\lenovo\appdata\roaming\mozilla\firefox\profiles\weeonb83.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4de1f7d6&v=7.005.030.004&i=23&tp=ab&iy=&ychte=sg&lng=en-US&q= FF - prefs.js: network.proxy.ftp - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.ftp_port - 3128 FF - prefs.js: network.proxy.gopher - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.gopher_port - 3128 FF - prefs.js: network.proxy.http - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.http_port - 3128 FF - prefs.js: network.proxy.socks - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.socks_port - 3128 FF - prefs.js: network.proxy.ssl - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.ssl_port - 3128 FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\ahnlab\asp\components\aosmgr\conflict_221\npaosmgr.dll FF - plugin: c:\program files\ahnlab\asp\mykeydefense 2.5\npmkd25aos.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll FF - plugin: c:\users\lenovo\appdata\local\google\update\1.3.21.65\npGoogleUpdate3.dll . ============= SERVICES / DRIVERS =============== . R1 funfrm;funfrm;c:\windows\system32\drivers\funfrm.sys [2009-11-6 54800] R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648] R1 MpKsl155ef9f8;MpKsl155ef9f8;c:\programdata\microsoft\microsoft antimalware\definition updates\{b2d7a4b0-b083-47c3-b3b2-04b16a08a58c}\MpKsl155ef9f8.sys [2011-8-21 28752] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2011-7-13 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-13 67664] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2011-5-5 116608] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952] R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-6-30 21992] R2 IGRS;IGRS;c:\program files\lenovo\readycomm\common\IGRS.exe [2009-7-15 38152] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-7-1 2214504] R2 ReadyComm.DirectRouter;ReadyComm.DirectRouter;c:\windows\system32\igrssvcs.exe -k igrssvcs –> c:\windows\system32\IgrsSvcs.exe -k IgrsSvcs [?] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-5-20 378472] R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [2010-1-20 23136] R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-4-14 45736] R3 itecir;ITECIR Infrared Receiver;c:\windows\system32\drivers\itecir.sys [2010-7-13 65640] R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2009-11-5 119256] R3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60x.sys [2009-11-5 273448] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392] R3 NETw5s32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\drivers\NETw5s32.sys [2009-9-15 6114816] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-11-5 139368] R3 wdmirror;wdmirror;c:\windows\system32\drivers\WDMirror.sys [2009-11-6 11792] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 Firefox Service;Firefox Service; [x] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888] S3 Bridge0;Bridge0;c:\windows\system32\drivers\wdbridge.sys [2009-11-6 63240] S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2011-3-30 180736] S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2011-3-30 101248] S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\lenovo\readycomm\AppSvc.exe [2009-11-6 414984] S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\lenovo\readycomm\ConnSvc.exe [2009-11-6 472328] S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2009-11-5 4231680] S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 65024] S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944] S3 PS_MDP;ReadyComm Presentation Space Helper Service;c:\windows\system32\igrssvcs.exe -k igrssvcs –> c:\windows\system32\IgrsSvcs.exe -k IgrsSvcs [?] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-20 52224] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-8-31 1343400] S3 wsvd;wsvd;c:\windows\system32\drivers\wsvd.sys [2009-7-22 81704] S4 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\games\minecraft\hamachi\hamachi-2.exe -s –> d:\games\minecraft\hamachi\hamachi-2.exe -s [?] . =============== Created Last 30 ================ . 2011-08-21 14:32:30 28752 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{b2d7a4b0-b083-47c3-b3b2-04b16a08a58c}\MpKsl155ef9f8.sys 2011-08-21 03:37:50 ——– d—–w- c:\users\lenovo\appdata\local\{16372E66-67AB-4361-9794-FDC4D8075B1C} 2011-08-21 03:37:40 ——– d—–w- c:\users\lenovo\appdata\local\{4BDF85CC-EF7A-459F-A8EF-23571BB39F5A} 2011-08-20 11:12:23 7152464 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{b2d7a4b0-b083-47c3-b3b2-04b16a08a58c}\mpengine.dll 2011-08-20 11:03:31 ——– d—–w- c:\users\lenovo\appdata\local\{19A446D4-B545-4763-9793-C21DFC7C252E} 2011-08-20 11:03:19 ——– d—–w- c:\users\lenovo\appdata\local\{F820D61D-6C48-46FD-9D58-A95C6CE42556} 2011-08-19 12:13:57 ——– d—–w- c:\users\lenovo\appdata\local\{1DA6738D-44A7-4B29-AD58-79B5F0AF4CCE} 2011-08-19 12:13:49 ——– d—–w- c:\users\lenovo\appdata\local\{BEC4DB7C-284A-4A30-9F44-EDA69DCBB41D} 2011-08-18 15:08:46 ——– d—–w- c:\program files\MSXML 4.0 2011-08-18 13:58:03 ——– d—–w- c:\users\lenovo\appdata\roaming\Uniblue 2011-08-18 13:58:02 ——– dc-h–w- c:\programdata\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42} 2011-08-18 13:58:02 ——– d—–w- c:\program files\Uniblue 2011-08-18 13:57:59 ——– d—–w- c:\users\lenovo\appdata\local\PackageAware 2011-08-18 13:43:38 ——– d—–w- c:\users\lenovo\appdata\local\{A04390E5-7D72-4643-9062-764B452F6861} 2011-08-18 13:43:28 ——– d—–w- c:\users\lenovo\appdata\local\{365D954A-7790-4326-9FEF-54F23DF8B7E3} 2011-08-17 14:12:18 ——– d—–w- c:\users\lenovo\appdata\local\{660DB088-72AA-47F0-BB55-97778DA5D77C} 2011-08-17 14:12:08 ——– d—–w- c:\users\lenovo\appdata\local\{6588D645-3870-40DA-B89B-0D46103B07CD} 2011-08-17 00:03:55 ——– d—–w- c:\users\lenovo\appdata\local\{5D533057-0B0E-47A6-8F15-735769C14674} 2011-08-16 14:26:07 ——– d—–w- c:\users\lenovo\appdata\local\Adobe 2011-08-16 09:15:32 ——– d—–w- c:\users\lenovo\appdata\local\{C7125987-62B1-4877-801B-4F924CF84D50} 2011-08-16 09:15:21 ——– d—–w- c:\users\lenovo\appdata\local\{9BAAC7E6-98F3-4B43-9DA3-8D4E944B84AE} 2011-08-15 16:17:03 ——– d-sh–w- C:\$RECYCLE.BIN 2011-08-15 16:09:16 ——– d—–w- C:\ComboFix 2011-08-15 15:52:51 ——– d—–w- C:\_OTL 2011-08-15 15:47:18 ——– d—–w- c:\users\lenovo\appdata\roaming\Malwarebytes 2011-08-15 15:47:14 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-15 15:47:14 ——– d—–w- c:\programdata\Malwarebytes 2011-08-15 15:47:11 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-15 15:47:11 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-08-15 13:36:41 ——– d—–w- c:\users\lenovo\appdata\local\temp 2011-08-15 13:26:34 98816 —-a-w- c:\windows\sed.exe 2011-08-15 13:26:34 518144 —-a-w- c:\windows\SWREG.exe 2011-08-15 13:26:34 256000 —-a-w- c:\windows\PEV.exe 2011-08-15 13:26:34 208896 —-a-w- c:\windows\MBR.exe 2011-08-15 12:55:39 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2011-08-15 12:55:39 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-08-15 11:42:37 ——– d—–w- c:\users\lenovo\appdata\local\{74D3B174-9DB8-4576-808A-9FCC57556158} 2011-08-15 11:42:06 ——– d—–w- c:\users\lenovo\appdata\local\{DBBAF2A6-19C1-4A37-AD0A-2E203A982319} 2011-08-15 07:34:26 ——– d—–w- c:\users\lenovo\appdata\local\{347EB51C-D9C1-4FAE-86C6-1C392361423F} 2011-08-14 22:46:19 ——– d—–w- c:\users\lenovo\appdata\local\{F9D46105-0899-49B1-9FD6-8251C26B37AC} 2011-08-14 06:39:14 ——– d—–w- c:\users\lenovo\appdata\local\{1376B538-C223-4AF9-A995-EF31471CB77A} 2011-08-14 06:39:02 ——– d—–w- c:\users\lenovo\appdata\local\{6C3CAAFC-D1EB-4EDB-9C70-E5733213620B} 2011-08-13 15:01:15 ——– d—–w- c:\users\lenovo\appdata\local\{1E15E3D4-1364-463E-8061-077B9F7110EB} 2011-08-13 15:01:01 ——– d—–w- c:\users\lenovo\appdata\local\{BFEB8BDD-6195-4AA5-A723-64505A5602F3} 2011-08-13 03:00:32 ——– d—–w- c:\users\lenovo\appdata\local\{5DECD55D-1B3E-40C1-9421-9BE88D6341AC} 2011-08-13 03:00:21 ——– d—–w- c:\users\lenovo\appdata\local\{244D50C3-AA57-4666-9AD5-4B7C3B9167EB} 2011-08-12 14:43:37 ——– d—–w- c:\users\lenovo\appdata\local\{3E8A24F8-C8EF-4FDD-9F19-76EB1AACD64B} 2011-08-12 14:43:25 ——– d—–w- c:\users\lenovo\appdata\local\{86E5B493-9096-441D-B03A-0AB62FF207EC} 2011-08-12 11:18:27 ——– d—–w- c:\users\lenovo\appdata\local\{C58B3B03-2CA1-4DA8-BF80-455D80B78B3B} 2011-08-11 23:38:53 ——– d—–w- c:\users\lenovo\appdata\local\{2C827F69-0F8C-4DAC-AAF8-3D75354D42F5} 2011-08-11 16:17:00 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-08-11 16:17:00 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-08-11 16:15:51 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2011-08-11 16:13:32 94208 —-a-w- c:\program files\common files\system\ole db\msdaosp.dll 2011-08-11 16:13:32 86016 —-a-w- c:\windows\system32\odbccu32.dll 2011-08-11 16:13:32 81920 —-a-w- c:\windows\system32\odbccr32.dll 2011-08-11 16:13:32 122880 —-a-w- c:\windows\system32\odbccp32.dll 2011-08-11 16:13:31 319488 —-a-w- c:\windows\system32\odbcjt32.dll 2011-08-11 16:13:31 163840 —-a-w- c:\windows\system32\odbctrac.dll 2011-08-11 11:27:54 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll 2011-08-11 11:27:53 439632 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{6fc41fa3-fb02-4110-9eed-39cb9683777f}\gapaengine.dll 2011-08-11 11:18:16 ——– d—–w- c:\users\lenovo\appdata\local\{61F8E0B1-E0C1-4C11-9C96-2E2F18B546D8} 2011-08-11 11:17:56 ——– d—–w- c:\users\lenovo\appdata\local\{3ED25AD3-6F7D-442F-A924-31EFC688655F} 2011-08-10 15:59:09 ——– d—–w- c:\users\lenovo\appdata\local\{DF219DA4-AB41-42E4-9A6D-95B89E43807B} 2011-08-10 15:58:56 ——– d—–w- c:\users\lenovo\appdata\local\{4FE90007-5C33-4E6E-B674-0C0BD01BF47C} 2011-08-10 03:58:42 ——– d—–w- c:\users\lenovo\appdata\local\{3EDAF27F-FD4D-4EF7-89CF-C84E8CF68506} 2011-08-10 03:58:31 ——– d—–w- c:\users\lenovo\appdata\local\{D66A6978-60FA-4EF3-89DE-F99CDBD7A765} 2011-08-09 15:58:03 ——– d—–w- c:\users\lenovo\appdata\local\{1626272A-1E0F-45FB-AE89-791FCD732FBD} 2011-08-09 15:57:52 ——– d—–w- c:\users\lenovo\appdata\local\{484144A2-CB1D-4BAD-92DF-26A53D58E528} 2011-08-09 03:57:24 ——– d—–w- c:\users\lenovo\appdata\local\{7390B067-5A9C-4398-8738-C6D0FA3436B1} 2011-08-09 03:57:11 ——– d—–w- c:\users\lenovo\appdata\local\{8EE78B9C-44FB-4D6F-BE37-865C29EF76DF} 2011-08-08 07:06:58 ——– d—–w- c:\users\lenovo\appdata\local\{6D4835EF-1B7B-4E2B-8C45-FE44608FA92A} 2011-08-08 07:06:48 ——– d—–w- c:\users\lenovo\appdata\local\{C2967522-5942-46DD-9DB0-CEA59A8E267B} 2011-08-07 17:02:03 ——– d—–w- c:\users\lenovo\appdata\local\{B7BC91AB-9A11-407D-BCB2-642E53F6BBAF} 2011-08-07 17:01:52 ——– d—–w- c:\users\lenovo\appdata\local\{6914A2E5-C4BA-45C0-B75A-394ECBC41FFE} 2011-08-07 05:01:25 ——– d—–w- c:\users\lenovo\appdata\local\{7C84EE8B-30F5-45B0-AEB9-6937F0565BB2} 2011-08-07 05:01:15 ——– d—–w- c:\users\lenovo\appdata\local\{0F4F659A-45EC-4357-A9A1-93A99BC91B62} 2011-08-06 13:57:20 ——– d—–w- c:\users\lenovo\appdata\local\{CFCE8FDE-B627-40C5-88C5-DB142F61A5A5} 2011-08-06 13:57:09 ——– d—–w- c:\users\lenovo\appdata\local\{7896A563-B84B-451E-B7BC-776A78CBD05B} 2011-08-06 01:56:29 ——– d—–w- c:\users\lenovo\appdata\local\{719CDEFC-6FFC-42DC-8838-9A5A22EB0E6D} 2011-08-06 01:56:16 ——– d—–w- c:\users\lenovo\appdata\local\{74E7FA4B-D3BB-4548-9952-5314D0B6221D} 2011-08-05 11:45:46 ——– d—–w- c:\users\lenovo\appdata\local\{D65DA9D3-2047-409A-AF00-94A39FFE3B16} 2011-08-05 11:45:33 ——– d—–w- c:\users\lenovo\appdata\local\{71127BB1-40D0-4603-8CA1-30C418F89973} 2011-08-05 08:22:33 ——– d—–w- c:\users\lenovo\appdata\local\{064CA3F2-DD85-4618-BC82-C3B4FD63DBD7} 2011-08-04 12:27:58 ——– d—–w- c:\users\lenovo\appdata\local\{BBAC2F5F-7736-4C73-B15B-46649C643D70} 2011-08-04 12:27:47 ——– d—–w- c:\users\lenovo\appdata\local\{B90E8607-D4CA-41C0-856D-90139D7DACFE} 2011-08-04 11:55:41 ——– d—–w- c:\windows\en 2011-08-04 11:49:16 ——– d—–w- c:\users\lenovo\appdata\local\{BCB57905-7024-4E5D-871E-2F8CA8FBECB5} 2011-08-04 09:09:28 ——– d—–w- c:\users\lenovo\appdata\local\{79FBF067-3605-415F-A854-E5FB0F74918D} 2011-08-04 09:07:45 ——– d—–w- c:\programdata\!SASCORE 2011-08-04 09:07:42 ——– d—–w- c:\users\lenovo\appdata\local\{A3501D8A-5B3A-4B1E-A2CE-5AA824A8A6C8} 2011-08-04 09:07:19 ——– d—–w- c:\users\lenovo\appdata\local\{3F0E9F54-225A-46B7-AFD2-9750BD123F0B} 2011-08-03 08:46:01 ——– d—–w- c:\users\lenovo\appdata\local\{1F6A84BE-B0EA-450D-9B89-FC8BA87AFD45} 2011-08-03 02:26:20 ——– d—–w- c:\users\lenovo\appdata\local\{890978CF-0BE5-4EBE-A20B-098385A8A154} 2011-08-02 23:48:13 ——– d—–w- c:\users\lenovo\appdata\local\{B0D0996B-9BEE-46FE-B461-7ED779084BDA} 2011-08-02 08:16:28 ——– d—–w- c:\users\lenovo\appdata\local\{07DDB8C8-F7D8-45E1-B573-953986C3D1AD} 2011-08-01 10:03:37 ——– d—–w- c:\users\lenovo\appdata\local\{55E57EFB-89D7-43CE-9F5F-7CE2AB25876D} 2011-08-01 08:33:24 ——– d—–w- c:\users\lenovo\appdata\local\{4CAB9EDC-F32F-42CF-8092-F8340795846E} 2011-07-31 14:37:45 ——– d—–w- c:\users\lenovo\appdata\local\{21E21808-BA26-43F3-B266-BE5CFD8FF811} 2011-07-31 02:37:21 ——– d—–w- c:\users\lenovo\appdata\local\{24D8668B-4685-4D62-90E1-9856A122AC31} 2011-07-30 09:29:09 ——– d—–w- c:\users\lenovo\appdata\local\{3F2870DC-0F76-4AFC-AE4C-86A6F7F84F29} 2011-07-29 13:06:00 ——– d—–w- c:\windows\system32\wbem\Logs 2011-07-29 13:05:57 ——– d—–w- c:\users\lenovo\appdata\roaming\SUPERAntiSpyware.com 2011-07-29 13:05:57 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2011-07-29 13:05:52 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-07-29 12:12:08 ——– d—–w- c:\users\lenovo\appdata\local\{FB45F52D-4A45-4F61-88A2-0E76F18ACE19} 2011-07-29 08:28:12 ——– d—–w- c:\users\lenovo\appdata\local\{5885E11B-D821-428C-B57B-C71A77FAB54A} 2011-07-29 06:33:02 ——– d—–w- c:\users\lenovo\appdata\local\{EE6778D1-C939-477A-B251-AD38F0485F27} 2011-07-29 05:30:57 6881616 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\updates\mpengine.dll 2011-07-28 11:11:32 ——– d—–w- c:\users\lenovo\appdata\local\{D614AB1E-A8A0-4372-AAC9-51A667CE7821} 2011-07-28 08:24:39 ——– d—–w- c:\users\lenovo\appdata\local\{5628E700-46D1-464D-9936-FF799F94676D} 2011-07-28 04:36:28 ——– d—–w- c:\users\lenovo\appdata\local\{29A9AD50-EF35-4EF0-9BC5-71BA4B8D5697} 2011-07-27 22:48:14 ——– d—–w- c:\users\lenovo\appdata\local\{47ABBB8B-5553-438B-B492-17F86B463ABD} 2011-07-27 08:50:13 ——– d—–w- c:\users\lenovo\appdata\local\{CA2E9BF2-C961-4E43-9F65-E9045F543994} 2011-07-26 22:46:56 ——– d—–w- c:\users\lenovo\appdata\local\{D5E1E823-1086-4619-A799-39EC1B2335A8} 2011-07-26 08:07:31 ——– d—–w- c:\users\lenovo\appdata\local\{6960C30A-E242-4F9A-8CE4-67F6975E850E} 2011-07-25 11:54:38 ——– d—–w- c:\users\lenovo\appdata\local\{4AFC2654-5A4E-49F7-BD35-81411C33FF58} 2011-07-25 11:13:03 ——– d—–w- c:\users\lenovo\appdata\local\{06BDA1DA-6887-4183-AE65-1F49DC410145} 2011-07-25 09:17:49 ——– d—–w- c:\users\lenovo\appdata\local\{BBD6EE60-0AE0-45D1-A5C9-F4D5F8869496} 2011-07-25 09:11:21 ——– d—–w- c:\users\lenovo\appdata\local\{E16B2F5E-AE59-43C0-9BC8-FD956AB97760} 2011-07-25 09:00:44 ——– d—–w- c:\users\lenovo\appdata\local\{0D22B4E3-535A-49F9-9136-6AD269D31644} 2011-07-25 02:19:48 ——– d—–w- c:\users\lenovo\appdata\local\{D0BB76B5-AD78-4015-BF84-105C154F2852} 2011-07-24 22:57:05 ——– d—–w- c:\users\lenovo\appdata\local\{81E05961-FF32-40AC-8E00-1CD33C105F16} 2011-07-24 06:47:29 ——– d—–w- c:\users\lenovo\appdata\local\{E7D43C93-0FE7-4990-8F9E-1D4D684DB7F1} 2011-07-23 13:31:33 ——– d—–w- c:\users\lenovo\appdata\local\{6878901A-ECB5-4DC5-8274-318AD5C4A551} 2011-07-23 00:13:44 ——– d—–w- c:\users\lenovo\appdata\local\{A29545D5-EE64-4A15-BC78-3FB97E28613B} . ==================== Find3M ==================== . 2011-08-20 12:21:26 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-29 14:05:52 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-07-22 02:54:43 1797632 —-a-w- c:\windows\system32\jscript9.dll 2011-07-22 02:48:26 1126912 —-a-w- c:\windows\system32\wininet.dll 2011-07-22 02:44:36 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-07-16 04:27:30 290816 —-a-w- c:\windows\system32\KernelBase.dll 2011-07-16 02:17:19 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2011-07-16 02:17:19 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2011-07-16 02:17:19 3584 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2011-07-16 02:17:19 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2011-07-09 02:30:00 223744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-24 04:27:01 169984 —-a-w- c:\windows\system32\winsrv.dll 2011-06-24 04:22:20 271360 —-a-w- c:\windows\system32\conhost.exe 2011-06-22 12:57:40 152576 —-a-w- c:\windows\system32\msclmd.dll 2011-06-21 05:34:23 1290624 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-06-11 02:29:25 2334208 —-a-w- c:\windows\system32\win32k.sys 2011-05-24 10:44:59 293376 —-a-w- c:\windows\system32\umpnpmgr.dll . ============= FINISH: 22:40:47.43 =============== Thank you, hotshot
Yes, i did run ComboFix. This is the log: ComboFix 11-08-15.07 - lenovo 16/08/2011 0:10.2.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.65.1033.18.3037.1680 [GMT 8:00] Running from: c:\users\[removed]\Desktop\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2011-07-15 to 2011-08-15 ))))))))))))))))))))))))))))))) . . 2011-08-15 16:15 . 2011-08-15 16:15 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2011-08-15 16:15 . 2011-08-15 16:15 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-08-15 16:15 . 2011-08-15 16:15 ——– d—–w- c:\users\Administrator\AppData\Local\temp 2011-08-15 15:52 . 2011-08-15 15:52 ——– d—–w- C:\_OTL 2011-08-15 15:47 . 2011-08-15 15:47 ——– d—–w- c:\users\lenovo\AppData\Roaming\Malwarebytes 2011-08-15 15:47 . 2011-08-15 15:47 ——– d—–w- c:\programdata\Malwarebytes 2011-08-15 15:47 . 2011-07-06 11:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-15 15:47 . 2011-08-15 15:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-08-15 15:47 . 2011-07-06 11:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-15 13:36 . 2011-08-15 16:16 ——– d—–w- c:\users\lenovo\AppData\Local\temp 2011-08-15 12:55 . 2011-08-15 15:30 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2011-08-15 12:55 . 2011-08-15 12:58 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-08-15 11:52 . 2011-07-13 03:39 6881616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DCD095DB-EB54-429B-A4C1-C05DE1943F82}\mpengine.dll 2011-08-11 16:17 . 2011-06-23 04:33 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-08-11 16:17 . 2011-06-23 04:33 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-08-11 16:15 . 2011-07-16 04:15 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2011-08-11 16:13 . 2011-06-15 08:55 86016 —-a-w- c:\windows\system32\odbccu32.dll 2011-08-11 16:13 . 2011-06-15 08:55 81920 —-a-w- c:\windows\system32\odbccr32.dll 2011-08-11 16:13 . 2011-06-15 08:55 122880 —-a-w- c:\windows\system32\odbccp32.dll 2011-08-11 16:13 . 2011-06-15 08:54 94208 —-a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll 2011-08-11 16:13 . 2011-06-15 08:55 319488 —-a-w- c:\windows\system32\odbcjt32.dll 2011-08-11 16:13 . 2011-06-15 08:55 163840 —-a-w- c:\windows\system32\odbctrac.dll 2011-08-11 11:27 . 2011-07-14 11:49 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2011-08-11 11:27 . 2011-07-14 11:49 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6FC41FA3-FB02-4110-9EED-39CB9683777F}\gapaengine.dll 2011-08-04 11:55 . 2011-08-04 11:55 ——– d—–w- c:\windows\en 2011-08-04 09:07 . 2011-08-04 09:07 ——– d—–w- c:\programdata\!SASCORE 2011-07-29 14:06 . 2011-07-29 14:06 ——– d—–w- c:\program files\Common Files\Java 2011-07-29 13:06 . 2011-07-29 13:06 ——– d—–w- c:\windows\system32\wbem\Logs 2011-07-29 13:05 . 2011-07-29 13:05 ——– d—–w- c:\users\lenovo\AppData\Roaming\SUPERAntiSpyware.com 2011-07-29 13:05 . 2011-07-29 13:05 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2011-07-29 13:05 . 2011-08-13 08:01 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-07-29 05:30 . 2011-07-13 03:39 6881616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll 2011-07-26 08:13 . 2011-07-26 08:13 ——– d—–w- c:\program files\Common Files\Adobe 2011-07-19 07:27 . 2011-07-19 07:27 ——– d—–w- c:\program files\DivX 2011-07-19 07:27 . 2011-07-19 07:27 ——– d—–w- c:\programdata\DivX . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-04 11:54 . 2010-06-24 03:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-07-29 14:05 . 2010-09-09 12:19 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-07-13 03:39 . 2011-07-15 14:53 6881616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-06-23 05:08 . 2011-06-05 14:02 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-22 12:57 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll 2011-06-11 02:29 . 2011-07-13 12:11 2334208 —-a-w- c:\windows\system32\win32k.sys 2011-06-07 15:55 . 2011-07-12 09:42 7074640 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EC284FDB-A59E-4E35-94E9-9CBB8AB196DE}\mpengine.dll 2011-05-24 10:44 . 2011-06-29 12:59 293376 —-a-w- c:\windows\system32\umpnpmgr.dll 2011-05-21 06:01 . 2011-07-09 10:00 66664 —-a-w- c:\windows\system32\nvshext.dll 2011-05-21 06:01 . 2011-07-09 10:00 615528 —-a-w- c:\windows\system32\nvvsvc.exe 2011-05-21 06:01 . 2011-07-09 10:00 3693672 —-a-w- c:\windows\system32\nvcpl.dll 2011-05-21 06:01 . 2011-07-09 10:00 2560616 —-a-w- c:\windows\system32\nvsvcr.dll 2011-05-21 06:01 . 2011-07-09 10:00 2557544 —-a-w- c:\windows\system32\nvsvc.dll 2011-05-21 06:01 . 2011-07-09 10:00 111208 —-a-w- c:\windows\system32\nvmctray.dll 2011-05-21 06:01 . 2011-07-09 10:00 543336 —-a-w- c:\windows\system32\easyupdatusapiu.dll 2011-05-21 06:01 . 2011-07-09 10:00 319592 —-a-w- c:\windows\system32\oemdspif.dll 2011-05-21 06:01 . 2011-06-30 16:20 899688 —-a-w- c:\windows\system32\nvdispco3220150.dll 2011-05-21 06:01 . 2011-06-30 16:20 865896 —-a-w- c:\windows\system32\nvgenco322090.dll 2011-05-21 06:01 . 2011-06-30 16:20 6555240 —-a-w- c:\windows\system32\nvwgf2um.dll 2011-05-21 06:01 . 2011-06-30 16:20 57960 —-a-w- c:\windows\system32\OpenCL.dll 2011-05-21 06:01 . 2011-06-30 16:20 5301352 —-a-w- c:\windows\system32\nvcuda.dll 2011-05-21 06:01 . 2011-06-30 16:20 2804328 —-a-w- c:\windows\system32\nvcuvid.dll 2011-05-21 06:01 . 2011-06-30 16:20 2082408 —-a-w- c:\windows\system32\nvcuvenc.dll 2011-05-21 06:01 . 2011-06-30 16:20 16456296 —-a-w- c:\windows\system32\nvoglv32.dll 2011-05-21 06:01 . 2011-06-30 16:20 13011560 —-a-w- c:\windows\system32\nvcompiler.dll 2011-05-21 06:01 . 2011-06-30 16:20 12392 —-a-w- c:\windows\system32\drivers\nvBridge.kmd 2011-05-21 06:01 . 2011-06-30 16:20 10589800 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2011-05-21 06:01 . 2009-11-05 01:45 2335848 —-a-w- c:\windows\system32\nvapi.dll 2011-05-21 06:01 . 2009-11-05 01:45 11992680 —-a-w- c:\windows\system32\nvd3dum.dll 2011-05-20 14:35 . 2011-05-20 14:35 304744 —-a-w- c:\windows\system32\nvStreaming.exe 2011-06-23 05:04 . 2011-05-07 07:39 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256] "Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-07-08 3077528] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-08-13 4600704] "cereal_9e1e131bd184c0c6b4e0cbfc53fa5867d8b767c1"="c:\users\lenovo\Documents\cereal_9e1e131bd184c0c6b4e0cbfc53fa5867d8b767c1.vbs" [2011-08-15 3256] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-06-16 7547424] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-08-14 1549608] "EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2009-07-15 4081480] "Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2009-06-25 5064520] "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoSMHelp"= 1 (0x1) "GreyMSIAds"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-04 113024] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R1 MpKsl04371109;MpKsl04371109;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1779E245-7D2D-40FD-A0C5-06B18C8E6652}\MpKsl04371109.sys [x] R1 MpKsl3cf4348d;MpKsl3cf4348d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1779E245-7D2D-40FD-A0C5-06B18C8E6652}\MpKsl3cf4348d.sys [x] R1 MpKsl3e61cb6c;MpKsl3e61cb6c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{42D69F88-63D6-477A-A45A-AFFAD37B2544}\MpKsl3e61cb6c.sys [x] R1 MpKsl4c8d54ca;MpKsl4c8d54ca;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{51E9197E-7267-4CB2-B4C9-19BCB6213B2B}\MpKsl4c8d54ca.sys [x] R1 MpKsl87d59fde;MpKsl87d59fde;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{44380725-DDE1-44D8-ABC1-D416D8D1A60B}\MpKsl87d59fde.sys [x] R1 MpKsl92ae3f66;MpKsl92ae3f66;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{44380725-DDE1-44D8-ABC1-D416D8D1A60B}\MpKsl92ae3f66.sys [x] R1 MpKsla8f38b44;MpKsla8f38b44;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{952CC2EF-0716-484A-856C-1EFBC3DDF736}\MpKsla8f38b44.sys [x] R1 MpKslac026884;MpKslac026884;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{952CC2EF-0716-484A-856C-1EFBC3DDF736}\MpKslac026884.sys [x] R1 MpKslb0d659db;MpKslb0d659db;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8A24AA0C-7092-412D-A3A7-AEB702C70DF9}\MpKslb0d659db.sys [x] R1 MpKslb1a2cf4c;MpKslb1a2cf4c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2FE57078-AFC4-4F2D-809F-0ECC14EF1198}\MpKslb1a2cf4c.sys [x] R1 MpKslb93796a3;MpKslb93796a3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7B9CC389-9FD4-4DC7-BBDC-AAEAF6FD3F57}\MpKslb93796a3.sys [x] R1 MpKslbe879802;MpKslbe879802;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D1401CDC-1703-49E4-BB7B-932716FD3C7D}\MpKslbe879802.sys [x] R1 MpKslc6d3926d;MpKslc6d3926d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F8F79754-7FAB-4CC0-8D9B-A827B20C10FF}\MpKslc6d3926d.sys [x] R1 MpKslde2defd0;MpKslde2defd0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D1401CDC-1703-49E4-BB7B-932716FD3C7D}\MpKslde2defd0.sys [x] R1 MpKslef3df543;MpKslef3df543;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0B5883E5-6468-4EEA-AF53-1762382CEE52}\MpKslef3df543.sys [x] R1 MpKslf1dccbe1;MpKslf1dccbe1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{42D69F88-63D6-477A-A45A-AFFAD37B2544}\MpKslf1dccbe1.sys [x] R1 MpKslf8fb5338;MpKslf8fb5338;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2F0DCD9A-F3EA-4DED-82E6-3BDF63C50800}\MpKslf8fb5338.sys [x] R1 MpKslfab4b37d;MpKslfab4b37d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7B9CC389-9FD4-4DC7-BBDC-AAEAF6FD3F57}\MpKslfab4b37d.sys [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 Firefox Service;Firefox Service; [x] R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [2009-07-29 63240] R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x] R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-09-04 180736] R3 GGSAFERDriver;GGSAFER Driver;c:\users\lenovo\Desktop\Random\Garena\safedrv.sys [x] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-07-24 101248] R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-07-28 414984] R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-07-28 472328] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392] R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-05-14 4231680] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944] R3 PS_MDP;ReadyComm Presentation Space Helper Service;c:\windows\System32\IgrsSvcs.exe [2009-07-14 20992] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-31 1343400] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-22 81704] R4 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\games\MineCraft\Hamachi\hamachi-2.exe [2011-05-25 1336712] S1 funfrm;funfrm; [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-08-04 12880] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-13 116608] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2010-11-09 21992] S2 IGRS;IGRS;c:\program files\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152] S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-01-27 50704] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504] S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter;c:\windows\System32\IgrsSvcs.exe [2009-07-14 20992] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-05-20 378472] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2010-01-19 23136] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-04-13 45736] S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2010-07-13 65640] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-05-18 119256] S3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-06-19 273448] S3 NETw5s32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2009-09-15 6114816] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-05-10 139368] S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792] . . — Other Services/Drivers In Memory — . *Deregistered* - MBAMSwissArmy . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP . Contents of the 'Scheduled Tasks' folder . 2011-08-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2366000599-2193686838-973492706-1002Core.job - c:\users\lenovo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-31 08:30] . 2011-08-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2366000599-2193686838-973492706-1002UA.job - c:\users\lenovo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-31 08:30] . . ——- Supplementary Scan ——- . uStart Page = hxxp://msn.com/ uInternet Settings,ProxyServer = proxy.hci.edu.sg:8080 uInternet Settings,ProxyOverride = *.local IE: Add to Evernote 4.0 - c:\program files\Evernote\Evernote\EvernoteIE.dll/204 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: {{A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\Evernote\Evernote\EvernoteIE.dll/204 TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{314728E9-AB3B-4ACB-B74A-7BA8907BC378}: NameServer = 203.116.1.94 203.116.254.150 TCP: Interfaces\{A6FBD4A1-6B92-4253-8A1F-A0496BADEDF8}: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{A6FBD4A1-6B92-4253-8A1F-A0496BADEDF8}\2427164666F6274602C4F6862E08993702960586F6E656: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{A6FBD4A1-6B92-4253-8A1F-A0496BADEDF8}\75962756C656373704843494: NameServer = 8.8.8.8,8.8.4.4 FF - ProfilePath - c:\users\lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\weeonb83.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4de1f7d6&v=7.005.030.004&i=23&tp=ab&iy=&ychte=sg&lng=en-US&q= FF - prefs.js: network.proxy.ftp - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.ftp_port - 3128 FF - prefs.js: network.proxy.gopher - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.gopher_port - 3128 FF - prefs.js: network.proxy.http - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.http_port - 3128 FF - prefs.js: network.proxy.socks - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.socks_port - 3128 FF - prefs.js: network.proxy.ssl - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.ssl_port - 3128 FF - prefs.js: network.proxy.type - 0 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-2366000599-2193686838-973492706-1002\Software\SecuROM\License information*] "datasecu"=hex:29,7f,44,5b,96,fe,ba,32,18,50,14,f1,f7,3a,c8,5a,6b,83,fe,35,6d, 0c,9e,4f,32,e7,f6,26,e8,58,dd,40,22,cd,a8,59,e2,65,1e,42,15,54,63,6f,29,4a,\ "rkeysecu"=hex:27,13,4a,a4,c5,42,e0,b4,5b,72,b8,31,15,f0,7d,69 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-08-16 00:17:33 ComboFix-quarantined-files.txt 2011-08-15 16:17 ComboFix2.txt 2011-08-15 13:36 . Pre-Run: 45,720,965,120 bytes free Post-Run: 45,660,033,024 bytes free . - - End Of File - - 15D4591A09FF24141662020F9F394861 Thanks
hotshot,

I'm just not seeing the problem.

Let's get an online scan:

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Hi, So i ran the ESET.exe as you requested but there was no text file in the C drive. However, i managed to export the list of threats into a text file. So the contents are here: C:\Program Files\Uniblue\RegistryBooster\Launcher.exe Win32/RegistryBooster application C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe Win32/RegistryBooster application C:\Program Files\Uniblue\RegistryBooster\rbnotifier.exe Win32/RegistryBooster application C:\Program Files\Uniblue\RegistryBooster\rb_move_serial.exe Win32/RegistryBooster application C:\Program Files\Uniblue\RegistryBooster\rb_ubm.exe Win32/RegistryBooster application C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe Win32/RegistryBooster application C:\Users\lenovo\AppData\Local\temp\mia319B.tmp\data\OFFLINE\D038292B\DBD9B16A\Launcher.exe Win32/RegistryBooster application C:\Users\lenovo\AppData\Local\temp\mia319B.tmp\data\OFFLINE\D038292B\DBD9B16A\rbmonitor.exe Win32/RegistryBooster application C:\Users\lenovo\AppData\Local\temp\mia319B.tmp\data\OFFLINE\D038292B\DBD9B16A\rbnotifier.exe Win32/RegistryBooster application C:\Users\lenovo\AppData\Local\temp\mia319B.tmp\data\OFFLINE\D038292B\DBD9B16A\rb_move_serial.exe Win32/RegistryBooster application C:\Users\lenovo\AppData\Local\temp\mia319B.tmp\data\OFFLINE\D038292B\DBD9B16A\rb_ubm.exe Win32/RegistryBooster application C:\Users\lenovo\AppData\Local\temp\mia319B.tmp\data\OFFLINE\D038292B\DBD9B16A\registrybooster.exe Win32/RegistryBooster application C:\Users\lenovo\Desktop\Downloads\registrybooster.exe Win32/RegistryBooster application Operating memory Win32/RegistryBooster application These don't actually seem to be the problem i am looking for. As mentioned, it is a advertisement/popup on the desktop itself, not an online one. The first time i managed to disable it temporarily by disabling some task i found in the Task Scheduler, the second time by letting the timer run out on the popup. However, it is now back and there are no tasks that actually fit the program…. I tried disabling the Google Updates but it did not work. Maybe we can trace something from the mshta.exe process? Thank you
hotshot, Running registry booser is a good way to bork your system. There is virtually no chance it can do you any good… yet there is a high probablility that it can mess you up. I advise that you uninstall it immediately. That being said… it doesn't sound like it is the problem you have described. mshta.exe is part of your windows operating system. It is the routine that allows your computer to run .HTA files. .HTA files are executable HTML documents. mshta.exe will run whenever you use internet explorer, Visual Studio, Microsoft Office, and probably a few others. Can you post me a screenshot of your pop-up?
Here it is along with screen shots of the task manager. It's rather offensive and highly irritating… It only stops when i end the mshta.exe process, but upon restart the pop up comes back again… I really don't know how to permanently stop it as it just survives whatever i throw at it. It's also because mshta.exe is regarded as safe by most of the AV programs hence usually it isn't scanned or something like that. Is there a way to follow through from the mshta.exe part? Thank you hotshot
hotshot,

You are only seeing mshta.exe running because that pop-up is .html. It is effect… not cause.

Do you have any idea what this script is that is running on your machine? c:\users\lenovo\Documents\cereal_9e1e131bd184c0c6b4e0cbfc53fa5867d8b767c1.vbs

If not… let's get rid of it and see if that is where the pop-up is hiding.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    uRun: [cereal_9e1e131bd184c0c6b4e0cbfc53fa5867d8b767c1] c:\users\lenovo\documents\cereal_9e1e131bd184c0c6b4e0cbfc53fa5867d8b767c1.vbs
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Here is the log of the ComboFix: ComboFix 11-08-23.03 - lenovo 23/08/2011 22:37:03.3.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.65.1033.18.3037.2084 [GMT 8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\lenovo\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\lenovo\documents\cereal_9e1e131bd184c0c6b4e0cbfc53fa5867d8b767c1.vbs . . ((((((((((((((((((((((((( Files Created from 2011-07-23 to 2011-08-23 ))))))))))))))))))))))))))))))) . . 2011-08-23 14:44 . 2011-08-23 14:44 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2011-08-23 14:44 . 2011-08-23 14:44 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-08-23 14:44 . 2011-08-23 14:44 ——– d—–w- c:\users\Casey\AppData\Local\temp 2011-08-23 14:44 . 2011-08-23 14:44 ——– d—–w- c:\users\Administrator\AppData\Local\temp 2011-08-23 11:35 . 2011-08-23 11:35 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A969704C-7F61-4628-84D0-8A245E33F302}\MpKsl4a5d5fe1.sys 2011-08-23 07:34 . 2011-08-23 07:34 ——– d—–w- c:\programdata\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42} 2011-08-23 07:29 . 2011-08-12 02:44 7152464 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A969704C-7F61-4628-84D0-8A245E33F302}\mpengine.dll 2011-08-22 07:51 . 2011-08-22 07:51 ——– d—–w- c:\program files\ESET 2011-08-18 15:08 . 2011-08-18 15:08 ——– d—–w- c:\program files\MSXML 4.0 2011-08-18 13:57 . 2011-08-18 13:57 ——– d—–w- c:\users\lenovo\AppData\Local\PackageAware 2011-08-16 14:26 . 2011-08-16 14:26 ——– d—–w- c:\users\lenovo\AppData\Local\Adobe 2011-08-15 15:52 . 2011-08-15 15:52 ——– d—–w- C:\_OTL 2011-08-15 15:47 . 2011-08-15 15:47 ——– d—–w- c:\users\lenovo\AppData\Roaming\Malwarebytes 2011-08-15 15:47 . 2011-08-15 15:47 ——– d—–w- c:\programdata\Malwarebytes 2011-08-15 15:47 . 2011-07-06 11:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-15 15:47 . 2011-08-15 15:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-08-15 15:47 . 2011-07-06 11:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-15 13:36 . 2011-08-23 14:44 ——– d—–w- c:\users\lenovo\AppData\Local\temp 2011-08-15 12:55 . 2011-08-15 15:30 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2011-08-15 12:55 . 2011-08-15 12:58 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-08-11 16:17 . 2011-06-23 04:33 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-08-11 16:17 . 2011-06-23 04:33 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-08-11 16:15 . 2011-07-16 04:15 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2011-08-11 16:13 . 2011-06-15 08:55 86016 —-a-w- c:\windows\system32\odbccu32.dll 2011-08-11 16:13 . 2011-06-15 08:55 81920 —-a-w- c:\windows\system32\odbccr32.dll 2011-08-11 16:13 . 2011-06-15 08:55 122880 —-a-w- c:\windows\system32\odbccp32.dll 2011-08-11 16:13 . 2011-06-15 08:54 94208 —-a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll 2011-08-11 16:13 . 2011-06-15 08:55 319488 —-a-w- c:\windows\system32\odbcjt32.dll 2011-08-11 16:13 . 2011-06-15 08:55 163840 —-a-w- c:\windows\system32\odbctrac.dll 2011-08-11 11:27 . 2011-07-14 11:49 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2011-08-11 11:27 . 2011-07-14 11:49 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6FC41FA3-FB02-4110-9EED-39CB9683777F}\gapaengine.dll 2011-08-04 11:55 . 2011-08-04 11:55 ——– d—–w- c:\windows\en 2011-08-04 09:07 . 2011-08-04 09:07 ——– d—–w- c:\programdata\!SASCORE 2011-07-29 14:06 . 2011-07-29 14:06 ——– d—–w- c:\program files\Common Files\Java 2011-07-29 13:06 . 2011-07-29 13:06 ——– d—–w- c:\windows\system32\wbem\Logs 2011-07-29 13:05 . 2011-07-29 13:05 ——– d—–w- c:\users\lenovo\AppData\Roaming\SUPERAntiSpyware.com 2011-07-29 13:05 . 2011-07-29 13:05 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2011-07-29 13:05 . 2011-08-18 14:15 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-07-29 05:30 . 2011-07-13 03:39 6881616 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll 2011-07-26 08:13 . 2011-07-26 08:13 ——– d—–w- c:\program files\Common Files\Adobe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-08-20 12:21 . 2011-06-05 14:02 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-08-12 02:44 . 2011-07-15 14:53 7152464 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-08-04 11:54 . 2010-06-24 03:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-07-29 14:05 . 2010-09-09 12:19 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-06-22 12:57 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll 2011-06-11 02:29 . 2011-07-13 12:11 2334208 —-a-w- c:\windows\system32\win32k.sys 2011-06-07 15:55 . 2011-07-12 09:42 7074640 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EC284FDB-A59E-4E35-94E9-9CBB8AB196DE}\mpengine.dll 2011-06-23 05:04 . 2011-05-07 07:39 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256] "Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-07-08 3077528] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-08-18 4603264] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-06-16 7547424] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-08-14 1549608] "EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2009-07-15 4081480] "Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2009-06-25 5064520] "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2010-04-12 180224] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoSMHelp"= 1 (0x1) "GreyMSIAds"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-04 113024] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R1 MpKsl04371109;MpKsl04371109; [x] R1 MpKsl3cf4348d;MpKsl3cf4348d; [x] R1 MpKsl3e61cb6c;MpKsl3e61cb6c; [x] R1 MpKsl4c8d54ca;MpKsl4c8d54ca; [x] R1 MpKsl7da863da;MpKsl7da863da;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CBFD7EF4-13D4-4CEC-AB2A-2BE8514C6982}\MpKsl7da863da.sys [x] R1 MpKsl87d59fde;MpKsl87d59fde; [x] R1 MpKsl92ae3f66;MpKsl92ae3f66; [x] R1 MpKsla8f38b44;MpKsla8f38b44; [x] R1 MpKslac026884;MpKslac026884; [x] R1 MpKslb0d659db;MpKslb0d659db; [x] R1 MpKslb1a2cf4c;MpKslb1a2cf4c; [x] R1 MpKslb93796a3;MpKslb93796a3; [x] R1 MpKslbe879802;MpKslbe879802; [x] R1 MpKslc6d3926d;MpKslc6d3926d; [x] R1 MpKslde2defd0;MpKslde2defd0; [x] R1 MpKslef3df543;MpKslef3df543; [x] R1 MpKslf1dccbe1;MpKslf1dccbe1; [x] R1 MpKslf8fb5338;MpKslf8fb5338; [x] R1 MpKslfab4b37d;MpKslfab4b37d; [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 Firefox Service;Firefox Service; [x] R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [2009-07-29 63240] R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x] R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-09-04 180736] R3 GGSAFERDriver;GGSAFER Driver;c:\users\lenovo\Desktop\Random\Garena\safedrv.sys [x] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-07-24 101248] R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-07-28 414984] R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-07-28 472328] R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-05-14 4231680] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944] R3 PS_MDP;ReadyComm Presentation Space Helper Service;c:\windows\System32\IgrsSvcs.exe [2009-07-14 20992] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-31 1343400] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-22 81704] R4 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\games\MineCraft\Hamachi\hamachi-2.exe [2011-05-25 1336712] S1 funfrm;funfrm; [x] S1 MpKsl4a5d5fe1;MpKsl4a5d5fe1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A969704C-7F61-4628-84D0-8A245E33F302}\MpKsl4a5d5fe1.sys [2011-08-23 28752] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-08-04 12880] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-18 116608] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2010-11-09 21992] S2 IGRS;IGRS;c:\program files\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152] S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-01-27 50704] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504] S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter;c:\windows\System32\IgrsSvcs.exe [2009-07-14 20992] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-05-20 378472] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2010-01-19 23136] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-04-13 45736] S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2010-07-13 65640] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-05-18 119256] S3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-06-19 273448] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392] S3 NETw5s32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2009-09-15 6114816] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-05-10 139368] S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792] . . — Other Services/Drivers In Memory — . *NewlyCreated* - MPKSL4A5D5FE1 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP . Contents of the 'Scheduled Tasks' folder . 2011-08-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2366000599-2193686838-973492706-1002Core.job - c:\users\lenovo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-31 08:30] . 2011-08-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2366000599-2193686838-973492706-1002UA.job - c:\users\lenovo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-31 08:30] . . ——- Supplementary Scan ——- . uStart Page = hxxp://msn.com/ uInternet Settings,ProxyServer = proxy4.hci.edu.sg:8080 uInternet Settings,ProxyOverride = *.local IE: Add to Evernote 4.0 - c:\program files\Evernote\Evernote\EvernoteIE.dll/204 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: {{A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\Evernote\Evernote\EvernoteIE.dll/204 TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{314728E9-AB3B-4ACB-B74A-7BA8907BC378}: NameServer = 203.116.1.94 203.116.254.150 TCP: Interfaces\{A6FBD4A1-6B92-4253-8A1F-A0496BADEDF8}: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{A6FBD4A1-6B92-4253-8A1F-A0496BADEDF8}\2427164666F6274602C4F6862E08993702960586F6E656: NameServer = 8.8.8.8,8.8.4.4 FF - ProfilePath - c:\users\lenovo\AppData\Roaming\Mozilla\Firefox\Profiles\weeonb83.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4de1f7d6&v=7.005.030.004&i=23&tp=ab&iy=&ychte=sg&lng=en-US&q= FF - prefs.js: network.proxy.ftp - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.ftp_port - 3128 FF - prefs.js: network.proxy.gopher - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.gopher_port - 3128 FF - prefs.js: network.proxy.http - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.http_port - 3128 FF - prefs.js: network.proxy.socks - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.socks_port - 3128 FF - prefs.js: network.proxy.ssl - hcip1d.hci.edu.sg FF - prefs.js: network.proxy.ssl_port - 3128 FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\bm_installer.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-2366000599-2193686838-973492706-1002\Software\SecuROM\License information*] "datasecu"=hex:29,7f,44,5b,96,fe,ba,32,18,50,14,f1,f7,3a,c8,5a,6b,83,fe,35,6d, 0c,9e,4f,32,e7,f6,26,e8,58,dd,40,22,cd,a8,59,e2,65,1e,42,15,54,63,6f,29,4a,\ "rkeysecu"=hex:27,13,4a,a4,c5,42,e0,b4,5b,72,b8,31,15,f0,7d,69 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-08-23 22:46:15 ComboFix-quarantined-files.txt 2011-08-23 14:46 ComboFix2.txt 2011-08-15 16:17 ComboFix3.txt 2011-08-15 13:36 . Pre-Run: 38,802,599,936 bytes free Post-Run: 39,392,788,480 bytes free . - - End Of File - - 548E57A4DD72F4AB379BBED57C848AF2 I noticed that when ComboFix was done the program no longer appeared in the desktop or when i was alt-tabbing… While this is a very good sign, i did previously delete a task that was cereal(lots of numbers and symbols here) that was quite similar to that in Task Scheduler and the effect was the same. I wonder if the program will reappear after a few days again though… Thanks, hotshot
hotshot,

That's good news.

Let's run a different scan. It is pretty quick.

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Alright, did it, and the results are as follows: aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software Run date: 2011-08-23 23:29:38 —————————– 23:29:38.325 OS Version: Windows 6.1.7601 Service Pack 1 23:29:38.325 Number of processors: 2 586 0x1706 23:29:38.327 ComputerName: LENOVO-PC UserName: lenovo 23:29:40.125 Initialize success 23:33:13.467 AVAST engine defs: 11082300 23:34:52.556 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 23:34:52.559 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3 23:34:52.578 Disk 0 MBR read successfully 23:34:52.583 Disk 0 MBR scan 23:34:52.603 Disk 0 Windows 7 default MBR code 23:34:52.607 Disk 0 scanning sectors +976771120 23:34:52.698 Disk 0 scanning C:\windows\system32\drivers 23:35:03.191 Service scanning 23:35:05.232 Service MpKsl4a5d5fe1 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A969704C-7F61-4628-84D0-8A245E33F302}\MpKsl4a5d5fe1.sys **LOCKED** 32 23:35:05.277 Service MpNWMon C:\windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32 23:35:06.133 Modules scanning 23:35:21.790 Disk 0 trace - called modules: 23:35:21.809 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys 23:35:21.836 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x878e82e0] 23:35:21.836 3 CLASSPNP.SYS[8bf7259e] -> nt!IofCallDriver -> [0x86b23958] 23:35:21.837 5 ACPI.sys[840be3d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x86acc028] 23:35:24.587 AVAST engine scan C:\windows 23:35:27.199 AVAST engine scan C:\windows\system32 23:37:31.789 AVAST engine scan C:\windows\system32\drivers 23:37:45.303 AVAST engine scan C:\Users\lenovo 23:44:53.835 AVAST engine scan C:\ProgramData 23:45:55.767 Disk 0 MBR has been saved successfully to "C:\Users\lenovo\Desktop\MBR.dat" 23:45:55.768 The log file has been saved successfully to "C:\Users\lenovo\Desktop\SaveLog.txt" Not sure what "Service MpNWMon C:\windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32" though. Thanks, hotshot

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI