I cant even install anti-virus software. i have (luckily) an old copy of "Hijack this" on my pc.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:50:49 PM, on 2/2/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Novatel Wireless\Virgin Mobile\MobiLink3.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10x_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Parker\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.facebook.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
R3 - URLSearchHook: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn2.dll
R3 - URLSearchHook: FCToolbarURLSearchHook Class - {f78bf7a8-cf12-4de7-a6da-c463d1b539a7} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Helper.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Arcadeweb - {78919608-B066-4B5A-B248-38E12A783E05} - C:\Program Files (x86)\ArcadeWeb\arcadeweb32.dll
O2 - BHO: Zynga - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn2.dll
O2 - BHO: BitTorrentBar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (file missing)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: FCTBPos00Pos - {BFE4B5CB-63F7-4A51-9266-6167655D5B4F} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Toolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn2.dll
O3 - Toolbar: Dogpile Bundle Toolbar - {C80BDEB2-8735-44C6-BD55-A1CCD555667A} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Toolbar.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [AW TrayIcon] RunDll32.exe "C:\Program Files (x86)\ArcadeWeb\arcadeweb32.dll", RunTrayIcon
O4 - HKLM\..\RunOnce:
"C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer
O4 - HKLM\..\RunOnce: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DFXAudioPlugin.dll",DllRegisterServer
O4 - HKLM\..\RunOnce: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer
O4 - HKLM\..\RunOnce: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} (FBootloaderAX) - http://static.ak.facebook.com/fbplugin/win…fbootloader.cab
O16 - DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} (GameTap Player) - http://archives.gametap.com/static/cab_hea…apWebPlayer.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} (MysteryPI Control) - http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{014D6342-EBB7-4481-B483-7E9E8BCFCE27}: NameServer = 68.28.138.132 68.28.137.132
O17 - HKLM\System\CS1\Services\Tcpip\..\{014D6342-EBB7-4481-B483-7E9E8BCFCE27}: NameServer = 68.28.138.132 68.28.137.132
O17 - HKLM\System\CS2\Services\Tcpip\..\{014D6342-EBB7-4481-B483-7E9E8BCFCE27}: NameServer = 68.28.138.132 68.28.137.132
O18 - Protocol: intu-help-qb3 - {C5E479EA-0A65-4B05-8C6C-2FC8CC682EB4} - c:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (file missing)
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - AppInit_DLLs: vbttvkk9miag32.dll,vbttvkk9miag32.dlln9s315532.dll,vbttvkk9miag32.dlln9s315532.d
llcu460v43c32.dll,vbttvkk9miag32.dlln9s315532.dllcu460v43c32.dll7ck7uunofbf04zf32
.dll,9oi3p332.dll,9oi3p332.dllad9al6vgmpi2iuu32.dll,9oi3p332.dllad9al6vgmpi2iuu32
.dllyo9ns132.dll,9oi3p332.dllad9al6vgmpi2iuu32.dllyo9ns132.dllq4cfv6a2bz0532.dll,
iqykd32.dll,iqykd32.dllae8rj32.dll,iqykd32.dllae8rj32.dllrak8mkkvofum8pm32.dll,iq
ykd32.dllae8rj32.dllrak8mkkvofum8pm32.dllahen5ye7iyekpz32.dll,mui7b0sl32.dll,mui7
b0sl32.dll9a4zexced632.dll,mui7b0sl32.dll9a4zexced632.dllaxzat5cev32.dll,mui7b0sl
32.dll9a4zexced632.dllaxzat5cev32.dllcv1yfn32.dll
O23 - Service: 1257629727 (.1257629727) - Unknown owner - C:\Program Files (x86)\1257629727\Parker1257629727L.exe
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Dragon Service (DragonSvc) - Nuance Communications, Inc. - C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NovaCore SDK Service (NvtlService) - Unknown owner - C:\Program Files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - c:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - c:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
–
End of file - 15097 bytes
for the record: I cant get my window installer to work at all. even when I inserted a disk.
Hello
pdpfishin and
My name is
JonTom
Malware Logs can sometimes take a lot of time to research and interpret.
Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
Lets see if we can get the following scans to run:
Please perform the following scan
Please download DDS from here and save it to your desktop. Disable any script blocking protection (How to Disable your Security Programs ) Right click on the DDS icon and select "Run as Administrator" to run the tool (may take up to 3 minutes to run). When done, DDS.txt will open. After a few moments, attach.txt will open in a second window. Save both reports to your desktop. Please post the contents of the DDS.txt and Attach.txt logs in your next reply.
aswMBR
Download aswMBR.exe to your desktop. Double click the aswMBR.exe to run it. When asked if you want to download Avast's virus definitions please select Yes . Click the "Scan" button to start scan.
[external image: Posted Image]
On completion of the scan click save log , save it to your desktop and post in your next reply.
[external image: Posted Image]
Please post both DDS logs and the aswMBR log in your next reply.
If you have any problems with the scans just let me know.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by [removed] at 18:51:52 on 2012-02-03
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3966.2886 [GMT -5:00]
.
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe
c:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Novatel Wireless\Virgin Mobile\MobiLink3.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\AVG PC TuneUp 2011 (Tom_Da_Man)\BoostSpeed.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.facebook.com/
uSearch Bar = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
uURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn2.dll
uURLSearchHooks: FCToolbarURLSearchHook Class: {f78bf7a8-cf12-4de7-a6da-c463d1b539a7} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Helper.dll
uURLSearchHooks: H - No File
mURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
mURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn2.dll
BHO: AutorunsDisabled - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: ArcadeWeb Class: {78919608-b066-4b5a-b248-38e12a783e05} - C:\Program Files (x86)\ArcadeWeb\arcadeweb32.dll
BHO: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn2.dll
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Dogpile Bundle Toolbar BHO: {bfe4b5cb-63f7-4a51-9266-6167655d5b4f} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Toolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
TB: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn2.dll
TB: Dogpile Bundle Toolbar: {c80bdeb2-8735-44c6-bd55-a1ccd555667a} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Toolbar.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10x_ActiveX.exe -update activex
mRun: [AW TrayIcon] RunDll32.exe "C:\Program Files (x86)\ArcadeWeb\arcadeweb32.dll", RunTrayIcon
mRunOnce: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer
mRunOnce: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DFXAudioPlugin.dll",DllRegisterServer
mRunOnce: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer
mRunOnce: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49}
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} - hxxp://archives.gametap.com/static/cab_headless/GameTapWebPlayer.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} - hxxp://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://zone.msn.com/bingame/popcaploader_v10.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: Interfaces\{014D6342-EBB7-4481-B483-7E9E8BCFCE27} : NameServer = 68.28.138.132 68.28.137.132
TCP: Interfaces\{D38C9554-89CB-416A-AB97-F98ECFC65AA7} : DhcpNameServer = [removed] [removed] [removed]
TCP: Interfaces\{ED71C190-65F2-42FC-845C-9876F5790CDD}\C696E6B6379737 : DhcpNameServer = [removed] [removed]
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\microsoft shared\Web Folders\PKMCDO.DLL
Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} -
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\System32\mscoree.dll
AppInit_DLLs: vbttvkk9miag32.dll,vbttvkk9miag32.dlln9s315532.dll,vbttvkk9miag32.dlln9s315532.d
llcu460v43c32.dll,vbttvkk9miag32.dlln9s315532.dllcu460v43c32.dll7ck7uunofbf04zf32
.dll,9oi3p332.dll,9oi3p332.dllad9al6vgmpi2iuu32.dll,9oi3p332.dllad9al6vgmpi2iuu32
.dllyo9ns132.dll,9oi3p332.dllad9al6vgmpi2iuu32.dllyo9ns132.dllq4cfv6a2bz0532.dll,
iqykd32.dll,iqykd32.dllae8rj32.dll,iqykd32.dllae8rj32.dllrak8mkkvofum8pm32.dll,iq
ykd32.dllae8rj32.dllrak8mkkvofum8pm32.dllahen5ye7iyekpz32.dll,mui7b0sl32.dll,mui7
b0sl32.dll9a4zexced632.dll,mui7b0sl32.dll9a4zexced632.dllaxzat5cev32.dll,mui7b0sl
32.dll9a4zexced632.dllaxzat5cev32.dllcv1yfn32.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: AutorunsDisabled - No File
BHO-X64: Babylon toolbar helper - No File
BHO-X64: Ask Toolbar BHO - No File
BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
BHO-X64: 0x1 - No File
BHO-X64: ContributeBHO Class: {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: DivX Plus Web Player HTML5 : {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO-X64: Increase performance and video formats for your HTML5 - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: ArcadeWeb Class: {78919608-B066-4B5A-B248-38E12A783E05} - C:\Program Files (x86)\ArcadeWeb\arcadeweb32.dll
BHO-X64: Arcadeweb - No File
BHO-X64: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn2.dll
BHO-X64: Zynga - No File
BHO-X64: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
BHO-X64: BitTorrentBar - No File
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: Dogpile Bundle Toolbar BHO: {BFE4B5CB-63F7-4A51-9266-6167655D5B4F} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Toolbar.dll
BHO-X64: FCTBPos00Pos - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: SmartSelect - No File
BHO-X64: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB-X64: Contribute Toolbar: {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
TB-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB-X64: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll
TB-X64: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn2.dll
TB-X64: Dogpile Bundle Toolbar: {C80BDEB2-8735-44C6-BD55-A1CCD555667A} - C:\Program Files (x86)\Dogpile Bundle Toolbar\Toolbar.dll
TB-X64: Babylon Toolbar: {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
mRun-x64: [AW TrayIcon] RunDll32.exe "C:\Program Files (x86)\ArcadeWeb\arcadeweb32.dll", RunTrayIcon
mRunOnce-x64: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer
mRunOnce-x64: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DSEPlugins\DFXAudioPlugin.dll",DllRegisterServer
mRunOnce-x64: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer
mRunOnce-x64: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer
IE-X64: {2670000A-7350-4f3c-8081-5663EE0C6C49}
IE-X64: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
AppInit_DLLs-X64: vbttvkk9miag32.dll,vbttvkk9miag32.dlln9s315532.dll,vbttvkk9miag32.dlln9s315532.d
llcu460v43c32.dll,vbttvkk9miag32.dlln9s315532.dllcu460v43c32.dll7ck7uunofbf04zf32
.dll,9oi3p332.dll,9oi3p332.dllad9al6vgmpi2iuu32.dll,9oi3p332.dllad9al6vgmpi2iuu32
.dllyo9ns132.dll,9oi3p332.dllad9al6vgmpi2iuu32.dllyo9ns132.dllq4cfv6a2bz0532.dll,
iqykd32.dll,iqykd32.dllae8rj32.dll,iqykd32.dllae8rj32.dllrak8mkkvofum8pm32.dll,iq
ykd32.dllae8rj32.dllrak8mkkvofum8pm32.dllahen5ye7iyekpz32.dll,mui7b0sl32.dll,mui7
b0sl32.dll9a4zexced632.dll,mui7b0sl32.dll9a4zexced632.dllaxzat5cev32.dll,mui7b0sl
32.dll9a4zexced632.dllaxzat5cev32.dllcv1yfn32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 DragonSvc;Dragon Service;C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe [2010-7-23 296808]
R2 NvtlService;NovaCore SDK Service;C:\Program Files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe [2009-8-24 82432]
R3 netr7364;USB Wireless 802.11 b/g Adaptor Driver for Vista;C:\Windows\system32\DRIVERS\netr7364.sys –> C:\Windows\system32\DRIVERS\netr7364.sys [?]
R3 NWVMModem;Virgin Mobile USB Modem Driver;C:\Windows\system32\DRIVERS\nwvmmdm.sys –> C:\Windows\system32\DRIVERS\nwvmmdm.sys [?]
R3 NWVMPort;Virgin Mobile USB Status Port Driver;C:\Windows\system32\DRIVERS\nwvmser.sys –> C:\Windows\system32\DRIVERS\nwvmser.sys [?]
R3 NWVMPort2;Virgin Mobile USB Status2 Port Driver;C:\Windows\system32\DRIVERS\nwvmser2.sys –> C:\Windows\system32\DRIVERS\nwvmser2.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys –> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 .1257629727;1257629727;C:\Program Files (x86)\1257629727\Parker1257629727L.exe [2009-9-9 423016]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-8-17 136176]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-8-15 284016]
S3 BrSerIb;Brother MFC Serial Interface Driver(WDM);C:\Windows\system32\DRIVERS\BrSerIb.sys –> C:\Windows\system32\DRIVERS\BrSerIb.sys [?]
S3 BrUsbSIb;Brother MFC Serial USB Driver(WDM);C:\Windows\system32\DRIVERS\BrUsbSIb.sys –> C:\Windows\system32\DRIVERS\BrUsbSIb.sys [?]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2009-11-8 1038088]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-8-17 136176]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\system32\drivers\nmwcdnsux64.sys –> C:\Windows\system32\drivers\nmwcdnsux64.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys –> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-02-03 00:45:39 ——– d—–w- C:\_CLTUI_E894D6B5_E3CA_4561_A244_272400640573_Session0
2012-02-02 07:37:31 ——– d–h–w- C:\kleaner.tmp
2012-01-16 19:12:09 ——– d—–w- C:\Program Files (x86)\Microsoft Visual Studio 8
2012-01-16 19:10:52 ——– d—–w- C:\Program Files (x86)\Microsoft Analysis Services
2012-01-16 19:10:21 ——– d—–w- C:\Users\Parker\AppData\Local\Microsoft Help
2012-01-12 02:58:50 ——– d—–w- C:\ProgramData\AVG
2012-01-11 07:09:07 ——– d—–w- C:\Users\Parker\AppData\Roaming\AVG
2012-01-11 07:06:04 ——– d—–w- C:\Program Files (x86)\AVG PC TuneUp 2011 (Tom_Da_Man)
2012-01-11 02:05:15 514560 —-a-w- C:\Windows\SysWow64\qdvd.dll
2012-01-11 02:05:15 1572864 —-a-w- C:\Windows\System32\quartz.dll
2012-01-11 02:05:15 1328128 —-a-w- C:\Windows\SysWow64\quartz.dll
2012-01-11 02:05:14 366592 —-a-w- C:\Windows\System32\qdvd.dll
2012-01-11 02:03:01 1731920 —-a-w- C:\Windows\System32\ntdll.dll
2012-01-11 02:03:01 1292080 —-a-w- C:\Windows\SysWow64\ntdll.dll
2012-01-11 01:10:37 77312 —-a-w- C:\Windows\System32\packager.dll
2012-01-11 01:10:37 67072 —-a-w- C:\Windows\SysWow64\packager.dll
2012-01-10 19:47:36 ——– d—–w- C:\Program Files (x86)\FoxTabMusicConverter
2012-01-10 19:43:41 ——– d—–w- C:\Program Files (x86)\BabylonToolbar
2012-01-10 19:40:41 ——– d—–w- C:\Users\Parker\AppData\Local\Babylon
2012-01-10 19:40:40 ——– d—–w- C:\Users\Parker\AppData\Roaming\Babylon
2012-01-10 19:40:40 ——– d—–w- C:\ProgramData\Babylon
2012-01-10 19:28:27 ——– d—–w- C:\Program Files (x86)\NCH Software
2012-01-10 19:27:40 ——– d—–w- C:\Users\Parker\AppData\Roaming\NCH Software
2012-01-10 14:51:30 ——– d—–w- C:\Techno Bass - Beat Dominator - FLAC
2012-01-10 03:43:45 ——– d—–w- C:\Program Files (x86)\Pando Networks
2012-01-10 03:34:25 ——– d—–w- C:\Program Files (x86)\Raptr
2012-01-09 18:51:54 ——– d—–w- C:\Program Files (x86)\2K Games
2012-01-09 18:50:16 757760 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2012-01-09 18:50:16 69715 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2012-01-09 18:50:16 65024 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2012-01-09 18:50:16 5632 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2012-01-09 18:50:16 274432 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2012-01-09 18:50:16 204800 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2012-01-09 18:50:12 200836 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2012-01-09 18:50:11 331908 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2012-01-08 01:21:12 580096 —-a-w- C:\Windows\System32\ac3filter64.acm
2012-01-08 01:21:12 497664 —-a-w- C:\Windows\SysWow64\ac3filter.acm
2012-01-08 01:21:12 ——– d—–w- C:\Program Files (x86)\AC3Filter
.
==================== Find3M ====================
.
2011-11-24 04:52:09 3145216 —-a-w- C:\Windows\System32\win32k.sys
2011-11-17 06:49:14 95600 —-a-w- C:\Windows\System32\drivers\ksecdd.sys
2011-11-17 06:49:14 152432 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys
2011-11-17 06:44:43 459232 —-a-w- C:\Windows\System32\drivers\cng.sys
2011-11-17 06:35:28 395776 —-a-w- C:\Windows\System32\webio.dll
2011-11-17 06:35:26 29184 —-a-w- C:\Windows\System32\sspisrv.dll
2011-11-17 06:35:26 136192 —-a-w- C:\Windows\System32\sspicli.dll
2011-11-17 06:35:25 340992 —-a-w- C:\Windows\System32\schannel.dll
2011-11-17 06:35:25 28160 —-a-w- C:\Windows\System32\secur32.dll
2011-11-17 06:35:19 1447936 —-a-w- C:\Windows\System32\lsasrv.dll
2011-11-17 06:33:55 31232 —-a-w- C:\Windows\System32\lsass.exe
2011-11-17 05:35:02 314880 —-a-w- C:\Windows\SysWow64\webio.dll
2011-11-17 05:34:52 224768 —-a-w- C:\Windows\SysWow64\schannel.dll
2011-11-17 05:34:52 22016 —-a-w- C:\Windows\SysWow64\secur32.dll
2011-11-17 05:28:48 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll
2011-11-10 10:54:13 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
.
============= FINISH: 18:52:37.28 ===============
will reply with other in a minute!
aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software
Run date: 2012-02-03 19:05:46
—————————–
19:05:46.573 OS Version: Windows x64 6.1.7601 Service Pack 1
19:05:46.573 Number of processors: 4 586 0x203
19:05:46.573 ComputerName: PARKER-PC UserName: Parker
19:05:47.993 Initialize success
19:06:06.476 AVAST engine download error: 0
19:06:53.292 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-3
19:06:53.292 Disk 0 Vendor: HDS722580VLAT20 V32OA6MA Size: 58644MB BusType: 3
19:06:53.307 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\00000064
19:06:53.307 Disk 1 Vendor: ST350062 HP26 Size: 476940MB BusType: 3
19:06:53.323 Disk 1 MBR read successfully
19:06:53.338 Disk 1 MBR scan
19:06:53.338 Disk 1 Windows 7 default MBR code
19:06:53.354 Disk 1 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
19:06:53.370 Disk 1 Partition 2 00 07 HPFS/NTFS NTFS 476838 MB offset 206848
19:06:53.370 Service scanning
19:06:54.758 Modules scanning
19:06:54.758 Disk 1 trace - called modules:
19:06:54.774 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor.sys
19:06:54.774 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa80045cf060]
19:06:54.789 3 CLASSPNP.SYS[fffff880019c443f] -> nt!IofCallDriver -> [0xfffffa80042b9e40]
19:06:54.789 5 ACPI.sys[fffff88000ec97a1] -> nt!IofCallDriver -> \Device\00000064[0xfffffa80037dd430]
19:06:54.805 Scan finished successfully
19:07:13.338 Disk 1 MBR has been saved successfully to "C:\Users\Parker\Desktop\MBR.dat"
19:07:13.338 The log file has been saved successfully to "C:\Users\Parker\Desktop\aswMBR.txt"
Hello pdpfishin
When you ran DDS, two logs would have been produced. You have posted the DDS.txt log, but I also need to review the attach.txt log.
Please post the attach.txt log in your next reply.
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume3
Install Date: 11/7/2009 5:35:27 PM
System Uptime: 2/3/2012 2:41:22 AM (16 hours ago)
.
Motherboard: ECS | | Nettle3
Processor: AMD Phenom™ 9150e Quad-Core Processor | Socket AM2 | 900/201mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 466 GiB total, 238.166 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 0 GiB total, 0.045 GiB free.
F: is FIXED (NTFS) - 57 GiB total, 55 GiB free.
G: is CDROM ()
H: is Removable
I: is Removable
J: is Removable
K: is Removable
L: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB CF Reader
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_CF_READER&REV_1.01#920321111113&1#
Manufacturer: Generic
Name: J:\
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_CF_READER&REV_1.01#920321111113&1#
Service: WUDFRd
.
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: MMC Storage
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_NOVATEL&PROD_MMC_STORAGE&REV_2.31#7&2F31DF07&0&091034564041000&0#
Manufacturer: Novatel
Name: H:\
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_NOVATEL&PROD_MMC_STORAGE&REV_2.31#7&2F31DF07&0&091034564041000&0#
Service: WUDFRd
.
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB MS Reader
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_MS_READER&REV_1.03#920321111113&3#
Manufacturer: Generic
Name: L:\
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_MS_READER&REV_1.03#920321111113&3#
Service: WUDFRd
.
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB SD Reader
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_SD_READER&REV_1.00#920321111113&0#
Manufacturer: Generic
Name: I:\
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_SD_READER&REV_1.00#920321111113&0#
Service: WUDFRd
.
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: USB SM Reader
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_SM_READER&REV_1.02#920321111113&2#
Manufacturer: Generic
Name: K:\
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC&PROD_USB_SM_READER&REV_1.02#920321111113&2#
Service: WUDFRd
.
==== System Restore Points ===================
.
RP281: 1/11/2012 3:00:54 AM - Windows Update
RP282: 1/14/2012 3:51:54 PM - Windows Update
RP283: 1/16/2012 2:07:02 PM - Installed Microsoft Office Professional Plus 2010
RP284: 1/16/2012 2:23:36 PM - Installed Microsoft Office Professional Plus 2010
RP285: 1/18/2012 2:09:15 AM - Installed Microsoft Office Professional Plus 2010
RP286: 1/18/2012 2:21:58 AM - Installed Microsoft Office Professional Plus 2010
RP287: 1/25/2012 9:22:49 PM - Scheduled Checkpoint
RP288: 2/2/2012 1:53:21 AM - Scheduled Checkpoint
.
==== Installed Programs ======================
.
100,000 Mahjongg Games
1001 Japanese Crosswords
1001 Minigolf Challenge
1001 Tangram Puzzles
2002 Games
2002 Kakuro Puzzles
2002 Pentamino Puzzles
2002 Space Out Games
2002 Sudoku Games
500 Solitaire Games
AC3Filter 1.63b
Acrobat.com
Adobe Acrobat 9 Pro - English, Français, Deutsch
Adobe After Effects CS4
Adobe After Effects CS4 Presets
Adobe After Effects CS4 Template Projects & Footage
Adobe After Effects CS4 Third Party Content
Adobe AIR
Adobe Anchor Service CS4
Adobe Asset Services CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Recommended Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Extra Settings CS4
Adobe Color Video Profiles AE CS4
Adobe Color Video Profiles CS CS4
Adobe Contribute CS4
Adobe Creative Suite 4 Master Collection
Adobe CS4 American English Speech Analysis Models
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Dreamweaver CS4
Adobe Drive CS4
Adobe Dynamiclink Support
Adobe Encore CS4
Adobe Encore CS4 Codecs
Adobe Encore CS4 Library
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Fireworks CS4
Adobe Flash CS4
Adobe Flash CS4 Extension - Flash Lite STI en
Adobe Flash CS4 STI-en
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Illustrator CS4
Adobe InDesign CS4
Adobe InDesign CS4 Application Feature Set Files (Roman)
Adobe InDesign CS4 Common Base Files
Adobe InDesign CS4 Icon Handler
Adobe Linguistics CS4
Adobe Media Encoder CS4
Adobe Media Encoder CS4 Additional Exporter
Adobe Media Encoder CS4 Dolby
Adobe Media Encoder CS4 Exporter
Adobe Media Encoder CS4 Importer
Adobe Media Player
Adobe MotionPicture Color Files CS4
Adobe OnLocation CS4
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Premiere Pro CS4
Adobe Premiere Pro CS4 Functional Content
Adobe Premiere Pro CS4 Third Party Content
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe SGM CS4
Adobe SING CS4
Adobe Soundbooth CS4
Adobe Soundbooth CS4 Codecs
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe Version Cue CS4 Server
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Advertising Center
Apple Application Support
Apple Software Update
ArcadeWeb
Ask Toolbar
AVG PC TuneUp 2011 (Tom_Da_Man)
Babylon toolbar on IE
Best Games Hits 4
Bing Bar
BitTorrent
BitTorrentBar Toolbar
Broadband2Go
Brother MFL-Pro Suite MFC-440CN
Cheetah DVD Burner
Chess Brain Teasers 50,000
Chess Reversi 50,000
Chicken Invaders 2 v2.40
Connect
ConvertXtoDVD 3.6.12.174c
DivX Setup
Dogpile Bundle Toolbar
DolbyFiles
Dragon NaturallySpeaking 11
Dream Chronicles 2 The Eternal Maze 1.00
Empress of the Deep
Facebook Plug-In
FoxTab Music Converter
Frog Race
GameTap Web Player
Goddess Chronicles Free Trial
Gold Miner Vegas (remove only)
Google Chrome
Google Earth Plug-in
Google Update Helper
GTA San Andreas
Hexagon Mahjongg
ImagXpress
Immortal Lovers
InstallVC90Support
Java Auto Updater
Java™ 6 Update 30
Kakuro Mania! 10,000
kuler
LightScribe System Software
Menu Templates - Starter Kit
Merriam-Webster's Reference Library
Microsoft .NET Framework 1.1
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Office XP Professional with FrontPage
Microsoft Primary Interoperability Assemblies 2005
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Monopoly by Parker Brothers
Movie Templates - Starter Kit
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Music Oasis
Mystery Case Files - Prime Suspects (remove only)
Nero 9 Trial
Nero BurnRights
Nero ControlCenter
Nero CoverDesigner
Nero Disc Copy Gadget
Nero DiscSpeed
Nero DriveSpeed
Nero InfoTool
Nero Installer
Nero PhotoSnap
Nero Recode
Nero Rescue Agent
Nero ShowTime
Nero StartSmart
Nero Vision
Nero WaveEditor
NeroBurningROM
NeroExpress
neroxml
OpenOffice.org 3.1
Pcsx2 0.9.2 Watermoose
PDF Settings CS4
Photoshop Camera Raw
Pixel Bender Toolkit
Puzzle and Board XP Championship
Puzzle XP Championship 3000
QuickBooks
QuickBooks Simple Start 2010 Free Edition
QuickTime
R.C. Cars
ResultDns 1.0 build 121
Rosetta Stone V3
SoundTrax
Sudoku Mania! 50,000
Suite Shared Configuration CS4
Super Word Games 10,000
Switch Sound File Converter
Taipei Mahjongg 25K
Tango
The Da Vinci Code
The Weather Channel Desktop 6
VC80CRTRedist - 8.0.50727.4053
VC80CRTRedist - 8.0.50727.6195
Virgin Mobile Broadband Modem Drivers
WavePad Sound Editor
Who Wants To Be A Millionaire
WinRAR archiver
Yahoo! BrowserPlus 2.9.8
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
ZSNES (a FREE GNU licensed SNES Famicom Game Emulator) version
Zynga Toolbar
.
==== Event Viewer Messages From Past Week ========
.
2/2/2012 7:45:40 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the 1257629727 service to connect.
2/2/2012 7:45:40 PM, Error: Service Control Manager [7000] - The 1257629727 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/2/2012 7:26:24 PM, Error: Service Control Manager [7031] - The Norton Internet Security service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
.
==== End Of File ===========================
Hello
pdpfishin
Thank you for the logs.
Please work your way through the following steps:
P2P Programs :
P2P programs are a major source of Malware infections. From your log I see you have BitTorrent . We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections. The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them. If you wish to keep the program(s), please do not use them until your computer is cleaned.
Information regarding the risk of using these programs can be found from here and here. It is strongly recommend that you uninstall any P2P programs you have on your system. To do this, Click on the "Windows Orb" (bottom left hand corner of your screen), then on "Conrol Panel" and then on the "Programs and Features" tab. A list of currently installed programs will be displayed. Find the "BitTorrent" program, click on it once and then click on the "Uninstall" button. If you are prompted to re-boot your computer to complete the uninstall please do so. Repeat for BitTorrentBar Toolbar .
PLEASE NOTE: Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files. Please un-install the following
Click on "Start" then on "Control Panel" and then on the "Programs and Features" tab. Find the "ArcadeWeb" program, click on it once and then click on the "uninstall" button. If you are prompted to re-boot your computer to complete the uninstall please do so. Repeat for Babylon toolbar on IE and Ask Toolbar .
The following toolbars are reported to have certain trackware functionalities. If you do not use them I suggest you uninstall them.
Dogpile Bundle Toolbar
Zynga Toolbar
Combofix
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
IMPORTANT - Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .Right click on ComboFix.exe and select "Run as Administrator" to run the program. Follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. Please note : If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes , to continue scanning for malware.When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.Do not "re-run" Combofix. If you have a problem, reply back for further instructions. Should there be issues with internet afterward:
In IE : Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> un check "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.
In Firefox : Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy .
Please post the Combofix log in your next reply.
ComboFix 12-02-05.01 - Parker 02/04/2012 17:21:08.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3966.2813 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\ArcadeWeb\arcadeweb32.dll
c:\program files (x86)\ArcadeWeb\awun.exe
c:\program files (x86)\ResultDns
c:\program files (x86)\ResultDns\uninstall.exe
c:\programdata\ResultDns
c:\users\Parker\AppData\Roaming\inst.exe
c:\users\Parker\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]
c:\users\Parker\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome.manifest
c:\users\Parker\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\gvtextlinks.jar
c:\users\Parker\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\gvtlf.dll
c:\users\Parker\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\components\gvtlf.xpt
c:\users\Parker\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\install.rdf
c:\users\Parker\AppData\Roaming\vso_ts_preview.xml
c:\windows\SysWow64\ActNAV_cltDynam.dat
.
.
((((((((((((((((((((((((( Files Created from 2012-01-04 to 2012-02-04 )))))))))))))))))))))))))))))))
.
.
2012-02-04 22:33 . 2012-02-04 22:33 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-02-03 00:45 . 2012-02-03 00:45 ——– d—–w- C:\_CLTUI_E894D6B5_E3CA_4561_A244_272400640573_Session0
2012-02-02 07:37 . 2012-02-02 07:37 ——– d—–w- C:\kleaner.tmp
2012-01-16 19:12 . 2012-01-16 19:12 ——– d—–w- c:\program files (x86)\Microsoft Visual Studio 8
2012-01-16 19:10 . 2012-01-16 19:10 ——– d—–w- c:\program files (x86)\Microsoft Analysis Services
2012-01-16 19:10 . 2012-01-16 19:10 ——– d—–w- c:\users\Parker\AppData\Local\Microsoft Help
2012-01-16 19:10 . 2012-01-18 07:26 ——– d—–w- c:\programdata\Microsoft Help
2012-01-12 02:58 . 2012-01-12 02:58 ——– d—–w- c:\programdata\AVG
2012-01-11 07:09 . 2012-01-11 07:12 ——– d—–w- c:\users\Parker\AppData\Roaming\AVG
2012-01-11 07:06 . 2012-01-11 07:06 ——– d—–w- c:\program files (x86)\AVG PC TuneUp 2011 (Tom_Da_Man)
2012-01-11 02:05 . 2011-10-26 05:25 1572864 —-a-w- c:\windows\system32\quartz.dll
2012-01-11 02:05 . 2011-10-26 04:32 514560 —-a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 02:05 . 2011-10-26 04:32 1328128 —-a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 02:05 . 2011-10-26 05:25 366592 —-a-w- c:\windows\system32\qdvd.dll
2012-01-11 02:03 . 2011-11-17 06:41 1731920 —-a-w- c:\windows\system32\ntdll.dll
2012-01-11 02:03 . 2011-11-17 05:38 1292080 —-a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 01:10 . 2011-11-19 14:58 77312 —-a-w- c:\windows\system32\packager.dll
2012-01-11 01:10 . 2011-11-19 14:01 67072 —-a-w- c:\windows\SysWow64\packager.dll
2012-01-10 19:47 . 2012-01-10 20:13 ——– d—–w- c:\program files (x86)\FoxTabMusicConverter
2012-01-10 19:43 . 2012-01-10 19:43 1491 —-a-w- C:\user.js
2012-01-10 19:40 . 2012-01-10 19:40 ——– d—–w- c:\users\Parker\AppData\Local\Babylon
2012-01-10 19:40 . 2012-01-10 19:40 ——– d—–w- c:\users\Parker\AppData\Roaming\Babylon
2012-01-10 19:40 . 2012-01-10 19:40 ——– d—–w- c:\programdata\Babylon
2012-01-10 19:29 . 2012-01-17 19:32 ——– d—–w- c:\programdata\NCH Software
2012-01-10 19:28 . 2012-01-10 19:32 ——– d—–w- c:\program files (x86)\NCH Software
2012-01-10 19:27 . 2012-01-17 19:32 ——– d—–w- c:\users\Parker\AppData\Roaming\NCH Software
2012-01-10 14:51 . 2012-01-10 14:51 ——– d—–w- C:\Techno Bass - Beat Dominator - FLAC
2012-01-10 03:43 . 2012-01-10 03:43 ——– d—–w- c:\program files (x86)\Pando Networks
2012-01-10 03:34 . 2012-01-10 03:34 ——– d—–w- c:\program files (x86)\Raptr
2012-01-09 18:51 . 2012-01-09 18:51 ——– d—–w- c:\program files (x86)\2K Games
2012-01-09 18:50 . 2006-02-07 20:45 757760 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2012-01-09 18:50 . 2006-02-07 20:44 65024 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2012-01-09 18:50 . 2006-02-07 20:40 204800 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2012-01-09 18:50 . 2006-02-07 20:40 69715 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2012-01-09 18:50 . 2006-02-07 20:40 274432 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2012-01-09 18:50 . 2005-11-14 04:19 5632 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2012-01-09 18:50 . 2012-01-09 18:50 200836 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2012-01-09 18:50 . 2012-01-09 18:50 331908 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2012-01-08 01:21 . 2012-01-08 01:21 ——– d—–w- c:\program files (x86)\AC3Filter
2012-01-08 01:21 . 2009-08-12 02:22 580096 —-a-w- c:\windows\system32\ac3filter64.acm
2012-01-08 01:21 . 2009-08-12 02:18 497664 —-a-w- c:\windows\SysWow64\ac3filter.acm
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-24 04:52 . 2011-12-17 07:39 3145216 —-a-w- c:\windows\system32\win32k.sys
2011-11-14 18:48 . 2010-05-19 05:22 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2011-11-14 18:47 . 2010-05-19 05:22 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2011-11-14 18:44 . 2010-05-19 05:21 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-11-14 18:44 . 2010-05-15 13:02 539968 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-11-10 10:54 . 2010-05-11 02:56 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files (x86)\Zynga\prxtbZyn2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
2011-05-09 09:49 176936 —-a-w- c:\program files (x86)\Zynga\prxtbZyn2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
"{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files (x86)\Zynga\prxtbZyn2.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"B Register c:\program files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll"="c:\windows\system32\rundll32.exe" [2009-07-14 44544]
"B Register c:\program files (x86)\DivX\DivX Plus Player\DSEPlugins\DFXAudioPlugin.dll"="c:\windows\system32\rundll32.exe" [2009-07-14 44544]
"B Register c:\program files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll"="c:\windows\system32\rundll32.exe" [2009-07-14 44544]
"B Register c:\program files (x86)\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll"="c:\windows\system32\rundll32.exe" [2009-07-14 44544]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 .1257629727;1257629727;c:\program files (x86)\1257629727\Parker1257629727L.exe [2009-09-14 423016]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-17 136176]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R3 BrSerIb;Brother MFC Serial Interface Driver(WDM);c:\windows\system32\DRIVERS\BrSerIb.sys [x]
R3 BrUsbSIb;Brother MFC Serial USB Driver(WDM);c:\windows\system32\DRIVERS\BrUsbSIb.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2009-11-08 1038088]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-17 136176]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 DragonSvc;Dragon Service;c:\program files (x86)\Common Files\Nuance\dgnsvc.exe [2010-07-23 296808]
S2 NvtlService;NovaCore SDK Service;c:\program files (x86)\Novatel Wireless\Novacore\Server\NvtlSrvr.exe [2009-08-24 82432]
S3 netr7364;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys [x]
S3 NWVMModem;Virgin Mobile USB Modem Driver;c:\windows\system32\DRIVERS\nwvmmdm.sys [x]
S3 NWVMPort;Virgin Mobile USB Status Port Driver;c:\windows\system32\DRIVERS\nwvmser.sys [x]
S3 NWVMPort2;Virgin Mobile USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwvmser2.sys [x]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 18:24 451872 —-a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-17 07:58]
.
2012-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-17 07:58]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.facebook.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Bar = hxxp://www.google.com
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office10\EXCEL.EXE/3000
TCP: Interfaces\{014D6342-EBB7-4481-B483-7E9E8BCFCE27}: NameServer = 68.28.138.132 68.28.137.132
DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} - hxxp://archives.gametap.com/static/cab_headless/GameTapWebPlayer.cab
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)
WebBrowser-{7B13EC3E-999A-4B70-B9CB-2617B8323822} - (no file)
AddRemove-100,000 Mahjongg Games - c:\program files (x86)\100
AddRemove-Chess Brain Teasers 50,000 - c:\program files (x86)\Chess Brain Teasers 50
AddRemove-Chess Reversi 50,000 - c:\program files (x86)\Chess Reversi 50
AddRemove-Kakuro Mania! 10,000 - c:\program files (x86)\Kakuro Mania! 10
AddRemove-ResultDns - c:\program files (x86)\ResultDns\uninstall.exe
AddRemove-Sudoku Mania! 50,000 - c:\program files (x86)\Selectsoft\Sudoku Mania! 50
AddRemove-Super Word Games 10,000 - c:\program files (x86)\Super Word Games 10
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1157795500-1992200003-1279654967-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:61,2e,78,e8,e5,06,f5,8c,2a,50,86,2c,3d,f1,7f,e3,23,2e,57,4b,8e,f7,80,
21,a2,f7,6b,d0,8c,50,59,a8,df,ab,17,c3,48,52,58,e8,35,50,c0,5a,3f,f2,55,05,\
"??"=hex:31,47,55,aa,dc,a5,62,51,c4,9c,b1,09,eb,75,75,0b
.
[HKEY_USERS\S-1-5-21-1157795500-1992200003-1279654967-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:56,fd,63,63,4d,47,9e,d6,ff,08,38,29,ad,e8,a7,b2,80,c3,40,90,44,
dc,c4,f5,a7,a1,29,fc,26,62,1b,d8,37,1a,1f,8e,f9,f2,14,f5,d1,2d,89,f3,a1,d8,\
"rkeysecu"=hex:2a,94,43,e1,b8,0e,a8,72,fd,94,5a,d8,99,95,14,ae
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10x_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10x.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
.
**************************************************************************
.
Completion time: 2012-02-04 18:23:33 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-04 23:23
.
Pre-Run: 258,774,900,736 bytes free
Post-Run: 261,960,425,472 bytes free
.
- - End Of File - - E52F7F9EEDBBDC1E0721EA19F7CEE63A
now all my applications will not work unless I open as administrator. even my media player. should I not do this now ?
Hello
pdpfishin
now all my applications will not work unless I open as administrator
Thanks for letting me know. For the moment I would like to concentrate on making sure that your machine is malware free. Once the system appreas to be clean we will address this issue.
Lets continue:
it didnt give me the "send file" but scanned anyway. Here is the results:
Antivirus Result Update
AhnLab-V3 Trojan/Win32.Image 20120205
AntiVir DR/Kiser.FB 20120205
Antiy-AVL - 20120203
Avast Win32:AutoIt-UM [PUP] 20120205
AVG Suspicion: unknown virus 20120205
BitDefender Trojan.Generic.4313735 20120205
ByteHero - 20120126
CAT-QuickHeal - 20120205
ClamAV PUA.Script.Packed-3 20120205
Commtouch W32/MalwareF.EXFI 20120204
Comodo UnclassifiedMalware 20120205
DrWeb - 20120205
Emsisoft Downloader.Kiser!IK 20120205
eSafe Win32.DRKiser.Fb 20120202
eTrust-Vet Win32/Orsam.J 20120203
F-Prot W32/MalwareF.EXFI 20120201
F-Secure Trojan.Generic.4313735 20120205
GData Trojan.Generic.4313735 20120205
Ikarus Downloader.Kiser 20120205
Jiangmin - 20120205
K7AntiVirus Riskware 20120203
Kaspersky - 20120205
McAfee Generic.dx!uru 20120205
McAfee-GW-Edition Generic.dx!uru 20120204
Microsoft Worm:Win32/Orbina!rts 20120205
NOD32 Win32/RiskWare.HackAV.EX 20120205
Norman AutoRun.AGUK 20120205
nProtect - 20120205
Panda Trj/CI.A 20120205
PCTools - 20120205
Prevx - 20120205
Rising AdWare.Win32.Autoit.x 20120118
Sophos Mal/Generic-L 20120205
SUPERAntiSpyware - 20120203
Symantec - 20120205
TheHacker - 20120203
TrendMicro TROJ_IMAGE.MCL 20120205
TrendMicro-HouseCall TROJ_IMAGE.MCL 20120205
VBA32 Trojan.Autoit.F 20120203
VIPRE Trojan.Win32.Generic!BT 20120205
ViRobot - 20120205
VirusBuster Worm.Autoit.Gen 20120205
OK SystemLook took 2 seconds and this was the results: (I Had to "Open as Administrator")
SystemLook 30.07.11 by jpshortstuff
Log created at 11:54 on 05/02/2012 by Parker
Administrator - Elevation successful
========== dir ==========
C:\_CLTUI_E894D6B5_E3CA_4561_A244_272400640573_Session0 - Parameters: "/sub"
—Files—
None found.
No folders found.
-= EOF =-
Hello
pdpfishin
Thank you for the scan data and log information.
We need to use Combofix again but this time, we will be running it in a slightly different way.
Please work through the following steps
Hold down the Windows key (has the Windows symbol on it) and press the "R" key. A Run box will open. Type in Notepad and press Enter then click on "OK" ). NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.Copy and Paste the text in the quotebox below into the open Notepad window:
File::
C:\Program Files (x86)\1257629727\Parker1257629727L.exe
Folder::
C:\Program Files (x86)\1257629727
C:\_CLTUI_E894D6B5_E3CA_4561_A244_272400640573_Session0
c:\users\Parker\AppData\Local\Babylon
c:\users\Parker\AppData\Roaming\Babylon
c:\programdata\Babylon
Driver::
.1257629727
Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop. Close any open browsers. Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix . Refering to the picture below, drag CFScript.txt into ComboFix.exe
[external image: Posted Image]
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. Once the log is produced, re-engage your resident anti virus.
Temporary File Cleaner
Download TFC to your desktop . Close any open windows. Right click the TFC icon and select "Run as Administrator" to run the program. TFC will close all open programs itself in order to run. Click the Start button to begin the process. Allow TFC to run uninterrupted. The program should not take long to finish. Once complete it should automatically reboot your machine . If your machine does not reboot automatically, manually reboot to ensure a complete clean. Note : After running TFC your machine may take slightly longer to boot the first time. This is normal.
Please perform the following scan :
Please download MalwareBytes AntiMalware by clicking here and save the file (called mbam-setup.exe) to your desktop.
Right click on the mbam-setup.exe icon and select "Run as Administrator" to install the program. Follow the prompts during installation and have the Installation Wizzard create a desktop icon. Once installed, double click on the MalwareBytes AntiMalware icon to launch the program. Click on the "Update" tab and then on "Check for Updates" . The program will now install the latest Malware definition files. Once complete, click on the "Scanner" tab, select "Perform Quick Scan" and then click on "Scan" . Once the program has scanned your computer, a log file will be created in Notepad. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
If the scan detects any Malware-related objects , make sure that everything is checked, and click "Remove Selected" <– Very Important. When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer. The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab. Note : If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.Come back here to this thread and Paste the log in your next reply .
Please post the Combofix log and the MBAM log in your next reply.
Ok JonTom. I ran into a problem. When I attempted to drag the "CFScript.txt" to ComboFix I had a popup that Said:
"Illegal Operation Attempted on a Registry Key that has been Marked for deletion"
The ComboFix on my Desktop is Just the installer as well - should it not be the installer (ComboFixNSIS Installer)? I followed your directions when downloading except the fact I used Google Chrome and drug the download to my desktop. If I need to do something else I surely will.
Thanks For the Help!