hi my anti virus keeps detecting a virus but fails to remove it. it tells me it is blocking viruses on my computer and happens on every web page that message comes up. im using bitdefender. thanks
Hi and Welcome!!
My name is
Jeff . I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision .
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
———-
Please download DDS from one of the following links and save it to your desktop.
Disable any script blocking protection (How to Disable your Security Programs ) Double click DDS icon to run the tool (may take up to 3 minutes to run) When done, DDS.txt will open. After a few moments, attach.txt will open in a second window. Save both reports to your desktop. —————————————————
Post the contents of the DDS.txt report in your next replyAttach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse . Browse to where you saved the file, and click Open and then click UPLOAD .
———-
Please download
aswMBR to your desktop.
Double click the aswMBR icon to run it.
Vista and Windows 7 users right click the icon and choose "Run as administrator" . Click the Scan button to start scan. When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
Click the image to enlarge it
———-
In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 10:01:58 on 2012-04-11
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8174.6298 [GMT -4:00]
.
AV: Bitdefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Bitdefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
FW: Bitdefender Firewall *Enabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Bitdefender\Bitdefender 2012\bdagent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_2_202_228_ActiveX.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SoftwareDistribution\Download\Install\NDP40-KB2656368-x64.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Bar = Preserve
uInternet Settings,ProxyOverride = 127.0.0.1:9421
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
TCP: DhcpNameServer = [removed] [removed] 192.168.1.1
TCP: Interfaces\{0F716DF8-2219-4192-A13F-41621AEBA92B} : DhcpNameServer = [removed] [removed] 192.168.1.1
TCP: Interfaces\{11C1EE4A-EBA1-4ABE-9C26-A34A2CAD753A} : DhcpNameServer = [removed] [removed] 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO-X64: 0x1 - No File
BHO-X64: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
BHO-X64: McAfee Phishing Filter - No File
BHO-X64: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
.
============= SERVICES / DRIVERS ===============
.
R0 avc3;avc3;C:\Windows\system32\DRIVERS\avc3.sys –> C:\Windows\system32\DRIVERS\avc3.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [2011-11-14 90192]
R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2011-11-14 103504]
R1 BDVEDISK;BDVEDISK;C:\Windows\system32\DRIVERS\bdvedisk.sys –> C:\Windows\system32\DRIVERS\bdvedisk.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-6-1 13336]
R2 UPDATESRV;BitDefender Desktop Update Service;C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe [2012-3-13 66096]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys –> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 avchv;avchv Function Driver;C:\Windows\system32\DRIVERS\avchv.sys –> C:\Windows\system32\DRIVERS\avchv.sys [?]
R3 avckf;avckf;C:\Windows\system32\DRIVERS\avckf.sys –> C:\Windows\system32\DRIVERS\avckf.sys [?]
R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys –> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys –> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-29 253600]
S3 bdsandbox;bdsandbox;\??\C:\Windows\system32\drivers\bdsandbox.sys –> C:\Windows\system32\drivers\bdsandbox.sys [?]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys –> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
S3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys –> C:\Windows\system32\DRIVERS\Impcd.sys [?]
S3 LeapFrog-USBLAN;LeapFrog-USBLAN;C:\Windows\system32\DRIVERS\btblan.sys –> C:\Windows\system32\DRIVERS\btblan.sys [?]
S3 McAWFwk;McAfee Activation Service;c:\PROGRA~1\mcafee\msc\mcawfwk.exe –> c:\PROGRA~1\mcafee\msc\mcawfwk.exe [?]
S3 pmxdrv;pmxdrv;\??\C:\Windows\system32\drivers\pmxdrv.sys –> C:\Windows\system32\drivers\pmxdrv.sys [?]
S3 SafeBox;SafeBox;C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe [2012-2-21 75384]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 Update Server;BitDefender Update Server v2;C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe [2011-10-14 466736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
JSEFile=NOTEPAD.EXE %1
regfile=NOTEPAD.EXE %1
scrfile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2012-04-11 14:02:02 ——– d—–w- C:\d2ca49080448910cf36d68
2012-04-11 05:55:39 5559152 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-04-11 05:55:39 3968368 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-04-11 05:55:39 3913072 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-04-11 05:54:05 81408 —-a-w- C:\Windows\System32\imagehlp.dll
2012-04-11 05:54:05 5120 —-a-w- C:\Windows\SysWow64\wmi.dll
2012-04-11 05:54:05 5120 —-a-w- C:\Windows\System32\wmi.dll
2012-04-11 05:54:05 23408 —-a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-04-11 05:54:05 220672 —-a-w- C:\Windows\System32\wintrust.dll
2012-04-11 05:54:05 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll
2012-04-11 05:54:05 159232 —-a-w- C:\Windows\SysWow64\imagehlp.dll
2012-04-04 03:33:49 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{3BE5F393-E15F-40DD-94C5-EE853D895174}
2012-04-02 21:35:15 210561 —-a-w- C:\ProgramData\1333402294.bdinstall.bin
2012-04-02 21:34:58 ——– d—–w- C:\ProgramData\BDLogging
2012-04-02 21:34:33 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Roaming\Bitdefender
2012-04-02 21:34:31 ——– d—–w- C:\ProgramData\Bitdefender
2012-04-02 21:32:04 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Roaming\QuickScan
2012-04-02 21:31:54 ——– d—–w- C:\Program Files\Bitdefender
2012-04-02 21:31:39 442088 —-a-w- C:\Windows\System32\drivers\bdfsfltr.sys
2012-04-02 21:31:39 329800 —-a-w- C:\Windows\System32\drivers\trufos.sys
2012-04-02 21:31:27 ——– d—–w- C:\Program Files\Common Files\Bitdefender
2012-04-02 04:43:52 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{44083660-15AC-4725-8127-66023ED0FFBF}
2012-03-29 11:08:02 418464 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-03-27 07:10:27 ——– d—–r- C:\Program Files (x86)\Skype
2012-03-25 13:37:44 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{A58AEE26-98F5-4620-A15E-61B998AA138E}
2012-03-25 13:37:33 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{5F3433CE-425D-4E0F-B2F9-2A225F0554BB}
2012-03-21 22:07:28 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{D53D4FDB-DF1D-4C43-82E0-034E0FF7FA39}
2012-03-21 22:07:17 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{FB659531-B7BF-4CCF-A551-D1DAEFDAC91C}
2012-03-21 00:22:46 691896 —-a-w- C:\Windows\System32\drivers\avc3.sys
2012-03-16 02:56:36 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\Mozilla
2012-03-16 02:16:11 ——– d—–w- C:\ProgramData\IBUpdaterService
2012-03-16 01:35:25 525544 —-a-w- C:\Windows\System32\deployJava1.dll
2012-03-15 21:24:44 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-03-14 15:07:10 3145728 —-a-w- C:\Windows\System32\win32k.sys
2012-03-14 15:07:08 1544192 —-a-w- C:\Windows\System32\DWrite.dll
2012-03-14 15:07:08 1077248 —-a-w- C:\Windows\SysWow64\DWrite.dll
2012-03-14 15:06:56 826880 —-a-w- C:\Windows\SysWow64\rdpcore.dll
2012-03-14 15:06:56 23552 —-a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-03-14 15:06:56 210944 —-a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-03-14 15:06:56 1031680 —-a-w- C:\Windows\System32\rdpcore.dll
2012-03-14 15:06:55 9216 —-a-w- C:\Windows\System32\rdrmemptylst.exe
2012-03-14 15:06:54 77312 —-a-w- C:\Windows\System32\rdpwsx.dll
2012-03-14 15:06:54 149504 —-a-w- C:\Windows\System32\rdpcorekmts.dll
.
==================== Find3M ====================
.
2012-03-29 11:08:02 70304 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-03-16 02:50:01 103272 —-a-w- C:\Users\Daniel Ulrich\GoToAssistDownloadHelper.exe
2012-02-17 20:45:56 545064 —-a-w- C:\Windows\System32\drivers\avckf.sys
.
============= FINISH: 10:04:07.36 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 7/31/2011 6:42:36 PM
System Uptime: 4/11/2012 9:56:31 AM (1 hours ago)
.
Motherboard: Dell Inc. | | 0Y2MRG
Processor: Intel® Core™ i7-2600 CPU @ 3.40GHz | CPU 1 | 3401/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 1385 GiB total, 1323.048 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: DW1501 Wireless-N WLAN Half-Mini Card
Device ID: PCI\VEN_14E4&DEV_4727&SUBSYS_00101028&REV_01\4&AA4FEAE&0&00E0
Manufacturer: Broadcom
Name: DW1501 Wireless-N WLAN Half-Mini Card
PNP Device ID: PCI\VEN_14E4&DEV_4727&SUBSYS_00101028&REV_01\4&AA4FEAE&0&00E0
Service: BCM43XX
.
==== System Restore Points ===================
.
RP112: 3/27/2012 11:56:38 AM - Removed RuneScape Launcher 1.2
RP113: 3/27/2012 11:58:28 AM - Installed RuneScape Launcher 1.2
RP114: 4/2/2012 2:04:00 PM - Removed Dell MusicStage
RP115: 4/2/2012 2:04:31 PM - Removed Dell PhotoStage.
RP116: 4/2/2012 2:05:21 PM - Removed Dell Stage
RP117: 4/2/2012 2:05:52 PM - Removed Dell Stage Remote.
RP118: 4/2/2012 2:07:23 PM - Removed Dell Getting Started Guide.
RP119: 4/2/2012 2:07:43 PM - Removed Dell Product Registration.
RP120: 4/2/2012 2:09:08 PM - Removed Windows Live Mesh ActiveX Control for Remote Connections
RP121: 4/2/2012 2:10:38 PM - Configured VideoStage
RP122: 4/2/2012 2:12:36 PM - Removed Dell Support Center
RP123: 4/2/2012 9:58:29 PM - Removed Java™ 6 Update 31 (64-bit)
RP124: 4/2/2012 9:59:02 PM - Removed Java™ 6 Update 31
RP125: 4/2/2012 10:00:05 PM - Removed THX TruStudio PC
RP126: 4/2/2012 11:45:52 PM - Installed Java™ 6 Update 31 (64-bit)
RP127: 4/3/2012 2:10:08 AM - Windows Update
RP128: 4/11/2012 1:44:46 AM - Scheduled Checkpoint
RP129: 4/11/2012 1:53:47 AM - Windows Update
RP130: 4/11/2012 10:00:36 AM - Windows Update
.
==== Installed Programs ======================
.
Best Buy pc app
Catalyst Control Center - Branding
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
D3DX10
Dell Driver Download Manager - 1
Dell PhotoStage
Dell Stage Remote
DirectX 9 Runtime
Intel® Rapid Storage Technology
Junk Mail filter update
Mesh Runtime
Messenger Companion
Microsoft Office 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Multimedia Card Reader
PhotoShowExpress
Realtek High Definition Audio Driver
RIFT
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Creator Starter
Roxio Express Labeler 3
RuneScape Launcher 1.2
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Skype™ 5.8
Sonic CinePlayer Decoder Pack
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== End Of File ===========================
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-04-11 10:07:10
—————————–
10:07:10.249 OS Version: Windows x64 6.1.7601 Service Pack 1
10:07:10.249 Number of processors: 8 586 0x2A07
10:07:10.249 ComputerName: DANIELULRICH-PC UserName: Daniel Ulrich
10:07:15.646 Initialize success
10:07:42.293 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
10:07:42.308 Disk 0 Vendor: ST315003 CC4G Size: 1430799MB BusType: 3
10:07:42.324 Disk 0 MBR read successfully
10:07:42.324 Disk 0 MBR scan
10:07:42.324 Disk 0 Windows VISTA default MBR code
10:07:42.324 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63
10:07:42.339 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 12542 MB offset 81920
10:07:42.339 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 1418216 MB offset 25767936
10:07:42.355 Disk 0 scanning C:\Windows\system32\drivers
10:07:47.909 Service scanning
10:07:57.877 Modules scanning
10:07:57.877 Disk 0 trace - called modules:
10:07:57.908 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
10:07:57.908 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80093db790]
10:07:57.924 3 CLASSPNP.SYS[fffff88001a5143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800763e050]
10:07:57.924 Scan finished successfully
10:08:08.953 Disk 0 MBR has been saved successfully to "C:\Users\Daniel Ulrich\Desktop\MBR.dat"
10:08:08.953 The log file has been saved successfully to "C:\Users\Daniel Ulrich\Desktop\aswMBR.txt"
Hi,
Download
Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————–
IMPORTANT -
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
here
——————————————————————–
Right-Click and Run as Administrator on
ComboFix.exe & follow the prompts.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.
When finished, it will produce a report for you. Please post the C:\ComboFix.txt for further review.
———-
ComboFix 12-04-11.03 - Daniel Ulrich 04/11/2012 18:33:13.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8174.6213 [GMT -4:00]
Running from: c:\users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CESWS63K\ComboFix.exe
AV: Bitdefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
FW: Bitdefender Firewall *Disabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
SP: Bitdefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daniel Ulrich\AppData\Local\Temp\{45C0298F-2F8A-4749-A06F-29C2B77C695C}\fpb.tmp
c:\users\Daniel Ulrich\GoToAssistDownloadHelper.exe
c:\users\DANIEL~1\AppData\Local\Temp\{45C0298F-2F8A-4749-A06F-29C2B77C695C}\fpb.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-03-11 to 2012-04-11 )))))))))))))))))))))))))))))))
.
.
2012-04-11 22:37 . 2012-04-11 22:37 ——– d—–w- c:\users\Public\AppData\Local\temp
2012-04-11 22:37 . 2012-04-11 22:37 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-04-11 05:55 . 2012-03-06 06:53 5559152 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 05:55 . 2012-03-06 05:59 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-04-11 05:55 . 2012-03-06 05:59 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-04-11 05:54 . 2012-03-01 06:46 23408 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-11 05:54 . 2012-03-01 06:38 220672 —-a-w- c:\windows\system32\wintrust.dll
2012-04-11 05:54 . 2012-03-01 06:33 81408 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-11 05:54 . 2012-03-01 06:28 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-11 05:54 . 2012-03-01 05:37 172544 —-a-w- c:\windows\SysWow64\wintrust.dll
2012-04-11 05:54 . 2012-03-01 05:33 159232 —-a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-11 05:54 . 2012-03-01 05:29 5120 —-a-w- c:\windows\SysWow64\wmi.dll
2012-04-03 03:46 . 2012-04-03 03:46 ——– d—–w- c:\program files\Java
2012-04-02 21:35 . 2012-04-02 21:35 210561 —-a-w- c:\programdata\1333402294.bdinstall.bin
2012-04-02 21:34 . 2012-04-02 21:34 ——– d—–w- c:\programdata\BDLogging
2012-04-02 21:34 . 2012-04-02 21:34 ——– d—–w- c:\users\Daniel Ulrich\AppData\Roaming\Bitdefender
2012-04-02 21:34 . 2012-04-02 21:34 ——– d—–w- c:\programdata\Bitdefender
2012-04-02 21:32 . 2012-04-02 21:32 ——– d—–w- c:\users\Daniel Ulrich\AppData\Roaming\QuickScan
2012-04-02 21:31 . 2012-04-02 21:34 ——– d—–w- c:\program files\Bitdefender
2012-04-02 21:31 . 2011-10-27 19:07 329800 —-a-w- c:\windows\system32\drivers\trufos.sys
2012-04-02 21:31 . 2011-08-16 18:59 442088 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2012-04-02 21:31 . 2012-04-02 21:31 ——– d—–w- c:\program files\Common Files\Bitdefender
2012-03-29 11:08 . 2012-03-29 11:08 418464 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-03-27 07:10 . 2012-03-27 07:10 ——– d—–w- c:\program files (x86)\Common Files\Skype
2012-03-27 07:10 . 2012-03-27 07:10 ——– d—–r- c:\program files (x86)\Skype
2012-03-21 00:22 . 2012-03-21 00:22 691896 —-a-w- c:\windows\system32\drivers\avc3.sys
2012-03-16 02:56 . 2012-03-16 02:56 ——– d—–w- c:\users\Daniel Ulrich\AppData\Local\Mozilla
2012-03-16 02:16 . 2012-03-16 02:16 ——– d—–w- c:\programdata\IBUpdaterService
2012-03-16 01:35 . 2012-04-03 03:46 525544 —-a-w- c:\windows\system32\deployJava1.dll
2012-03-15 21:24 . 2012-03-15 21:24 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-03-14 15:07 . 2012-02-03 04:34 3145728 —-a-w- c:\windows\system32\win32k.sys
2012-03-14 15:07 . 2012-02-10 06:36 1544192 —-a-w- c:\windows\system32\DWrite.dll
2012-03-14 15:07 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\SysWow64\DWrite.dll
2012-03-14 15:06 . 2012-02-17 06:38 1031680 —-a-w- c:\windows\system32\rdpcore.dll
2012-03-14 15:06 . 2012-02-17 05:34 826880 —-a-w- c:\windows\SysWow64\rdpcore.dll
2012-03-14 15:06 . 2012-02-17 04:58 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-14 15:06 . 2012-02-17 04:57 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys
2012-03-14 15:06 . 2012-01-25 06:33 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe
2012-03-14 15:06 . 2012-01-25 06:38 77312 —-a-w- c:\windows\system32\rdpwsx.dll
2012-03-14 15:06 . 2012-01-25 06:38 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-29 11:08 . 2012-02-07 21:51 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-03-05 20:48 . 2012-03-05 20:48 162664 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin
2012-02-17 20:45 . 2012-02-17 20:45 545064 —-a-w- c:\windows\system32\drivers\avckf.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160]
"ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2010-03-10 237568]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-12-09 336384]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-10-13 9216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 253600]
R3 bdsandbox;bdsandbox;c:\windows\system32\drivers\bdsandbox.sys [x]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
R3 LeapFrog-USBLAN;LeapFrog-USBLAN;c:\windows\system32\DRIVERS\btblan.sys [x]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [x]
R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [x]
R3 pmxdrv;pmxdrv;c:\windows\system32\drivers\pmxdrv.sys [x]
R3 SafeBox;SafeBox;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [2012-02-21 75384]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe [2011-10-15 466736]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [2011-11-15 90192]
S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2011-11-15 103504]
S1 BDVEDISK;BDVEDISK;c:\windows\system32\DRIVERS\bdvedisk.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-13 13336]
S2 UPDATESRV;BitDefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender 2012\updatesrv.exe [2012-03-13 66096]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys [x]
S3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 11:08]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox1]
@="{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}"
[HKEY_CLASSES_ROOT\CLSID\{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}]
2012-02-22 17:55 266952 —-a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox2]
@="{342DAA0B-D796-460D-8566-901E08A1CCAD}"
[HKEY_CLASSES_ROOT\CLSID\{342DAA0B-D796-460D-8566-901E08A1CCAD}]
2012-02-22 17:55 266952 —-a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox3]
@="{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}"
[HKEY_CLASSES_ROOT\CLSID\{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}]
2012-02-22 17:55 266952 —-a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox4]
@="{33816773-98AE-4723-ADE0-EBE54C8B5A67}"
[HKEY_CLASSES_ROOT\CLSID\{33816773-98AE-4723-ADE0-EBE54C8B5A67}]
2012-02-22 17:55 266952 —-a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-23 10920552]
"BDAgent"="c:\program files\Bitdefender\Bitdefender 2012\bdagent.exe" [2012-03-22 1067256]
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = 127.0.0.1:9421
TCP: DhcpNameServer = [removed] [removed] 192.168.1.1
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-04-11 18:42:10 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-11 22:42
ComboFix2.txt 2011-11-24 08:17
.
Pre-Run: 1,420,488,904,704 bytes free
Post-Run: 1,420,377,120,768 bytes free
.
- - End Of File - - 2AC2FCE03342C522F1AE026415B7A334
Hi,
Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
ClearJavaCache::
DDS::
uInternet Settings,ProxyOverride = 127.0.0.1:9421
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
File::
c:\progra~1\mcafee\msc\mcawfwk.exe
Driver::
McAWFwk
Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.
[external image: Posted Image]
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".Referring to the screenshot above, drag CFScript.txt into ComboFix.exe. ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal. When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION : Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Hi,
Do you still need help.
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic