This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32/Small.CA Virus [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thank you so much for helping me! Here's the DDS log: . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29 Run by [removed] at 12:13:54 on 2012-01-25 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.4023.2202 [GMT -8:00] . AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC} FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe C:\OEM\USBDECTION\USBS3S4Detection.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\CNAB3RPD.EXE C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files (x86)\Steam\Steam.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe C:\Program Files (x86)\Xfire\Xfire.exe C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUI.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe C:\Program Files (x86)\Xfire\Xfire.exe C:\Program Files (x86)\Xfire\xfire64.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Razer\DeathAdder\razertra.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\PROGRA~2\Java\jre6\bin\jp2launcher.exe C:\Program Files (x86)\Java\jre6\bin\java.exe C:\Windows\system32\conhost.exe C:\Windows\system32\taskeng.exe C:\Windows\splwow64.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=1009&m=sx2850&r=17360710f407p0448v1m5k46j1r42o uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent uRun: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe" uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized uRun: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s uRun: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe uRun: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Hotkey Utility] C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED mRun: [Gateway Photo Frame] C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe -A mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray StartupFolder: C:\Users\Jeff\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Xfire.lnk - C:\Program Files (x86)\Xfire\Xfire.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\CANONL~1.LNK - C:\Windows\System32\spool\drivers\x64\3\CNAB3LAD.EXE mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{475DBF2A-A864-4E4D-B8D1-73AABDF71136} : DhcpNameServer = 192.168.1.254 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO-X64: SkypeIEPluginBHO - No File BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun-x64: [Hotkey Utility] C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED mRun-x64: [Gateway Photo Frame] C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe -A mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun-x64: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray AppInit_DLLs-X64: C:\Windows\SysWOW64\guard32.dll . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\8vsmmb4b.default\ FF - prefs.js: browser.search.selectedEngine - AVG Secure Search FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cf6fbd5&v=6.103.018.001&i=23&tp=ab&iy=&ychte=ca&lng=en-US&q= FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Jeff\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . ============= SERVICES / DRIVERS =============== . R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys –> C:\Windows\system32\DRIVERS\cmdguard.sys [?] R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys –> C:\Windows\system32\DRIVERS\cmdhlp.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?] R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys –> C:\Windows\system32\drivers\aswMonFlt.sys [?] R2 Greg_Service;GRegService;C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe [2009-8-28 1150496] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-1-24 652872] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-10-8 1153368] R2 Updater Service;Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2010-3-22 243232] R2 USBS3S4Detection;USBS3S4Detection;C:\OEM\USBDECTION\USBS3S4Detection.exe [2010-3-22 76320] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atipmdag.sys –> C:\Windows\system32\DRIVERS\atipmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys –> C:\Windows\system32\drivers\AtihdW76.sys [?] R3 danewFltr;NewDeathAdder Mouse;C:\Windows\system32\drivers\danew.sys –> C:\Windows\system32\drivers\danew.sys [?] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 VKbms;Virtual HID Minidriver;C:\Windows\system32\DRIVERS\VKbms.sys –> C:\Windows\system32\DRIVERS\VKbms.sys [?] S2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2012-1-23 44768] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-28 135664] S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\system32\DRIVERS\ssudbus.sys –> C:\Windows\system32\DRIVERS\ssudbus.sys [?] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-28 135664] S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\system32\DRIVERS\ssudmdm.sys –> C:\Windows\system32\DRIVERS\ssudmdm.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] . =============== Created Last 30 ================ . 2012-01-25 19:58:27 ——– d—–w- C:\Users\Jeff\AppData\Local\{D7AA8494-436E-4989-8F79-9D8CC8586504} 2012-01-25 19:58:17 ——– d—–w- C:\Users\Jeff\AppData\Local\{7D10DA6A-A070-4C89-8C8B-1AAAFDD13288} 2012-01-25 19:23:40 ——– d-sh–w- C:\$RECYCLE.BIN 2012-01-25 02:08:33 ——– d—–w- C:\Program Files (x86)\ESET 2012-01-25 02:08:18 ——– d—–w- C:\Users\Jeff\AppData\Roaming\Malwarebytes 2012-01-25 02:08:05 ——– d—–w- C:\ProgramData\Malwarebytes 2012-01-25 02:08:04 23152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2012-01-25 02:08:04 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-01-25 00:57:15 8602168 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DF952423-C592-494F-B856-368367AC590A}\mpengine.dll 2012-01-24 19:18:45 ——– d—–w- C:\Users\Jeff\AppData\Local\{84DD7E88-0AA4-4B18-8DDC-232B49609D52} 2012-01-24 19:18:34 ——– d—–w- C:\Users\Jeff\AppData\Local\{376E6677-A11A-43F0-BA8E-ACBCF5ECF634} 2012-01-24 01:58:50 98816 —-a-w- C:\Windows\sed.exe 2012-01-24 01:58:50 518144 —-a-w- C:\Windows\SWREG.exe 2012-01-24 01:58:50 256000 —-a-w- C:\Windows\PEV.exe 2012-01-24 01:58:50 208896 —-a-w- C:\Windows\MBR.exe 2012-01-23 22:37:48 ——– d—–w- C:\Program Files (x86)\PCHealthDoc Unzip 2012-01-11 21:32:33 51504 —-a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\rmdll\Final\RandomMap.dll 2012-01-11 21:32:33 19248 —-a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\rmdll\Final\CLRBinder.dll 2012-01-11 21:32:33 13616 —-a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\rmdll\Final\RandomMapBinder.dll 2012-01-11 20:53:14 81998 —-a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\RockallDLL.dll 2012-01-11 20:53:12 746496 —-a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\granny2.dll 2012-01-11 20:53:09 139568 —-a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\eulax.dll 2012-01-11 20:53:07 173408 —-a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\pw32b.dll 2012-01-11 20:50:22 ——– d—–w- C:\Program Files (x86)\Microsoft Games 2012-01-10 21:40:59 1572864 —-a-w- C:\Windows\System32\quartz.dll 2012-01-10 21:40:58 514560 —-a-w- C:\Windows\SysWow64\qdvd.dll 2012-01-10 21:40:58 366592 —-a-w- C:\Windows\System32\qdvd.dll 2012-01-10 21:40:58 1328128 —-a-w- C:\Windows\SysWow64\quartz.dll 2012-01-10 21:40:54 1731920 —-a-w- C:\Windows\System32\ntdll.dll 2012-01-10 21:40:54 1292080 —-a-w- C:\Windows\SysWow64\ntdll.dll 2012-01-10 21:40:53 77312 —-a-w- C:\Windows\System32\packager.dll 2012-01-10 21:40:53 67072 —-a-w- C:\Windows\SysWow64\packager.dll 2012-01-06 18:07:29 ——– d—–w- C:\Users\Jeff\AppData\Roaming\Razer 2012-01-06 01:16:00 85504 —-a-w- C:\Windows\SysWow64\DeathAdder64.cpl 2012-01-06 01:15:54 6656 —-a-w- C:\Windows\System32\drivers\hidkmdf.sys 2012-01-06 01:15:54 13312 —-a-w- C:\Windows\System32\drivers\VKbms.sys 2012-01-06 01:15:52 12032 —-a-w- C:\Windows\System32\drivers\danew.sys 2012-01-04 09:23:21 626688 —-a-w- C:\Program Files (x86)\Mozilla Firefox\msvcr80.dll 2012-01-04 09:23:21 548864 —-a-w- C:\Program Files (x86)\Mozilla Firefox\msvcp80.dll 2012-01-04 09:23:21 479232 —-a-w- C:\Program Files (x86)\Mozilla Firefox\msvcm80.dll 2012-01-04 09:23:21 43992 —-a-w- C:\Program Files (x86)\Mozilla Firefox\mozutils.dll 2012-01-03 16:22:01 103864 —-a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll 2012-01-03 16:22:01 103864 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll 2012-01-03 00:26:24 ——– d—–w- C:\Program Files\iPod 2012-01-03 00:26:23 ——– d—–w- C:\Program Files\iTunes 2012-01-03 00:26:23 ——– d—–w- C:\Program Files (x86)\iTunes 2012-01-03 00:24:17 ——– d—–w- C:\Program Files\Bonjour 2012-01-03 00:24:17 ——– d—–w- C:\Program Files (x86)\Bonjour . ==================== Find3M ==================== . 2012-01-17 21:00:44 577824 —-a-w- C:\Windows\System32\drivers\cmdGuard.sys 2011-12-19 18:59:17 43248 —-a-w- C:\Windows\System32\drivers\cmdhlp.sys 2011-12-19 18:59:15 22696 —-a-w- C:\Windows\System32\drivers\cmderd.sys 2011-12-19 18:58:57 41200 —-a-w- C:\Windows\System32\cmdcsr.dll 2011-12-19 18:58:55 301224 —-a-w- C:\Windows\SysWow64\guard32.dll 2011-12-19 18:58:54 389840 —-a-w- C:\Windows\System32\guard64.dll 2011-12-15 04:39:42 42392 —-a-w- C:\Windows\SysWow64\xfcodec.dll 2011-12-15 04:39:42 28056 —-a-w- C:\Windows\System32\xfcodec64.dll 2011-11-28 18:01:25 41184 —-a-w- C:\Windows\avastSS.scr 2011-11-28 17:54:06 591192 —-a-w- C:\Windows\System32\drivers\aswSnx.sys 2011-11-28 17:52:11 66904 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2011-11-26 17:41:17 178800 —-a-w- C:\Windows\SysWow64\CmdLineExt_x64.dll 2011-11-24 15:36:57 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-24 04:52:09 3145216 —-a-w- C:\Windows\System32\win32k.sys 2011-11-19 21:38:40 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2011-11-17 06:49:14 95600 —-a-w- C:\Windows\System32\drivers\ksecdd.sys 2011-11-17 06:49:14 152432 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys 2011-11-17 06:44:43 459232 —-a-w- C:\Windows\System32\drivers\cng.sys 2011-11-17 06:35:28 395776 —-a-w- C:\Windows\System32\webio.dll 2011-11-17 06:35:26 29184 —-a-w- C:\Windows\System32\sspisrv.dll 2011-11-17 06:35:26 136192 —-a-w- C:\Windows\System32\sspicli.dll 2011-11-17 06:35:25 340992 —-a-w- C:\Windows\System32\schannel.dll 2011-11-17 06:35:25 28160 —-a-w- C:\Windows\System32\secur32.dll 2011-11-17 06:35:19 1447936 —-a-w- C:\Windows\System32\lsasrv.dll 2011-11-17 06:33:55 31232 —-a-w- C:\Windows\System32\lsass.exe 2011-11-17 05:35:02 314880 —-a-w- C:\Windows\SysWow64\webio.dll 2011-11-17 05:34:52 224768 —-a-w- C:\Windows\SysWow64\schannel.dll 2011-11-17 05:34:52 22016 —-a-w- C:\Windows\SysWow64\secur32.dll 2011-11-17 05:28:48 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll 2011-11-15 22:29:56 270720 ——w- C:\Windows\System32\MpSigStub.exe 2011-11-05 05:41:43 1188864 —-a-w- C:\Windows\System32\wininet.dll 2011-11-05 05:32:50 2048 —-a-w- C:\Windows\System32\tzres.dll 2011-11-05 04:35:00 981504 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-11-05 04:26:03 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2011-11-05 03:32:47 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2011-11-05 02:48:51 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb . ============= FINISH: 12:14:43.91 =============== Here's the Attach.txt: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 28/07/2010 7:59:32 PM System Uptime: 25/01/2012 11:28:44 AM (1 hours ago) . Motherboard: Gateway | | SX2850 Processor: Intel® Core™ i3 CPU 540 @ 3.07GHz | CPU 1 | 3067/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 918 GiB total, 549.509 GiB free. D: is CDROM () E: is Removable F: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318} Description: Microsoft PS/2 Mouse Device ID: ACPI\PNP0F03\4&153956B5&0 Manufacturer: Microsoft Name: Microsoft PS/2 Mouse PNP Device ID: ACPI\PNP0F03\4&153956B5&0 Service: i8042prt . ==== System Restore Points =================== . RP224: 11/01/2012 2:02:42 AM - Windows Update RP225: 11/01/2012 12:49:41 PM - Installed DirectX RP226: 11/01/2012 5:24:58 PM - Installed Microsoft Games for Windows - LIVE Redistributable RP227: 16/01/2012 12:42:17 AM - Windows Update RP228: 20/01/2012 10:23:19 AM - Windows Update RP229: 23/01/2012 5:58:55 PM - ComboFix created restore point RP230: 24/01/2012 4:56:51 PM - Windows Update . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) 2007 Microsoft Office Suite Service Pack 2 (SP2) Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Reader 9.5.0 MUI Advertising Center Age of Empires Online Aliens vs. Predator Apple Application Support Apple Software Update ATI Catalyst Registration avast! Free Antivirus BitTorrent Call of Duty: Black Ops Call of Duty: Black Ops - Multiplayer Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy ccc-core-static CCC Help English Cockatrice Compatibility Pack for the 2007 Office system Counter-Strike: Source CyberLink PowerDVD 9 D3DX10 eBay Worldwide ESET Online Scanner v3 Gateway InfoCentre Gateway Photo Frame [removed] Gateway Recovery Management Gateway Registration Gateway ScreenSaver Gateway Updater Google Chrome Google Toolbar for Internet Explorer Google Update Helper Grand Theft Auto IV Hotfix for Microsoft .NET Framework 4 Client Profile (KB2461678) Hotkey Utility Identity Card ImagXpress Java Auto Updater Java™ 6 Update 29 Junk Mail filter update Magic Online Magic Workstation 0.94f Malwarebytes Anti-Malware version 1.60.0.1800 Microsoft Games for Windows - LIVE Redistributable Microsoft Games for Windows Marketplace Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Suite Activation Assistant Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works Mozilla Firefox 9.0.1 (x86 en-US) MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MTG GamePack for Magic Workstation MyFreeCodec Nero 9 Essentials Nero ControlCenter Nero DiscSpeed Nero DiscSpeed Help Nero DriveSpeed Nero DriveSpeed Help Nero Express Help Nero InfoTool Nero InfoTool Help Nero Installer Nero Online Upgrade Nero StartSmart Nero StartSmart Help Nero StartSmart OEM NeroExpress neroxml Norton Online Backup Pando Media Booster QuickTime Razer DeathAdder™ Mouse Realtek Ethernet Controller Driver For Windows 7 Realtek High Definition Audio Driver Samsung Kies Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2553089) Security Update for 2007 Microsoft Office System (KB2553090) Security Update for 2007 Microsoft Office System (KB2584063) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Skype Click to Call Skype™ 5.5 Spybot - Search & Destroy StarCraft II Steam The Ship The Ship Single Player Update for 2007 Microsoft Office System (KB2284654) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Ventrilo Client Visual C++ 8.0 Runtime Setup Package (x64) Visual Studio 2008 x64 Redistributables VLC media player 1.1.4 Warhammer® 40,000â„¢: Dawn of War® II Welcome Center Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources World of Warcraft Xfire (remove only) . ==== Event Viewer Messages From Past Week ======== . 25/01/2012 11:22:36 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 25/01/2012 11:22:07 AM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. . ==== End Of File ===========================
Okie dokie…almost done. Let's get some updates on your system.


You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 9.5.0 first. Be sure to move any PDF documents to another folder first though.
———-

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-

When you get this completed let me know. There will not be any logs made so you know. :thumbup:
Providing there are not any other problems I think that we can clean things up…

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

7. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

8.Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Hey Jeff, I'd just like to thank you for helping me out! I really appreciate it. I was really impressed by your response time and professionalism. I wish you all the best. Cheers, Jeff

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI