This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Outlook send spam emails [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, I have outlook 2007 for email and i have friends telling me i'm sending them spam emails. I do get some emails bounced back from time to time but i never see any emails in the sent folder..!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:36:08 PM, on 12/8/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\fpplock.exe
C:\Program Files\Logitech\G35\G35.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Windows\system32\WerCon.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Users\TheMadMan\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360 Premier Edition\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360 Premier Edition\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\5.1.0.29\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Warning: do not remove it!] fpplock.exe
O4 - HKLM\..\Run: [Logitech G35] C:\Program Files\Logitech\G35\G35.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [Live Update 5] C:\Program Files\MSI\Live Update 5\LU5.exe /reminder
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - HKUS\S-1-5-18\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlcdnet.asus.com/pub/ASUS/misc/dlm-…vex-2.2.5.0.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ABBYY FineReader 10 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.10.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iRacing.com Helper Service (iRacingService) - iRacing.com Motorsport Simulations, LLC
Bedford, MA 01730 - C:\Program Files\iRacing\iRacingService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP4\RpcAgentSrv.exe

–
End of file - 10243 bytes
Hi Bobby Jarrell

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
===================================================

Download aswMBR.exe ( 1.8mb ) to your desktop.

Double click the aswMBR.exe to run it.

When prompted to download the latest AVAST! definitions, click YES.

[external image: Posted Image]
Click the "Scan" button to start scan.

[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply.

===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-09 18:45:17 —————————– 18:45:17.956 OS Version: Windows 6.0.6002 Service Pack 2 18:45:17.956 Number of processors: 4 586 0x1707 18:45:17.956 ComputerName: THEMADMAN-PC UserName: TheMadMan 18:45:19.126 Initialize success 18:45:21.669 AVAST engine defs: 11120801 18:45:28.673 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 18:45:28.673 Disk 0 Vendor: Intel___ 1.0. Size: 286173MB BusType: 8 18:45:28.689 Disk 0 MBR read successfully 18:45:28.689 Disk 0 MBR scan 18:45:28.704 Disk 0 Windows VISTA default MBR code 18:45:28.704 Disk 0 scanning sectors +586080256 18:45:28.736 Disk 0 scanning C:\Windows\system32\drivers 18:45:35.990 Service scanning 18:45:37.300 Modules scanning 18:45:40.997 Disk 0 trace - called modules: 18:45:41.028 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll 18:45:41.028 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89841280] 18:45:41.028 3 CLASSPNP.SYS[8d5c38b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x88d60028] 18:45:42.058 AVAST engine scan C:\ 21:03:33.763 Scan finished successfully 21:07:23.270 Disk 0 MBR has been saved successfully to "C:\Users\TheMadMan\Desktop\MBR.dat" 21:07:23.270 The log file has been saved successfully to "C:\Users\TheMadMan\Desktop\aswMBR.txt"
DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 21:13:46 on 2011-12-09 Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3070.1938 [GMT -5:00] . AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\ASUS\AASP\1.00.59\aaCenter.exe C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe C:\Windows\System32\fpplock.exe C:\Program Files\Logitech\G35\G35.exe C:\Program Files\Logitech\Gaming Software\LWEMon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Bluebeam Software\Brewery\V45\Printer Support\BBPrint.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\iRacing\iRacingService.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\PSIService.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\ASUS\AI Direct Link\AsCmd.exe C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Ask.com\Updater\Updater.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\ASUS\AI Direct Link\AsShare.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\SearchProtocolHost.exe c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe . ============== Pseudo HJT Report =============== . uSearch Bar = Preserve uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = *.local uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn3\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [Warning: do not remove it!] fpplock.exe mRun: [Logitech G35] c:\program files\logitech\g35\G35.exe mRun: [Start WingMan Profiler] c:\program files\logitech\gaming software\LWEMon.exe /noui mRun: [Live Update 5] c:\program files\msi\live update 5\LU5.exe /reminder mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [BbInstallUser] c:\program files\bluebeam software\pushbutton pdf\Bluebeam Admin User.exe mRun: [BbPrintMonitor] c:\program files\common files\bluebeam software\brewery\v45\printer support\BBPrint.exe mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll" mRun: [CPU Power Monitor] "c:\program files\asus\ai suite\aigear3\CpuPowerMonitor.exe" mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [Ai Nap] "c:\program files\asus\ai suite\ainap\AiNap.exe" mRun: [Launch Direct Link] "c:\program files\asus\ai direct link\AsShare.exe" mRun: [ASUS Camera ScreenSaver] c:\windows\ASScrProlog.exe mRun: [Bonus.SSR.FR10] "c:\program files\abbyy finereader 10\Bonus.ScreenshotReader.exe" /autorun mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup mRun: [Cpu Level Up help] c:\program files\asus\ai suite\CpuLevelUpHelp.exe mRun: [Launch As Cmd Runner] "c:\program files\asus\ai direct link\AsCmd.exe" -reg mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [] mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe" dRun: [DevconDefaultDB] c:\windows\system32\READREG /SILENT /FAIL=1 StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg Trusted Zone: rhapsody.com\rhap-app-4-0 Trusted Zone: rhapsody.com\rhapreg DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlcdnet.asus.com/pub/ASUS/misc/dlm-activex-2.2.5.0.cab DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{2D7BE3E5-D0BF-4915-8AAF-C541E24FA1D8} : DhcpNameServer = 192.168.1.254 TCP: Interfaces\{36242DD6-25FC-4EF5-9207-88608F78F6D6} : DhcpNameServer = 192.168.1.254 Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\intuit\quickbooks 2009\HelpAsyncPluggableProtocol.dll Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll . ============= SERVICES / DRIVERS =============== . R0 bmpanapi;bmpanapi;c:\windows\system32\drivers\bmpanapi.sys [2008-1-20 44544] R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [2009-1-22 16048] R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264] R2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files\common files\abbyy\finereader\10.00\licensing\pe\NetworkLicenseServer.exe [2009-12-22 814344] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-7-7 176128] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 iRacingService;iRacing.com Helper Service;c:\program files\iracing\iRacingService.exe [2010-2-17 475808] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-7-7 8312832] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-7-7 244736] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH3.sys [2011-3-30 97808] R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2009-6-23 99352] R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2009-6-23 555032] R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2009-6-23 566296] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\drivers\a38usb.sys [2009-10-30 36736] S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2009-6-23 99352] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2010-2-17 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-2-17 79360] S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2009-6-23 555032] S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2009-6-23 100888] S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2009-6-23 100888] S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2009-6-23 566296] S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2009-10-30 12032] S3 LADF_DHP2;G35 DHP2 Filter Driver;c:\windows\system32\drivers\ladfDHP2i386.sys [2010-9-29 53976] S3 LADF_SBVM;G35 SBVM Filter Driver;c:\windows\system32\drivers\ladfSBVMi386.sys [2010-9-29 335064] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392] S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files\msi\live update 5\msibios32_100507.sys [2011-8-3 25912] S3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files\msi\live update 5\NTIOLib.sys [2011-8-3 7680] S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2009.sp4\RpcAgentSrv.exe [2009-10-28 99176] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-12-10 02:10:44 56200 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{1691f84f-6263-40a9-923c-c65351f899c5}\offreg.dll 2011-12-09 23:54:58 ——– d—–w- c:\program files\Ask.com 2011-12-09 23:44:41 ——– d—–w- c:\programdata\Ask 2011-12-09 23:23:55 ——– d—–w- c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1} 2011-12-09 06:15:18 6823496 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{1691f84f-6263-40a9-923c-c65351f899c5}\mpengine.dll 2011-12-09 04:08:38 ——– d—–w- c:\users\themadman\appdata\local\PackageAware 2011-11-21 14:41:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll 2011-11-21 14:41:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll 2011-11-21 14:41:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll 2011-11-21 14:41:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll 2011-11-21 14:41:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll 2011-11-21 14:41:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll 2011-11-21 14:41:17 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll 2011-11-21 14:38:07 ——– d—–w- c:\program files\iPod 2011-11-21 14:38:06 ——– d—–w- c:\program files\iTunes 2011-11-21 14:35:11 ——– d—–w- c:\program files\Bonjour 2011-11-20 16:28:57 ——– d—–w- c:\users\themadman\appdata\local\Yahoo! . ==================== Find3M ==================== . 2011-11-28 13:54:18 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-24 19:29:02 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2011-10-24 19:29:02 69632 —-a-w- c:\windows\system32\QuickTime.qts 2011-10-03 10:06:03 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-09-20 21:02:55 913280 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-09-20 13:44:04 31232 —-a-w- c:\windows\system32\drivers\tcpipreg.sys 2003-12-07 02:12:54 121856 –sha-w- c:\windows\system32\fpplock.exe . ============= FINISH: 21:14:09.47 ===============

Attachments:

Hi Bobby Jarrell,

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8346 Windows 6.0.6002 Service Pack 2 Internet Explorer 9.0.8112.16421 12/10/2011 4:41:24 AM mbam-log-2011-12-10 (04-41-24).txt Scan type: Quick scan Objects scanned: 170159 Time elapsed: 2 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Users\themadman\downloads\ophcrack-win32-installer-3.3.1.exe (PSWTool.OphCrack) -> Quarantined and deleted successfully.
Hi Bobby Jarrell,

Please download ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 11-12-10.01 - TheMadMan 12/10/2011 15:03:23.1.4 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3070.1709 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\users\TheMadMan\AppData\Roaming\redline2stapler.tmp
.
.
((((((((((((((((((((((((( Files Created from 2011-11-10 to 2011-12-10 )))))))))))))))))))))))))))))))
.
.
2011-12-10 20:07 . 2011-12-10 20:07 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-12-10 16:39 . 2011-12-10 16:40 ——– d—–w- C:\124e73ff64be800470740a
2011-12-10 10:03 . 2011-12-10 10:20 ——– d—–w- c:\users\TheMadMan\AppData\Roaming\vlc
2011-12-10 10:03 . 2011-12-10 10:03 ——– d—–w- c:\programdata\Verizon
2011-12-10 10:03 . 2011-12-10 16:38 ——– d—–w- c:\users\TheMadMan\AppData\Local\V CAST Media Manager
2011-12-10 10:03 . 2008-12-18 00:22 57344 —-a-w- c:\windows\system32\ff_vfw.dll
2011-12-10 10:03 . 2008-12-11 18:26 60273 —-a-w- c:\windows\system32\pthreadGC2.dll
2011-12-10 10:03 . 2011-12-10 10:03 ——– d—–w- c:\program files\ffdshow
2011-12-10 10:02 . 2011-12-10 10:03 ——– d—–w- c:\program files\Verizon V CAST Media Manager
2011-12-10 09:34 . 2011-12-10 09:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-10 09:34 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-10 09:30 . 2011-12-10 09:30 ——– d—–w- c:\program files\HTC
2011-12-10 09:26 . 2011-12-10 03:00 703824 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{43CEFCE8-5CD4-41F8-A439-D27E3027CF3F}\gapaengine.dll
2011-12-10 09:26 . 2011-12-10 09:47 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1691F84F-6263-40A9-923C-C65351F899C5}\offreg.dll
2011-12-10 03:00 . 2011-11-21 07:47 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3464EDD2-2422-4460-8AFB-428B7A8A924F}\mpengine.dll
2011-12-10 03:00 . 2011-12-10 03:00 703824 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\gapaengine.dll
2011-12-10 03:00 . 2011-11-21 07:47 6823496 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-12-10 02:24 . 2011-12-10 02:24 ——– d—–w- c:\users\TheMadMan\AppData\Local\Deployment
2011-12-10 02:24 . 2011-12-10 02:24 ——– d—–w- c:\users\TheMadMan\AppData\Local\Apps
2011-12-09 23:44 . 2011-12-09 23:44 ——– d—–w- c:\program files\Common Files\Java
2011-12-09 23:44 . 2011-12-09 23:44 ——– d—–w- c:\programdata\Ask
2011-12-09 23:23 . 2011-12-09 23:23 ——– d—–w- c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
2011-12-09 06:15 . 2011-11-21 10:47 6823496 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1691F84F-6263-40A9-923C-C65351F899C5}\mpengine.dll
2011-12-09 04:08 . 2011-12-09 04:08 ——– d—–w- c:\users\TheMadMan\AppData\Local\PackageAware
2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2011-11-21 14:41 . 2011-11-21 14:41 ——– d—–w- c:\program files\QuickTime
2011-11-21 14:38 . 2011-11-21 14:38 ——– d—–w- c:\program files\iPod
2011-11-21 14:38 . 2011-11-21 14:38 ——– d—–w- c:\program files\iTunes
2011-11-21 14:35 . 2011-11-21 14:35 ——– d—–w- c:\program files\Bonjour
2011-11-20 16:28 . 2011-11-20 16:28 ——– d—–w- c:\users\TheMadMan\AppData\Local\Yahoo!
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-10 03:00 . 2011-08-12 00:25 703824 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-11-28 13:54 . 2011-08-25 22:47 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 19:29 . 2011-10-24 19:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29 . 2011-10-24 19:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-24 15:16 . 2011-10-24 15:16 602112 —-a-w- c:\windows\system32\xvid.dll
2011-10-03 10:06 . 2010-10-24 22:22 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-09-20 21:02 . 2011-11-09 16:16 913280 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-09-20 13:44 . 2011-11-09 16:16 31232 —-a-w- c:\windows\system32\drivers\tcpipreg.sys
2011-09-18 15:35 . 2011-09-18 15:35 86528 —-a-w- c:\windows\system32\iesysprep.dll
2011-09-18 15:35 . 2011-09-18 15:35 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-09-18 15:35 . 2011-09-18 15:35 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-09-18 15:35 . 2011-09-18 15:35 74752 —-a-w- c:\windows\system32\iesetup.dll
2011-09-18 15:35 . 2011-09-18 15:35 63488 —-a-w- c:\windows\system32\tdc.ocx
2011-09-18 15:35 . 2011-09-18 15:35 48640 —-a-w- c:\windows\system32\mshtmler.dll
2011-09-18 15:35 . 2011-09-18 15:35 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-09-18 15:35 . 2011-09-18 15:35 367104 —-a-w- c:\windows\system32\html.iec
2011-09-18 15:35 . 2011-09-18 15:35 23552 —-a-w- c:\windows\system32\licmgr10.dll
2011-09-18 15:35 . 2011-09-18 15:35 161792 —-a-w- c:\windows\system32\msls31.dll
2011-09-18 15:35 . 2011-09-18 15:35 152064 —-a-w- c:\windows\system32\wextract.exe
2011-09-18 15:35 . 2011-09-18 15:35 150528 —-a-w- c:\windows\system32\iexpress.exe
2011-09-18 15:35 . 2011-09-18 15:35 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2011-09-18 15:35 . 2011-09-18 15:35 35840 —-a-w- c:\windows\system32\imgutil.dll
2011-09-18 15:35 . 2011-09-18 15:35 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2011-09-18 15:35 . 2011-09-18 15:35 11776 —-a-w- c:\windows\system32\mshta.exe
2011-09-18 15:35 . 2011-09-18 15:35 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
2011-09-18 15:35 . 2011-09-18 15:35 101888 —-a-w- c:\windows\system32\admparse.dll
2003-12-07 02:12 121856 –sha-w- c:\windows\System32\fpplock.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-14 39408]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2011-08-22 6276408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"HLBackupScheduler"="c:\program files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe" [2011-10-23 5013128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Warning: do not remove it!"="fpplock.exe" [2003-12-07 121856]
"Logitech G35"="c:\program files\Logitech\G35\G35.exe" [2010-10-05 1811800]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
"Live Update 5"="c:\program files\MSI\Live Update 5\LU5.exe" [2011-07-15 1752376]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-08 336384]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-13 421736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"BbInstallUser"="c:\program files\Bluebeam Software\Pushbutton PDF\Bluebeam Admin User.exe" [2008-11-25 49824]
"BbPrintMonitor"="c:\program files\Common Files\Bluebeam Software\Brewery\V45\Printer Support\BBPrint.exe" [2008-04-16 156320]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"Launch Direct Link"="c:\program files\ASUS\AI Direct Link\AsShare.exe" [2007-11-16 1209856]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2009-01-28 37232]
"Bonus.SSR.FR10"="c:\program files\ABBYY FineReader 10\Bonus.ScreenshotReader.exe" [2010-01-29 941320]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-12-22 1092872]
"Launch As Cmd Runner"="c:\program files\ASUS\AI Direct Link\AsCmd.exe" [2007-04-11 376832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\READREG" [X]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-2-2 984352]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux6"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiSpywareOverride"=dword:00000001
.
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 136176]
R3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\DRIVERS\a38usb.sys [2009-01-23 36736]
R3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [2009-06-23 99352]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-02-18 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-02-18 79360]
R3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [2009-06-23 555032]
R3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\System32\drivers\CTERFXFX.SYS [2009-06-23 100888]
R3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [2009-06-23 100888]
R3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [2009-06-23 566296]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 136176]
R3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-08 12032]
R3 LADF_DHP2;G35 DHP2 Filter Driver;c:\windows\system32\DRIVERS\ladfDHP2i386.sys [2010-09-29 53976]
R3 LADF_SBVM;G35 SBVM Filter Driver;c:\windows\system32\DRIVERS\ladfSBVMi386.sys [2010-09-29 335064]
R3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files\MSI\Live Update 5\msibios32_100507.sys [2010-05-10 25912]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files\MSI\Live Update 5\NTIOLib.sys [2010-10-20 7680]
R3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2009.SP4\RpcAgentSrv.exe [2009-08-17 99176]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 bmpanapi;bmpanapi;c:\windows\system32\DRIVERS\bmpanapi.sys [2008-01-21 44544]
S1 CLBStor;InstantBurn Storage Helper Driver; [x]
S2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2009-12-22 814344]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-07-08 176128]
S2 iRacingService;iRacing.com Helper Service;c:\program files\iRacing\iRacingService.exe [2011-12-02 475808]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-07-08 8312832]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-07-08 244736]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH3.sys [2011-03-30 97808]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\System32\drivers\COMMONFX.SYS [2009-06-23 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\System32\drivers\CTAUDFX.SYS [2009-06-23 555032]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\System32\drivers\CTSBLFX.SYS [2009-06-23 566296]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - MBAMSwissArmy
*Deregistered* - pctgntdi
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-26 14:59]
.
2011-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 02:24]
.
2011-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 02:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
Trusted Zone: rhapsody.com\rhap-app-4-0
Trusted Zone: rhapsody.com\rhapreg
TCP: DhcpNameServer = 192.168.1.254
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\bm_installer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-10 15:07
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\windows\system32\subenurl
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-4246842962-803938559-1680518877-1000\Software\SecuROM\License information*]
"datasecu"=hex:05,aa,d9,65,a8,cd,1a,f6,3f,66,77,9d,8f,29,77,fd,8d,a2,fc,73,7b,
90,33,27,5a,a4,2d,c4,a0,3e,b4,ad,e6,7c,6f,7b,88,7a,12,c8,dd,a9,d8,4d,2b,68,\
"rkeysecu"=hex:25,87,2e,7f,ad,f4,1a,66,3b,ba,b3,17,ee,91,a3,2c
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-12-10 15:08:30
ComboFix-quarantined-files.txt 2011-12-10 20:08
.
Pre-Run: 180,609,081,344 bytes free
Post-Run: 180,867,633,152 bytes free
.
- - End Of File - - 850F214A35D19799DCC5E2F303176F6D
Hi Bobby Jarrell,

I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
C:\Users\TheMadMan\AppData\Local\Google\Chrome\User Data\Default\Default\lnjcgbgmfglmffejbpllpkpbkbmmgbgo\contentscript.js Win32/TrojanDownloader.Tracur.F trojan C:\Users\TheMadMan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\2cc07e61-2b8d8097 a variant of Java/TrojanDownloader.OpenStream.NCE trojan C:\Users\TheMadMan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\2cc07e61-466dec98 a variant of Java/TrojanDownloader.OpenStream.NCE trojan C:\Users\TheMadMan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\2cc07e61-4673c6b9 a variant of Java/TrojanDownloader.OpenStream.NCE trojan C:\Users\TheMadMan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\2cc07e61-59543347 a variant of Java/TrojanDownloader.OpenStream.NCE trojan C:\Users\TheMadMan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\2cc07e61-61ad8faf a variant of Java/TrojanDownloader.OpenStream.NCE trojan C:\Users\TheMadMan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\2cc07e61-6ec9286b a variant of Java/TrojanDownloader.OpenStream.NCE trojan C:\Users\TheMadMan\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\51d1c3f7-4d795635 a variant of Java/TrojanDownloader.OpenStream.NCE trojan C:\Windows\System32\adurmag.dll a variant of Win32/Urlbot.NAP trojan C:\Windows\System32\cpyervid.dll a variant of Win32/Urlbot.NAO trojan C:\Windows\System32\devaxrip.exe a variant of Win32/Urlbot.NAS trojan
Hi Bobby Jarrell,

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/index.php?s=&showtopic=121486&view=findpost&p=762375

Collect::
C:\Windows\System32\adurmag.dll
C:\Windows\System32\cpyervid.dll
C:\Windows\System32\devaxrip.exe

File::
C:\Users\TheMadMan\AppData\Local\Google\Chrome\User Data\Default\Default\lnjcgbgmfglmffejbpllpkpbkbmmgbgo\contentscript.js
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste
ComboFix 11-12-10.01 - TheMadMan 12/10/2011 23:00:49.2.4 - x86 Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3070.1928 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\TheMadMan\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\users\TheMadMan\AppData\Local\Google\Chrome\User Data\Default\Default\lnjcgbgmfglmffejbpllpkpbkbmmgbgo\contentscript.js" . file zipped: c:\windows\System32\adurmag.dll file zipped: c:\windows\System32\cpyervid.dll file zipped: c:\windows\System32\devaxrip.exe . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\TheMadMan\AppData\Local\Google\Chrome\User Data\Default\Default\lnjcgbgmfglmffejbpllpkpbkbmmgbgo\contentscript.js c:\windows\System32\adurmag.dll c:\windows\System32\cpyervid.dll c:\windows\System32\devaxrip.exe . . ((((((((((((((((((((((((( Files Created from 2011-11-11 to 2011-12-11 ))))))))))))))))))))))))))))))) . . 2011-12-11 04:04 . 2011-12-11 04:08 ——– d—–w- c:\users\TheMadMan\AppData\Local\temp 2011-12-11 04:04 . 2011-12-11 04:04 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2011-12-11 04:04 . 2011-12-11 04:04 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-12-11 03:50 . 2011-12-10 03:00 703824 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{23F08941-DD82-4289-8BB8-767AA1C09169}\gapaengine.dll 2011-12-11 03:50 . 2011-12-11 03:50 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1691F84F-6263-40A9-923C-C65351F899C5}\offreg.dll 2011-12-10 20:40 . 2011-12-10 20:40 ——– d—–w- c:\program files\ESET 2011-12-10 10:03 . 2011-12-10 10:20 ——– d—–w- c:\users\TheMadMan\AppData\Roaming\vlc 2011-12-10 10:03 . 2011-12-10 10:03 ——– d—–w- c:\programdata\Verizon 2011-12-10 10:03 . 2011-12-10 16:38 ——– d—–w- c:\users\TheMadMan\AppData\Local\V CAST Media Manager 2011-12-10 10:03 . 2008-12-18 00:22 57344 —-a-w- c:\windows\system32\ff_vfw.dll 2011-12-10 10:03 . 2008-12-11 18:26 60273 —-a-w- c:\windows\system32\pthreadGC2.dll 2011-12-10 10:03 . 2011-12-10 10:03 ——– d—–w- c:\program files\ffdshow 2011-12-10 10:02 . 2011-12-10 10:03 ——– d—–w- c:\program files\Verizon V CAST Media Manager 2011-12-10 09:34 . 2011-12-10 09:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-12-10 09:34 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-10 09:30 . 2011-12-10 09:30 ——– d—–w- c:\program files\HTC 2011-12-10 03:00 . 2011-11-21 07:47 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3464EDD2-2422-4460-8AFB-428B7A8A924F}\mpengine.dll 2011-12-10 03:00 . 2011-12-10 03:00 703824 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\gapaengine.dll 2011-12-10 03:00 . 2011-11-21 07:47 6823496 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll 2011-12-10 02:24 . 2011-12-10 02:24 ——– d—–w- c:\users\TheMadMan\AppData\Local\Deployment 2011-12-10 02:24 . 2011-12-10 02:24 ——– d—–w- c:\users\TheMadMan\AppData\Local\Apps 2011-12-09 23:44 . 2011-12-09 23:44 ——– d—–w- c:\program files\Common Files\Java 2011-12-09 23:44 . 2011-12-09 23:44 ——– d—–w- c:\programdata\Ask 2011-12-09 23:23 . 2011-12-09 23:23 ——– d—–w- c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1} 2011-12-09 06:15 . 2011-11-21 10:47 6823496 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1691F84F-6263-40A9-923C-C65351F899C5}\mpengine.dll 2011-12-09 04:08 . 2011-12-09 04:08 ——– d—–w- c:\users\TheMadMan\AppData\Local\PackageAware 2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll 2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll 2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll 2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll 2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll 2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll 2011-11-21 14:41 . 2011-11-21 14:41 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll 2011-11-21 14:41 . 2011-11-21 14:41 ——– d—–w- c:\program files\QuickTime 2011-11-21 14:38 . 2011-11-21 14:38 ——– d—–w- c:\program files\iPod 2011-11-21 14:38 . 2011-11-21 14:38 ——– d—–w- c:\program files\iTunes 2011-11-21 14:35 . 2011-11-21 14:35 ——– d—–w- c:\program files\Bonjour 2011-11-20 16:28 . 2011-11-20 16:28 ——– d—–w- c:\users\TheMadMan\AppData\Local\Yahoo! . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-10 03:00 . 2011-08-12 00:25 703824 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2011-11-28 13:54 . 2011-08-25 22:47 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-24 19:29 . 2011-10-24 19:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2011-10-24 19:29 . 2011-10-24 19:29 69632 —-a-w- c:\windows\system32\QuickTime.qts 2011-10-24 15:16 . 2011-10-24 15:16 602112 —-a-w- c:\windows\system32\xvid.dll 2011-10-03 10:06 . 2010-10-24 22:22 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-09-20 21:02 . 2011-11-09 16:16 913280 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-09-20 13:44 . 2011-11-09 16:16 31232 —-a-w- c:\windows\system32\drivers\tcpipreg.sys 2011-09-18 15:35 . 2011-09-18 15:35 86528 —-a-w- c:\windows\system32\iesysprep.dll 2011-09-18 15:35 . 2011-09-18 15:35 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-09-18 15:35 . 2011-09-18 15:35 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-09-18 15:35 . 2011-09-18 15:35 74752 —-a-w- c:\windows\system32\iesetup.dll 2011-09-18 15:35 . 2011-09-18 15:35 63488 —-a-w- c:\windows\system32\tdc.ocx 2011-09-18 15:35 . 2011-09-18 15:35 48640 —-a-w- c:\windows\system32\mshtmler.dll 2011-09-18 15:35 . 2011-09-18 15:35 420864 —-a-w- c:\windows\system32\vbscript.dll 2011-09-18 15:35 . 2011-09-18 15:35 367104 —-a-w- c:\windows\system32\html.iec 2011-09-18 15:35 . 2011-09-18 15:35 23552 —-a-w- c:\windows\system32\licmgr10.dll 2011-09-18 15:35 . 2011-09-18 15:35 161792 —-a-w- c:\windows\system32\msls31.dll 2011-09-18 15:35 . 2011-09-18 15:35 152064 —-a-w- c:\windows\system32\wextract.exe 2011-09-18 15:35 . 2011-09-18 15:35 150528 —-a-w- c:\windows\system32\iexpress.exe 2011-09-18 15:35 . 2011-09-18 15:35 1427456 —-a-w- c:\windows\system32\inetcpl.cpl 2011-09-18 15:35 . 2011-09-18 15:35 35840 —-a-w- c:\windows\system32\imgutil.dll 2011-09-18 15:35 . 2011-09-18 15:35 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2011-09-18 15:35 . 2011-09-18 15:35 11776 —-a-w- c:\windows\system32\mshta.exe 2011-09-18 15:35 . 2011-09-18 15:35 110592 —-a-w- c:\windows\system32\IEAdvpack.dll 2011-09-18 15:35 . 2011-09-18 15:35 101888 —-a-w- c:\windows\system32\admparse.dll 2003-12-07 02:12 121856 –sha-w- c:\windows\System32\fpplock.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-14 39408] "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2011-08-22 6276408] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472] "HLBackupScheduler"="c:\program files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe" [2011-10-23 5013128] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Warning: do not remove it!"="fpplock.exe" [2003-12-07 121856] "Logitech G35"="c:\program files\Logitech\G35\G35.exe" [2010-10-05 1811800] "Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672] "Live Update 5"="c:\program files\MSI\Live Update 5\LU5.exe" [2011-07-15 1752376] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-08 336384] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-13 421736] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888] "BbInstallUser"="c:\program files\Bluebeam Software\Pushbutton PDF\Bluebeam Admin User.exe" [2008-11-25 49824] "BbPrintMonitor"="c:\program files\Common Files\Bluebeam Software\Brewery\V45\Printer Support\BBPrint.exe" [2008-04-16 156320] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "Launch Direct Link"="c:\program files\ASUS\AI Direct Link\AsShare.exe" [2007-11-16 1209856] "ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2009-01-28 37232] "Bonus.SSR.FR10"="c:\program files\ABBYY FineReader 10\Bonus.ScreenshotReader.exe" [2010-01-29 941320] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152] "Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-12-22 1092872] "Launch As Cmd Runner"="c:\program files\ASUS\AI Direct Link\AsCmd.exe" [2007-04-11 376832] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DevconDefaultDB"="c:\windows\system32\READREG" [X] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360] QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-2-2 984352] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux6"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiSpywareOverride"=dword:00000001 . R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 136176] R3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\DRIVERS\a38usb.sys [2009-01-23 36736] R3 CFcatchme;CFcatchme;c:\users\THEMAD~1\AppData\Local\Temp\CFcatchme.sys [x] R3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [2009-06-23 99352] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-02-18 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-02-18 79360] R3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [2009-06-23 555032] R3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\System32\drivers\CTERFXFX.SYS [2009-06-23 100888] R3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [2009-06-23 100888] R3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [2009-06-23 566296] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 136176] R3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-08 12032] R3 LADF_DHP2;G35 DHP2 Filter Driver;c:\windows\system32\DRIVERS\ladfDHP2i386.sys [2010-09-29 53976] R3 LADF_SBVM;G35 SBVM Filter Driver;c:\windows\system32\DRIVERS\ladfSBVMi386.sys [2010-09-29 335064] R3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files\MSI\Live Update 5\msibios32_100507.sys [2010-05-10 25912] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360] R3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files\MSI\Live Update 5\NTIOLib.sys [2010-10-20 7680] R3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2009.SP4\RpcAgentSrv.exe [2009-08-17 99176] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S0 bmpanapi;bmpanapi;c:\windows\system32\DRIVERS\bmpanapi.sys [2008-01-21 44544] S1 CLBStor;InstantBurn Storage Helper Driver; [x] S2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2009-12-22 814344] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-07-08 176128] S2 iRacingService;iRacing.com Helper Service;c:\program files\iRacing\iRacingService.exe [2011-12-02 475808] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-07-08 8312832] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-07-08 244736] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH3.sys [2011-03-30 97808] S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\System32\drivers\COMMONFX.SYS [2009-06-23 99352] S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\System32\drivers\CTAUDFX.SYS [2009-06-23 555032] S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\System32\drivers\CTSBLFX.SYS [2009-06-23 566296] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392] . . — Other Services/Drivers In Memory — . *Deregistered* - pctgntdi . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder . 2011-09-15 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-26 14:59] . 2011-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 02:24] . 2011-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 02:24] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = *.local Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg Trusted Zone: rhapsody.com\rhap-app-4-0 Trusted Zone: rhapsody.com\rhapreg TCP: DhcpNameServer = 192.168.1.254 . . ************************************************************************** scanning hidden processes … . scanning hidden autostart entries … . scanning hidden files … . scan completed successfully hidden files: . ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-4246842962-803938559-1680518877-1000\Software\SecuROM\License information*] "datasecu"=hex:05,aa,d9,65,a8,cd,1a,f6,3f,66,77,9d,8f,29,77,fd,8d,a2,fc,73,7b, 90,33,27,5a,a4,2d,c4,a0,3e,b4,ad,e6,7c,6f,7b,88,7a,12,c8,dd,a9,d8,4d,2b,68,\ "rkeysecu"=hex:25,87,2e,7f,ad,f4,1a,66,3b,ba,b3,17,ee,91,a3,2c . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\program files\Creative\Shared Files\CTAudSvc.exe c:\windows\system32\atieclxx.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe c:\windows\system32\PSIService.exe c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\windows\system32\WUDFHost.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\ASUS\AASP\1.00.59\aaCenter.exe c:\windows\System32\fpplock.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\iPod\bin\iPodService.exe c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe c:\program files\HP\Digital Imaging\bin\hpqbam08.exe c:\program files\Yahoo!\Messenger\ymsgr_tray.exe . ************************************************************************** . Completion time: 2011-12-10 23:10:00 - machine was rebooted ComboFix-quarantined-files.txt 2011-12-11 04:09 ComboFix2.txt 2011-12-10 20:08 . Pre-Run: 180,726,579,200 bytes free Post-Run: 180,608,995,328 bytes free . - - End Of File - - 11C5A9D82F8BFE618A1E678C2CB90019
Hi Bobby Jarrell,

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 7 Update 1.
  • Click on jre-7u1-windows-i586.exe if you are running 32-bit Windows or jre-7u1-windows-x64.exe if you are running 64-bit Windows.
  • After the download completes, close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
Hey, I really what to Thank You for all the help..! I have been spamming people for 6 months or so and have tried everything under the sun. I know you have spent time and I would love to compensate you for that…! What is the best way for me to do that ? Lastly what protection would you put on the computer it has a router with but in firewall but want to put the best protection on it. I have about $7000 in the water cooling and parts would like to protect my investment..! Again Thanks So So Much …! Bobby
Hi Bobby Jarrell,

It's my pleasure :) I'm glad we were able to get to the bottom of the issue. You can hit the yellow donate button in my signature to send a PayPal donation.

As far as security protection for your computer goes, you are already on the right track. You have Microsoft Security Essentials installed which is a great antivirus and antimalware program. Remember to keep it updated and to install Windows Updates regularly. The router with built-in firewall will do a good job of protecting you against many threats as well. If you haven't already, it would be a good idea to enable the Windows Firewall on your computer.

If you are talking about protecting your hardware (CPU, RAM, hard drive, video card, etc), I would suggest investing in a Uninterrupted Power Supply (if you don't already have one) which will protect your computer from power surges and allow you to properly shut down your computer in case of power outage. It's also good practice to clean the dust out of your computer once in a while with a can of compressed air.

We still have several things to do before I let you go. I need you to run the following program to see if there is any more outdated software on your computer.

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI