Hi Deception35, welcome to the forum.
To make cleaning this machine easier
Please do not uninstall/install any programs unless asked to
It is more difficult when files/programs are appearing in/disappearing from the logs. Please do not run any scans other than those requested Please follow all instructions in the order posted All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked. Do not attach any logs/reports, etc.. unless specifically requested to do so. If you have problems with or do not understand the instructions, Please ask before continuing. Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
When i tried to post it went to a page saying my internet was down. Sry
That sometimes happens, I'll remove your additional topics.
Please download
DeFogger to your
desktop .
Double click
DeFogger to run the tool.
The application window will appear Click the Disable button to disable your CD Emulation drivers Click Yes to continue A 'Finished!' message will appear Click OK DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log
defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.
I see you have
aswMBR on your computer. Please run a scan with it and post the log and attach the
mbr.zip that is also produced.
To run aswMBR:
Right click the aswMBR.exeand click "Run as Administrator" to run it
Click the "Scan" button to start scan
[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
Next
Please open OTL.
Make sure all other windows are closed and to let it run uninterrupted. When the window appears, click the None button near the top (it may looked greyed out)
In the window under Custom Scans/Fixes copy and paste the following
%USERPROFILE%\..|smtmp;true;true;true /FP
%temp%\smtmp\*.* /s
/md5start
iexplore.*
explorer.*
winlogon.*
dll
zx.dll
hlp.dat
consrv.dll
/md5stop
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window,
OTL.Txt . Please post this log.
Please post back with
aswmbr log OTL.txt mbr.zip (attached)
Thanks
Thanks for the quick response. Im running the MBR test now. B4 i got your reply i re -installed firefox. i dont know if thats a big deal or not. Also i just got a BSOD while running the scan so im re running it now.
aswMBR log
aswMBR version 0.9.8.986 CopyrightΒ© 2011 AVAST Software
Run date: 2011-12-14 13:03:09
ββββββββββ
13:03:09.043 OS Version: Windows 6.0.6002 Service Pack 2
13:03:09.043 Number of processors: 2 586 0x4B02
13:03:09.044 ComputerName: FAXCOOLWAREZ037 UserName: Owner35
13:03:55.480 Initialize success
13:04:07.034 AVAST engine defs: 11121401
13:04:55.894 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-3
13:04:55.898 Disk 0 Vendor: ST3100011A 3.02 Size: 95396MB BusType: 3
13:04:57.934 Disk 0 MBR read successfully
13:04:57.938 Disk 0 MBR scan
13:04:57.956 Disk 0 Windows VISTA default MBR code
13:04:57.962 Disk 0 scanning sectors +195366912
13:04:59.961 Disk 0 scanning C:\Windows\system32\drivers
13:05:08.932 File: C:\Windows\system32\drivers\serial.sys **INFECTED** Win32:Alureon-AOV [Rtk]
13:05:13.329 Service scanning
13:05:15.783 Modules scanning
13:05:21.287 Module: C:\Windows\system32\DRIVERS\serial.sys **SUSPICIOUS**
13:05:28.249 Disk 0 trace - called modules:
13:05:28.257 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86617f10]<<
13:05:28.259 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85bf6ac8]
13:05:28.259 3 CLASSPNP.SYS[883c68b3] -> nt!IofCallDriver -> [0x865e0e08]
13:05:28.260 \Driver\00000907[0x8640a030] -> IRP_MJ_CREATE -> 0x86617f10
13:05:28.989 AVAST engine scan C:\Windows
13:05:33.974 AVAST engine scan C:\Windows\system32
13:12:35.568 AVAST engine scan C:\Windows\system32\drivers
13:13:02.299 File: C:\Windows\system32\drivers\serial.sys **INFECTED** Win32:Alureon-AOV [Rtk]
13:13:20.785 AVAST engine scan C:\Users\Owner35
13:15:01.294 AVAST engine scan C:\ProgramData
13:25:31.677 File: C:\ProgramData\Gjz6R8Hp5yxecj.exe **INFECTED** Win32:FakeAV-CQI [Trj]
13:26:48.614 Scan finished successfully
13:27:25.928 Disk 0 MBR has been saved successfully to "C:\Users\Owner35\Desktop\MBR.dat"
13:27:25.935 The log file has been saved successfully to "C:\Users\Owner35\Desktop\aswMBR.txt"
OTL.txt
OTL logfile created on: 12/14/2011 1:29:32 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Owner35\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19154)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.99 Gb Available Physical Memory | 49.41% Memory free
4.23 Gb Paging File | 3.25 Gb Available in Paging File | 76.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 50.78 Gb Total Space | 6.84 Gb Free Space | 13.47% Space Free | Partition Type: NTFS
Drive E: | 42.38 Gb Total Space | 10.58 Gb Free Space | 24.98% Space Free | Partition Type: NTFS
Computer Name: FAXCOOLWAREZ037 | User Name: Owner35 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s >
< MD5 for: EXPLORER.ADML >
[2011/08/12 16:54:22 | 000,002,823 | β- | M] () MD5=A3CE2A219D9C2AC33F5218210FA2A1E9 β C:\Windows\PolicyDefinitions\zh-CN\Explorer.adml
[2011/08/12 16:54:06 | 000,002,823 | β- | M] () MD5=A3CE2A219D9C2AC33F5218210FA2A1E9 β C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_80502804548c3b9b\Explorer.adml
[2011/08/12 16:54:22 | 000,002,823 | β- | M] () MD5=A3CE2A219D9C2AC33F5218210FA2A1E9 β C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6001.18000_zh-cn_8286ea0051774c6f\Explorer.adml
[2006/11/02 07:40:18 | 000,002,791 | β- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 β C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2006/11/02 07:40:18 | 000,002,791 | β- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 β C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6000.16386_en-us_20c9bd966d6a6189\Explorer.adml
[2006/11/02 07:40:18 | 000,002,791 | β- | M] () MD5=B17D3F048712809BE9643AE542B7D6B0 β C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6001.18000_en-us_23007f926a55725d\Explorer.adml
[2008/02/05 12:12:38 | 000,004,443 | β- | M] () MD5=F4E6889482DBDBA9F6A69B18EDDCE1DC β C:\Windows\PolicyDefinitions\ru-RU\Explorer.adml
[2008/02/05 12:12:08 | 000,004,443 | β- | M] () MD5=F4E6889482DBDBA9F6A69B18EDDCE1DC β C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_69ead54abe6f5d30\Explorer.adml
[2008/02/05 12:12:38 | 000,004,443 | β- | M] () MD5=F4E6889482DBDBA9F6A69B18EDDCE1DC β C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6001.18000_ru-ru_6c219746bb5a6e04\Explorer.adml
[2011/07/13 20:03:59 | 000,003,104 | β- | M] () MD5=FF640A46B12B353734E33CAB8AA03F0C β C:\Windows\PolicyDefinitions\ko-KR\Explorer.adml
[2011/07/13 20:03:36 | 000,003,104 | β- | M] () MD5=FF640A46B12B353734E33CAB8AA03F0C β C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_f303e2821d2127ff\Explorer.adml
[2011/07/13 20:03:59 | 000,003,104 | β- | M] () MD5=FF640A46B12B353734E33CAB8AA03F0C β C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.0.6001.18000_ko-kr_f53aa47e1a0c38d3\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2006/11/02 07:34:28 | 000,002,840 | β- | M] () MD5=66DA9157D2CBE355555739AA9EDA1C6D β C:\Windows\PolicyDefinitions\Explorer.admx
[2006/11/02 07:34:28 | 000,002,840 | β- | M] () MD5=66DA9157D2CBE355555739AA9EDA1C6D β C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.0.6001.18000_none_15baa9b3f0d5e010\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2008/10/29 01:20:29 | 002,923,520 | β- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE β C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | β- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D β C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 22:59:17 | 002,927,616 | β- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E β C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | β- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 β C:\Windows\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | β- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 β C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 21:15:02 | 002,923,520 | β- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB β C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 21:22:34 | 002,927,104 | β- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F β C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 07:39:48 | 000,036,864 | β- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 β C:\Windows\en-US\explorer.exe.mui
[2006/11/02 07:39:48 | 000,036,864 | β- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 β C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui
[2011/08/12 16:51:21 | 000,868,352 | β- | M] (Microsoft Corporation) MD5=7B0AE29051B64A5FB58BBAB1F219F68B β C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_63422f8f5dd89432\explorer.exe.mui
[2011/08/12 16:51:21 | 000,868,352 | β- | M] (Microsoft Corporation) MD5=7B0AE29051B64A5FB58BBAB1F219F68B β C:\Windows\zh-CN\explorer.exe.mui
[2011/07/13 20:00:40 | 000,905,216 | β- | M] (Microsoft Corporation) MD5=98DE732839371F343C2C21C8E5B1CDFC β C:\Windows\ko-KR\explorer.exe.mui
[2011/07/13 20:00:40 | 000,905,216 | β- | M] (Microsoft Corporation) MD5=98DE732839371F343C2C21C8E5B1CDFC β C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_d5f5ea0d266d8096\explorer.exe.mui
[2008/02/05 12:09:22 | 000,950,272 | β- | M] (Microsoft Corporation) MD5=DC4D522F50D2C3742F37243A50CF397F β C:\Windows\ru-RU\explorer.exe.mui
[2008/02/05 12:09:22 | 000,950,272 | β- | M] (Microsoft Corporation) MD5=DC4D522F50D2C3742F37243A50CF397F β C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_4cdcdcd5c7bbb5c7\explorer.exe.mui
< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2011/12/14 12:56:38 | 000,235,378 | β- | M] () MD5=9730800C1634CCF9721674B3B7A8BCC5 β C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf
< MD5 for: IEXPLORE.EXE >
[2011/07/23 06:02:27 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=04D1DC458C723B291179F8449ACC281D β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19120_none_12355fcb2fdc2111\iexplore.exe
[2009/01/14 23:14:36 | 000,634,024 | β- | M] (Microsoft Corporation) MD5=0844F5B9CB3BB85A917D347EF1565B6C β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16809_none_2d84c7c91ccfce35\iexplore.exe
[2011/09/30 18:49:11 | 000,638,216 | β- | M] (Microsoft Corporation) MD5=0E1695AD4C30E72D68170F01B4818A80 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23250_none_129e8cd2491214ae\iexplore.exe
[2008/10/01 22:50:01 | 000,633,632 | β- | M] (Microsoft Corporation) MD5=19403B64906C9EAC627E3C10847B0FDA β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\iexplore.exe
[2009/11/21 01:42:38 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=1B6362BB14FCEB9E76BCF9A953B04788 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18865_none_120f459f2ff7e1f8\iexplore.exe
[2009/03/02 23:18:52 | 000,636,072 | β- | M] (Microsoft Corporation) MD5=1DD66A2851DACDEC32EAE8F9A8865ABD β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21023_none_2df29b2236034119\iexplore.exe
[2009/04/24 11:25:27 | 000,634,648 | β- | M] (Microsoft Corporation) MD5=1F44940EF1D07D0BDAF80E55853DFBD0 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16851_none_2d46b5dd1cff8f32\iexplore.exe
[2010/02/23 10:06:13 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=25DB705A7DC85C208B3CF2D20F118AA7 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22995_none_127872a6492dd595\iexplore.exe
[2009/04/11 01:27:44 | 000,636,080 | β- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2009/08/27 00:23:17 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=2E48756F12C21F46895036AC089AAD97 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\iexplore.exe
[2010/01/02 09:58:26 | 000,638,216 | β- | M] (Microsoft Corporation) MD5=3D8DA00B028DEA9517066F1CECBFC4A2 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22973_none_128c11ea491f6b05\iexplore.exe
[2010/05/04 01:32:18 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=48A6109E8DF0365195298CC527B7426A β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab\iexplore.exe
[2010/09/08 01:26:34 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=4A719476A6393B1DCACFEB4F3AC6599C β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23067_none_129abb204913e7b2\iexplore.exe
[2009/07/22 01:04:09 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=4B5AEA50CE77FBA4C2D169622DC9B489 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22903_none_12d7c15e48e6a76e\iexplore.exe
[2008/10/15 23:27:53 | 000,634,024 | β- | M] (Microsoft Corporation) MD5=4CBA2F58668F2D5F3259CBE73E227F25 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20937_none_2debf43c36078f24\iexplore.exe
[2011/07/23 06:42:34 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=4D08A4234D645EFCB30605CC0BFA87F4 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23216_none_12cfce3e48ec3cf4\iexplore.exe
[2010/11/02 01:03:13 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=5AB037B17F8A87D052F5A88E0D29A3C8 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18999_none_11f2d8e9300c984e\iexplore.exe
[2008/01/20 21:21:57 | 000,625,664 | β- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2010/05/04 01:00:35 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=5C9B1062EA7A44E8F6BFDE994B68C7AA β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60\iexplore.exe
[2008/10/01 22:32:01 | 000,633,632 | β- | M] (Microsoft Corporation) MD5=6655B851D9EEF7C83395EE52D551B448 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\iexplore.exe
[2010/06/26 01:06:48 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\iexplore.exe
[2010/12/18 02:19:44 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=7852371DA9EFBC17B645558E23780EAC β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a\iexplore.exe
[2011/09/30 18:07:49 | 000,638,216 | β- | M] (Microsoft Corporation) MD5=7ACBBC85FCE4989B533220FC3B291633 β C:\Program Files\Internet Explorer\iexplore.exe
[2011/09/30 18:07:49 | 000,638,216 | β- | M] (Microsoft Corporation) MD5=7ACBBC85FCE4989B533220FC3B291633 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19154_none_1218f12f2ff0da40\iexplore.exe
[2009/08/27 08:31:08 | 000,638,216 | β- | M] (Microsoft Corporation) MD5=7DD482E4A2E3CBB0A72F718C342F5B75 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22918_none_12d1f2e448ea4212\iexplore.exe
[2011/05/28 02:09:20 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=7EE10C5413AD7ED1AF9E8FAE1B58FC3E β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23181_none_127f1b72492984b1\iexplore.exe
[2010/01/02 01:40:20 | 000,638,216 | β- | M] (Microsoft Corporation) MD5=88BD42DAE7CFFEB256CA7145A15E4843 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18882_none_11f6a4e9300acdd5\iexplore.exe
[2009/03/02 23:32:44 | 000,636,072 | β- | M] (Microsoft Corporation) MD5=8BA2B7A05F88BE0D45237A0994AD8366 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22389_none_2f9e23da3354de78\iexplore.exe
[2010/11/02 02:13:47 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=92A17B0A89D14815AACC62CD190B6CE3 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23091_none_127449a04931a37b\iexplore.exe
[2011/02/22 02:18:28 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=9CE5543464432CA73134F170FA2BF823 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23143_none_12ac5bb64907479b\iexplore.exe
[2009/03/02 23:40:22 | 000,636,072 | β- | M] (Microsoft Corporation) MD5=9E6C1527D9A2C64BFD780AA23075380F β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18226_none_2f5265b91a094b03\iexplore.exe
[2010/02/23 01:39:16 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=9F52FBE99C749E3F32C75124F09F1B03 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18904_none_124f26c32fc81e22\iexplore.exe
[2009/03/08 16:09:24 | 000,638,816 | β- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
[2010/12/18 01:28:35 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=B988D7F127B94BD5BF8356FE81B985C4 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08\iexplore.exe
[2011/02/22 01:21:12 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=C1D36A2CBE0CEC4DF593DB1288CF586E β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19048_none_1227c05d2fe52684\iexplore.exe
[2009/07/21 16:53:43 | 000,638,216 | β- | M] (Microsoft Corporation) MD5=C33BD196A0301F9B23D9A003D30ED8B0 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18813_none_124354a72fd12395\iexplore.exe
[2009/04/24 11:03:18 | 000,634,648 | β- | M] (Microsoft Corporation) MD5=D5271AC4A06AD9D1E2EA0151B79B2657 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21046_none_2ddffc283610c500\iexplore.exe
[2010/09/08 01:02:42 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=D5A730DFDEAE005373E62BC2A866E3BB β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18975_none_120477992ffffb10\iexplore.exe
[2009/04/24 11:01:36 | 000,634,648 | β- | M] (Microsoft Corporation) MD5=D6157423C117F24D24695866A1D0A93F β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22418_none_2fe8d4ea331cfeb1\iexplore.exe
[2008/10/15 23:42:58 | 000,634,024 | β- | M] (Microsoft Corporation) MD5=D762642A109433EEDCD332B0A9511137 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16764_none_2d3ee4e91d04fa01\iexplore.exe
[2009/11/21 10:05:17 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=E7F8DF50E483D165BB01F367D3519AA7 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22956_none_12a4b2a0490c7f28\iexplore.exe
[2009/03/02 23:22:10 | 000,636,072 | β- | M] (Microsoft Corporation) MD5=EA4BE33726155F89D89A3FE7142878E0 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16830_none_2d5b556b1cf03df9\iexplore.exe
[2011/05/28 01:09:21 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=ED65737D70FDEAC29F738E77D2496EE5 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19088_none_11fc80ad30059648\iexplore.exe
[2010/06/26 01:52:42 | 000,638,232 | β- | M] (Microsoft Corporation) MD5=F05B3A2C6CB319DD1377AD566CF5ECE5 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\iexplore.exe
[2009/01/14 23:18:47 | 000,634,024 | β- | M] (Microsoft Corporation) MD5=F0B1CA517977BA2FF6DA33F1B966C488 β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20996_none_2daa146a36391d73\iexplore.exe
[2009/04/24 11:08:04 | 000,634,632 | β- | M] (Microsoft Corporation) MD5=F294D8EEB05C835EC44A12CE0A1DFE7A β C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18248_none_2f3ec6751a17b593\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 16:22:03 | 000,016,384 | β- | M] (Microsoft Corporation) MD5=19F8D1204566F758DC785AE6ABA899E7 β C:\Program Files\Internet Explorer\ru-RU\iexplore.exe.mui
[2009/03/08 16:22:03 | 000,016,384 | β- | M] (Microsoft Corporation) MD5=19F8D1204566F758DC785AE6ABA899E7 β C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_ru-ru_6998ad24bb95d268\iexplore.exe.mui
[2006/11/02 07:39:45 | 000,016,384 | β- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B β C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2011/08/12 16:51:11 | 000,016,384 | β- | M] (Microsoft Corporation) MD5=694CBEB73AEAEC29FF6A23DA408BCA35 β C:\Program Files\Internet Explorer\zh-CN\iexplore.exe.mui
[2011/08/12 16:51:11 | 000,016,384 | β- | M] (Microsoft Corporation) MD5=694CBEB73AEAEC29FF6A23DA408BCA35 β C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_9adc1b883efc2fa2\iexplore.exe.mui
[2009/03/08 16:27:11 | 000,012,288 | β- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 β C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 16:27:11 | 000,012,288 | β- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 β C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1\iexplore.exe.mui
[2011/07/13 20:00:31 | 000,016,384 | β- | M] (Microsoft Corporation) MD5=F1E00EE507CA34658D1EF19F92759246 β C:\Program Files\Internet Explorer\ko-KR\iexplore.exe.mui
[2011/07/13 20:00:31 | 000,016,384 | β- | M] (Microsoft Corporation) MD5=F1E00EE507CA34658D1EF19F92759246 β C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_0d8fd60607911c06\iexplore.exe.mui
[2008/02/05 12:09:00 | 000,016,384 | β- | M] (Microsoft Corporation) MD5=F2DF8388FA40DC94A9763F651F2B032D β C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_8476c8cea8df5137\iexplore.exe.mui
< MD5 for: WINLOGON.ADML >
[2006/11/02 07:40:19 | 000,008,051 | β- | M] () MD5=5911AB4AD86759363C6C00408A522692 β C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2006/11/02 07:40:19 | 000,008,051 | β- | M] () MD5=5911AB4AD86759363C6C00408A522692 β C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.0.6000.16386_en-us_92cd4f8bdff6e8f5\WinLogon.adml
[2011/08/12 16:54:09 | 000,007,518 | β- | M] () MD5=8EE4434BAEFC6AA664BAB623D59223B4 β C:\Windows\PolicyDefinitions\zh-CN\WinLogon.adml
[2011/08/12 16:54:09 | 000,007,518 | β- | M] () MD5=8EE4434BAEFC6AA664BAB623D59223B4 β C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_f253b9f9c718c307\WinLogon.adml
[2008/02/05 12:11:59 | 000,013,524 | β- | M] () MD5=9358642BF730B5075BE48625B5E13192 β C:\Windows\PolicyDefinitions\ru-RU\WinLogon.adml
[2008/02/05 12:11:59 | 000,013,524 | β- | M] () MD5=9358642BF730B5075BE48625B5E13192 β C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_dbee674030fbe49c\WinLogon.adml
[2011/07/13 20:03:40 | 000,009,315 | β- | M] () MD5=F4230DAE1C4683BF3F8235C724C6AC91 β C:\Windows\PolicyDefinitions\ko-KR\WinLogon.adml
[2011/07/13 20:03:40 | 000,009,315 | β- | M] () MD5=F4230DAE1C4683BF3F8235C724C6AC91 β C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_650774778fadaf6b\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2006/11/02 07:34:27 | 000,005,237 | β- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C β C:\Windows\PolicyDefinitions\WinLogon.admx
[2006/11/02 07:34:27 | 000,005,237 | β- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C β C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.0.6000.16386_none_78d69ac67c572ad2\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2009/04/11 01:28:13 | 000,314,368 | β- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 β C:\Windows\System32\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | β- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 β C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 21:22:59 | 000,314,880 | β- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 β C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2011/08/12 16:52:28 | 000,020,480 | β- | M] (Microsoft Corporation) MD5=244E6DA8FD192052A86689871F682EB2 β C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_284839fcee4d3b78\winlogon.exe.mui
[2008/01/20 21:23:53 | 000,028,672 | β- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 β C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/20 21:23:53 | 000,028,672 | β- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 β C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2011/07/13 20:04:47 | 000,020,480 | β- | M] (Microsoft Corporation) MD5=469DD6B7AC87B0BB5D11029090E2AF65 β C:\Windows\System32\ko-KR\winlogon.exe.mui
[2011/07/13 20:04:47 | 000,020,480 | β- | M] (Microsoft Corporation) MD5=469DD6B7AC87B0BB5D11029090E2AF65 β C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_ko-kr_9d32b676b3cd38b0\winlogon.exe.mui
[2011/08/12 16:55:01 | 000,020,480 | β- | M] (Microsoft Corporation) MD5=6AFF70D82F7052B63F5D5B9A8A566322 β C:\Windows\System32\zh-CN\winlogon.exe.mui
[2011/08/12 16:55:01 | 000,020,480 | β- | M] (Microsoft Corporation) MD5=6AFF70D82F7052B63F5D5B9A8A566322 β C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_zh-cn_2a7efbf8eb384c4c\winlogon.exe.mui
[2011/07/13 20:01:41 | 000,020,480 | β- | M] (Microsoft Corporation) MD5=89BCC89E68F88E9BF63D69F43BB05C12 β C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_ko-kr_9afbf47ab6e227dc\winlogon.exe.mui
[2006/11/02 07:39:20 | 000,028,672 | β- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 β C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui
[2008/02/05 12:07:29 | 000,028,672 | β- | M] (Microsoft Corporation) MD5=A7ADA5EEC138C00987695D7C48A9FA01 β C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_ru-ru_11e2e74358305d0d\winlogon.exe.mui
[2008/02/05 12:13:19 | 000,032,768 | β- | M] (Microsoft Corporation) MD5=B5F51822FB382E5840FD5BDF2B17F16A β C:\Windows\System32\ru-RU\winlogon.exe.mui
[2008/02/05 12:13:19 | 000,032,768 | β- | M] (Microsoft Corporation) MD5=B5F51822FB382E5840FD5BDF2B17F16A β C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_ru-ru_1419a93f551b6de1\winlogon.exe.mui
< MD5 for: WINLOGON.EXE-8163EECC.PF >
[2011/12/13 14:23:30 | 000,034,034 | β- | M] () MD5=6B70413238BB0A57AA1473F4A7342380 β C:\Windows\Prefetch\WINLOGON.EXE-8163EECC.pf
< MD5 for: WINLOGON.MOF >
[2006/09/18 16:41:56 | 000,002,794 | β- | M] () MD5=545C578F290B9CDD280966939935B9EA β C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 16:41:56 | 000,002,794 | β- | M] () MD5=545C578F290B9CDD280966939935B9EA β C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof
< End of report >
Did i upload eveything u asked?
Also ive been gettin Redirected to a site saying ive won a prize. just happend
Hi Deception35,
Download
ComboFix from one of these locations:
Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note : If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
Right click on ComboFix.exe, click Run as Administrator & follow the prompts.
When finished, it shall produce a log for you. Please include the
C:\ComboFix.txt in your next reply.
Notes:
1.
Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely , the connection can be manually restored by restarting your machine.
Please post back with the
combofix log .
Thanks
I try to run ComboFix but it keeps saying Avg Free anti virus is running but i dont even have that on my computer anymore. So i dont know what to do
Hi Deception35,
Go ahead and run it.
I've been running it for a half hour now and its still running is that normal?
Is there any harddrive activity at all? What is displayed on the screen?
It says
Scanning for infected filesβ¦
This typically doesn't take more then 10 minutes
However, scan times for badly infected machines may easily double.
That's all it says
Hi
Ok it seems it may have stalled. Restart your computer. Delete the copy you have and download a new one from
Link 1 or
Link 2 to your Desktop. Please read these instructions before you down load it.
If you are using Firefox, make sure that your download settings are as follows:
-Tools->Options->Main tab
-Set to "Always ask me where to Save the files".
During the download, before you save it to your desktop, rename Combofix to svchost.exe
It is important you rename Combofix during the download, but not after. Please do not rename Combofix to other names, but only to the one indicated. Close any open browsers. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix
ββββββββββββββββββββ
Right click on ComboFix.exe (svchost.exe in your case) and click "Run as Administrator" & follow the prompts.
When finished, it shall produce a log for you. Please include the
C:\ComboFix.txt in your next reply.
Notes:
1.
Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty
and terminates prematurely , the connection can be manually restored by restarting your machine.
Please post back with
How is the computer?
Thanks
.