This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Why won't my computer start right? [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello again Whatthetech!

I'm back again with of course another fun project for anyone willing to undertake this one. I really have no idea what is going on with my computer. I've updated all the drivers, virus scanned, run Malwarebytes a few times and I still can't shake what ever it is that is kicking my computer's butt.

I occasionally get blue screens, sometimes while on the internet I'll get these "Script error" messages telling to stop the script of the web page based on some error, and most times my computer just won't even turn on when I physically turn it on. That last one is the biggest one. I have to turn off and on several times before the computer actually begins to work. I really would like either some advice on where to go or best option, a solution to my problem. I should also state that is a self built computer and I'm sure I've double checked my connections, but I am always open to suggestions. Below is the HijackThis report, I've copied and pasted it as well as set it as a file. PLEASE HELP!


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:40:42 AM, on 12/13/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Seriocode\Desktop\hijack this.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll
O2 - BHO: Javaβ„’ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\Alwil Software\Avast5\afwServ.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 9086 bytes
Hi,

This may not be malware related, but we can check your system just to make certain, if it's clean, then perhaps the techs can help, but let's run the scans first.

Please do the following:


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
ok here are the reports: . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29 Run by [removed] at 15:10:59 on 2011-12-16 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2047.901 [GMT -5:00] . AV: avast! Internet Security *Enabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308} SP: avast! Internet Security *Enabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: avast! Internet Security *Enabled* {FB460EB6-4C6D-E564-6BF5-EEEF2B44B473} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Program Files\Alwil Software\Avast5\afwServ.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files\Alwil Software\Avast5\setup\avast.setup C:\Windows\system32\DllHost.exe C:\Program Files (x86)\Nero\Update\NASvc.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\system32\notepad.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll BHO: Javaβ„’ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll uRun: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" -s mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun: [] mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xportar a Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{508BB353-0FEE-4357-A2B1-DD9F21607233} : DhcpNameServer = [removed] [removed] Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll BHO-X64: Search Helper - No File BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll BHO-X64: Javaβ„’ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui mRun-x64: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun-x64: [(Default)] SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Seriocode\AppData\Roaming\Mozilla\Firefox\Profiles\o0o0szmc.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/ FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll FF - plugin: C:\Users\Seriocode\AppData\Roaming\Mozilla\Firefox\Profiles\o0o0szmc.default\extensions\[removed]\plugins\npLogitechDeviceDetection.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . β€”- FIREFOX POLICIES β€”- FF - user.js: general.useragent.extra.brc - BRI/1 . ============= SERVICES / DRIVERS =============== . R0 aswNdis;avast! Firewall NDIS Filter Service;C:\Windows\system32\DRIVERS\aswNdis.sys –> C:\Windows\system32\DRIVERS\aswNdis.sys [?] R0 aswNdis2;avast! Firewall Core Firewall Service;C:\Windows\system32\drivers\aswNdis2.sys –> C:\Windows\system32\drivers\aswNdis2.sys [?] R1 aswFW;avast! TDI Firewall driver;C:\Windows\system32\drivers\aswFW.sys –> C:\Windows\system32\drivers\aswFW.sys [?] R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys –> C:\Windows\system32\drivers\aswSnx.sys [?] R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys –> C:\Windows\system32\drivers\aswSP.sys [?] R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys –> C:\Windows\system32\drivers\aswFsBlk.sys [?] R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys –> C:\Windows\system32\drivers\aswMonFlt.sys [?] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-10-26 40384] R2 avast! Firewall;avast! Firewall;C:\Program Files\Alwil Software\Avast5\afwServ.exe [2010-10-26 119200] R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-1-26 573224] R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-12-13 2253120] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248] R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-4-22 92592] R3 avast! Mail Scanner;avast! Mail Scanner;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-10-26 40384] R3 avast! Web Scanner;avast! Web Scanner;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-10-26 40384] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys –> C:\Windows\system32\drivers\rdpvideominiport.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] . =============== Created Last 30 ================ . 2011-12-16 08:06:09 69000 β€”-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9C49F7F3-7759-42C7-8F6D-9645CAA108E9}\offreg.dll 2011-12-16 08:06:07 8822856 β€”-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9C49F7F3-7759-42C7-8F6D-9645CAA108E9}\mpengine.dll 2011-12-15 00:23:43 ——– d—–w- C:\Program Files (x86)\Content Manager 2011-12-13 06:45:10 7581504 β€”-a-w- C:\Windows\System32\nvcuda.dll 2011-12-13 06:44:30 ——– d—–w- C:\NVIDIA 2011-12-13 06:09:57 837952 β€”-a-w- C:\Windows\System32\easyupdatusapiu64.dll 2011-12-13 06:09:57 5067584 β€”-a-w- C:\Windows\System32\nvsvc64.dll 2011-12-13 06:09:57 2560616 β€”-a-w- C:\Windows\System32\nvsvcr.dll 2011-12-13 06:09:57 222528 β€”-a-w- C:\Windows\System32\nvmctray.dll 2011-12-13 06:09:57 1640768 β€”-a-w- C:\Windows\System32\nvvsvc.exe 2011-12-13 06:09:57 137536 β€”-a-w- C:\Windows\System32\nvshext.dll 2011-12-13 06:09:57 10406208 β€”-a-w- C:\Windows\System32\nvcpl.dll 2011-12-13 06:09:07 ——– d—–w- C:\ProgramData\NVIDIA Corporation 2011-12-13 06:08:57 ——– d—–w- C:\Program Files\NVIDIA Corporation 2011-12-13 03:28:03 2106216 β€”-a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll 2011-12-13 03:28:03 1998168 β€”-a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll 2011-12-13 03:28:03 134104 β€”-a-w- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll 2011-12-13 03:28:02 89048 β€”-a-w- C:\Program Files (x86)\Mozilla Firefox\libEGL.dll 2011-12-13 03:28:02 801752 β€”-a-w- C:\Program Files (x86)\Mozilla Firefox\mozsqlite3.dll 2011-12-13 03:28:02 478168 β€”-a-w- C:\Program Files (x86)\Mozilla Firefox\libGLESv2.dll 2011-12-13 03:28:02 1989592 β€”-a-w- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2011-12-13 03:28:02 15832 β€”-a-w- C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll 2011-12-10 15:52:50 ——– d—–w- C:\ProgramData\HP Photo Creations 2011-12-10 15:52:50 ——– d—–w- C:\Program Files (x86)\HP Photo Creations 2011-12-10 15:52:32 ——– d—–w- C:\Program Files (x86)\Coupons 2011-12-10 15:52:21 ——– d—–w- C:\Users\Seriocode\AppData\Roaming\HpUpdate 2011-12-10 15:52:08 750440 β€”β€”w- C:\Windows\System32\HPDiscoPM9311.dll 2011-12-10 15:51:54 ——– d—–w- C:\Program Files (x86)\HP 2011-12-10 15:51:53 ——– d—–w- C:\Program Files\HP 2011-12-10 15:51:40 ——– d—–w- C:\Users\Seriocode\AppData\Local\HP 2011-12-10 00:58:52 ——– d—–w- C:\Windows\System32\SPReview 2011-12-10 00:57:41 ——– d—–w- C:\Windows\System32\EventProviders 2011-12-08 17:27:06 48976 β€”-a-w- C:\Windows\System32\netfxperf.dll 2011-12-08 17:27:06 1942856 β€”-a-w- C:\Windows\System32\dfshim.dll 2011-12-08 17:25:59 695808 β€”-a-w- C:\Windows\System32\netlogon.dll 2011-12-08 17:24:59 88576 β€”-a-w- C:\Windows\System32\setupcl.exe 2011-12-08 17:23:59 93184 β€”-a-w- C:\Program Files\Windows Mail\oeimport.dll 2011-12-08 17:20:02 529408 β€”-a-w- C:\Windows\System32\wbemcomn.dll 2011-12-08 17:20:02 524288 β€”-a-w- C:\Windows\System32\wmicmiplugin.dll 2011-12-08 17:20:02 244736 β€”-a-w- C:\Program Files\Windows Portable Devices\sqmapi.dll 2011-12-08 17:20:02 1225216 β€”-a-w- C:\Windows\System32\wbem\wbemcore.dll 2011-12-08 17:19:54 933376 β€”-a-w- C:\Windows\System32\SmiEngine.dll 2011-12-08 17:19:54 244736 β€”-a-w- C:\Windows\System32\sqmapi.dll 2011-12-08 17:19:48 199168 β€”-a-w- C:\Windows\System32\PkgMgr.exe 2011-12-08 17:19:15 422912 β€”-a-w- C:\Windows\System32\drvstore.dll 2011-12-08 17:19:14 399872 β€”-a-w- C:\Windows\System32\dpx.dll 2011-12-07 14:14:25 579880 β€”-a-w- C:\Windows\System32\dsNcSmartCardProv.dll 2011-12-07 14:14:25 405288 β€”-a-w- C:\Windows\System32\dsNcCredProv.dll 2011-12-07 14:13:15 ——– d—–w- C:\Program Files (x86)\Juniper Networks 2011-12-07 14:10:18 476904 β€”-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll 2011-12-07 14:10:18 472808 β€”-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-12-07 14:05:59 476160 β€”-a-w- C:\Windows\System32\XpsGdiConverter.dll 2011-12-07 14:05:59 288256 β€”-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll 2011-12-07 14:04:34 244736 β€”-a-w- C:\Program Files\Internet Explorer\sqmapi.dll 2011-12-07 14:04:29 189952 β€”-a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll 2011-12-07 14:02:54 421888 β€”-a-w- C:\Windows\System32\KernelBase.dll 2011-12-07 13:58:24 5561216 β€”-a-w- C:\Windows\System32\ntoskrnl.exe 2011-12-07 13:58:22 3912576 β€”-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2011-12-07 13:58:21 3967872 β€”-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2011-12-07 13:57:53 861696 β€”-a-w- C:\Windows\System32\oleaut32.dll 2011-12-07 13:57:53 331776 β€”-a-w- C:\Windows\System32\oleacc.dll 2011-12-07 13:57:53 233472 β€”-a-w- C:\Windows\SysWow64\oleacc.dll 2011-12-07 13:57:52 571904 β€”-a-w- C:\Windows\SysWow64\oleaut32.dll 2011-12-07 13:57:50 976896 β€”-a-w- C:\Windows\System32\inetcomm.dll 2011-12-07 13:57:50 741376 β€”-a-w- C:\Windows\SysWow64\inetcomm.dll 2011-12-07 13:57:48 974336 β€”-a-w- C:\Windows\System32\WFS.exe 2011-12-07 13:57:48 267776 β€”-a-w- C:\Windows\System32\FXSCOVER.exe 2011-12-07 13:57:46 31232 β€”-a-w- C:\Windows\SysWow64\prevhost.exe 2011-12-07 13:57:46 31232 β€”-a-w- C:\Windows\System32\prevhost.exe 2011-12-07 13:57:44 90624 β€”-a-w- C:\Windows\System32\drivers\bowser.sys . ==================== Find3M ==================== . 2011-12-10 01:08:48 175616 β€”-a-w- C:\Windows\System32\msclmd.dll 2011-12-10 01:08:48 152576 β€”-a-w- C:\Windows\SysWow64\msclmd.dll 2011-12-07 14:23:52 270720 β€”β€”w- C:\Windows\System32\MpSigStub.exe 2011-11-24 04:52:09 3145216 β€”-a-w- C:\Windows\System32\win32k.sys 2011-11-05 05:41:43 1188864 β€”-a-w- C:\Windows\System32\wininet.dll 2011-11-05 05:32:50 2048 β€”-a-w- C:\Windows\System32\tzres.dll 2011-11-05 04:35:00 981504 β€”-a-w- C:\Windows\SysWow64\wininet.dll 2011-11-05 04:26:03 2048 β€”-a-w- C:\Windows\SysWow64\tzres.dll 2011-11-05 03:32:47 1638912 β€”-a-w- C:\Windows\System32\mshtml.tlb 2011-11-05 02:48:51 1638912 β€”-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-10-26 05:21:20 43520 β€”-a-w- C:\Windows\System32\csrsrv.dll 2011-10-15 06:31:56 723456 β€”-a-w- C:\Windows\System32\EncDec.dll 2011-10-15 05:54:52 321856 β€”-a-w- C:\Windows\SysWow64\nvStreaming.exe 2011-10-15 05:38:59 534528 β€”-a-w- C:\Windows\SysWow64\EncDec.dll 2011-09-29 16:29:28 1923952 β€”-a-w- C:\Windows\System32\drivers\tcpip.sys . ============= FINISH: 15:11:53.34 =============== aswMBR version 0.9.8.986 CopyrightΒ© 2011 AVAST Software Run date: 2011-12-16 15:20:20 —————————– 15:20:20.303 OS Version: Windows x64 6.1.7601 Service Pack 1 15:20:20.304 Number of processors: 2 586 0x203 15:20:20.304 ComputerName: SERIOCODE-PC UserName: Seriocode 15:20:21.916 Initialize success 15:20:22.453 AVAST engine defs: 11033001 15:20:32.277 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000068 15:20:32.279 Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3 15:20:34.309 Disk 0 MBR read successfully 15:20:34.312 Disk 0 MBR scan 15:20:34.314 Disk 0 Windows 7 default MBR code 15:20:34.316 Service scanning 15:20:35.013 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 15:20:35.587 Modules scanning 15:20:35.590 Disk 0 trace - called modules: 15:20:35.594 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80018a22c0]<< 15:20:35.597 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8002acc060] 15:20:35.600 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa800270e7a0] 15:20:35.603 5 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\00000068[0xfffffa800270e060] 15:20:35.955 \Driver\nvstor[0xfffffa80026fa9e0] -> IRP_MJ_CREATE -> 0xfffffa80018a22c0 15:20:37.143 AVAST engine scan C:\Windows 15:20:39.356 AVAST engine scan C:\Windows\system32 15:21:53.373 AVAST engine scan C:\Windows\system32\drivers 15:22:00.621 AVAST engine scan C:\Users\Seriocode 15:24:21.433 Disk 0 MBR has been saved successfully to "C:\Users\Seriocode\Desktop\MBR.dat" 15:24:21.440 The log file has been saved successfully to "C:\Users\Seriocode\Desktop\aswMBR.txt"

Attachments:

Hi,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
ComboFix 11-12-16.03 - Seriocode 12/16/2011 15:48:29.1.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2047.616 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Internet Security *Disabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308} FW: avast! Internet Security *Disabled* {FB460EB6-4C6D-E564-6BF5-EEEF2B44B473} SP: avast! Internet Security *Disabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . β€”β€”-\Service_conhost.exe pid: 3484 24: c:\windows\System32\en-US\conhost.exe.mui β€”β€”-\Service_Copyright Β© 1997-2008 Mark Russinovich β€”β€”-\Service_Handle v3.42 β€”β€”-\Service_lsm.exe pid: 532 240: c:\windows\System32\en-US\lsm.exe.mui β€”β€”-\Service_NASvc.exe pid: 1992 5C: c:\program files (x86)\Nero\Update\en-US\NASvc.exe.mui β€”β€”-\Service_svchost.exe pid: 1004 C94: c:\combofix\handle64.exe β€”β€”-\Service_svchost.exe pid: 1004 13E0: c:\combofix\handle64.exe β€”β€”-\Service_Sysinternals - www.sysinternals.com β€”β€”-\Service_wmpnetwk.exe pid: 3284 40: c:\program files\Windows Media Player\en-US\wmpnetwk.exe.mui β€”β€”-\Service_WUDFHost.exe pid: 952 40: c:\windows\System32\en-US\WUDFHost.exe.mui . . ((((((((((((((((((((((((( Files Created from 2011-11-16 to 2011-12-16 ))))))))))))))))))))))))))))))) . . 2011-12-16 21:02 . 2011-12-16 21:02 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-12-16 08:06 . 2011-12-07 14:23 8822856 β€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9C49F7F3-7759-42C7-8F6D-9645CAA108E9}\mpengine.dll 2011-12-15 00:23 . 2011-12-15 00:23 ——– d—–w- c:\program files (x86)\Content Manager 2011-12-15 00:09 . 2011-12-15 00:09 ——– d—–w- c:\users\Seriocode\AppData\Roaming\InstallShield 2011-12-13 06:45 . 2011-10-15 08:53 7581504 β€”-a-w- c:\windows\system32\nvcuda.dll 2011-12-13 06:44 . 2011-12-13 06:44 ——– d—–w- C:\NVIDIA 2011-12-13 06:10 . 2011-12-13 06:10 ——– d—–w- c:\users\UpdatusUser 2011-12-13 06:09 . 2011-10-15 08:53 837952 β€”-a-w- c:\windows\system32\easyupdatusapiu64.dll 2011-12-13 06:09 . 2011-10-15 08:53 5067584 β€”-a-w- c:\windows\system32\nvsvc64.dll 2011-12-13 06:09 . 2011-10-15 08:53 222528 β€”-a-w- c:\windows\system32\nvmctray.dll 2011-12-13 06:09 . 2011-10-15 08:53 1640768 β€”-a-w- c:\windows\system32\nvvsvc.exe 2011-12-13 06:09 . 2011-10-15 08:53 137536 β€”-a-w- c:\windows\system32\nvshext.dll 2011-12-13 06:09 . 2011-10-15 08:53 10406208 β€”-a-w- c:\windows\system32\nvcpl.dll 2011-12-13 06:09 . 2011-05-21 11:01 2560616 β€”-a-w- c:\windows\system32\nvsvcr.dll 2011-12-13 06:09 . 2011-12-13 06:09 ——– d—–w- c:\programdata\NVIDIA Corporation 2011-12-13 06:08 . 2011-12-13 06:18 ——– d—–w- c:\program files\NVIDIA Corporation 2011-12-13 03:28 . 2011-12-13 03:28 2106216 β€”-a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll 2011-12-13 03:28 . 2011-12-13 03:28 1998168 β€”-a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll 2011-12-13 03:28 . 2011-12-13 03:28 134104 β€”-a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll 2011-12-13 03:28 . 2011-12-13 03:28 89048 β€”-a-w- c:\program files (x86)\Mozilla Firefox\libEGL.dll 2011-12-13 03:28 . 2011-12-13 03:28 801752 β€”-a-w- c:\program files (x86)\Mozilla Firefox\mozsqlite3.dll 2011-12-13 03:28 . 2011-12-13 03:28 478168 β€”-a-w- c:\program files (x86)\Mozilla Firefox\libGLESv2.dll 2011-12-13 03:28 . 2011-12-13 03:28 1989592 β€”-a-w- c:\program files (x86)\Mozilla Firefox\mozjs.dll 2011-12-13 03:28 . 2011-12-13 03:28 15832 β€”-a-w- c:\program files (x86)\Mozilla Firefox\mozalloc.dll 2011-12-10 15:52 . 2011-12-10 15:57 ——– d—–w- c:\programdata\HP Photo Creations 2011-12-10 15:52 . 2011-12-10 15:52 ——– d—–w- c:\program files (x86)\HP Photo Creations 2011-12-10 15:52 . 2011-12-10 15:52 ——– d—–w- c:\program files (x86)\Coupons 2011-12-10 15:52 . 2011-12-10 15:52 ——– d—–w- c:\users\Seriocode\AppData\Roaming\HpUpdate 2011-12-10 15:52 . 2010-11-17 02:24 750440 β€”β€”w- c:\windows\system32\HPDiscoPM9311.dll 2011-12-10 15:51 . 2011-12-10 15:51 ——– d—–w- c:\programdata\HP 2011-12-10 15:51 . 2011-12-10 15:52 ——– d—–w- c:\program files (x86)\HP 2011-12-10 15:51 . 2011-12-10 15:51 ——– d—–w- c:\program files\HP 2011-12-10 15:51 . 2011-12-10 15:51 ——– d—–w- c:\users\Seriocode\AppData\Local\HP 2011-12-10 00:58 . 2011-12-10 00:58 ——– d—–w- c:\windows\system32\SPReview 2011-12-10 00:57 . 2011-12-10 00:57 ——– d—–w- c:\windows\system32\EventProviders 2011-12-08 17:27 . 2010-11-05 01:57 48976 β€”-a-w- c:\windows\system32\netfxperf.dll 2011-12-08 17:27 . 2010-11-05 01:57 1942856 β€”-a-w- c:\windows\system32\dfshim.dll 2011-12-08 17:25 . 2010-11-20 13:27 695808 β€”-a-w- c:\windows\system32\netlogon.dll 2011-12-08 17:24 . 2010-11-20 13:33 31104 β€”-a-w- c:\windows\system32\drivers\msahci.sys 2011-12-08 17:23 . 2010-11-20 13:27 93184 β€”-a-w- c:\program files\Windows Mail\oeimport.dll 2011-12-08 17:20 . 2010-11-20 13:27 524288 β€”-a-w- c:\windows\system32\wmicmiplugin.dll 2011-12-08 17:20 . 2010-11-20 13:27 529408 β€”-a-w- c:\windows\system32\wbemcomn.dll 2011-12-08 17:20 . 2010-11-20 13:27 1225216 β€”-a-w- c:\windows\system32\wbem\wbemcore.dll 2011-12-08 17:20 . 2010-11-20 13:27 244736 β€”-a-w- c:\program files\Windows Portable Devices\sqmapi.dll 2011-12-08 17:19 . 2010-11-20 13:27 244736 β€”-a-w- c:\windows\system32\sqmapi.dll 2011-12-08 17:19 . 2010-11-20 13:27 933376 β€”-a-w- c:\windows\system32\SmiEngine.dll 2011-12-08 17:19 . 2010-11-20 13:25 199168 β€”-a-w- c:\windows\system32\PkgMgr.exe 2011-12-08 17:19 . 2010-11-20 13:26 422912 β€”-a-w- c:\windows\system32\drvstore.dll 2011-12-08 17:19 . 2010-11-20 13:26 399872 β€”-a-w- c:\windows\system32\dpx.dll 2011-12-07 14:14 . 2011-12-07 14:14 ——– d—–w- c:\users\Public\Juniper Networks 2011-12-07 14:14 . 2009-08-25 23:11 579880 β€”-a-w- c:\windows\system32\dsNcSmartCardProv.dll 2011-12-07 14:14 . 2009-08-25 23:11 405288 β€”-a-w- c:\windows\system32\dsNcCredProv.dll 2011-12-07 14:13 . 2011-12-07 14:14 ——– d—–w- c:\program files (x86)\Juniper Networks 2011-12-07 14:10 . 2011-12-07 14:10 ——– d—–w- c:\program files (x86)\Common Files\Java 2011-12-07 14:10 . 2011-12-07 14:10 476904 β€”-a-w- c:\program files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll 2011-12-07 14:10 . 2011-12-07 14:10 472808 β€”-a-w- c:\windows\SysWow64\deployJava1.dll 2011-12-07 14:10 . 2011-12-07 14:10 ——– d—–w- c:\program files (x86)\Java 2011-12-07 14:05 . 2011-02-24 06:15 476160 β€”-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-12-07 14:05 . 2011-02-24 05:38 288256 β€”-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2011-12-07 14:04 . 2011-04-29 05:55 244736 β€”-a-w- c:\program files\Internet Explorer\sqmapi.dll 2011-12-07 14:04 . 2011-04-29 04:57 189952 β€”-a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll 2011-12-07 14:02 . 2011-07-16 05:37 421888 β€”-a-w- c:\windows\system32\KernelBase.dll 2011-12-07 13:58 . 2011-06-23 05:43 5561216 β€”-a-w- c:\windows\system32\ntoskrnl.exe 2011-12-07 13:58 . 2011-06-23 04:33 3912576 β€”-a-w- c:\windows\SysWow64\ntoskrnl.exe 2011-12-07 13:58 . 2011-06-23 04:33 3967872 β€”-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2011-12-07 13:57 . 2011-08-27 05:37 861696 β€”-a-w- c:\windows\system32\oleaut32.dll 2011-12-07 13:57 . 2011-08-27 05:37 331776 β€”-a-w- c:\windows\system32\oleacc.dll 2011-12-07 13:57 . 2011-08-27 04:26 233472 β€”-a-w- c:\windows\SysWow64\oleacc.dll 2011-12-07 13:57 . 2011-08-27 04:26 571904 β€”-a-w- c:\windows\SysWow64\oleaut32.dll 2011-12-07 13:57 . 2011-05-03 05:29 976896 β€”-a-w- c:\windows\system32\inetcomm.dll 2011-12-07 13:57 . 2011-05-03 04:30 741376 β€”-a-w- c:\windows\SysWow64\inetcomm.dll 2011-12-07 13:57 . 2011-02-12 11:34 267776 β€”-a-w- c:\windows\system32\FXSCOVER.exe 2011-12-07 13:57 . 2010-11-20 13:25 974336 β€”-a-w- c:\windows\system32\WFS.exe 2011-12-07 13:57 . 2011-02-18 10:51 31232 β€”-a-w- c:\windows\system32\prevhost.exe 2011-12-07 13:57 . 2011-02-18 05:39 31232 β€”-a-w- c:\windows\SysWow64\prevhost.exe 2011-12-07 13:57 . 2011-02-23 04:55 90624 β€”-a-w- c:\windows\system32\drivers\bowser.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-10 01:08 . 2009-07-14 02:36 175616 β€”-a-w- c:\windows\system32\msclmd.dll 2011-12-10 01:08 . 2009-07-14 02:36 152576 β€”-a-w- c:\windows\SysWow64\msclmd.dll 2011-12-07 14:23 . 2010-10-12 05:43 270720 β€”β€”w- c:\windows\system32\MpSigStub.exe 2011-10-15 08:53 . 2011-05-21 11:01 2808128 β€”-a-w- c:\windows\system32\nvapi64.dll 2011-10-15 08:53 . 2011-05-21 11:01 15693120 β€”-a-w- c:\windows\system32\nvd3dumx.dll 2011-10-15 08:53 . 2011-05-21 11:01 13205312 β€”-a-w- c:\windows\SysWow64\nvd3dum.dll 2011-10-15 08:53 . 2009-07-13 21:59 8791360 β€”-a-w- c:\windows\system32\nvwgf2umx.dll 2011-10-15 05:54 . 2011-10-15 05:54 321856 β€”-a-w- c:\windows\SysWow64\nvStreaming.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell] @="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}" [HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}] 2010-09-07 15:14 152160 β€”-a-w- c:\program files\Alwil Software\Avast5\snxPlugins.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2011-04-22 247728] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [x] S0 aswNdis2;avast! Firewall Core Firewall Service; [x] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x] S1 aswFW;avast! TDI Firewall driver; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 avast! Firewall;avast! Firewall;c:\program files\Alwil Software\Avast5\afwServ.exe [2010-09-07 119200] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-01-26 573224] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248] S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2011-04-22 92592] . . Contents of the 'Scheduled Tasks' folder . 2011-12-11 c:\windows\Tasks\hpwebreg_CN0AM291JT05HX.job - c:\program files\HP\HP Deskjet 3050 J610 series\Bin\hpwebreg.exe [2010-11-17 02:29] . . β€”β€”β€” x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell] @="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}" [HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}] 2010-09-07 15:11 176904 β€”-a-w- c:\program files\Alwil Software\Avast5\snxPlugins64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Logitech Download Assistant"="c:\windows\system32\rundll32.exe" [2009-07-14 45568] "combofix"="c:\combofix\CF14454.3XE" [2010-11-20 345088] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . β€”β€”- Supplementary Scan β€”β€”- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xportar a Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = [removed] [removed] FF - ProfilePath - c:\users\Seriocode\AppData\Roaming\Mozilla\Firefox\Profiles\o0o0szmc.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/ FF - prefs.js: network.proxy.type - 0 FF - user.js: general.useragent.extra.brc - BRI/1 . "ImagePath"="%SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\conhost.exe pid: 3484 24: C:] – "ImagePath"="\SystemRoot\system32\DRIVERS\lsi_scsi.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lsm.exe pid: 532 240: C:] – "ServiceDLL"="%SystemRoot%\system32\qagentRT.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NASvc.exe pid: 1992 5C: C:] – "ImagePath"="\SystemRoot\system32\drivers\storvsc.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\svchost.exe pid: 1004 C94: C:] . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\svchost.exe pid: 1004 13E0: C:] – "ImagePath"="%systemroot%\system32\wbem\WmiApSrv.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmpnetwk.exe pid: 3284 40: C:] – "ServiceDll"="%systemroot%\system32\wuaueng.dll" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WUDFHost.exe pid: 952 40: C:] . β€”β€”β€”β€”β€”β€”β€” LOCKED REGISTRY KEYS β€”β€”β€”β€”β€”β€”β€” . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . β€”β€”β€”β€”β€”β€”β€”β€” Other Running Processes β€”β€”β€”β€”β€”β€”β€”β€” . c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files (x86)\Juniper Networks\Common Files\dsNcService.exe c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe . ************************************************************************** . Completion time: 2011-12-16 16:16:03 - machine was rebooted ComboFix-quarantined-files.txt 2011-12-16 21:16 . Pre-Run: 368,341,266,432 bytes free Post-Run: 368,700,067,840 bytes free . - - End Of File - - F7FFD87DE997CB1EC5D214BA81A5E28A
Hi,

Please do the following:


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8382 Windows 6.1.7601 Service Pack 1 Internet Explorer 8.0.7601.17514 12/16/2011 7:49:58 PM mbam-log-2011-12-16 (19-49-58).txt Scan type: Quick scan Objects scanned: 192842 Time elapsed: 2 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

Please do the following:

Press the WinKey + R to open a run box, then copy/paste the following single-line command into the Run box and click OK:

cmd /c del /f/a/q "C:\Users\Seriocode\Documents\Vuze Downloads\AVAST PRO AntiVirus .With Internet Security ( Crack Full Version.Upto May 2020)\Crack\ashBase.dll"




Windows 7 has a very aggressive repair feature which can resolve most issues that you are experiencing, it can replace many corrupt or missing files, without disturbing your installed programs or documents etc. I would give that a try

Follow the tutorial here

http://www.sevenforums.com/tutorials/681-startup-repair.html


Let me know if there are any outstanding issues
Thank you CatByte, So far so good. I have not had anything really strange happen just yet since the scans you had me run through, but I am still on some occasions having a weird startups. Would this mean that it is a hardware issue? If so, what can I do to find out what it is? (another part of this site dedicated to hardware issues? another site for this issue? or just am I SOL? lol) Or are we not all the way done with the testing?
Hi,

There is no indication this is malware related, there may be something the Expert Techs here can do if you post a new thread in the Hardware section

but I will give my usual clean up instructions for the tools now, let them know in Hardware that you have been cleared by Malware Removal forum ( provide a link to this topic)

please do the following:


You can delete the DDS and aswMBR logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI