This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus issue [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, i believe this computer is infected, It is my sisters computer so i am trying to fix it for her. I notice that when i run firefox, there is a plugin.exe that uses up physical memory up into the 700k range which obvously would cause Firefox to stall. My sister has told me that she has problems running video's on the computer, the computer would freeze. I do happen to know there are a few infections, just running some of my tools on the pc found a few threats. MSE also detected a threat just now as i write this.

Details of the threat is "Exploit:java/CVE-2008-5353.Zn" Status sever, i just cleaned it just now as it prompt me to. I have a few logs that i want to post. First my DDS log of course

I ran a ESET scanner as well and it found one threat. Being the "windows 7 codec pack" which i find that hard to believe but never less it located it as a threat. I also ran antimalware, it found 1 threat, i will post that log as well.

The last scanner i ran was Gmer and i will post that log to. I noticed that the "firefox plugin.exe" appeared on the maleware log.

Anyways i realize that i am not supposed to jump the gun here, but i have done what i can to try and fix the issues on this pc, for now i will just post the logs i have and hopefully one of you guys can figure out the rest because the computer is still having issues. One of the main issue is Adobe Flash player is crashing quite frequently and that is one of the plugins that is used for most video streaming on firefox.

Well here are the logs



DDS LOG

DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29
Run by [removed] at 23:51:04 on 2012-01-09
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.685 [GMT -8:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Firewall *Disabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CrossriderWebApps\Crossrider.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\ESET\ESET Online Scanner\OnlineScannerApp.exe
C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
C:\Windows\system32\conhost.exe
C:\Users\Ashley\Desktop\gmer\gmer.exe
C:\Windows\servicing\TrustedInstaller.exe
c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP
uURLSearchHooks: H - No File
mURLSearchHooks: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - c:\program files\zonealarm_security\prxtbZone.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - c:\program files\zonealarm_security\prxtbZone.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: IplexToALLPlayer: {df925ef3-7a87-44e4-9caf-8d7b280bf616} - c:\progra~1\opensu~1\iplex\IPLEXT~1.DLL
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: ZoneAlarm Security Toolbar: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - c:\program files\zonealarm_security\prxtbZone.dll
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
uRun: [CrossRiderPlugin] c:\program files\crossriderwebapps\Crossrider.exe
uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
uRun: [Xvid] c:\program files\xvid\CheckUpdate.exe
uRun: [ALLUpdate] "c:\program files\opensubtitlesplayer\ALLUpdate.exe" "sleep"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\users\ashley\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{B2774F38-E956-4A48-8A89-372D806B599C} : DhcpNameServer = 192.168.0.1 [removed]
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\ashley\appdata\roaming\mozilla\firefox\profiles\7em8o8q5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
.
—- FIREFOX POLICIES —-
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
============= SERVICES / DRIVERS ===============
.
R0 72481612;72481612 Boot Guard Driver;c:\windows\system32\drivers\72481612.sys [2011-6-29 37392]
R1 72481611;72481611;c:\windows\system32\drivers\72481611.sys [2011-6-29 128016]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648]
R1 MpKsl4f3797da;MpKsl4f3797da;c:\programdata\microsoft\microsoft antimalware\definition updates\{9aab4f9d-9ab2-4280-9ea4-58cbfb62245c}\MpKsl4f3797da.sys [2012-1-9 29904]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-6-29 1153368]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-6-20 15872]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-20 52224]
S3 utewntc4;AVZ Kernel Driver;c:\windows\system32\drivers\utewntc4.sys [2011-6-30 7168]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-4-29 1343400]
.
=============== Created Last 30 ================
.
2012-01-10 06:10:02 ——– d—–w- c:\windows\pss
2012-01-10 06:05:34 29904 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{9aab4f9d-9ab2-4280-9ea4-58cbfb62245c}\MpKsl4f3797da.sys
2012-01-10 06:05:32 56200 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{9aab4f9d-9ab2-4280-9ea4-58cbfb62245c}\offreg.dll
2012-01-10 01:21:57 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll
2012-01-10 01:21:57 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll
2012-01-10 01:21:57 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll
2012-01-10 01:21:57 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll
2012-01-09 08:19:22 6823496 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{9aab4f9d-9ab2-4280-9ea4-58cbfb62245c}\mpengine.dll
2011-12-16 21:45:25 539984 —-a-w- c:\programdata\microsoft\ehome\packages\mcespotlight\mcespotlight-2\SpotlightResources.dll
2011-12-14 05:51:04 3967856 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 05:51:04 3912560 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 05:45:49 2342912 —-a-w- c:\windows\system32\win32k.sys
2011-12-14 05:45:45 2048 —-a-w- c:\windows\system32\tzres.dll
2011-12-14 05:45:36 534528 —-a-w- c:\windows\system32\EncDec.dll
2011-12-14 05:43:59 38912 —-a-w- c:\windows\system32\csrsrv.dll
.
==================== Find3M ====================
.
2012-01-03 19:58:05 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-10 23:24:06 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-05 04:35:00 981504 —-a-w- c:\windows\system32\wininet.dll
2011-11-05 02:48:51 1638912 —-a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 23:51:36.29 ===============


MBAM Log




Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.10.02

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Ashley :: ASHLEY-PC [limited]

1/9/2012 10:42:07 PM
mbam-log-2012-01-09 (22-47-45).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213520
Time elapsed: 3 minute(s), 26 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\Ashley\Desktop\Codec-C.exe (Affiliate.Downloader) -> No action taken.

(end)


Gmer Log



GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-09 23:45:13
Windows 6.1.7601 Service Pack 1 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-2 WDC_WD1600AAJS-08PSA0 rev.05.06H05
Running: gmer.exe; Driver: C:\Users\Ashley\AppData\Local\Temp\uxdiqpod.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwAlpcConnectPort [0x8D901BBA]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwAlpcCreatePort [0x8D90248A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwConnectPort [0x8D901610]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0x8D8FAE42]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateKey [0x8D91C760]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreatePort [0x8D90211A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0x8D902278]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0x8D8FBB7E]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteKey [0x8D91E212]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0x8D91DB06]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey [0x8D91EBE0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0x8D91EE1E]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKeyEx [0x8D91F2D0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0x8D8FB730]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRenameKey [0x8D91FCB8]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0x8D91F59A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0x8D9011A4]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRestoreKey [0x8D92071E]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0x8D8FBF8A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSecurityObject [0x8D920242]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetValueKey [0x8D91D226]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKey + 13D1 8284F369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82888D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 8288FDB4 8 Bytes [BA, 1B, 90, 8D, 8A, 24, 90, …]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 8288FE48 4 Bytes [10, 16, 90, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11AF 8288FE64 4 Bytes [42, AE, 8F, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11BF 8288FE74 4 Bytes [60, C7, 91, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11DB 8288FE90 4 Bytes [1A, 21, 90, 8D]
.text …

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[724] ntdll.dll!LdrLoadDll 771F22B8 5 Bytes JMP 67E5B750 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2932] USER32.dll!SetWindowLongA 76DF8BA3 5 Bytes JMP 68233A89 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2932] USER32.dll!SetWindowLongW 76E04449 5 Bytes JMP 68233A1B C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2932] USER32.dll!GetWindowInfo 76E04B5E 5 Bytes JMP 67FDC909 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2932] USER32.dll!TrackPopupMenu 76E12228 5 Bytes JMP 67FDCEBD C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Real\RealPlayer\Update\realsched.exe[3068] kernel32.dll!SetUnhandledExceptionFilter 7597F4FB 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}

—- Devices - GMER 1.0.15 —-

Device \Driver\ACPI_HAL \Device\00000053 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-



Ok there ya go, i will wait for a reply, i plan on also changing this system to a 64 bit OS, because a 32 bit OS with 4 gb of ram installed is only using 2 gb, so its not using its full ram compacity. But i will do that after i clean the pc. I do not plan on formating, just reinstalling and upgrading windows.

Attachments:

Hi jeff matthews and welcome to WhatTheTech forums!
I'm Sunyata and I will be helping you with your computer problems.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.

Please read the following guidelines which will help to make cleaning your machine easier:

  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
  • Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
  • Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
  • PLEASE DO NOT install/uninstall any programs unless asked to.
  • PLEASE DO NOT run any malware scans other than those requested.
  • Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
  • I will reply back shortly with instructions

Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
Ok thank you very much, i will be waiting for your replies. This has been a continuous problem with this computer. No matter what type of protection i use, my sister always seems to some how get viruses or infections. She likes to go to alot of those streaming websites and im not entirely sure which ones are safe or not but i need a strong enough firewall that will prevent or at least bring up a message stating that this website may contain malicious code or something of that nature. I have used WOT, addblock+ with firefox and Zone alarm, coupled with MSE. Still with all that in affect, another month rolls by and she is infected again. its a constant issue. I almost need to have like some kind of monitoring system, like a spy bot that i can use my self that monitors which websites she visits and were these infections are coming from. That way i can completely block the sites on firefox and eliminate this problem all together. Would you happen to know of any program that can utilize that type of feature, i know there are some out their that people use. One of my friends says he uses some type of software that takes pictures of the computer and he can go back and look at what his little brother was using the internet for. But i do not want something like that, i don't want to invade some one's privacy, i just want to some how monitor the sites she goes to and find out exactly where the infections are coming from. One of the infections i noticed by looking at the logs is from "Zugo" what ever that is, the string was from bing.com. I may try a different firewall, cause i guess zone alarm is just not working. Maybe she is denying every update on the computer or allowing every intrusion, i really don't know. But that is what zone alarm does, is it gives you the ability to choose which sites to block or allow. Maybe i need something a little more strict, that will actually block harmful sites automatically, and you have no control over it unless you mess with the settings. Because honestly this is driving me nuts and she claims to me that i am horrible tech and can't fix the computer because it breaks down every time i go through these processes, her answer, is buy a new computer? lol Well its not the computer that is the problem, its the user. There is 4 user accounts on this machine, and every infection that i find is in her account, every time i try to repair the pc.
After this thread is all said and done, i will ask if you have any recommendations for any top of the line firewalls, payed or free. I don't care. I need the protection, its critical, because this machine has alot of important documents and stuff on it as well from other users accounts.
Hello jeff mathews

I recommend you remove your P2P programs

I noticed you have µTorrent installed. Strictly speaking, P2P programs are legal. However, the reality is that the most popular networks are a hotbed of theft and malware. If you use P2P software or allow it on your system:

  • You can have stolen intellectual property downloaded to your machine without your knowledge.
  • You can get in trouble with law enforcement because of that.
  • You can get sued by those seeking to protect their intellectual property rights because of that.
  • You all but guarantee that your machine gets infected with trojans, worms, and/or other malware.
  • You can get your identity stolen and compromise your online financial dealings because of that.
  • You can get inundated with adware because of that.
  • I strongly recommend that you remove this software from your system.
  • To do this, go to Control Panel > Add/Remove Programs and uninstall µTorrent.

Next,

Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.

    Vista and Windows 7 users right click the icon and choose "Run as administrator".

  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]

Ok yeah, we have used Utorrent in the past, but she hasn't used utorrent in a very long time. It has just been simply installed on this machine, i just never removed it from the pc. Is it possible still for viruses or maleware to get into the machine with it just simply being installed? That is a question I've always wanted to ask. Or do you actually have to use the program. Because last time i was on this site trying to get rid of infections, Utorrent has not been used since. So i doubt that could be whats causing these recent problems. But will see.


Here is the log file as you requested.



aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-12 20:23:38
—————————–
20:23:38.799 OS Version: Windows 6.1.7601 Service Pack 1
20:23:38.799 Number of processors: 2 586 0x4303
20:23:38.799 ComputerName: ASHLEY-PC UserName: Ashley
20:23:55.912 Initialize success
20:24:15.771 AVAST engine download error: 0
20:24:37.174 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2
20:24:37.174 Disk 0 Vendor: WDC_WD800JB-00JJC0 05.01C05 Size: 76318MB BusType: 3
20:24:37.174 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-4
20:24:37.174 Disk 1 Vendor: WDC_WD1600AAJS-08PSA0 05.06H05 Size: 152627MB BusType: 3
20:24:37.189 Disk 1 MBR read successfully
20:24:37.189 Disk 1 MBR scan
20:24:37.189 Disk 1 Windows 7 default MBR code
20:24:37.205 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
20:24:37.205 Disk 1 Partition 2 00 07 HPFS/NTFS NTFS 152525 MB offset 206848
20:24:37.205 Disk 1 scanning sectors +312578048
20:24:37.299 Disk 1 scanning C:\Windows\system32\drivers
20:24:44.381 Service scanning
20:24:46.721 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32
20:24:46.908 Service Vsdatant C:\Windows\system32\DRIVERS\vsdatant.sys **LOCKED** 32
20:24:47.454 Modules scanning
20:24:51.276 Disk 1 trace - called modules:
20:24:51.307 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
20:24:51.307 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x84870ac8]
20:24:51.307 3 CLASSPNP.SYS[87fbd59e] -> nt!IofCallDriver -> [0x843a9918]
20:24:51.323 5 ACPI.sys[87c3a3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0x843a1908]
20:24:51.323 Scan finished successfully
20:26:03.691 Disk 1 MBR has been saved successfully to "C:\Users\Ashley\Desktop\Virus Removal Tool1\MBR.dat"
20:26:03.691 The log file has been saved successfully to "C:\Users\Ashley\Desktop\Virus Removal Tool1\aswMBR.txt"
Hello jeff mathews

Your aswMBR scan looks good. Let's take a closer look at that codec file MBAM found and do a ComboFix scan.

Please scan the following file(s)
  • Please visit Virus Total by clicking here.
  • Click the Browse button and search for the following files (if present):
    • C:\Users\Ashley\Desktop\Codec-C.exe
  • Click Open.
  • Then click Send File.
  • Please be patient while the file is scanned.
  • If Virus Total tells you that the file has already been scanned, click "reanalyse now".
  • Once scanned, copy and paste the link to the results page in your next reply.

Next,

Please read through these instructions to familarize yourself with what to expect when this tool runs

Please download ComboFix from one of the following locations:

  • LINK 1
  • LINK 2
**IMPORTANT! Save ComboFix to your Desktop. Read the following thoroughly
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link :How to Disable your Security Programs
  • Double click on 'ComboFix.exe' & follow the prompts.
  • Allow it to scan your machine for malware.


When finished, it will produce a log for you.
Please include the contents of C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making Internet Explorer the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please let me know.
5. ComboFix disconnects your machine from the internet. The connection is automatically restored before ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


In your next reply please post the log created by ComboFix.


How is the machine behaving? Any issues?

Ok i was in safe mode before doing all this and i looked at the bottom of my taskbar and no antivirses were running. MSE was turned off comletly how ever combofix stated that there was still two conflicting firewalls so hopefully this log is fine. I wanted to say that before combofix ran, it came up with a message that stated that "Exploit:java/CVE-2008-5353.Zn" was a very dangerous exploit file and i think it removed it first before the regular scan even started.

Anyways here is my results link from total virus

https://www.virustotal.com/file/f2ce7378de0…sis/1326479236/


and here is my combofix log

ComboFix 12-01-13.03 - Ashley 01/13/2012 10:33:25.4.2 - x86 NETWORK
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.1407 [GMT -8:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
FW: ZoneAlarm Firewall *Enabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\QuestScan
c:\program files\Shop to Win 15
c:\users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\7em8o8q5.default\searchplugins\bing-zugo.xml
c:\users\Ashley\AppData\Roaming\vso_ts_preview.xml
.
.
((((((((((((((((((((((((( Files Created from 2011-12-13 to 2012-01-13 )))))))))))))))))))))))))))))))
.
.
2012-01-13 18:37 . 2012-01-13 18:37 ——– d—–w- c:\users\Ashley\AppData\Local\temp
2012-01-13 18:24 . 2012-01-13 18:24 56200 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3D422440-51D9-49A8-A90D-A9B3376E53A5}\offreg.dll
2012-01-13 01:18 . 2011-11-21 10:47 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3D422440-51D9-49A8-A90D-A9B3376E53A5}\mpengine.dll
2012-01-11 01:37 . 2011-11-17 05:38 1288472 —-a-w- c:\windows\system32\ntdll.dll
2012-01-11 01:36 . 2011-11-19 14:01 67072 —-a-w- c:\windows\system32\packager.dll
2012-01-11 01:36 . 2011-10-26 04:32 1328128 —-a-w- c:\windows\system32\quartz.dll
2012-01-11 01:36 . 2011-10-26 04:32 514560 —-a-w- c:\windows\system32\qdvd.dll
2012-01-10 01:21 . 2012-01-10 01:21 626688 —-a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-10 01:21 . 2012-01-10 01:21 548864 —-a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-10 01:21 . 2012-01-10 01:21 479232 —-a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-10 01:21 . 2012-01-10 01:21 43992 —-a-w- c:\program files\Mozilla Firefox\mozutils.dll
2011-12-16 21:45 . 2011-12-16 21:45 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-03 19:58 . 2011-05-19 16:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-10 23:24 . 2011-06-29 18:58 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-24 04:25 . 2011-12-14 05:45 2342912 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 10:47 . 2011-04-29 02:31 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-05 04:35 . 2011-12-14 06:18 981504 —-a-w- c:\windows\system32\wininet.dll
2011-11-05 04:26 . 2011-12-14 05:45 2048 —-a-w- c:\windows\system32\tzres.dll
2011-11-05 02:48 . 2011-12-14 06:18 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-10-26 04:47 . 2011-12-14 05:51 3967856 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-26 04:47 . 2011-12-14 05:51 3912560 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-26 04:28 . 2011-12-14 05:43 38912 —-a-w- c:\windows\system32\csrsrv.dll
2012-01-10 01:21 . 2011-08-03 07:33 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
2011-03-28 16:22 176936 —-a-w- c:\program files\ZoneAlarm_Security\prxtbZone.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"CrossRiderPlugin"="c:\program files\CrossriderWebApps\Crossrider.exe" [2011-05-15 478720]
"Xvid"="c:\program files\Xvid\CheckUpdate.exe" [2011-01-17 8192]
"ALLUpdate"="c:\program files\OpenSubtitlesPlayer\ALLUpdate.exe" [2011-08-17 1064448]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 1808784]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-12-25 981680]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-18 1043968]
"TkBellExe"="c:\program files\Real\RealPlayer\Update\realsched.exe" [2011-09-20 273528]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\users\Chuck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\users\Kristi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 72481611;72481611;c:\windows\system32\DRIVERS\72481611.sys [2009-09-26 128016]
R1 MpKsl7a01961b;MpKsl7a01961b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C033A27C-0C20-41DC-BF1D-9A177AD6CF9F}\MpKsl7a01961b.sys [x]
R1 MpKsl8478b0f0;MpKsl8478b0f0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{62854255-3EDB-478A-82FF-ED92D16A397A}\MpKsl8478b0f0.sys [x]
R1 MpKsla61174da;MpKsla61174da;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0382905C-9D84-4647-AF68-3C55B1C5A1A1}\MpKsla61174da.sys [x]
R1 MpKslbce87479;MpKslbce87479;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{016F7C81-E4BB-4E7D-BE00-26D5079FF49F}\MpKslbce87479.sys [x]
R1 MpKslcf3a2cb7;MpKslcf3a2cb7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D3C768B4-5E20-40A4-A623-1E4669B1264C}\MpKslcf3a2cb7.sys [x]
R1 MpKsle07eb13f;MpKsle07eb13f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D40D2A58-B1A5-4ECE-8C9C-39526D01A169}\MpKsle07eb13f.sys [x]
R1 MpKslf294ff7a;MpKslf294ff7a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{28BB3497-8CCC-4B60-971A-AB0850EFB40F}\MpKslf294ff7a.sys [x]
R1 MpKslff998a3b;MpKslff998a3b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{746FADB5-DE36-4D36-984C-EEDF34C5B5BD}\MpKslff998a3b.sys [x]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 utewntc4;AVZ Kernel Driver;c:\windows\system32\Drivers\utewntc4.sys [2011-06-30 7168]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-29 1343400]
S0 72481612;72481612 Boot Guard Driver;c:\windows\system32\DRIVERS\72481612.sys [2009-10-22 37392]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390664944-2205315937-618608627-1000Core.job
- c:\users\Ashley\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-13 06:39]
.
2012-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390664944-2205315937-618608627-1000UA.job
- c:\users\Ashley\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-13 06:39]
.
2012-01-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3390664944-2205315937-618608627-1000.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 22:22]
.
2012-01-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3390664944-2205315937-618608627-1001.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 22:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP
TCP: DhcpNameServer = 192.168.0.1 [removed]
FF - ProfilePath - c:\users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\7em8o8q5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
HKCU-Run-VeohPlugin - c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-01-13 10:38:29
ComboFix-quarantined-files.txt 2012-01-13 18:38
ComboFix2.txt 2011-07-04 14:28
.
Pre-Run: 110,681,243,648 bytes free
Post-Run: 110,806,536,192 bytes free
.
- - End Of File - - DC377F903244518669572DE6D08E282B


One other thing i wanted to add was my sister just recently went on my laptop, went to two sites

http://www.videoob.com

http://www.videozer.com

Immediately every video she tried to stream there after said "missing plugin" so i did a system restore on my laptop, everything was fine. So evidently one of those two sites that i caught her using is infectious in some way.





Now if would really help me if when you look through these logs, if you can pinpoint exactly where these files are hooked to. The exploit file in paticular because that one looks like a very dangerous file.
Oops i made one slight error, forgot to uninstall Utorrent, i am just letting you know that i just now did that. I also properly disabled my antiviruses again so let me know if you want me to re scan with combofix for a new log.
Well apparently its stating that they are still enabled. When i obvously disabled them this time around. But i dont want to scan twice cause it can cause registry failures.
Hello jeff mathews

The file you uploaded only got flagged by 3 out of 41 virus scanners. I would doubt there is any real problem with it. You could rename it and see if that breaks an audio/vid application that you (or your sister) really like. Then rename it back if it does. It looks to be used by Quicktime.

Exploit:java/CVE-2008-5353.Zn - This is just a warning that there is an exploit in the old java. Nothing on your machine indicates that you have such a problem. Just keep your Java updated. It looks like yours is pretty current: java 6.29. The latest is 6.30.

For your Firefox memory problems associated with "plugin.exe," I think you mean "plugin-container.exe." Firefox uses this program to keep a/v plugins from messing up the rest of your Firefox browsing experience. Of course if it uses up all your machine's memory, it'll mess up everything you try to run :) The only Firefox plugins I see that might be loaded by plugin-container.exe are for RealPlayer. You may want to try and update that plugin to see if it helps or maybe run it from a different browser.

In your first post, you asked about your anti-malware defenses. The ones you have are good: Microsoft Security Essentials, ZoneAlarm, WOT - this is fabulous compared to most of what we see here every day. I suspect that whatever gets by these programs is just "invited" on your box by risky behavior. If you just click past warnings that pop up in MSE, ZoneAlarm or WOT, or you use P2P programs, you could be asking for trouble.

As it stands, there is not much I see on your machine. We have a few more scans to run to make sure. Next up is a ComfoFix fix:

Create and Run a CFScript:
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

DDS::
uURLSearchHooks: H - No File
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
R0 72481612;72481612 Boot Guard Driver;c:\windows\system32\drivers\72481612.sys [2011-6-29 37392]
R1 72481611;72481611;c:\windows\system32\drivers\72481611.sys [2011-6-29 128016]

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

[external image: Posted Image]

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Ok here is the log


ComboFix 12-01-13.05 - Ashley 01/13/2012 18:31:06.6.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.1288 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Ashley\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
FW: ZoneAlarm Firewall *Disabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-12-14 to 2012-01-14 )))))))))))))))))))))))))))))))
.
.
2012-01-14 02:35 . 2012-01-14 02:35 ——– d—–w- c:\users\Public\AppData\Local\temp
2012-01-14 02:35 . 2012-01-14 02:35 ——– d—–w- c:\users\Kristi\AppData\Local\temp
2012-01-14 02:35 . 2012-01-14 02:35 ——– d—–w- c:\users\Guest\AppData\Local\temp
2012-01-14 02:35 . 2012-01-14 02:35 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-01-14 02:35 . 2012-01-14 02:35 ——– d—–w- c:\users\Chuck\AppData\Local\temp
2012-01-14 02:24 . 2012-01-14 02:24 56200 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3D422440-51D9-49A8-A90D-A9B3376E53A5}\offreg.dll
2012-01-13 18:38 . 2012-01-14 02:35 ——– d—–w- c:\users\Ashley\AppData\Local\temp
2012-01-13 01:18 . 2011-11-21 10:47 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3D422440-51D9-49A8-A90D-A9B3376E53A5}\mpengine.dll
2012-01-11 01:37 . 2011-11-17 05:38 1288472 —-a-w- c:\windows\system32\ntdll.dll
2012-01-11 01:36 . 2011-11-19 14:01 67072 —-a-w- c:\windows\system32\packager.dll
2012-01-11 01:36 . 2011-10-26 04:32 1328128 —-a-w- c:\windows\system32\quartz.dll
2012-01-11 01:36 . 2011-10-26 04:32 514560 —-a-w- c:\windows\system32\qdvd.dll
2012-01-10 01:21 . 2012-01-10 01:21 626688 —-a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2012-01-10 01:21 . 2012-01-10 01:21 548864 —-a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2012-01-10 01:21 . 2012-01-10 01:21 479232 —-a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2012-01-10 01:21 . 2012-01-10 01:21 43992 —-a-w- c:\program files\Mozilla Firefox\mozutils.dll
2011-12-16 21:45 . 2011-12-16 21:45 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-03 19:58 . 2011-05-19 16:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-10 23:24 . 2011-06-29 18:58 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-24 04:25 . 2011-12-14 05:45 2342912 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 10:47 . 2011-04-29 02:31 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-05 04:35 . 2011-12-14 06:18 981504 —-a-w- c:\windows\system32\wininet.dll
2011-11-05 04:26 . 2011-12-14 05:45 2048 —-a-w- c:\windows\system32\tzres.dll
2011-11-05 02:48 . 2011-12-14 06:18 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-10-26 04:47 . 2011-12-14 05:51 3967856 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-26 04:47 . 2011-12-14 05:51 3912560 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-26 04:28 . 2011-12-14 05:43 38912 —-a-w- c:\windows\system32\csrsrv.dll
2012-01-10 01:21 . 2011-08-03 07:33 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
2011-03-28 16:22 176936 —-a-w- c:\program files\ZoneAlarm_Security\prxtbZone.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"CrossRiderPlugin"="c:\program files\CrossriderWebApps\Crossrider.exe" [2011-05-15 478720]
"Xvid"="c:\program files\Xvid\CheckUpdate.exe" [2011-01-17 8192]
"ALLUpdate"="c:\program files\OpenSubtitlesPlayer\ALLUpdate.exe" [2011-08-17 1064448]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 1808784]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-12-25 981680]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-18 1043968]
"TkBellExe"="c:\program files\Real\RealPlayer\Update\realsched.exe" [2011-09-20 273528]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\users\Chuck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\users\Kristi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 MpKsl7a01961b;MpKsl7a01961b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C033A27C-0C20-41DC-BF1D-9A177AD6CF9F}\MpKsl7a01961b.sys [x]
R1 MpKsl8478b0f0;MpKsl8478b0f0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{62854255-3EDB-478A-82FF-ED92D16A397A}\MpKsl8478b0f0.sys [x]
R1 MpKsla61174da;MpKsla61174da;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0382905C-9D84-4647-AF68-3C55B1C5A1A1}\MpKsla61174da.sys [x]
R1 MpKslbce87479;MpKslbce87479;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{016F7C81-E4BB-4E7D-BE00-26D5079FF49F}\MpKslbce87479.sys [x]
R1 MpKslcf3a2cb7;MpKslcf3a2cb7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D3C768B4-5E20-40A4-A623-1E4669B1264C}\MpKslcf3a2cb7.sys [x]
R1 MpKsle07eb13f;MpKsle07eb13f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D40D2A58-B1A5-4ECE-8C9C-39526D01A169}\MpKsle07eb13f.sys [x]
R1 MpKslf294ff7a;MpKslf294ff7a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{28BB3497-8CCC-4B60-971A-AB0850EFB40F}\MpKslf294ff7a.sys [x]
R1 MpKslff998a3b;MpKslff998a3b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{746FADB5-DE36-4D36-984C-EEDF34C5B5BD}\MpKslff998a3b.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 utewntc4;AVZ Kernel Driver;c:\windows\system32\Drivers\utewntc4.sys [2011-06-30 7168]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-29 1343400]
S0 72481612;72481612 Boot Guard Driver;c:\windows\system32\DRIVERS\72481612.sys [2009-10-22 37392]
S1 72481611;72481611;c:\windows\system32\DRIVERS\72481611.sys [2009-09-26 128016]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390664944-2205315937-618608627-1000Core.job
- c:\users\Ashley\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-13 06:39]
.
2012-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390664944-2205315937-618608627-1000UA.job
- c:\users\Ashley\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-13 06:39]
.
2012-01-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3390664944-2205315937-618608627-1000.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 22:22]
.
2012-01-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3390664944-2205315937-618608627-1001.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-08-11 22:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP
TCP: DhcpNameServer = 192.168.0.1 [removed]
FF - ProfilePath - c:\users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\7em8o8q5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q=
FF - user.js: keyword.enabled - 1
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-01-13 18:36:21
ComboFix-quarantined-files.txt 2012-01-14 02:36
ComboFix2.txt 2012-01-13 19:11
ComboFix3.txt 2012-01-13 18:38
ComboFix4.txt 2011-07-04 14:28
.
Pre-Run: 110,843,703,296 bytes free
Post-Run: 110,794,469,376 bytes free
.
- - End Of File - - EB5399350A663CABD4C5D53D9B27F08F


I just want to make note that each time i run combofix. It says "this registry key has been locked for deleted" or something like that and it does that to every single program i try to run, even the firefox. I have to reboot the pc in order to fix the issue.

Which file are you referring to that got flagged? Can you elaborate a little bit.

Ok so the exploit your saying is just an out of date java, ok ill just update java and see if that fixes it. How ever ive had out of date java's on the machine before and this is the first time my scanner picked something like that.


Ahh i see, so the "plugin-container" process is a normal process that just uses plugins from firefox. So what if i removed realplayer? That would probably solve the problem then huh?

So let me ask you, what infections files did we actually remove that may of caused problems with video streaming and or sites stalling.
Hello jeff mathews


I just want to make note that each time i run combofix. It says "this registry key has been locked for deleted" or something like that and it does that to every single program i try to run, even the firefox. I have to reboot the pc in order to fix the issue.

The "Illegal operation attempted on a registry key that has been marked for deletion" is a common bug that appears after a ComboFix run. But you already found the fix for it: reboot the computer!

Which file are you referring to that got flagged? Can you elaborate a little bit.

The flagged file is the file you uploaded to Virus Total, C:\Users\Ashley\Desktop\Codec-C.exe
The link to the scan you posted ran that file against 41 different virus scanners. Only 3 of them "flagged" it as malware.

Ok so the exploit your saying is just an out of date java, ok ill just update java and see if that fixes it. How ever ive had out of date java's on the machine before and this is the first time my scanner picked something like that.

The Java warning is not a real problem, just yet. The warning is about a vulnerability to infection. Not a real infection. The Software Industry works together, somewhat, to discover these vulnerabilities before the bad guys do. This particular vulnerability in the Java Runtime Environment (JRE) has been found by Microsoft engineers. They have not even published any details about it yet, and they won't until the folks responsible for Java (Oracle) have fixed it. Just try to keep your Java up to date. The message will go away when they have a fixed version and you install it.

So let me ask you, what infections files did we actually remove that may of caused problems with video streaming and or sites stalling.

I think the streaming video problems you experience are because of the memory used by the RealPlayer plugins in your Firefox. I suggested trying to update the plugins might solve the problem. If you want to remove them, I think that might fix it too. Also you might just try restarting Firefox when you see problems or when it is using too much memory.



It seems that I did not format your Combofix code box correctly. My apologies. Let's try again please:

Create and Run a CFScript:
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

Driver::
72481612
72481611

DDS::
uURLSearchHooks: H - No File
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File

Firefox::
FF - ProfilePath - c:\users\ashley\appdata\roaming\mozilla\firefox\profiles\7em8o8q5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}

File::
c:\windows\system32\drivers\72481612.sys
c:\windows\system32\drivers\72481611.sys

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

[external image: Posted Image]

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Alrighty then, here is the log once again. It deleted just two driver files, what were those driver files for? ComboFix 12-01-13.05 - Ashley 01/14/2012 13:41:57.7.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2046.1341 [GMT -8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Ashley\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} FW: ZoneAlarm Firewall *Disabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\windows\system32\drivers\72481611.sys" "c:\windows\system32\drivers\72481612.sys" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\drivers\72481611.sys c:\windows\system32\drivers\72481612.sys . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Legacy_72481611 ——-\Legacy_72481612 ——-\Service_72481611 ——-\Service_72481612 . . ((((((((((((((((((((((((( Files Created from 2011-12-14 to 2012-01-14 ))))))))))))))))))))))))))))))) . . 2012-01-14 21:45 . 2012-01-14 21:47 ——– d—–w- c:\users\Ashley\AppData\Local\temp 2012-01-14 21:45 . 2012-01-14 21:45 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-01-14 21:45 . 2012-01-14 21:45 ——– d—–w- c:\users\Kristi\AppData\Local\temp 2012-01-14 21:45 . 2012-01-14 21:45 ——– d—–w- c:\users\Guest\AppData\Local\temp 2012-01-14 21:45 . 2012-01-14 21:45 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-01-14 21:45 . 2012-01-14 21:45 ——– d—–w- c:\users\Chuck\AppData\Local\temp 2012-01-14 03:02 . 2012-01-14 03:02 29904 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB5DF102-6E6C-41EC-9DD0-A800F65A66F5}\MpKsl77486b0b.sys 2012-01-14 03:02 . 2012-01-14 21:47 56200 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB5DF102-6E6C-41EC-9DD0-A800F65A66F5}\offreg.dll 2012-01-14 03:00 . 2011-11-21 10:47 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB5DF102-6E6C-41EC-9DD0-A800F65A66F5}\mpengine.dll 2012-01-14 02:57 . 2012-01-14 02:57 ——– d—–w- c:\program files\Common Files\Java 2012-01-14 02:57 . 2012-01-14 02:57 ——– d—–w- c:\program files\Java 2012-01-11 01:37 . 2011-11-17 05:38 1288472 —-a-w- c:\windows\system32\ntdll.dll 2012-01-11 01:36 . 2011-11-19 14:01 67072 —-a-w- c:\windows\system32\packager.dll 2012-01-11 01:36 . 2011-10-26 04:32 1328128 —-a-w- c:\windows\system32\quartz.dll 2012-01-11 01:36 . 2011-10-26 04:32 514560 —-a-w- c:\windows\system32\qdvd.dll 2012-01-10 01:21 . 2012-01-10 01:21 626688 —-a-w- c:\program files\Mozilla Firefox\msvcr80.dll 2012-01-10 01:21 . 2012-01-10 01:21 548864 —-a-w- c:\program files\Mozilla Firefox\msvcp80.dll 2012-01-10 01:21 . 2012-01-10 01:21 479232 —-a-w- c:\program files\Mozilla Firefox\msvcm80.dll 2012-01-10 01:21 . 2012-01-10 01:21 43992 —-a-w- c:\program files\Mozilla Firefox\mozutils.dll 2012-01-03 13:10 . 2012-01-03 13:10 182672 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll 2011-12-16 21:45 . 2011-12-16 21:45 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-01-14 02:57 . 2011-04-28 03:29 472808 —-a-w- c:\windows\system32\deployJava1.dll 2012-01-03 19:58 . 2011-05-19 16:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-12-10 23:24 . 2011-06-29 18:58 20464 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-24 04:25 . 2011-12-14 05:45 2342912 —-a-w- c:\windows\system32\win32k.sys 2011-11-21 10:47 . 2011-04-29 02:31 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-11-05 04:35 . 2011-12-14 06:18 981504 —-a-w- c:\windows\system32\wininet.dll 2011-11-05 04:26 . 2011-12-14 05:45 2048 —-a-w- c:\windows\system32\tzres.dll 2011-11-05 02:48 . 2011-12-14 06:18 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-10-26 04:47 . 2011-12-14 05:51 3967856 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-26 04:47 . 2011-12-14 05:51 3912560 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-26 04:28 . 2011-12-14 05:43 38912 —-a-w- c:\windows\system32\csrsrv.dll 2012-01-10 01:21 . 2011-08-03 07:33 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}] 2011-03-28 16:22 176936 —-a-w- c:\program files\ZoneAlarm_Security\prxtbZone.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936] . [HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{91DA5E8A-3318-4F8C-B67E-5964DE3AB546}"= "c:\program files\ZoneAlarm_Security\prxtbZone.dll" [2011-03-28 176936] . [HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704] "CrossRiderPlugin"="c:\program files\CrossriderWebApps\Crossrider.exe" [2011-05-15 478720] "Xvid"="c:\program files\Xvid\CheckUpdate.exe" [2011-01-17 8192] "ALLUpdate"="c:\program files\OpenSubtitlesPlayer\ALLUpdate.exe" [2011-08-17 1064448] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 1808784] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-12-25 981680] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-18 1043968] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] . c:\users\Chuck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . c:\users\Kristi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . c:\users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R1 MpKsl7a01961b;MpKsl7a01961b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C033A27C-0C20-41DC-BF1D-9A177AD6CF9F}\MpKsl7a01961b.sys [x] R1 MpKsl8478b0f0;MpKsl8478b0f0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{62854255-3EDB-478A-82FF-ED92D16A397A}\MpKsl8478b0f0.sys [x] R1 MpKsla61174da;MpKsla61174da;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0382905C-9D84-4647-AF68-3C55B1C5A1A1}\MpKsla61174da.sys [x] R1 MpKslbce87479;MpKslbce87479;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{016F7C81-E4BB-4E7D-BE00-26D5079FF49F}\MpKslbce87479.sys [x] R1 MpKslcf3a2cb7;MpKslcf3a2cb7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D3C768B4-5E20-40A4-A623-1E4669B1264C}\MpKslcf3a2cb7.sys [x] R1 MpKsle07eb13f;MpKsle07eb13f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D40D2A58-B1A5-4ECE-8C9C-39526D01A169}\MpKsle07eb13f.sys [x] R1 MpKslf294ff7a;MpKslf294ff7a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{28BB3497-8CCC-4B60-971A-AB0850EFB40F}\MpKslf294ff7a.sys [x] R1 MpKslff998a3b;MpKslff998a3b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{746FADB5-DE36-4D36-984C-EEDF34C5B5BD}\MpKslff998a3b.sys [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 utewntc4;AVZ Kernel Driver;c:\windows\system32\Drivers\utewntc4.sys [2011-06-30 7168] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-29 1343400] S1 MpKsl77486b0b;MpKsl77486b0b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB5DF102-6E6C-41EC-9DD0-A800F65A66F5}\MpKsl77486b0b.sys [2012-01-14 29904] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC . Contents of the 'Scheduled Tasks' folder . 2012-01-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390664944-2205315937-618608627-1000Core.job - c:\users\Ashley\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-13 06:39] . 2012-01-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3390664944-2205315937-618608627-1000UA.job - c:\users\Ashley\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-13 06:39] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP TCP: DhcpNameServer = 192.168.0.1 [removed] FF - ProfilePath - c:\users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\7em8o8q5.default\ FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q= FF - prefs.js: network.proxy.type - 0 FF - user.js: keyword.URL - hxxp://mp3tubetoolbar.com/?tmp=nemo_results_removelink2&q= FF - user.js: keyword.enabled - 1 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe c:\windows\system32\taskhost.exe c:\windows\system32\WUDFHost.exe c:\windows\system32\conhost.exe c:\program files\Microsoft IntelliPoint\dpupdchk.exe c:\program files\OpenOffice.org 3\program\soffice.exe c:\program files\OpenOffice.org 3\program\soffice.bin c:\windows\system32\sppsvc.exe . ************************************************************************** . Completion time: 2012-01-14 13:50:00 - machine was rebooted ComboFix-quarantined-files.txt 2012-01-14 21:50 ComboFix2.txt 2012-01-14 02:36 ComboFix3.txt 2012-01-13 19:11 ComboFix4.txt 2012-01-13 18:38 ComboFix5.txt 2012-01-14 21:41 . Pre-Run: 106,804,682,752 bytes free Post-Run: 106,639,847,424 bytes free . - - End Of File - - CD68D382B4574FA706EF0CCD5827AE1E So i guess thats it now huh? Is the computer completely clean?
Hello jeff mathews

It deleted just two driver files, what were those driver files for?

Those drivers were for Kaspersky's Free AV Tool. That tool is a one time deal. Every time you download and run it, it leaves a couple of useless drivers in your registry and file system.

Were in the final stretch now…

NOTE: When you run the MBAM scan below, be sure not to remove C:\Users\Ashley\Desktop\Codec-C.exe
Unless you have already determined you do not need it

Scan For Malware:

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked except C:\Users\Ashley\Desktop\Codec-C.exe, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.



Do An Online Scan For Viruses:

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
In your next reply please post the logs created by Malwarebytes and the ESET Online Scan.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI