This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot access search engines (google, etc) [Solved]

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Recently, I randomly get a bluescreen while watching videos and streams (youtube, own3d.tv, twitch.tv)

And I also cannot go into google, yahoo, or any kind of search engines. (tried all IE, firefox, chrome, none worked)

I ran malwarebyte, ccleaner, and mcafee, but it did not solve the issue.

I can't use other antivirus programs, because i can't use internet if i dont have either norton or mcafee.

I use korean Windows 7 laptop, if that makes any difference.

I used the hijackthis tool.

THANKS FOR HELP IN ADVANCE!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 오전 11:29:16, on 2012-03-23
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files\WTouch\WTouchUser.exe
C:\Windows\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Core Temp\Core Temp.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\HP\Downloads\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\adobearm.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: 곰TV알리미 - {21FFEC32-59FF-4A1F-BB42-7A315637617F} - C:\ProgramData\InfoFinder\gomtvhelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O4 - HKLM\..\Run: [HncUpdate] C:\Program Files\Common Files\Hnc\HncUtils\HncUpdate.exe /A
O4 - HKLM\..\Run: [Korean IME Migration] C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NACAgentUI] C:\Program Files\Cisco\Cisco NAC Agent\NACAgentUI.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [adobearm] C:\Windows\adobearm.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-848307109-4102649943-52888667-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-848307109-4102649943-52888667-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: OneNote 2007 화면 캡처 및 시작 기능.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: Microsoft Excel로 내보내기(&X) - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: OneNote로 보내기 - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: OneNote로 보내기 - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {063F7D71-5E0B-48F2-87D5-F63C5917947E} (Aosmgr Control) - https://platform.nexon.com/activex/ahnlab/aosmgr.cab
O16 - DPF: {4D2D3A17-9B46-483C-A5F4-1DC471080009} (Cisco NAC Web Agent Control) - https://resnet-cca1-cpl.reshsg.uci.edu/auth/taweb.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {8768D5EA-5412-4810-A032-09AD2A726C69} (DownStarter2 Control) - http://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe
O23 - Service: Apple 모바일 장비 (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour 서비스 (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google 업데이트 서비스 (gupdate) (gupdate) - Google Inc - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google 업데이트 서비스 (gupdatem) (gupdatem) - Google Inc - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: iPod 서비스 (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe
O23 - Service: Cisco NAC Agent (NACAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco\Cisco NAC Agent\NACAgent.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe

–
End of file - 9795 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Right-click and Run as Administrator CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs made by ckscanner, DDS and aswMBR.
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29 Run by [removed] at 13:21:31 on 2012-03-24 Microsoft Windows 7 Enterprise K 6.1.7601.1.949.82.1042.18.3039.1523 [GMT 9:00] . AV: V3 Lite *Enabled/Updated* {B5892DA8-3D3D-75E1-6A57-1270334145D3} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: V3 Lite *Enabled/Updated* {0EE8CC4C-1B07-7A6F-50E7-290248C60F6E} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\STacSV.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Hpservice.exe C:\Program Files\WTouch\WTouchService.exe C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\system32\vcsFPService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\taskhost.exe C:\Program Files\WTouch\WTouchUser.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Hotspot Shield\bin\openvpnas.exe C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe C:\Program Files\Hotspot Shield\bin\hsswd.exe C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\Windows\system32\mfevtps.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Steam\Steam.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\McAfee\Common Framework\naPrdMgr.exe C:\Program Files\Cisco\Cisco NAC Agent\NACAgent.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe C:\Windows\system32\conhost.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Program Files\Ventrilo\Ventrilo.exe C:\Windows\system32\sppsvc.exe C:\Program Files\Microsoft Office\Office12\WINWORD.EXE C:\Users\HP\Desktop\CKScanner.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local uURLSearchHooks: H - No File mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\adobearm.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: 곰TV알리미: {21ffec32-59ff-4a1f-bb42-7a315637617f} - c:\programdata\infofinder\gomtvhelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptsn.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll uRun: [Steam] "c:\program files\steam\steam.exe" -silent uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [HncUpdate] c:\program files\common files\hnc\hncutils\HncUpdate.exe /A mRun: [Korean IME Migration] c:\progra~1\common~1\micros~1\ime12\imekr\IMKRMIG.EXE mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [NACAgentUI] c:\program files\cisco\cisco nac agent\NACAgentUI.exe mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [adobearm] c:\windows\adobearm.exe StartupFolder: c:\users\hp\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe uPolicies-explorer: HideSCAHealth = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: Microsoft Excel로 내보내기(&X) - c:\progra~1\micros~1\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL DPF: {063F7D71-5E0B-48F2-87D5-F63C5917947E} - hxxps://platform.nexon.com/activex/ahnlab/aosmgr.cab DPF: {4D2D3A17-9B46-483C-A5F4-1DC471080009} - hxxps://resnet-cca1-cpl.reshsg.uci.edu/auth/taweb.cab DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {8768D5EA-5412-4810-A032-09AD2A726C69} - hxxp://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{688FD1EE-9771-4B11-A335-E78E924649CC}\44A4 : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{D452612B-B145-468A-9913-C15AB1D5A9BC} : DhcpNameServer = [removed] [removed] Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\hp\appdata\roaming\mozilla\firefox\profiles\xppp7i3m.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.daum.net/ FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z171&form=ZGAADF&install_date=20111116&q= FF - prefs.js: network.proxy.type - 0 FF - component: c:\program files\mozilla firefox\extensions\[removed]\components\afurladvisor.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\ahnlab\asp\components\aosmgr\conflict_440\npaosmgr.dll FF - plugin: c:\program files\ahnlab\asp\mykeydefense 2.5\npmkd25aos.dll FF - plugin: c:\program files\ahnlab\asp\mykeydefense 2.5\npmkd25sp.dll FF - plugin: c:\program files\common files\gretech\npgomtvx_nie.dll FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\programdata\nexon\ngm\npnxgame.dll FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll . ============= SERVICES / DRIVERS =============== . R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-1-3 475704] R1 AMonTDLH;AMonTDLH;c:\windows\system32\drivers\amontdlh.sys [2010-12-21 87648] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-1-3 91640] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-1-3 43288] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2012-3-22 148800] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-11 139776] S3 AhnFlt2k;AhnFlt2k;c:\windows\system32\drivers\AhnFlt2k.sys [2011-12-30 52960] S3 AhnRec2k;AhnRec2k;c:\windows\system32\drivers\AhnRec2k.sys [2011-12-30 20320] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888] S3 CdmDrvNt;CdmDrvNt;c:\windows\system32\drivers\CdmDrvNt.sys [2010-12-21 19616] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-3-24 40776] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-1-3 87656] S3 MfFWEnt;MfFWEnt;c:\program files\ahnlab\asp\myfirewall 4.0\mffwent.sys [2011-6-13 101368] S3 MfIPSEnt;MfIPSEnt;c:\program files\ahnlab\asp\myfirewall 4.0\mfipsent.sys [2011-6-13 121536] S3 Mkd2Bthf;Mkd2Bthf;c:\windows\system32\drivers\Mkd2BthF.sys [2010-12-22 80656] S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [2010-12-22 138384] S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2010-12-22 92304] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-6-23 15872] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2010-12-21 167424] . =============== Created Last 30 ================ . 2012-03-23 21:36:41 14664 —-a-w- c:\windows\stinger.sys 2012-03-23 21:35:23 ——– d—–w- c:\program files\stinger 2012-03-23 21:32:14 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2012-03-23 18:55:58 ——– d—–w- c:\users\hp\appdata\local\{03429C96-A834-4891-AF0A-99CB9A8CE3B8} 2012-03-23 18:55:45 ——– d—–w- c:\users\hp\appdata\local\{AEA3B850-409A-4123-B81B-BE68232482A1} 2012-03-22 19:07:35 ——– d—–w- c:\users\hp\appdata\local\{06E11339-D8E7-4239-B75E-BB745467FE34} 2012-03-22 07:50:18 ——– d—–w- c:\program files\Core Temp 2012-03-22 04:53:59 479752 —-a-w- c:\windows\system32\XAudio2_0.dll 2012-03-22 04:50:51 876864 —-a-w- c:\windows\system32\nvhdagenco3220103.dll 2012-03-22 04:31:54 ——– d—–w- c:\users\hp\appdata\local\{8168CD97-9A23-4427-82BE-FDA313980261} 2012-03-22 04:31:25 ——– d—–w- c:\users\hp\appdata\local\{00E5D3AE-2CAA-4537-AF1A-2A1946CD434C} 2012-03-21 23:57:27 ——– d—–w- c:\programdata\RegInOut 2012-03-21 23:57:23 ——– d—–w- c:\windows\RegInOut System Utilities 2012-03-21 15:21:47 ——– d—–w- c:\users\hp\appdata\local\{B7A45785-CABF-4C0C-9839-16439F7C507C} 2012-03-21 15:21:05 ——– d—–w- c:\users\hp\appdata\local\{FBF81C77-4A77-4D41-9BA9-23AB92171F1F} 2012-03-20 21:54:54 ——– d—–w- c:\users\hp\appdata\local\{99DC73F4-14ED-438D-AFBC-1C3BE31C4F96} 2012-03-20 21:54:39 ——– d—–w- c:\users\hp\appdata\local\{F55600A8-8392-4BE9-96A2-8B57D90217F4} 2012-03-19 18:18:44 ——– d—–w- c:\users\hp\appdata\local\{2F039A8F-421C-4C42-8E8F-D0B8D1F469D5} 2012-03-19 18:18:30 ——– d—–w- c:\users\hp\appdata\local\{2688C2E0-C258-4709-8314-856CD555CC28} 2012-03-18 19:15:08 ——– d—–w- c:\users\hp\appdata\local\{657CF891-17C7-41EA-96FE-ECCBE05B40F5} 2012-03-18 19:14:56 ——– d—–w- c:\users\hp\appdata\local\{1E795CEA-A667-4BF4-9976-52E0E3A0EDEA} 2012-03-17 21:09:36 592824 —-a-w- c:\program files\mozilla firefox\gkmedias.dll 2012-03-17 21:09:36 44472 —-a-w- c:\program files\mozilla firefox\mozglue.dll 2012-03-17 19:12:27 ——– d—–w- c:\users\hp\appdata\local\{BAFFD651-32AA-46CB-8A3A-3778696D7A08} 2012-03-16 17:37:58 ——– d—–w- c:\users\hp\appdata\local\{B9617E96-1D18-42C1-9886-E924B906500B} 2012-03-16 17:37:46 ——– d—–w- c:\users\hp\appdata\local\{525A9230-76D4-4DCD-AC52-B16235B72601} 2012-03-15 17:55:30 ——– d—–w- c:\users\hp\appdata\local\{DB469B46-115C-485E-A4EB-226527DA54C0} 2012-03-15 17:55:18 ——– d—–w- c:\users\hp\appdata\local\{F3E5EF70-75EF-4D44-9EC0-6C901016C396} 2012-03-14 18:01:41 ——– d—–w- c:\users\hp\appdata\local\{7C0A185C-D9EF-4B42-AF13-271C6C0DEB25} 2012-03-14 18:01:28 ——– d—–w- c:\users\hp\appdata\local\{FFEB93F8-2B14-4B74-907F-D2EBA23F44C6} 2012-03-14 09:00:33 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-03-14 09:00:32 3913584 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-13 19:49:00 2343424 —-a-w- c:\windows\system32\win32k.sys 2012-03-13 19:48:59 1077248 —-a-w- c:\windows\system32\DWrite.dll 2012-03-13 19:48:27 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-13 19:48:27 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-03-13 19:48:27 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-03-13 19:48:24 919040 —-a-w- c:\windows\system32\rdpcorets.dll 2012-03-13 19:48:24 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-03-13 19:48:23 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-03-13 19:48:23 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-13 19:42:55 ——– d—–w- c:\users\hp\appdata\local\{E618FC98-D12C-44A8-972E-BC98B22D68FD} 2012-03-13 19:42:43 ——– d—–w- c:\users\hp\appdata\local\{81D64C38-C37F-4337-9505-0A1A932EE4F1} 2012-03-12 18:22:06 ——– d—–w- c:\users\hp\appdata\local\{85C53300-C8E8-44EA-A019-E672A7EF6486} 2012-03-12 18:21:54 ——– d—–w- c:\users\hp\appdata\local\{D5B59B08-2B6A-4AC3-BA51-D8443046E47A} 2012-03-09 18:29:58 ——– d—–w- c:\users\hp\appdata\local\{1A8FBA77-E627-40F4-BB66-4E6760DF977C} 2012-03-09 18:29:45 ——– d—–w- c:\users\hp\appdata\local\{A24AA38C-6441-4362-BC00-CC4A04F8AED9} 2012-03-09 00:02:52 ——– d—–w- c:\users\hp\appdata\local\{B71C29A6-A159-441B-9BF6-5AD3090A4183} 2012-03-09 00:02:36 ——– d—–w- c:\users\hp\appdata\local\{59B7DFA4-16DF-4CF9-BA46-18706365877F} 2012-03-07 18:51:47 ——– d—–w- c:\users\hp\appdata\local\{FE127C6A-29B1-43AA-A53C-BF70A49FB09D} 2012-03-07 18:51:13 ——– d—–w- c:\users\hp\appdata\local\{041F476B-114E-4735-BD72-5FB6FA60FF9B} 2012-03-06 18:31:01 ——– d—–w- c:\users\hp\appdata\local\{45638CF8-743A-42A3-9570-BA897000E589} 2012-03-06 18:30:45 ——– d—–w- c:\users\hp\appdata\local\{06CC1E6A-C77C-4135-8B59-F853DD3ABAF3} 2012-03-06 01:47:47 ——– d—–w- c:\users\hp\appdata\local\{53EB42B5-1650-47A6-A276-129E56D684B9} 2012-03-06 01:47:18 ——– d—–w- c:\users\hp\appdata\local\{04263AB4-D308-47CE-8E82-D69B5C25BF53} 2012-03-05 10:11:43 ——– d—–w- c:\users\hp\appdata\local\{87315574-EDB8-4118-B296-0E40B2DF9ECB} 2012-03-05 10:11:28 ——– d—–w- c:\users\hp\appdata\local\{7680F0CB-38E1-4F3E-A98B-0C3B1F732C1F} 2012-03-04 21:29:59 ——– d—–w- c:\users\hp\appdata\local\{A4AE3AAA-D2B6-48C3-97C8-89B1BF373C8F} 2012-03-04 21:29:45 ——– d—–w- c:\users\hp\appdata\local\{92E1D5CB-DC52-4CD4-B7CF-0BDC46B8C405} 2012-03-03 22:41:25 ——– d—–w- c:\users\hp\appdata\local\{FF0DC55D-D0C8-4B28-AD38-134942FE3C20} 2012-03-03 22:41:08 ——– d—–w- c:\users\hp\appdata\local\{FDB16D65-4484-4202-AA25-DF1F0E07C8B0} 2012-03-02 17:57:08 ——– d—–w- c:\users\hp\appdata\local\{9BDF1174-0276-49C1-8611-7FD805EB0583} 2012-03-02 17:56:59 ——– d—–w- c:\users\hp\appdata\local\{483EF275-2FF8-484F-ABFD-AD44DEFA5F32} 2012-03-01 23:54:24 ——– d—–w- c:\users\hp\appdata\local\{B3456874-A00C-4A70-921C-4324F82E12CE} 2012-03-01 23:54:12 ——– d—–w- c:\users\hp\appdata\local\{704059F5-24CE-493A-9EE9-122228AE06C5} 2012-03-01 09:30:17 ——– d—–w- c:\users\hp\appdata\local\{33AE340B-3B50-4603-BA00-D3F6F3C9E744} 2012-03-01 09:30:04 ——– d—–w- c:\users\hp\appdata\local\{DDE619BA-BC92-4FB1-8088-ED9371F58CA2} 2012-02-29 18:46:02 ——– d—–w- c:\users\hp\appdata\local\{0E09CC39-CEEC-4C26-8972-6CB15294E82F} 2012-02-29 18:45:45 ——– d—–w- c:\users\hp\appdata\local\{AA879BE5-0D01-4D98-B11B-DDBAB1C4C9FA} 2012-02-28 18:41:41 ——– d—–w- c:\users\hp\appdata\local\{45048D7F-DE49-4D3E-AA62-5F33BF767501} 2012-02-28 18:41:29 ——– d—–w- c:\users\hp\appdata\local\{E3D3AD78-6137-403D-8C53-E5689297FB5D} 2012-02-28 00:39:15 ——– d—–w- c:\users\hp\appdata\local\{74F96F9B-1A3C-48B8-A9D9-9F5F48B4D124} 2012-02-28 00:39:00 ——– d—–w- c:\users\hp\appdata\local\{0DB5722F-07AE-4F66-9A91-E4CBF28D99A9} 2012-02-26 21:52:03 ——– d—–w- c:\users\hp\appdata\local\{9A93DF3B-C042-417D-834E-0269EDB96311} 2012-02-26 21:51:47 ——– d—–w- c:\users\hp\appdata\local\{E9C454B7-A895-45FA-8081-23BBD2FD249F} 2012-02-26 06:24:45 1654869 —-a-w- c:\programdata\DynuEncrypt.dll 2012-02-26 06:20:44 713312 —-a-w- c:\windows\system32\ijjiSetup.exe 2012-02-26 06:20:44 62048 —-a-w- c:\windows\system32\ijjiProcessRestarter.exe 2012-02-26 06:20:44 27136 —-a-w- c:\program files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll 2012-02-26 06:20:31 ——– d—–w- c:\program files\REACTOR 2012-02-26 06:14:16 ——– d—–w- C:\Allm 2012-02-25 20:28:40 ——– d—–w- c:\users\hp\appdata\local\{9F48CA7B-D409-479E-8475-C208BE86B57C} 2012-02-25 20:28:27 ——– d—–w- c:\users\hp\appdata\local\{7A4D7245-56D8-4E72-B842-BDD8920911CD} 2012-02-24 23:10:48 ——– d—–w- c:\users\hp\appdata\local\{A34E1A87-6296-47CB-864E-45493A8BF6EF} 2012-02-24 23:10:36 ——– d—–w- c:\users\hp\appdata\local\{58AC8AEF-B934-4B95-9515-AA57583F93A3} 2012-02-24 06:52:30 ——– d—–w- c:\users\hp\appdata\local\{6FB1AFDE-C526-4DD3-8876-76444EA7DE7B} 2012-02-24 06:52:17 ——– d—–w- c:\users\hp\appdata\local\{E4805593-CECF-4512-9028-AD0210126D0B} 2012-02-23 18:41:56 ——– d—–w- c:\users\hp\appdata\local\{A091557D-FDB7-4F41-BA04-4AEF2B96C864} 2012-02-23 18:41:36 ——– d—–w- c:\users\hp\appdata\local\{66F35B44-01C0-4FFC-A86F-91474A6501CA} . ==================== Find3M ==================== . 2012-03-23 21:35:34 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-03-23 21:35:34 475704 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2012-03-23 21:35:34 159608 —-a-w- c:\windows\system32\mfevtps.exe 2012-03-04 21:30:13 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-29 23:59:00 881984 —-a-w- c:\windows\system32\nvgenco32.dll 2012-02-29 23:59:00 7713088 —-a-w- c:\windows\system32\nvwgf2um.dll 2012-02-29 23:59:00 61248 —-a-w- c:\windows\system32\OpenCL.dll 2012-02-29 23:59:00 5892928 —-a-w- c:\windows\system32\nvcuda.dll 2012-02-29 23:59:00 2517312 —-a-w- c:\windows\system32\nvcuvid.dll 2012-02-29 23:59:00 2437440 —-a-w- c:\windows\system32\nvcuvenc.dll 2012-02-29 23:59:00 2301248 —-a-w- c:\windows\system32\nvapi.dll 2012-02-29 23:59:00 19444544 —-a-w- c:\windows\system32\nvoglv32.dll 2012-02-29 23:59:00 17543488 —-a-w- c:\windows\system32\nvcompiler.dll 2012-02-29 23:59:00 15009600 —-a-w- c:\windows\system32\nvd3dum.dll 2012-02-29 23:59:00 10819392 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2012-02-29 23:59:00 1000256 —-a-w- c:\windows\system32\nvdispco32.dll 2012-02-29 20:56:41 3881792 —-a-w- c:\windows\system32\nvcpl.dll 2012-02-29 20:55:16 2719040 —-a-w- c:\windows\system32\nvsvc.dll 2012-02-29 20:53:47 108352 —-a-w- c:\windows\system32\nvmctray.dll 2012-02-29 20:53:46 645440 —-a-w- c:\windows\system32\nvvsvc.exe 2012-02-29 20:53:46 62272 —-a-w- c:\windows\system32\nvshext.dll 2012-02-29 20:53:45 2561344 —-a-w- c:\windows\system32\nvsvcr.dll 2012-02-19 04:35:28 92320 —-a-w- c:\users\hp\appdata\roaming\svhosts.exe 2012-02-08 03:16:14 1230496 —-a-w- c:\windows\adobearm.exe 2012-01-17 12:46:00 27968 —-a-w- c:\windows\system32\nvhdap32.dll 2012-01-17 12:45:59 67392 —-a-w- c:\windows\system32\nvapo32v.dll 2012-01-17 12:45:56 148800 —-a-w- c:\windows\system32\drivers\nvhda32v.sys 2012-01-04 08:58:41 442880 —-a-w- c:\windows\system32\ntshrui.dll 2011-12-30 05:27:56 478720 —-a-w- c:\windows\system32\timedate.cpl 2011-12-26 11:23:00 2184432 —-a-w- c:\windows\system32\btscan.exe . ============= FINISH: 13:22:48.57 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Enterprise K Boot Device: \Device\HarddiskVolume1 Install Date: 2010-12-21 오후 5:10:29 System Uptime: 2012-03-24 오후 1:09:59 (0 hours ago) . Motherboard: Compal | | 306D Processor: Intel® Core™2 Duo CPU P7450 @ 2.13GHz | CPU | 2133/1066mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 111 GiB total, 46.518 GiB free. D: is FIXED (NTFS) - 178 GiB total, 171.956 GiB free. E: is FIXED (NTFS) - 9 GiB total, 1.616 GiB free. F: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: Description: Device ID: ACPI\ENE0100\3&21436425&0 Manufacturer: Name: PNP Device ID: ACPI\ENE0100\3&21436425&0 Service: . ==== System Restore Points =================== . RP140: 2012-03-22 오전 12:57:19 - 예약된 검사점 RP141: 2012-03-22 오전 3:42:36 - 복원 작업 RP143: 2012-03-22 오후 1:52:08 - DirectX 설치됨 . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) Adobe AIR Adobe Community Help Adobe Download Assistant Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.5.0 - Korean AhnLab Online Security Apple Application Support Apple Mobile Device Support Apple Software Update Bonjour CCleaner Character Builder Cisco NAC Agent Core Temp 1.0 RC3 Crystalline Solids D3DX10 DTS+AC3 필터 ESU for Microsoft Windows 7 Google Chrome Google Update Helper Hotspot Shield 1.56 HP Product Detection HP Quick Launch Buttons IDT Audio iTunes Java Auto Updater Java™ 6 Update 29 League of Legends Logger Pro 3.8 LoggerPro3 Lunia Malwarebytes Anti-Malware version 1.60.1.1000 MapleStory McAfee Agent McAfee Security Scan Plus McAfee VirusScan Enterprise Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (Korean) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel 2007 Help 업데이트 (KB963678) Microsoft Office Excel MUI (Korean) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (Korean) 2007 Microsoft Office IME (Korean) 2007 Microsoft Office InfoPath MUI (Korean) 2007 Microsoft Office OneNote MUI (Korean) 2007 Microsoft Office Outlook MUI (Korean) 2007 Microsoft Office Powerpoint 2007 Help 업데이트 (KB963669) Microsoft Office PowerPoint MUI (Korean) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (Korean) 2007 Microsoft Office Proofing (Korean) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (Korean) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared MUI (Korean) 2007 Microsoft Office Word 2007 Help 업데이트 (KB963665) Microsoft Office Word MUI (Korean) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft_VC80_ATL_x86 Microsoft_VC80_CRT_x86 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFCLOC_x86 Microsoft_VC90_ATL_x86 Microsoft_VC90_CRT_x86 Microsoft_VC90_MFC_x86 Microsoft_VC90_MFCLOC_x86 Mozilla Firefox 11.0 (x86 ko) MSVCRT Nexon Game Manager Nowcom 파일전송관리자 NVIDIA HD 오디오 드라이버 [removed] NVIDIA Install Application NVIDIA PhysX NVIDIA PhysX 시스템 소프트웨어 260.99 NVIDIA Update Components NVIDIA 그래픽 드라이버 296.10 NVIDIA 업데이트 1.7.11 NVIDIA 제어판 296.10 Pando Media Booster ProtectSmart Hard Drive Protection QLBCASL QuickTime REACTOR Realtek USB 2.0 Card Reader Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Spartan Student V4.1.2 Steam Synaptics Pointing Device Driver System Requirements Lab System Requirements Lab CYRI Team Fortress 2 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2597970) 32-Bit Edition Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition Update for Microsoft Office Script Editor Help (KB963671) Validity Sensors DDK Ventrilo Client Windows Live Communications Platform Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Messenger Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live 필수 패키지 곰TV 스트리머 곰TV 플러그인 곰TV도우미 제거 곰TV알리미 제거 곰플레이어 반디소프트 MPEG-1 디코더 반디캠 터치 드라이버 한글과컴퓨터 한글 2007 . ==== End Of File =========================== CKScanner - Additional Security Risks - These are not necessarily bad c:\allm\lunia\sounds\ambience\myth_treecrack.ogg scanner sequence 3.NA.11.NHAPWA —– EOF —– aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-03-24 13:26:22 —————————– 13:26:22.654 OS Version: Windows 6.1.7601 Service Pack 1 13:26:22.654 Number of processors: 2 586 0x1706 13:26:22.656 ComputerName: HP-PC UserName: HP 13:26:24.209 Initialize success 13:30:08.030 AVAST engine defs: 12032302 13:30:17.327 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 13:30:17.329 Disk 0 Vendor: Hitachi_HTS543232L9A300 FB4OC40J Size: 305245MB BusType: 11 13:30:17.351 Disk 0 MBR read successfully 13:30:17.354 Disk 0 MBR scan 13:30:17.366 Disk 0 unknown MBR code 13:30:17.376 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 113260 MB offset 2048 13:30:17.419 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 182578 MB offset 231958528 13:30:17.453 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 9402 MB offset 605880320 13:30:17.467 Disk 0 scanning sectors +625135616 13:30:17.538 Disk 0 scanning C:\Windows\system32\drivers 13:30:53.276 Service scanning 13:31:37.677 Service Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys **LOCKED** 32 13:31:41.524 Modules scanning 13:31:55.693 Disk 0 trace - called modules: 13:31:55.718 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS >>UNKNOWN [0x86de6979]<< 13:31:55.723 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86bba6f0] 13:31:55.729 3 CLASSPNP.SYS[8bc5259e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x86a87908] 13:31:56.579 AVAST engine scan C:\Windows 13:31:58.333 File: C:\Windows\adobearm.exe **INFECTED** Win32:Malware-gen 13:32:01.534 AVAST engine scan C:\Windows\system32 13:38:43.811 AVAST engine scan C:\Windows\system32\drivers 13:39:29.419 AVAST engine scan C:\Users\HP 13:41:13.673 File: C:\Users\HP\AppData\Roaming\svhosts.exe **INFECTED** Win32:VBCrypt-PX [Trj] 13:45:05.124 File: C:\Users\HP\Downloads\Shockwave_Flash_Installer (1).exe **INFECTED** Win32:Malware-gen 13:45:08.528 File: C:\Users\HP\Downloads\Shockwave_Flash_Installer.exe **INFECTED** Win32:Malware-gen 13:46:20.376 AVAST engine scan C:\ProgramData 13:53:42.164 Scan finished successfully 14:03:06.405 Disk 0 MBR has been saved successfully to "C:\Users\HP\Desktop\MBR.dat" 14:03:06.417 The log file has been saved successfully to "C:\Users\HP\Desktop\aswMBR.txt" Here it is!

Attachments:

Hi,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 12-03-22.01 - HP 2012-03-25 4:11.1.2 - x86 Microsoft Windows 7 Enterprise K 6.1.7601.1.949.82.1042.18.3039.1974 [GMT 9:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: V3 Lite *Enabled/Updated* {B5892DA8-3D3D-75E1-6A57-1270334145D3} SP: V3 Lite *Enabled/Updated* {0EE8CC4C-1B07-7A6F-50E7-290248C60F6E} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . Error: Cfiles.dat . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Hotspot Shield\HssIE\HsSIe.dll c:\programdata\Tarma Installer c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setup.dll c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setupx.dll c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.dat c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.exe c:\programdata\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\Setup.ico c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setup.dll c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.dat c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.exe c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\Setup.ico c:\users\HP\AppData\Local\{313A863A-14AB-4171-B625-945C19559C78} c:\users\HP\AppData\Local\{313A863A-14AB-4171-B625-945C19559C78}\chrome.manifest c:\users\HP\AppData\Local\{313A863A-14AB-4171-B625-945C19559C78}\chrome\content\_cfg.js c:\users\HP\AppData\Local\{313A863A-14AB-4171-B625-945C19559C78}\chrome\content\overlay.xul c:\users\HP\AppData\Local\{313A863A-14AB-4171-B625-945C19559C78}\install.rdf c:\users\HP\Favorites\쇼핑 스트리트, 11번가.url . . ((((((((((((((((((((((((( Files Created from 2012-02-24 to 2012-03-24 ))))))))))))))))))))))))))))))) . . 2012-03-24 19:20 . 2012-03-24 19:20 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-03-23 21:36 . 2012-03-23 21:36 14664 —-a-w- c:\windows\stinger.sys 2012-03-23 21:35 . 2012-03-23 22:46 ——– d—–w- c:\program files\stinger 2012-03-23 21:32 . 2012-03-23 21:32 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2012-03-22 07:50 . 2012-03-22 07:50 ——– d—–w- c:\program files\Core Temp 2012-03-22 04:55 . 2012-03-22 04:55 ——– d—–w- c:\users\UpdatusUser 2012-03-22 04:53 . 2008-05-30 05:11 467984 —-a-w- c:\windows\system32\d3dx10_38.dll 2012-03-22 04:50 . 2012-01-17 12:45 67392 —-a-w- c:\windows\system32\nvapo32v.dll 2012-03-21 23:57 . 2012-03-21 23:57 ——– d—–w- c:\programdata\RegInOut 2012-03-21 23:57 . 2012-03-21 23:57 ——– d—–w- c:\windows\RegInOut System Utilities 2012-03-17 21:09 . 2012-03-17 21:09 592824 —-a-w- c:\program files\Mozilla Firefox\gkmedias.dll 2012-03-17 21:09 . 2012-03-17 21:09 44472 —-a-w- c:\program files\Mozilla Firefox\mozglue.dll 2012-03-14 09:00 . 2011-11-19 14:50 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-03-14 09:00 . 2011-11-19 14:50 3913584 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-13 19:49 . 2012-02-03 03:54 2343424 —-a-w- c:\windows\system32\win32k.sys 2012-03-13 19:48 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\system32\DWrite.dll 2012-03-13 19:48 . 2012-01-25 05:32 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-03-13 19:48 . 2012-01-25 05:32 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-03-13 19:48 . 2012-01-25 05:27 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-13 19:48 . 2012-02-17 05:34 919040 —-a-w- c:\windows\system32\rdpcorets.dll 2012-03-13 19:48 . 2012-02-17 05:34 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-03-13 19:48 . 2012-02-17 04:14 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-13 19:48 . 2012-02-17 04:13 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-02-26 06:24 . 2011-05-16 11:36 1654869 —-a-w- c:\programdata\DynuEncrypt.dll 2012-02-26 06:20 . 2010-07-27 07:13 27136 —-a-w- c:\program files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll 2012-02-26 06:20 . 2010-03-24 07:57 713312 —-a-w- c:\windows\system32\ijjiSetup.exe 2012-02-26 06:20 . 2010-03-24 07:56 62048 —-a-w- c:\windows\system32\ijjiProcessRestarter.exe 2012-02-26 06:20 . 2012-02-26 06:21 ——– d—–w- c:\program files\REACTOR 2012-02-26 06:14 . 2012-02-26 06:14 ——– d—–w- C:\Allm . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-23 21:35 . 2011-01-03 00:06 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-03-23 21:35 . 2011-01-03 00:06 475704 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2012-03-23 21:35 . 2011-01-03 00:06 159608 —-a-w- c:\windows\system32\mfevtps.exe 2012-03-04 21:30 . 2011-05-18 21:26 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-29 23:59 . 2010-12-22 16:11 15009600 —-a-w- c:\windows\system32\nvd3dum.dll 2012-02-29 23:59 . 2009-07-23 06:01 7713088 —-a-w- c:\windows\system32\nvwgf2um.dll 2012-02-29 23:59 . 2009-07-23 06:01 2301248 —-a-w- c:\windows\system32\nvapi.dll 2012-02-29 20:56 . 2010-10-16 03:42 3881792 —-a-w- c:\windows\system32\nvcpl.dll 2012-02-29 20:55 . 2010-10-16 03:42 2719040 —-a-w- c:\windows\system32\nvsvc.dll 2012-02-29 20:53 . 2010-10-16 03:42 108352 —-a-w- c:\windows\system32\nvmctray.dll 2012-02-29 20:53 . 2010-10-16 03:42 645440 —-a-w- c:\windows\system32\nvvsvc.exe 2012-02-29 20:53 . 2009-07-23 06:39 62272 —-a-w- c:\windows\system32\nvshext.dll 2012-02-29 20:53 . 2010-10-16 03:42 2561344 —-a-w- c:\windows\system32\nvsvcr.dll 2012-02-19 04:35 . 2012-02-19 04:35 92320 —-a-w- c:\users\HP\AppData\Roaming\svhosts.exe 2012-02-08 03:16 . 2012-02-08 03:14 1230496 —-a-w- c:\windows\adobearm.exe 2012-01-04 08:58 . 2012-02-14 20:36 442880 —-a-w- c:\windows\system32\ntshrui.dll 2011-12-30 05:27 . 2012-02-14 20:36 478720 —-a-w- c:\windows\system32\timedate.cpl 2011-12-26 11:23 . 2010-12-21 08:50 2184432 —-a-w- c:\windows\system32\btscan.exe 2012-03-17 21:09 . 2011-05-06 01:10 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2009-04-29 11:07 . 2011-01-03 00:06 23864 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files\Steam\steam.exe" [2011-08-02 1242448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HncUpdate"="c:\program files\Common Files\Hnc\HncUtils\HncUpdate.exe" [2007-06-10 475136] "Korean IME Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE" [2006-10-26 26400] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-14 1541416] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 323640] "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-01-16 136512] "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-04-29 124240] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "NACAgentUI"="c:\program files\Cisco\Cisco NAC Agent\NACAgentUI.exe" [2011-01-06 524512] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-21 458844] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "adobearm"="c:\windows\adobearm.exe" [2012-02-08 1230496] . c:\users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 화면 캡처 및 시작 기능.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200412] Ime File REG_SZ IMKR12.IME . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2011-01-25 06:08 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google 업데이트 서비스 (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 136176] R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [2010-10-15 326704] R3 AhnFlt2k;AhnFlt2k;c:\windows\system32\Drivers\AhnFlt2k.sys [2010-12-21 52960] R3 AhnRec2k;AhnRec2k;c:\windows\system32\Drivers\AhnRec2k.sys [2010-12-21 20320] R3 ALSysIO;ALSysIO;c:\users\HP\AppData\Local\Temp\ALSysIO.sys [x] R3 CdmDrvNt;CdmDrvNt;c:\windows\system32\Drivers\CdmDrvNt.sys [2009-07-21 19616] R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x] R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [x] R3 gupdatem;Google 업데이트 서비스 (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 136176] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-03-23 40776] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-03-23 87656] R3 MfFWEnt;MfFWEnt;c:\program files\AhnLab\ASP\MyFirewall 4.0\MfFWEnt.sys [2010-06-28 101368] R3 MfIPSEnt;MfIPSEnt;c:\program files\AhnLab\ASP\MyFirewall 4.0\MfIPSEnt.sys [2010-06-28 121536] R3 Mkd2Bthf;Mkd2Bthf;c:\windows\system32\drivers\Mkd2Bthf.sys [2011-11-15 80656] R3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNt.sys [2011-11-15 138384] R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2011-11-15 92304] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows 정품 인증 기술 서비스;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-23 1343400] S1 AMonTDLH;AMonTDLH;c:\windows\system32\Drivers\AMonTDLH.sys [2010-07-12 87648] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe [2009-03-02 81920] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456] S2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [2009-04-29 21256] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-03-23 159608] S2 NACAgent;Cisco NAC Agent;c:\program files\Cisco\Cisco NAC Agent\NACAgent.exe [2011-01-06 1104608] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-29 2348352] S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2009-07-12 1656112] S2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [2009-07-23 98088] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2012-01-17 148800] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] S3 WacomVTHid;Virtual Touch Driver;c:\windows\system32\DRIVERS\WacomVTHid.sys [2009-05-20 13224] . . Contents of the 'Scheduled Tasks' folder . 2012-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 06:10] . 2012-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 06:10] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: Microsoft Excel로 내보내기(&X) - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = [removed] [removed] DPF: {4D2D3A17-9B46-483C-A5F4-1DC471080009} - hxxps://resnet-cca1-cpl.reshsg.uci.edu/auth/taweb.cab DPF: {8768D5EA-5412-4810-A032-09AD2A726C69} - hxxp://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab FF - ProfilePath - c:\users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\xppp7i3m.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.daum.net/ FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z171&form=ZGAADF&install_date=20111116&q= FF - prefs.js: network.proxy.type - 0 . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EverestDriver] "ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-03-25 04:22:56 ComboFix-quarantined-files.txt 2012-03-24 19:22 . Pre-Run: 52,194,422,784 바이트 남음 Post-Run: 52,270,960,640 바이트 남음 . - - End Of File - - 7FF0DBC97708505425E1A7C5F51DCC3A
Hi,

So are you actually in Korea? I was there for about 13 months myself. :)

I see that you are using V3 antivirus but I also see McAfee on your system as well. Are you still using McAfee because if not we can remove that.
———
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\adobearm.exe,
    BHO: ?TV???: {21ffec32-59ff-4a1f-bb42-7a315637617f} - c:\programdata\infofinder\gomtvhelper.dll
    BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
    
    Firefox::
    FF - ProfilePath - c:\users\hp\appdata\roaming\mozilla\firefox\profiles\xppp7i3m.default\
    FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Hello, I'm actually Korean, so I have Korean Windows 7 Laptop, but, I'm studying in US. The college dorm/campus didn't like Avast as antivirus, and it would trouble me to have internet access, and I installed McAfee unwillingly. Since now I've decided to not to use internet in campus, I want to install Avast or any other good free antivirus program and uninstall McAfee. It says I also have V3 Lite antivirus, but I deleted it a while ago. It must mean that it's still installed somewhere in the computer, but I don't see it in control panel. Anyways, here's the log. Thanks for the help so far! :) ComboFix 12-03-22.01 - HP 2012-03-25 5:56.2.2 - x86 Microsoft Windows 7 Enterprise K 6.1.7601.1.949.82.1042.18.3039.1875 [GMT 9:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\HP\Desktop\CFScript.txt AV: V3 Lite *Enabled/Updated* {B5892DA8-3D3D-75E1-6A57-1270334145D3} SP: V3 Lite *Enabled/Updated* {0EE8CC4C-1B07-7A6F-50E7-290248C60F6E} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Resident AV is active . . Error: Cfiles.dat . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\pando networks\media booster\npPandoWebPlugin.dll c:\programdata\infofinder\gomtvhelper.dll . . ((((((((((((((((((((((((( Files Created from 2012-02-24 to 2012-03-24 ))))))))))))))))))))))))))))))) . . 2012-03-24 21:06 . 2012-03-24 21:06 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-03-23 21:36 . 2012-03-23 21:36 14664 —-a-w- c:\windows\stinger.sys 2012-03-23 21:35 . 2012-03-23 22:46 ——– d—–w- c:\program files\stinger 2012-03-23 21:32 . 2012-03-23 21:32 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2012-03-22 07:50 . 2012-03-22 07:50 ——– d—–w- c:\program files\Core Temp 2012-03-22 04:55 . 2012-03-22 04:55 ——– d—–w- c:\users\UpdatusUser 2012-03-22 04:53 . 2008-05-30 05:11 467984 —-a-w- c:\windows\system32\d3dx10_38.dll 2012-03-22 04:50 . 2012-01-17 12:45 67392 —-a-w- c:\windows\system32\nvapo32v.dll 2012-03-21 23:57 . 2012-03-21 23:57 ——– d—–w- c:\programdata\RegInOut 2012-03-21 23:57 . 2012-03-21 23:57 ——– d—–w- c:\windows\RegInOut System Utilities 2012-03-17 21:09 . 2012-03-17 21:09 592824 —-a-w- c:\program files\Mozilla Firefox\gkmedias.dll 2012-03-17 21:09 . 2012-03-17 21:09 44472 —-a-w- c:\program files\Mozilla Firefox\mozglue.dll 2012-03-14 09:00 . 2011-11-19 14:50 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-03-14 09:00 . 2011-11-19 14:50 3913584 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-13 19:49 . 2012-02-03 03:54 2343424 —-a-w- c:\windows\system32\win32k.sys 2012-03-13 19:48 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\system32\DWrite.dll 2012-03-13 19:48 . 2012-01-25 05:32 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-03-13 19:48 . 2012-01-25 05:32 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-03-13 19:48 . 2012-01-25 05:27 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-13 19:48 . 2012-02-17 05:34 919040 —-a-w- c:\windows\system32\rdpcorets.dll 2012-03-13 19:48 . 2012-02-17 05:34 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-03-13 19:48 . 2012-02-17 04:14 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-13 19:48 . 2012-02-17 04:13 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-02-26 06:24 . 2011-05-16 11:36 1654869 —-a-w- c:\programdata\DynuEncrypt.dll 2012-02-26 06:20 . 2010-07-27 07:13 27136 —-a-w- c:\program files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll 2012-02-26 06:20 . 2010-03-24 07:57 713312 —-a-w- c:\windows\system32\ijjiSetup.exe 2012-02-26 06:20 . 2010-03-24 07:56 62048 —-a-w- c:\windows\system32\ijjiProcessRestarter.exe 2012-02-26 06:20 . 2012-02-26 06:21 ——– d—–w- c:\program files\REACTOR 2012-02-26 06:14 . 2012-02-26 06:14 ——– d—–w- C:\Allm . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-23 21:35 . 2011-01-03 00:06 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-03-23 21:35 . 2011-01-03 00:06 475704 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2012-03-23 21:35 . 2011-01-03 00:06 159608 —-a-w- c:\windows\system32\mfevtps.exe 2012-03-04 21:30 . 2011-05-18 21:26 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-29 23:59 . 2010-12-22 16:11 15009600 —-a-w- c:\windows\system32\nvd3dum.dll 2012-02-29 23:59 . 2009-07-23 06:01 7713088 —-a-w- c:\windows\system32\nvwgf2um.dll 2012-02-29 23:59 . 2009-07-23 06:01 2301248 —-a-w- c:\windows\system32\nvapi.dll 2012-02-29 20:56 . 2010-10-16 03:42 3881792 —-a-w- c:\windows\system32\nvcpl.dll 2012-02-29 20:55 . 2010-10-16 03:42 2719040 —-a-w- c:\windows\system32\nvsvc.dll 2012-02-29 20:53 . 2010-10-16 03:42 108352 —-a-w- c:\windows\system32\nvmctray.dll 2012-02-29 20:53 . 2010-10-16 03:42 645440 —-a-w- c:\windows\system32\nvvsvc.exe 2012-02-29 20:53 . 2009-07-23 06:39 62272 —-a-w- c:\windows\system32\nvshext.dll 2012-02-29 20:53 . 2010-10-16 03:42 2561344 —-a-w- c:\windows\system32\nvsvcr.dll 2012-02-19 04:35 . 2012-02-19 04:35 92320 —-a-w- c:\users\HP\AppData\Roaming\svhosts.exe 2012-02-08 03:16 . 2012-02-08 03:14 1230496 —-a-w- c:\windows\adobearm.exe 2012-01-04 08:58 . 2012-02-14 20:36 442880 —-a-w- c:\windows\system32\ntshrui.dll 2011-12-30 05:27 . 2012-02-14 20:36 478720 —-a-w- c:\windows\system32\timedate.cpl 2011-12-26 11:23 . 2010-12-21 08:50 2184432 —-a-w- c:\windows\system32\btscan.exe 2012-03-17 21:09 . 2011-05-06 01:10 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2009-04-29 11:07 . 2011-01-03 00:06 23864 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files\Steam\steam.exe" [2011-08-02 1242448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HncUpdate"="c:\program files\Common Files\Hnc\HncUtils\HncUpdate.exe" [2007-06-10 475136] "Korean IME Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE" [2006-10-26 26400] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-14 1541416] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 323640] "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-01-16 136512] "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-04-29 124240] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "NACAgentUI"="c:\program files\Cisco\Cisco NAC Agent\NACAgentUI.exe" [2011-01-06 524512] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-21 458844] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "adobearm"="c:\windows\adobearm.exe" [2012-02-08 1230496] . c:\users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 화면 캡처 및 시작 기능.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200412] Ime File REG_SZ IMKR12.IME . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2011-01-25 06:08 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google 업데이트 서비스 (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 136176] R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [2010-10-15 326704] R3 AhnFlt2k;AhnFlt2k;c:\windows\system32\Drivers\AhnFlt2k.sys [2010-12-21 52960] R3 AhnRec2k;AhnRec2k;c:\windows\system32\Drivers\AhnRec2k.sys [2010-12-21 20320] R3 ALSysIO;ALSysIO;c:\users\HP\AppData\Local\Temp\ALSysIO.sys [x] R3 CdmDrvNt;CdmDrvNt;c:\windows\system32\Drivers\CdmDrvNt.sys [2009-07-21 19616] R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x] R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [x] R3 gupdatem;Google 업데이트 서비스 (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 136176] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-03-23 40776] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-03-23 87656] R3 MfFWEnt;MfFWEnt;c:\program files\AhnLab\ASP\MyFirewall 4.0\MfFWEnt.sys [2010-06-28 101368] R3 MfIPSEnt;MfIPSEnt;c:\program files\AhnLab\ASP\MyFirewall 4.0\MfIPSEnt.sys [2010-06-28 121536] R3 Mkd2Bthf;Mkd2Bthf;c:\windows\system32\drivers\Mkd2Bthf.sys [2011-11-15 80656] R3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNt.sys [2011-11-15 138384] R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2011-11-15 92304] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows 정품 인증 기술 서비스;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-23 1343400] S1 AMonTDLH;AMonTDLH;c:\windows\system32\Drivers\AMonTDLH.sys [2010-07-12 87648] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe [2009-03-02 81920] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456] S2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [2009-04-29 21256] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-03-23 159608] S2 NACAgent;Cisco NAC Agent;c:\program files\Cisco\Cisco NAC Agent\NACAgent.exe [2011-01-06 1104608] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-29 2348352] S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2009-07-12 1656112] S2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [2009-07-23 98088] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2012-01-17 148800] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] S3 WacomVTHid;Virtual Touch Driver;c:\windows\system32\DRIVERS\WacomVTHid.sys [2009-05-20 13224] . . Contents of the 'Scheduled Tasks' folder . 2012-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 06:10] . 2012-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 06:10] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: Microsoft Excel로 내보내기(&X;) - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = [removed] [removed] DPF: {4D2D3A17-9B46-483C-A5F4-1DC471080009} - hxxps://resnet-cca1-cpl.reshsg.uci.edu/auth/taweb.cab DPF: {8768D5EA-5412-4810-A032-09AD2A726C69} - hxxp://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab FF - ProfilePath - c:\users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\xppp7i3m.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.daum.net/ FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z171&form;=ZGAADF&install;_date=20111116&q;= FF - prefs.js: network.proxy.type - 0 . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EverestDriver] "ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-03-25 06:17:46 ComboFix-quarantined-files.txt 2012-03-24 21:17 ComboFix2.txt 2012-03-24 19:22 . Pre-Run: 52,339,105,792 바이트 남음 Post-Run: 51,914,256,384 바이트 남음 . - - End Of File - - 7C4DC5864D3BA9BCC344EEA9B307B6E0
Hi DJKara,

Since now I've decided to not to use internet in campus, I want to install Avast or any other good free antivirus program and uninstall McAfee.

Let's get a couple more things done where I know your system is stable and then we can remove the other antivirus programs and get you a good, quality free one to use.
———-

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]
  • Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
———-

In your next reply please post the logs made by Malwarebytes and ESET online scanner.
Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org Database version: v2012.03.21.02 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 8.0.7601.17514 HP :: HP-PC [administrator] 2012-03-25 오전 6:39:48 mbam-log-2012-03-25 (06-39-48).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 208029 Time elapsed: 5 minute(s), 28 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) C:\Program Files\Hotspot Shield\bin\openvpnas.exe a variant of Win32/HotSpotShield application C:\Qoobox\Quarantine\C\ProgramData\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application C:\Qoobox\Quarantine\C\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application C:\Users\HP\AppData\Roaming\svhosts.exe a variant of Win32/Injector.NWX trojan C:\Users\HP\Downloads\BestVideoDownloaderSetup-OL(1).exe probably a variant of Win32/Adware.BMPKECQ application C:\Users\HP\Downloads\BestVideoDownloaderSetup-OL.exe probably a variant of Win32/Adware.BMPKECQ application C:\Users\HP\Downloads\cnet_arpr_zip.exe a variant of Win32/InstallCore.D application C:\Users\HP\Downloads\cnet_rpc412_zip.exe a variant of Win32/InstallCore.D application C:\Users\HP\Downloads\setup.exe Win32/Toolbar.Zugo application C:\Users\HP\Downloads\Shockwave_Flash_Installer (1).exe Win32/Lypserat.A trojan C:\Users\HP\Downloads\Shockwave_Flash_Installer.exe Win32/Lypserat.A trojan C:\Windows\adobearm.exe Win32/Lypserat.A trojan
Hi,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    File::
    C:\Program Files\Hotspot Shield\bin\openvpnas.exe	
    C:\Users\HP\AppData\Roaming\svhosts.exe	
    C:\Users\HP\Downloads\BestVideoDownloaderSetup-OL(1).exe	
    C:\Users\HP\Downloads\BestVideoDownloaderSetup-OL.exe	
    C:\Users\HP\Downloads\cnet_arpr_zip.exe	
    C:\Users\HP\Downloads\cnet_rpc412_zip.exe	
    C:\Users\HP\Downloads\setup.exe	
    C:\Users\HP\Downloads\Shockwave_Flash_Installer (1).exe	
    C:\Users\HP\Downloads\Shockwave_Flash_Installer.exe	
    C:\Windows\adobearm.exe	Win32/Lypserat.A trojan
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

In your next reply please post the log created by ComboFix and let me know how your system is running.
ComboFix 12-03-22.01 - HP 2012-03-25 9:19.3.2 - x86 Microsoft Windows 7 Enterprise K 6.1.7601.1.949.82.1042.18.3039.1751 [GMT 9:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\HP\Desktop\CFScript.txt AV: V3 Lite *Enabled/Updated* {B5892DA8-3D3D-75E1-6A57-1270334145D3} SP: V3 Lite *Enabled/Updated* {0EE8CC4C-1B07-7A6F-50E7-290248C60F6E} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Resident AV is active . . FILE :: "c:\program files\Hotspot Shield\bin\openvpnas.exe" "c:\users\HP\AppData\Roaming\svhosts.exe" "c:\users\HP\Downloads\BestVideoDownloaderSetup-OL(1).exe" "c:\users\HP\Downloads\BestVideoDownloaderSetup-OL.exe" "c:\users\HP\Downloads\cnet_arpr_zip.exe" "c:\users\HP\Downloads\cnet_rpc412_zip.exe" "c:\users\HP\Downloads\setup.exe" "c:\users\HP\Downloads\Shockwave_Flash_Installer (1).exe" "c:\users\HP\Downloads\Shockwave_Flash_Installer.exe" "c:\windows\adobearm.exe Win32/Lypserat.A trojan" . Error: Cfiles.dat . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Hotspot Shield\bin\openvpnas.exe c:\users\HP\AppData\Roaming\svhosts.exe c:\users\HP\Downloads\BestVideoDownloaderSetup-OL(1).exe c:\users\HP\Downloads\BestVideoDownloaderSetup-OL.exe c:\users\HP\Downloads\cnet_arpr_zip.exe c:\users\HP\Downloads\cnet_rpc412_zip.exe c:\users\HP\Downloads\setup.exe c:\users\HP\Downloads\Shockwave_Flash_Installer (1).exe c:\users\HP\Downloads\Shockwave_Flash_Installer.exe . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_HotspotShieldService . . ((((((((((((((((((((((((( Files Created from 2012-02-25 to 2012-03-25 ))))))))))))))))))))))))))))))) . . 2012-03-25 00:29 . 2012-03-25 00:29 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-03-24 21:42 . 2012-03-24 21:42 ——– d—–w- c:\program files\ESET 2012-03-23 21:36 . 2012-03-23 21:36 14664 —-a-w- c:\windows\stinger.sys 2012-03-23 21:35 . 2012-03-23 22:46 ——– d—–w- c:\program files\stinger 2012-03-22 07:50 . 2012-03-22 07:50 ——– d—–w- c:\program files\Core Temp 2012-03-22 04:55 . 2012-03-22 04:55 ——– d—–w- c:\users\UpdatusUser 2012-03-22 04:53 . 2008-05-30 05:11 467984 —-a-w- c:\windows\system32\d3dx10_38.dll 2012-03-22 04:50 . 2012-01-17 12:45 67392 —-a-w- c:\windows\system32\nvapo32v.dll 2012-03-21 23:57 . 2012-03-21 23:57 ——– d—–w- c:\programdata\RegInOut 2012-03-21 23:57 . 2012-03-21 23:57 ——– d—–w- c:\windows\RegInOut System Utilities 2012-03-17 21:09 . 2012-03-17 21:09 592824 —-a-w- c:\program files\Mozilla Firefox\gkmedias.dll 2012-03-17 21:09 . 2012-03-17 21:09 44472 —-a-w- c:\program files\Mozilla Firefox\mozglue.dll 2012-03-14 09:00 . 2011-11-19 14:50 3968368 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-03-14 09:00 . 2011-11-19 14:50 3913584 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-13 19:49 . 2012-02-03 03:54 2343424 —-a-w- c:\windows\system32\win32k.sys 2012-03-13 19:48 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\system32\DWrite.dll 2012-03-13 19:48 . 2012-01-25 05:32 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-03-13 19:48 . 2012-01-25 05:32 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-03-13 19:48 . 2012-01-25 05:27 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-13 19:48 . 2012-02-17 05:34 919040 —-a-w- c:\windows\system32\rdpcorets.dll 2012-03-13 19:48 . 2012-02-17 05:34 826880 —-a-w- c:\windows\system32\rdpcore.dll 2012-03-13 19:48 . 2012-02-17 04:14 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-13 19:48 . 2012-02-17 04:13 24576 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-02-26 06:24 . 2011-05-16 11:36 1654869 —-a-w- c:\programdata\DynuEncrypt.dll 2012-02-26 06:20 . 2010-07-27 07:13 27136 —-a-w- c:\program files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll 2012-02-26 06:20 . 2010-03-24 07:57 713312 —-a-w- c:\windows\system32\ijjiSetup.exe 2012-02-26 06:20 . 2010-03-24 07:56 62048 —-a-w- c:\windows\system32\ijjiProcessRestarter.exe 2012-02-26 06:20 . 2012-02-26 06:21 ——– d—–w- c:\program files\REACTOR 2012-02-26 06:14 . 2012-02-26 06:14 ——– d—–w- C:\Allm . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-23 21:35 . 2011-01-03 00:06 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-03-23 21:35 . 2011-01-03 00:06 475704 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2012-03-23 21:35 . 2011-01-03 00:06 159608 —-a-w- c:\windows\system32\mfevtps.exe 2012-03-04 21:30 . 2011-05-18 21:26 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-29 23:59 . 2010-12-22 16:11 15009600 —-a-w- c:\windows\system32\nvd3dum.dll 2012-02-29 23:59 . 2009-07-23 06:01 7713088 —-a-w- c:\windows\system32\nvwgf2um.dll 2012-02-29 23:59 . 2009-07-23 06:01 2301248 —-a-w- c:\windows\system32\nvapi.dll 2012-02-29 20:56 . 2010-10-16 03:42 3881792 —-a-w- c:\windows\system32\nvcpl.dll 2012-02-29 20:55 . 2010-10-16 03:42 2719040 —-a-w- c:\windows\system32\nvsvc.dll 2012-02-29 20:53 . 2010-10-16 03:42 108352 —-a-w- c:\windows\system32\nvmctray.dll 2012-02-29 20:53 . 2010-10-16 03:42 645440 —-a-w- c:\windows\system32\nvvsvc.exe 2012-02-29 20:53 . 2009-07-23 06:39 62272 —-a-w- c:\windows\system32\nvshext.dll 2012-02-29 20:53 . 2010-10-16 03:42 2561344 —-a-w- c:\windows\system32\nvsvcr.dll 2012-02-08 03:16 . 2012-02-08 03:14 1230496 —-a-w- c:\windows\adobearm.exe 2012-01-04 08:58 . 2012-02-14 20:36 442880 —-a-w- c:\windows\system32\ntshrui.dll 2011-12-30 05:27 . 2012-02-14 20:36 478720 —-a-w- c:\windows\system32\timedate.cpl 2011-12-26 11:23 . 2010-12-21 08:50 2184432 —-a-w- c:\windows\system32\btscan.exe 2012-03-17 21:09 . 2011-05-06 01:10 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2009-04-29 11:07 . 2011-01-03 00:06 23864 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll . . ((((((((((((((((((((((((((((( SnapShot@2012-03-24_21.06.34 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 04:55 . 2012-03-25 00:34 47826 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-12-21 08:49 . 2012-03-25 00:34 10644 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-848307109-4102649943-52888667-1000_UserData.bin + 2010-12-21 08:02 . 2012-03-25 00:31 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-12-21 08:02 . 2012-03-24 18:41 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:41 . 2012-03-24 18:41 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:41 . 2012-03-25 00:31 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-12-22 04:00 . 2012-03-25 00:33 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-12-22 04:00 . 2012-03-24 18:42 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-12-22 04:00 . 2012-03-25 00:33 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2010-12-22 04:00 . 2012-03-24 18:42 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2010-12-22 04:00 . 2012-03-24 18:42 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-12-22 04:00 . 2012-03-25 00:33 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2010-12-21 10:06 . 2012-03-24 20:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-12-21 10:06 . 2012-03-25 00:33 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-12-21 10:06 . 2012-03-24 20:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-12-21 10:06 . 2012-03-25 00:33 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2012-03-24 18:41 . 2012-03-24 18:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-03-24 18:41 . 2012-03-25 00:31 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-03-24 18:41 . 2012-03-24 18:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-03-24 18:41 . 2012-03-25 00:31 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2010-12-21 08:02 . 2012-03-24 18:41 344064 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2010-12-21 08:02 . 2012-03-25 00:31 344064 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files\Steam\steam.exe" [2011-08-02 1242448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HncUpdate"="c:\program files\Common Files\Hnc\HncUtils\HncUpdate.exe" [2007-06-10 475136] "Korean IME Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE" [2006-10-26 26400] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-14 1541416] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 323640] "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-01-16 136512] "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-04-29 124240] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "NACAgentUI"="c:\program files\Cisco\Cisco NAC Agent\NACAgentUI.exe" [2011-01-06 524512] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-21 458844] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "adobearm"="c:\windows\adobearm.exe" [2012-02-08 1230496] . c:\users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 화면 캡처 및 시작 기능.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="c:\windows\system32\userinit.exe,c:\windows\adobearm.exe" . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200412] Ime File REG_SZ IMKR12.IME . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2011-01-25 06:08 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google 업데이트 서비스 (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 136176] R3 AhnFlt2k;AhnFlt2k;c:\windows\system32\Drivers\AhnFlt2k.sys [2010-12-21 52960] R3 AhnRec2k;AhnRec2k;c:\windows\system32\Drivers\AhnRec2k.sys [2010-12-21 20320] R3 ALSysIO;ALSysIO;c:\users\HP\AppData\Local\Temp\ALSysIO.sys [x] R3 CdmDrvNt;CdmDrvNt;c:\windows\system32\Drivers\CdmDrvNt.sys [2009-07-21 19616] R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x] R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [x] R3 gupdatem;Google 업데이트 서비스 (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 136176] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-03-23 87656] R3 MfFWEnt;MfFWEnt;c:\program files\AhnLab\ASP\MyFirewall 4.0\MfFWEnt.sys [2010-06-28 101368] R3 MfIPSEnt;MfIPSEnt;c:\program files\AhnLab\ASP\MyFirewall 4.0\MfIPSEnt.sys [2010-06-28 121536] R3 Mkd2Bthf;Mkd2Bthf;c:\windows\system32\drivers\Mkd2Bthf.sys [2011-11-15 80656] R3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNt.sys [2011-11-15 138384] R3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2011-11-15 92304] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows 정품 인증 기술 서비스;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-23 1343400] S1 AMonTDLH;AMonTDLH;c:\windows\system32\Drivers\AMonTDLH.sys [2010-07-12 87648] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe [2009-03-02 81920] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456] S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [2010-10-15 326704] S2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [2009-04-29 21256] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-03-23 159608] S2 NACAgent;Cisco NAC Agent;c:\program files\Cisco\Cisco NAC Agent\NACAgent.exe [2011-01-06 1104608] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-29 2348352] S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2009-07-12 1656112] S2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [2009-07-23 98088] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2012-01-17 148800] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776] S3 WacomVTHid;Virtual Touch Driver;c:\windows\system32\DRIVERS\WacomVTHid.sys [2009-05-20 13224] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-03-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 06:10] . 2012-03-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-09-25 06:10] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: Microsoft Excel로 내보내기(&X) - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = [removed] [removed] DPF: {4D2D3A17-9B46-483C-A5F4-1DC471080009} - hxxps://resnet-cca1-cpl.reshsg.uci.edu/auth/taweb.cab DPF: {8768D5EA-5412-4810-A032-09AD2A726C69} - hxxp://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab FF - ProfilePath - c:\users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\xppp7i3m.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.daum.net/ FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z171&form=ZGAADF&install_date=20111116&q= FF - prefs.js: network.proxy.type - 0 . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EverestDriver] "ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\STacSV.exe c:\program files\NVIDIA Corporation\Display\nvxdsync.exe c:\windows\system32\nvvsvc.exe c:\windows\SYSTEM32\WISPTIS.EXE c:\windows\SYSTEM32\WISPTIS.EXE c:\program files\Common Files\microsoft shared\ink\TabTip.exe c:\program files\WTouch\WTouchUser.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\system32\taskhost.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Hotspot Shield\HssWPR\hsssrv.exe c:\windows\system32\conhost.exe c:\program files\McAfee\Common Framework\FrameworkService.exe c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe c:\program files\McAfee\Common Framework\naPrdMgr.exe c:\program files\Synaptics\SynTP\SynTPHelper.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\NVIDIA Corporation\Display\nvtray.exe c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\McAfee\VirusScan Enterprise\mfeann.exe c:\windows\system32\conhost.exe c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe c:\windows\system32\UI0Detect.exe c:\windows\system32\UI0Detect.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe c:\windows\system32\sppsvc.exe . ************************************************************************** . Completion time: 2012-03-25 09:47:02 - machine was rebooted ComboFix-quarantined-files.txt 2012-03-25 00:46 ComboFix2.txt 2012-03-24 21:17 ComboFix3.txt 2012-03-24 19:22 . Pre-Run: 51,547,467,776 바이트 남음 Post-Run: 51,324,186,624 바이트 남음 . - - End Of File - - 40DBD74BAEAFA841A00130E715B9DD2A
hm….. As of now, I can't go into google, or bing. I can go into yahoo, youtube, or any other common sites. I'm not very bright on computers and technical stuff, so i don't know what symptoms I'm suppsed to see after… Thanks for the help so far :)
Hi,

Ok…let's do the following…

Press Start
Type Run into the Start Search bar and when Run populates above select it

Now copy/paste the following into the Run bar and press OK…

cmd del c:\windows\adobearm.exe /f /q
————

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Farbar Service Scanner Version: 01-03-2012 Ran by [removed] (administrator) on 25-03-2012 at 10:34:03 Running from "C:\Users\HP\Desktop" Microsoft Windows 7 Enterprise K Service Pack 1 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Yahoo IP is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcore.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log ****

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI