This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

hijackthis, dds, otl log files [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok ladies and gentleman I hope I uploaded these files in the correct place. I need some help I am infected with some type of virus. I am running win7 home premium. If I posted this in the wrong place I am sorry for any inconvience this may have caused. . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 20:07:58.94 on Wed 12/28/2011 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6135.3830 [GMT -5:00] . AV: COMODO Antivirus *Enabled/Updated* {7554F4C5-5EC0-2FC6-8192-8DF831DBED51} AV: CA Anti-Virus Plus *Enabled/Updated* {57B5C44D-AAB5-DBC9-741B-542BE5A132EA} SP: CA Anti-Virus Plus *Enabled/Updated* {ECD425A9-8C8F-D447-4EAB-6F599E267857} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC} FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A} FW: CA Personal Firewall *Enabled* {6F8E4568-E0DA-DA91-5F44-FD1E1B727591} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Program Files (x86)\CA\SharedComponents\HIPSEngine\UmxCfg.exe C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\CA\SharedComponents\HIPSEngine\UmxPol.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\SysWOW64\svchost.exe -k Akamai C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe C:\Windows\SysWOW64\mdmcls32.exe C:\Windows\SysWOW64\cfgmig32.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\CA\CA Internet Security Suite\ccevtmgr.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Program Files\CA\CA Internet Security Suite\casc.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Windows\system32\taskeng.exe c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Citrix\ICA Client\concentr.exe C:\Program Files\COMODO\COMODO GeekBuddy\CLPS.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Windows iLivid Toolbar\Datamngr\datamngrUI.exe C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\notepad.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\notepad.exe C:\Windows\notepad.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\mancave\Desktop\dds.scr C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . uSearch Bar = Preserve uStart Page = hxxp://www.aol.com/ mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=userinit.exe, BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll BHO: DataMngr: {9d717f81-9148-4f12-8568-69135f087db0} - C:\PROGRA~2\WI3C8A~1\Datamngr\BROWSE~1.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll TB: CA Anti-Phishing Toolbar: {0123b506-0ad9-43aa-b0cf-916c122ad4c5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\toolbar\caIEToolbar.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File TB: {F29557FD-78AA-40E6-ABA8-9FA219764018} - No File TB: {E413A417-D00B-4A3B-9C17-19048046F1CE} - No File uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden uRun: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe mRun: [] mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe mRun: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup mRun: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun: [DATAMNGR] C:\PROGRA~2\WI3C8A~1\Datamngr\DATAMN~1.EXE mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL LSP: C:\Windows\system32\VetRedir.dll Trusted Zone: intuit.com\ttlc DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} - hxxp://www.auctiva.com/Aurigma/ImageUploader57.cab DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} - hxxp://ax.emsisoft.com/asquared.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://secureauth.carolinas.org/dana-cached/sc/JuniperSetupClient.cab Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll Notify: PFW - UmxWnp.Dll AppInit_DLLs: C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll UmxSbxExw.dll C:\Windows\SysWOW64\guard32.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe" BHO-X64: DataMngr: {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI3C8A~1\Datamngr\x64\BROWSE~1.DLL TB-X64: CA Anti-Phishing Toolbar: {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\toolbar\caIEToolbar.dll TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File TB-X64: {F29557FD-78AA-40E6-ABA8-9FA219764018} - No File TB-X64: {E413A417-D00B-4A3B-9C17-19048046F1CE} - No File mRun-x64: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background mRun-x64: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h mRun-x64: [cctray] "C:\Program Files\CA\CA Internet Security Suite\casc.exe" AppInit_DLLs-X64: C:\PROGRA~2\WI3C8A~1\Datamngr\x64\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\x64\IEBHO.dll UmxSbxExA64.dll C:\Windows\system32\guard64.dll . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\mancave\AppData\Roaming\Mozilla\Firefox\Profiles\21a5acyp.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Search Results FF - prefs.js: browser.startup.homepage - www.aol.com FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\10\NP_wtapp.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . —- FIREFOX POLICIES —- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . ============= SERVICES / DRIVERS =============== . R0 EnumProcessesDriver;EnumProcessesDriver;C:\Windows\System32\drivers\EnumProcessesDriver.sys [2011-12-26 20080] R0 KmxAMRT;KmxAMRT;C:\Windows\System32\drivers\KmxAMRT.sys [2011-7-29 178768] R0 KmxFw;KmxFw;C:\Windows\System32\drivers\KmxFw.sys [2011-7-28 143824] R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\System32\drivers\cmdGuard.sys [2011-6-30 577824] R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\System32\drivers\cmdhlp.sys [2011-6-30 43248] R1 ctxusbm;Citrix USB Monitor Driver;C:\Windows\System32\drivers\ctxusbm.sys [2010-4-16 87600] R1 KmxAgent;KmxAgent;C:\Windows\System32\drivers\KmxAgent.sys [2011-7-29 113744] R1 KmxCfg;KmxCfg;C:\Windows\System32\drivers\KmxCfg.sys [2011-7-29 364624] R1 KmxFile;KmxFile;C:\Windows\System32\drivers\KmxFile.sys [2011-7-29 87120] R1 KmxFilter;HIPS Core Filter Driver;C:\Windows\System32\drivers\KmxFilter.sys [2011-7-28 99024] R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368] R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952] R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 27136] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-10-25 203264] R2 CAAMSvc;CAAMSvc;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\CAAMSvc.exe [2011-6-29 291656] R2 CAISafe;CAISafe;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe [2011-10-5 312656] R2 ccSchedulerSVC;CA Common Scheduler Service;C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe [2011-10-5 286032] R2 CLPSLS;COMODO livePCsupport Service;C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-11-23 1267000] R2 HPBtnSrv;HP Easy Backup Button Service;C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe [2010-10-21 192512] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-1-25 92216] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-10-25 13336] R2 KmxCF;KmxCF;C:\Windows\System32\drivers\KmxCF.sys [2011-7-29 202320] R2 KmxSbx;KmxSbx;C:\Windows\System32\drivers\KmxSbx.sys [2011-7-29 81488] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-28 652872] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-7-20 2027840] R2 UmxAgent;HIPS Event Manager;C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2009-8-4 1479160] R2 UmxCfg;HIPS Configuration Interpreter;C:\Program Files (x86)\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2009-7-13 760664] R2 UmxEngine;TM Engine;C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe [2011-4-4 920656] R2 UmxPol;HIPS Policy Manager;C:\Program Files (x86)\CA\SharedComponents\HIPSEngine\UmxPol.exe [2009-7-27 227832] R2 WinExtManager;WinSock Extention Manager;C:\Windows\SysWOW64\mdmcls32.exe [2011-10-5 3207184] R2 WinSvchostManagerSrv;WinSvchostManagerSrv;C:\Windows\SysWOW64\cfgmig32.exe [2011-10-5 263504] R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-9-8 7767552] R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-9-8 279040] R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\System32\drivers\HCW85BDA.sys [2009-7-14 1708800] R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-12-28 23152] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-8-20 239616] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-7 11856] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-3-16 136176] S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-3-16 136176] S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2011-8-19 351136] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-26 59392] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-10-21 1255736] . =============== Created Last 30 ================ . 2011-12-28 23:42:46 ——– d—–w- C:\Users\mancave\AppData\Local\{AC17BFA6-40D9-42A4-BB3F-370297F169D2} 2011-12-28 23:42:23 ——– d—–w- C:\Users\mancave\AppData\Local\{A8B9002F-5104-4840-902D-0F409605886B} 2011-12-28 21:04:53 ——– d—–w- C:\Users\mancave\AppData\Roaming\Malwarebytes 2011-12-28 21:04:45 ——– d—–w- C:\PROGRA~3\Malwarebytes 2011-12-28 21:04:44 23152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-12-28 21:04:44 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-12-28 16:41:05 ——– d—–w- C:\Windows\pss 2011-12-28 16:14:00 ——– d—–w- C:\PROGRA~3\Kaspersky Lab 2011-12-28 15:41:13 ——– d—–w- C:\Users\mancave\AppData\Roaming\SUPERAntiSpyware.com 2011-12-28 15:40:43 ——– d—–w- C:\Program Files\SUPERAntiSpyware 2011-12-28 15:40:43 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com 2011-12-28 11:41:54 ——– d—–w- C:\Users\mancave\AppData\Local\{4EFEF447-AAA2-4A1C-B01F-F5C54507145C} 2011-12-28 11:41:42 ——– d—–w- C:\Users\mancave\AppData\Local\{001E0760-96EF-4E28-9DD1-94C8997E8D18} 2011-12-28 01:58:00 ——– d—–w- C:\Users\mancave\AppData\Local\Ilivid Player 2011-12-28 01:57:29 ——– d—–w- C:\Program Files (x86)\iLivid 2011-12-28 01:57:21 ——– d—–w- C:\PROGRA~3\boost_interprocess 2011-12-28 01:57:20 ——– d—–w- C:\Program Files (x86)\Windows iLivid Toolbar 2011-12-28 01:57:07 ——– d—–w- C:\Users\mancave\AppData\Local\PackageAware 2011-12-27 16:22:26 ——– d—–w- C:\Users\mancave\AppData\Local\{3DF41A66-7DCD-46EE-8011-9D793D31BCB0} 2011-12-27 16:22:04 ——– d—–w- C:\Users\mancave\AppData\Local\{54FF883D-4C8A-463F-B58C-D5DCBC087B5B} 2011-12-27 14:26:51 ——– d—–w- C:\Users\mancave\AppData\Roaming\SupportSoft 2011-12-27 14:02:56 ——– d—–w- C:\Program Files (x86)\Common Files\supportsoft 2011-12-27 04:26:28 42672 —-a-w- C:\Windows\SysWow64\drivers\fsbts.sys 2011-12-27 04:21:36 ——– d—–w- C:\Users\mancave\AppData\Local\{67571A3A-1AD8-40B9-9C2A-E1B09D04FEA8} 2011-12-27 04:21:24 ——– d—–w- C:\Users\mancave\AppData\Local\{96713664-DB5C-449C-8293-15EA392F856D} 2011-12-27 03:42:20 ——– d—–w- C:\PROGRA~3\CPA_VA 2011-12-27 03:41:39 20080 —-a-w- C:\Windows\System32\drivers\EnumProcessesDriver.sys 2011-12-27 02:51:32 ——– d—–w- C:\MFT 11102 2011-12-27 02:50:56 ——– d—–w- C:\MFT 136293 2011-12-27 02:50:56 ——– d—–w- C:\MFT 11105 2011-12-26 16:21:00 ——– d—–w- C:\Users\mancave\AppData\Local\{482F7F49-D3FF-491F-8F66-7BAED10CD7D5} 2011-12-26 04:20:22 ——– d—–w- C:\Users\mancave\AppData\Local\{1EC23B6B-5050-492A-A1E2-2449C8D7B570} 2011-12-25 16:19:44 ——– d—–w- C:\Users\mancave\AppData\Local\{ECB08FBD-701B-4866-8EC7-E470F3F6A30A} 2011-12-25 04:19:06 ——– d—–w- C:\Users\mancave\AppData\Local\{D0D014B1-B282-4B4A-ACB5-664EB6E04E1C} 2011-12-25 04:18:43 ——– d—–w- C:\Users\mancave\AppData\Local\{F015DB43-0640-4546-87B9-BDF5A25B5AB9} 2011-12-24 20:08:53 544768 —-a-w- C:\Windows\SysWow64\wbocx.ocx 2011-12-24 20:08:52 56496 —-a-w- C:\Windows\SysWow64\wbhelp2.dll 2011-12-24 20:08:52 4608 —-a-w- C:\Windows\SysWow64\W95INF32.DLL 2011-12-24 20:08:52 33968 —-a-w- C:\Windows\SysWow64\anim.dll 2011-12-24 20:08:52 2272 —-a-w- C:\Windows\SysWow64\W95INF16.DLL 2011-12-24 20:08:52 ——– d—–w- C:\Program Files (x86)\WinUtilities 2011-12-24 19:37:39 ——– d—–w- C:\Windows\Hewlett-Packard 2011-12-24 16:18:18 ——– d—–w- C:\Users\mancave\AppData\Local\{CBDCF220-DB6F-449D-BF12-6485BBFBDC0E} 2011-12-24 04:17:36 ——– d—–w- C:\Users\mancave\AppData\Local\{8A487720-F183-46C7-95F4-35D6052FE84A} 2011-12-24 04:17:24 ——– d—–w- C:\Users\mancave\AppData\Local\{C7FB5EC2-ED9C-4852-936D-E2C394E4E3FF} 2011-12-23 16:14:54 ——– d—–w- C:\Users\mancave\AppData\Local\{6CEE67B3-4882-4FBD-B701-A39437E5EF70} 2011-12-23 16:14:32 ——– d—–w- C:\Users\mancave\AppData\Local\{523211D7-B422-4270-AD1F-8E78EE9C5EF2} 2011-12-23 04:14:03 ——– d—–w- C:\Users\mancave\AppData\Local\{82C2CB2D-9717-4FB4-A861-1479B7A96E12} 2011-12-23 04:13:51 ——– d—–w- C:\Users\mancave\AppData\Local\{B1B6A2F4-4BF1-4404-A1D6-C8391FC9B3EC} 2011-12-23 01:38:42 27632 —-a-w- C:\Windows\SysWow64\Ctl3dv2.dll 2011-12-23 01:38:40 ——– d—–w- C:\Program Files (x86)\SimpleOCR 2011-12-23 00:42:58 98304 —-a-w- C:\Windows\SysWow64\redmonnt.dll 2011-12-22 00:59:18 737072 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2011-12-22 00:59:03 4283672 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2011-12-22 00:58:28 539984 —-a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2011-12-21 08:46:27 ——– d—–w- C:\Users\mancave\AppData\Local\{65C0A0B9-2E68-4F92-922D-D3975B9F5385} 2011-12-21 08:46:04 ——– d—–w- C:\Users\mancave\AppData\Local\{C0CAD2AB-DA2D-4872-814C-4C0B2FC1B1CE} 2011-12-20 20:45:38 ——– d—–w- C:\Users\mancave\AppData\Local\{30B701B7-0106-45D2-B3AE-355E7DF8BFBF} 2011-12-20 08:45:00 ——– d—–w- C:\Users\mancave\AppData\Local\{08430D5F-74FA-4F37-8CB5-00174D0C401E} 2011-12-19 20:44:25 ——– d—–w- C:\Users\mancave\AppData\Local\{D7B4E90D-F505-4479-9B14-4398EB5E0958} 2011-12-19 08:43:47 ——– d—–w- C:\Users\mancave\AppData\Local\{AFE7472E-104C-4526-8692-8EDD5D6BC17F} 2011-12-18 20:43:09 ——– d—–w- C:\Users\mancave\AppData\Local\{F1980CED-ADCB-42B2-BD33-804B86D50FA7} 2011-12-18 20:42:47 ——– d—–w- C:\Users\mancave\AppData\Local\{4FDB7BD4-6894-4E7E-ADA8-8FFBDEFB0933} 2011-12-18 08:42:19 ——– d—–w- C:\Users\mancave\AppData\Local\{A5E17B00-B199-46B8-AAF6-259090F3A436} 2011-12-18 08:41:57 ——– d—–w- C:\Users\mancave\AppData\Local\{48031767-67ED-46D5-A6A1-87A1E1CBD93B} 2011-12-17 20:41:32 ——– d—–w- C:\Users\mancave\AppData\Local\{2BA1B3B0-76CC-48F6-88FE-BF75E6923AE8} 2011-12-17 08:40:57 ——– d—–w- C:\Users\mancave\AppData\Local\{342AB1B9-08C2-40ED-9472-97207D93AF05} 2011-12-16 20:40:23 ——– d—–w- C:\Users\mancave\AppData\Local\{099643CB-D364-4484-9990-6C8075A44196} 2011-12-16 08:39:32 ——– d—–w- C:\Users\mancave\AppData\Local\{596BF8B6-9012-4A00-B6E6-E9C8F2AEFDCE} 2011-12-15 20:39:09 ——– d—–w- C:\Users\mancave\AppData\Local\{3DA0488D-F367-499B-99A1-6B87C54D0890} 2011-12-15 08:38:30 ——– d—–w- C:\Users\mancave\AppData\Local\{3C57B61E-F07A-4FC5-98A7-CBAB3084B0BB} 2011-12-15 08:38:18 ——– d—–w- C:\Users\mancave\AppData\Local\{2E0D22EE-AAEE-459C-8F02-5A278A04D20D} 2011-12-14 18:37:38 43520 —-a-w- C:\Windows\System32\csrsrv.dll 2011-12-14 18:37:35 3145216 —-a-w- C:\Windows\System32\win32k.sys 2011-12-14 18:37:34 723456 —-a-w- C:\Windows\System32\EncDec.dll 2011-12-14 18:37:33 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll 2011-12-14 18:37:20 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2011-12-14 18:37:20 2048 —-a-w- C:\Windows\System32\tzres.dll 2011-12-13 09:58:15 ——– d—–w- C:\Users\mancave\AppData\Local\{D99CA7F8-D152-4BA1-9F90-1BF05A86D9C3} 2011-12-12 21:57:41 ——– d—–w- C:\Users\mancave\AppData\Local\{F35BC6D3-0144-46FF-9C3F-1362D51ABC52} 2011-12-12 09:57:07 ——– d—–w- C:\Users\mancave\AppData\Local\{55530036-88D5-40CE-BEC1-84745E9F95DB} 2011-12-11 21:56:32 ——– d—–w- C:\Users\mancave\AppData\Local\{75E9D81E-ACB7-4232-91FA-CF24AF78FE15} 2011-12-11 09:55:56 ——– d—–w- C:\Users\mancave\AppData\Local\{E5637781-5DF4-4494-AD15-242378038D01} 2011-12-10 21:55:21 ——– d—–w- C:\Users\mancave\AppData\Local\{54C8ADA5-C20C-4765-911A-A1EC84C7635C} 2011-12-10 09:54:46 ——– d—–w- C:\Users\mancave\AppData\Local\{BA35E365-A008-462B-8EA4-64FE8590CE1F} 2011-12-09 21:54:12 ——– d—–w- C:\Users\mancave\AppData\Local\{02A0BF2C-B122-488B-8B9D-0EEA0C8A5ED3} 2011-12-09 09:53:38 ——– d—–w- C:\Users\mancave\AppData\Local\{04ED5A33-633C-4955-A3ED-ABD5F432DEE6} 2011-12-08 21:53:03 ——– d—–w- C:\Users\mancave\AppData\Local\{0AD34A8C-CD6A-4059-A0C8-91398DBB12A6} 2011-12-08 09:52:25 ——– d—–w- C:\Users\mancave\AppData\Local\{31C0CE3A-73D1-4F22-9482-CD2D741DF5AD} 2011-12-08 09:52:03 ——– d—–w- C:\Users\mancave\AppData\Local\{EC6A4830-D978-47AA-8A4A-6D56B7D72803} 2011-12-07 21:51:21 ——– d—–w- C:\Users\mancave\AppData\Local\{22543F89-E660-4B7E-9CA0-1C3195AE1116} 2011-12-07 21:51:09 ——– d—–w- C:\Users\mancave\AppData\Local\{08BE951A-3E92-4281-9C5B-EF70CF6D646A} 2011-12-06 17:00:09 ——– d—–w- C:\Users\mancave\AppData\Local\{EA660AFE-4EE2-4A96-9E58-05E7B91406DE} 2011-12-06 04:59:34 ——– d—–w- C:\Users\mancave\AppData\Local\{BE7049AB-8C91-4FC9-9609-830B747ACBBC} 2011-12-05 16:58:55 ——– d—–w- C:\Users\mancave\AppData\Local\{B62627DC-631B-42CE-9067-75BAC3A33AB8} 2011-12-05 16:58:44 ——– d—–w- C:\Users\mancave\AppData\Local\{ADAD716E-63E8-4EE9-ACE3-C0BCC592DAB9} 2011-12-04 12:44:23 ——– d—–w- C:\Users\mancave\AppData\Local\{3B9D44C4-1A3B-4E0A-A45B-CD62A61B2E2E} 2011-12-04 00:43:48 ——– d—–w- C:\Users\mancave\AppData\Local\{82DD6D35-3696-4BFE-8EB6-E569A875D4B8} 2011-12-03 12:43:11 ——– d—–w- C:\Users\mancave\AppData\Local\{B5887E55-0F10-4AAE-B3B2-A1DF5B1FAB26} 2011-12-03 00:42:33 ——– d—–w- C:\Users\mancave\AppData\Local\{9A195DF5-92FC-4FD0-9012-6E53497A0E27} 2011-12-03 00:42:10 ——– d—–w- C:\Users\mancave\AppData\Local\{C657522A-846F-47CE-B1DF-E849C93E9377} 2011-12-02 21:09:51 388096 —-a-r- C:\Users\mancave\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-12-02 21:09:51 ——– d—–w- C:\Program Files (x86)\Trend Micro 2011-12-02 12:41:45 ——– d—–w- C:\Users\mancave\AppData\Local\{BEF3C7B6-B9BE-4D99-B18D-39D6F21F15F3} 2011-12-02 00:41:08 ——– d—–w- C:\Users\mancave\AppData\Local\{6E2BA165-7359-437A-9FAB-0D487A224643} 2011-12-01 12:40:30 ——– d—–w- C:\Users\mancave\AppData\Local\{82710450-9FF9-404F-9D44-69C4D0E98350} 2011-12-01 00:39:55 ——– d—–w- C:\Users\mancave\AppData\Local\{A89E19E0-950B-4A8E-A9D4-94BD632BD3E7} 2011-12-01 00:39:42 ——– d—–w- C:\Users\mancave\AppData\Local\{3A2A500F-A4CC-4582-BA92-C0CA434DDE71} . ==================== Find3M ==================== . 2011-12-19 18:59:17 43248 —-a-w- C:\Windows\System32\drivers\cmdhlp.sys 2011-12-19 18:59:16 577824 —-a-w- C:\Windows\System32\drivers\cmdGuard.sys 2011-12-19 18:59:15 22696 —-a-w- C:\Windows\System32\drivers\cmderd.sys 2011-12-19 18:58:57 41200 —-a-w- C:\Windows\System32\cmdcsr.dll 2011-12-19 18:58:55 301224 —-a-w- C:\Windows\SysWow64\guard32.dll 2011-12-19 18:58:54 389840 —-a-w- C:\Windows\System32\guard64.dll 2011-12-15 12:25:55 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-26 18:33:44 644400 —-a-w- C:\Windows\SysWow64\mscomct2.ocx 2011-11-10 10:54:13 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-11-04 01:53:39 2309120 —-a-w- C:\Windows\System32\jscript9.dll 2011-11-04 01:44:47 1390080 —-a-w- C:\Windows\System32\wininet.dll 2011-11-04 01:44:21 1493504 —-a-w- C:\Windows\System32\inetcpl.cpl 2011-11-04 01:34:43 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2011-11-03 22:47:42 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll 2011-11-03 22:40:21 1427456 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2011-11-03 22:39:47 1127424 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-11-03 22:31:57 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-10-05 07:07:28 2524176 —-a-w- C:\Windows\System32\winsflt.dll 2011-10-05 07:07:28 1744912 —-a-w- C:\Windows\SysWow64\winsflt.dll 2011-10-05 07:06:19 1422672 —-a-w- C:\Windows\SysWow64\cfgmig32.dll 2011-10-05 07:06:19 1422672 —-a-w- C:\Windows\System32\cfgmig32.dll 2011-10-05 07:06:18 263504 —-a-w- C:\Windows\SysWow64\cfgmig32.exe 2011-10-05 07:06:13 95568 —-a-w- C:\Windows\System32\vetredir.dll 2011-10-05 07:06:13 141136 —-a-w- C:\Windows\System32\isafeif64.dll 2011-10-05 07:06:13 128336 —-a-w- C:\Windows\System32\isafeif.dll 2011-10-05 07:06:13 103760 —-a-w- C:\Windows\System32\vetredir64.dll . ============= FINISH: 20:10:57.44 ===============
Hi bigbo5678,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

I see you have multiple antivirus software installed. You should only be running one antivirus software at any given time to avoid conflicts and system slow downs. Please uninstall either CA Antivirus or Comodo Antivirus.

===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
===================================================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI