This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer infected [Closed]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi my anti virus keeps detecting a virus but fails to remove it. it tells me it is blocking viruses on my computer and happens on every web page that message comes up. im using bitdefender. thanks
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
. DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 10:01:58 on 2012-04-11 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8174.6298 [GMT -4:00] . AV: Bitdefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Bitdefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F} FW: Bitdefender Firewall *Enabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\atieclxx.exe C:\Windows\system32\taskhost.exe C:\Program Files\Bitdefender\Bitdefender 2012\bdagent.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil64_11_2_202_228_ActiveX.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Windows\system32\sppsvc.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\SearchFilterHost.exe \\?\C:\Windows\system32\wbem\WMIADAP.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\SoftwareDistribution\Download\Install\NDP40-KB2656368-x64.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uSearch Bar = Preserve uInternet Settings,ProxyOverride = 127.0.0.1:9421 uURLSearchHooks: H - No File BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab TCP: DhcpNameServer = [removed] [removed] 192.168.1.1 TCP: Interfaces\{0F716DF8-2219-4192-A13F-41621AEBA92B} : DhcpNameServer = [removed] [removed] 192.168.1.1 TCP: Interfaces\{11C1EE4A-EBA1-4ABE-9C26-A34A2CAD753A} : DhcpNameServer = [removed] [removed] 192.168.1.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO-X64: 0x1 - No File BHO-X64: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File BHO-X64: McAfee Phishing Filter - No File BHO-X64: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO-X64: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun-x64: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" . ============= SERVICES / DRIVERS =============== . R0 avc3;avc3;C:\Windows\system32\DRIVERS\avc3.sys –> C:\Windows\system32\DRIVERS\avc3.sys [?] R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys [?] R1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [2011-11-14 90192] R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2011-11-14 103504] R1 BDVEDISK;BDVEDISK;C:\Windows\system32\DRIVERS\bdvedisk.sys –> C:\Windows\system32\DRIVERS\bdvedisk.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-6-1 13336] R2 UPDATESRV;BitDefender Desktop Update Service;C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe [2012-3-13 66096] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys –> C:\Windows\system32\drivers\AtihdW76.sys [?] R3 avchv;avchv Function Driver;C:\Windows\system32\DRIVERS\avchv.sys –> C:\Windows\system32\DRIVERS\avchv.sys [?] R3 avckf;avckf;C:\Windows\system32\DRIVERS\avckf.sys –> C:\Windows\system32\DRIVERS\avckf.sys [?] R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys –> C:\Windows\system32\DRIVERS\IntcDAud.sys [?] R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys –> C:\Windows\system32\DRIVERS\k57nd60a.sys [?] R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-29 253600] S3 bdsandbox;bdsandbox;\??\C:\Windows\system32\drivers\bdsandbox.sys –> C:\Windows\system32\drivers\bdsandbox.sys [?] S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys –> C:\Windows\system32\DRIVERS\fssfltr.sys [?] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840] S3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys –> C:\Windows\system32\DRIVERS\Impcd.sys [?] S3 LeapFrog-USBLAN;LeapFrog-USBLAN;C:\Windows\system32\DRIVERS\btblan.sys –> C:\Windows\system32\DRIVERS\btblan.sys [?] S3 McAWFwk;McAfee Activation Service;c:\PROGRA~1\mcafee\msc\mcawfwk.exe –> c:\PROGRA~1\mcafee\msc\mcawfwk.exe [?] S3 pmxdrv;pmxdrv;\??\C:\Windows\system32\drivers\pmxdrv.sys –> C:\Windows\system32\drivers\pmxdrv.sys [?] S3 SafeBox;SafeBox;C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe [2012-2-21 75384] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 Update Server;BitDefender Update Server v2;C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe [2011-10-14 466736] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== File Associations =============== . JSEFile=NOTEPAD.EXE %1 regfile=NOTEPAD.EXE %1 scrfile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 . =============== Created Last 30 ================ . 2012-04-11 14:02:02 ——– d—–w- C:\d2ca49080448910cf36d68 2012-04-11 05:55:39 5559152 —-a-w- C:\Windows\System32\ntoskrnl.exe 2012-04-11 05:55:39 3968368 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2012-04-11 05:55:39 3913072 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2012-04-11 05:54:05 81408 —-a-w- C:\Windows\System32\imagehlp.dll 2012-04-11 05:54:05 5120 —-a-w- C:\Windows\SysWow64\wmi.dll 2012-04-11 05:54:05 5120 —-a-w- C:\Windows\System32\wmi.dll 2012-04-11 05:54:05 23408 —-a-w- C:\Windows\System32\drivers\fs_rec.sys 2012-04-11 05:54:05 220672 —-a-w- C:\Windows\System32\wintrust.dll 2012-04-11 05:54:05 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll 2012-04-11 05:54:05 159232 —-a-w- C:\Windows\SysWow64\imagehlp.dll 2012-04-04 03:33:49 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{3BE5F393-E15F-40DD-94C5-EE853D895174} 2012-04-02 21:35:15 210561 —-a-w- C:\ProgramData\1333402294.bdinstall.bin 2012-04-02 21:34:58 ——– d—–w- C:\ProgramData\BDLogging 2012-04-02 21:34:33 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Roaming\Bitdefender 2012-04-02 21:34:31 ——– d—–w- C:\ProgramData\Bitdefender 2012-04-02 21:32:04 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Roaming\QuickScan 2012-04-02 21:31:54 ——– d—–w- C:\Program Files\Bitdefender 2012-04-02 21:31:39 442088 —-a-w- C:\Windows\System32\drivers\bdfsfltr.sys 2012-04-02 21:31:39 329800 —-a-w- C:\Windows\System32\drivers\trufos.sys 2012-04-02 21:31:27 ——– d—–w- C:\Program Files\Common Files\Bitdefender 2012-04-02 04:43:52 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{44083660-15AC-4725-8127-66023ED0FFBF} 2012-03-29 11:08:02 418464 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-03-27 07:10:27 ——– d—–r- C:\Program Files (x86)\Skype 2012-03-25 13:37:44 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{A58AEE26-98F5-4620-A15E-61B998AA138E} 2012-03-25 13:37:33 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{5F3433CE-425D-4E0F-B2F9-2A225F0554BB} 2012-03-21 22:07:28 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{D53D4FDB-DF1D-4C43-82E0-034E0FF7FA39} 2012-03-21 22:07:17 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\{FB659531-B7BF-4CCF-A551-D1DAEFDAC91C} 2012-03-21 00:22:46 691896 —-a-w- C:\Windows\System32\drivers\avc3.sys 2012-03-16 02:56:36 ——– d—–w- C:\Users\Daniel Ulrich\AppData\Local\Mozilla 2012-03-16 02:16:11 ——– d—–w- C:\ProgramData\IBUpdaterService 2012-03-16 01:35:25 525544 —-a-w- C:\Windows\System32\deployJava1.dll 2012-03-15 21:24:44 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2012-03-14 15:07:10 3145728 —-a-w- C:\Windows\System32\win32k.sys 2012-03-14 15:07:08 1544192 —-a-w- C:\Windows\System32\DWrite.dll 2012-03-14 15:07:08 1077248 —-a-w- C:\Windows\SysWow64\DWrite.dll 2012-03-14 15:06:56 826880 —-a-w- C:\Windows\SysWow64\rdpcore.dll 2012-03-14 15:06:56 23552 —-a-w- C:\Windows\System32\drivers\tdtcp.sys 2012-03-14 15:06:56 210944 —-a-w- C:\Windows\System32\drivers\rdpwd.sys 2012-03-14 15:06:56 1031680 —-a-w- C:\Windows\System32\rdpcore.dll 2012-03-14 15:06:55 9216 —-a-w- C:\Windows\System32\rdrmemptylst.exe 2012-03-14 15:06:54 77312 —-a-w- C:\Windows\System32\rdpwsx.dll 2012-03-14 15:06:54 149504 —-a-w- C:\Windows\System32\rdpcorekmts.dll . ==================== Find3M ==================== . 2012-03-29 11:08:02 70304 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-03-16 02:50:01 103272 —-a-w- C:\Users\Daniel Ulrich\GoToAssistDownloadHelper.exe 2012-02-17 20:45:56 545064 —-a-w- C:\Windows\System32\drivers\avckf.sys . ============= FINISH: 10:04:07.36 ===============
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 7/31/2011 6:42:36 PM System Uptime: 4/11/2012 9:56:31 AM (1 hours ago) . Motherboard: Dell Inc. | | 0Y2MRG Processor: Intel® Core™ i7-2600 CPU @ 3.40GHz | CPU 1 | 3401/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 1385 GiB total, 1323.048 GiB free. D: is CDROM () E: is Removable F: is Removable G: is Removable H: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: DW1501 Wireless-N WLAN Half-Mini Card Device ID: PCI\VEN_14E4&DEV_4727&SUBSYS_00101028&REV_01\4&AA4FEAE&0&00E0 Manufacturer: Broadcom Name: DW1501 Wireless-N WLAN Half-Mini Card PNP Device ID: PCI\VEN_14E4&DEV_4727&SUBSYS_00101028&REV_01\4&AA4FEAE&0&00E0 Service: BCM43XX . ==== System Restore Points =================== . RP112: 3/27/2012 11:56:38 AM - Removed RuneScape Launcher 1.2 RP113: 3/27/2012 11:58:28 AM - Installed RuneScape Launcher 1.2 RP114: 4/2/2012 2:04:00 PM - Removed Dell MusicStage RP115: 4/2/2012 2:04:31 PM - Removed Dell PhotoStage. RP116: 4/2/2012 2:05:21 PM - Removed Dell Stage RP117: 4/2/2012 2:05:52 PM - Removed Dell Stage Remote. RP118: 4/2/2012 2:07:23 PM - Removed Dell Getting Started Guide. RP119: 4/2/2012 2:07:43 PM - Removed Dell Product Registration. RP120: 4/2/2012 2:09:08 PM - Removed Windows Live Mesh ActiveX Control for Remote Connections RP121: 4/2/2012 2:10:38 PM - Configured VideoStage RP122: 4/2/2012 2:12:36 PM - Removed Dell Support Center RP123: 4/2/2012 9:58:29 PM - Removed Java™ 6 Update 31 (64-bit) RP124: 4/2/2012 9:59:02 PM - Removed Java™ 6 Update 31 RP125: 4/2/2012 10:00:05 PM - Removed THX TruStudio PC RP126: 4/2/2012 11:45:52 PM - Installed Java™ 6 Update 31 (64-bit) RP127: 4/3/2012 2:10:08 AM - Windows Update RP128: 4/11/2012 1:44:46 AM - Scheduled Checkpoint RP129: 4/11/2012 1:53:47 AM - Windows Update RP130: 4/11/2012 10:00:36 AM - Windows Update . ==== Installed Programs ====================== . Best Buy pc app Catalyst Control Center - Branding Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai D3DX10 Dell Driver Download Manager - 1 Dell PhotoStage Dell Stage Remote DirectX 9 Runtime Intel® Rapid Storage Technology Junk Mail filter update Mesh Runtime Messenger Companion Microsoft Office 2010 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable - KB2467175 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Multimedia Card Reader PhotoShowExpress Realtek High Definition Audio Driver RIFT Roxio Activation Module Roxio BackOnTrack Roxio Burn Roxio Creator Starter Roxio Express Labeler 3 RuneScape Launcher 1.2 Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Skype™ 5.8 Sonic CinePlayer Decoder Pack Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Messenger Windows Live Messenger Companion Core Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources . ==== End Of File ===========================
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-04-11 10:07:10 —————————– 10:07:10.249 OS Version: Windows x64 6.1.7601 Service Pack 1 10:07:10.249 Number of processors: 8 586 0x2A07 10:07:10.249 ComputerName: DANIELULRICH-PC UserName: Daniel Ulrich 10:07:15.646 Initialize success 10:07:42.293 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 10:07:42.308 Disk 0 Vendor: ST315003 CC4G Size: 1430799MB BusType: 3 10:07:42.324 Disk 0 MBR read successfully 10:07:42.324 Disk 0 MBR scan 10:07:42.324 Disk 0 Windows VISTA default MBR code 10:07:42.324 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63 10:07:42.339 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 12542 MB offset 81920 10:07:42.339 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 1418216 MB offset 25767936 10:07:42.355 Disk 0 scanning C:\Windows\system32\drivers 10:07:47.909 Service scanning 10:07:57.877 Modules scanning 10:07:57.877 Disk 0 trace - called modules: 10:07:57.908 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 10:07:57.908 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80093db790] 10:07:57.924 3 CLASSPNP.SYS[fffff88001a5143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800763e050] 10:07:57.924 Scan finished successfully 10:08:08.953 Disk 0 MBR has been saved successfully to "C:\Users\Daniel Ulrich\Desktop\MBR.dat" 10:08:08.953 The log file has been saved successfully to "C:\Users\Daniel Ulrich\Desktop\aswMBR.txt"
Hi,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.


Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
ComboFix 12-04-11.03 - Daniel Ulrich 04/11/2012 18:33:13.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8174.6213 [GMT -4:00] Running from: c:\users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CESWS63K\ComboFix.exe AV: Bitdefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92} FW: Bitdefender Firewall *Disabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9} SP: Bitdefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Daniel Ulrich\AppData\Local\Temp\{45C0298F-2F8A-4749-A06F-29C2B77C695C}\fpb.tmp c:\users\Daniel Ulrich\GoToAssistDownloadHelper.exe c:\users\DANIEL~1\AppData\Local\Temp\{45C0298F-2F8A-4749-A06F-29C2B77C695C}\fpb.tmp . . ((((((((((((((((((((((((( Files Created from 2012-03-11 to 2012-04-11 ))))))))))))))))))))))))))))))) . . 2012-04-11 22:37 . 2012-04-11 22:37 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-04-11 22:37 . 2012-04-11 22:37 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-11 05:55 . 2012-03-06 06:53 5559152 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-11 05:55 . 2012-03-06 05:59 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-04-11 05:55 . 2012-03-06 05:59 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-04-11 05:54 . 2012-03-01 06:46 23408 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-11 05:54 . 2012-03-01 06:38 220672 —-a-w- c:\windows\system32\wintrust.dll 2012-04-11 05:54 . 2012-03-01 06:33 81408 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-11 05:54 . 2012-03-01 06:28 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-11 05:54 . 2012-03-01 05:37 172544 —-a-w- c:\windows\SysWow64\wintrust.dll 2012-04-11 05:54 . 2012-03-01 05:33 159232 —-a-w- c:\windows\SysWow64\imagehlp.dll 2012-04-11 05:54 . 2012-03-01 05:29 5120 —-a-w- c:\windows\SysWow64\wmi.dll 2012-04-03 03:46 . 2012-04-03 03:46 ——– d—–w- c:\program files\Java 2012-04-02 21:35 . 2012-04-02 21:35 210561 —-a-w- c:\programdata\1333402294.bdinstall.bin 2012-04-02 21:34 . 2012-04-02 21:34 ——– d—–w- c:\programdata\BDLogging 2012-04-02 21:34 . 2012-04-02 21:34 ——– d—–w- c:\users\Daniel Ulrich\AppData\Roaming\Bitdefender 2012-04-02 21:34 . 2012-04-02 21:34 ——– d—–w- c:\programdata\Bitdefender 2012-04-02 21:32 . 2012-04-02 21:32 ——– d—–w- c:\users\Daniel Ulrich\AppData\Roaming\QuickScan 2012-04-02 21:31 . 2012-04-02 21:34 ——– d—–w- c:\program files\Bitdefender 2012-04-02 21:31 . 2011-10-27 19:07 329800 —-a-w- c:\windows\system32\drivers\trufos.sys 2012-04-02 21:31 . 2011-08-16 18:59 442088 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys 2012-04-02 21:31 . 2012-04-02 21:31 ——– d—–w- c:\program files\Common Files\Bitdefender 2012-03-29 11:08 . 2012-03-29 11:08 418464 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-03-27 07:10 . 2012-03-27 07:10 ——– d—–w- c:\program files (x86)\Common Files\Skype 2012-03-27 07:10 . 2012-03-27 07:10 ——– d—–r- c:\program files (x86)\Skype 2012-03-21 00:22 . 2012-03-21 00:22 691896 —-a-w- c:\windows\system32\drivers\avc3.sys 2012-03-16 02:56 . 2012-03-16 02:56 ——– d—–w- c:\users\Daniel Ulrich\AppData\Local\Mozilla 2012-03-16 02:16 . 2012-03-16 02:16 ——– d—–w- c:\programdata\IBUpdaterService 2012-03-16 01:35 . 2012-04-03 03:46 525544 —-a-w- c:\windows\system32\deployJava1.dll 2012-03-15 21:24 . 2012-03-15 21:24 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-03-14 15:07 . 2012-02-03 04:34 3145728 —-a-w- c:\windows\system32\win32k.sys 2012-03-14 15:07 . 2012-02-10 06:36 1544192 —-a-w- c:\windows\system32\DWrite.dll 2012-03-14 15:07 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\SysWow64\DWrite.dll 2012-03-14 15:06 . 2012-02-17 06:38 1031680 —-a-w- c:\windows\system32\rdpcore.dll 2012-03-14 15:06 . 2012-02-17 05:34 826880 —-a-w- c:\windows\SysWow64\rdpcore.dll 2012-03-14 15:06 . 2012-02-17 04:58 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-14 15:06 . 2012-02-17 04:57 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-03-14 15:06 . 2012-01-25 06:33 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-14 15:06 . 2012-01-25 06:38 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-03-14 15:06 . 2012-01-25 06:38 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-29 11:08 . 2012-02-07 21:51 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-03-05 20:48 . 2012-03-05 20:48 162664 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10140.bin 2012-02-17 20:45 . 2012-02-17 20:45 545064 —-a-w- c:\windows\system32\drivers\avckf.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160] "ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2010-03-10 237568] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-12-09 336384] "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-10-13 9216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-02-29 158856] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 253600] R3 bdsandbox;bdsandbox;c:\windows\system32\drivers\bdsandbox.sys [x] R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] R3 LeapFrog-USBLAN;LeapFrog-USBLAN;c:\windows\system32\DRIVERS\btblan.sys [x] R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [x] R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [x] R3 pmxdrv;pmxdrv;c:\windows\system32\drivers\pmxdrv.sys [x] R3 SafeBox;SafeBox;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [2012-02-21 75384] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe [2011-10-15 466736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [2011-11-15 90192] S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [2011-11-15 103504] S1 BDVEDISK;BDVEDISK;c:\windows\system32\DRIVERS\bdvedisk.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-13 13336] S2 UPDATESRV;BitDefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender 2012\updatesrv.exe [2012-03-13 66096] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys [x] S3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-04-11 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 11:08] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox1] @="{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}" [HKEY_CLASSES_ROOT\CLSID\{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}] 2012-02-22 17:55 266952 —-a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox2] @="{342DAA0B-D796-460D-8566-901E08A1CCAD}" [HKEY_CLASSES_ROOT\CLSID\{342DAA0B-D796-460D-8566-901E08A1CCAD}] 2012-02-22 17:55 266952 —-a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox3] @="{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}" [HKEY_CLASSES_ROOT\CLSID\{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}] 2012-02-22 17:55 266952 —-a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox4] @="{33816773-98AE-4723-ADE0-EBE54C8B5A67}" [HKEY_CLASSES_ROOT\CLSID\{33816773-98AE-4723-ADE0-EBE54C8B5A67}] 2012-02-22 17:55 266952 —-a-w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-23 10920552] "BDAgent"="c:\program files\Bitdefender\Bitdefender 2012\bdagent.exe" [2012-03-22 1067256] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = 127.0.0.1:9421 TCP: DhcpNameServer = [removed] [removed] 192.168.1.1 . . ——- File Associations ——- . JSEFile=NOTEPAD.EXE %1 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0] "ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-04-11 18:42:10 - machine was rebooted ComboFix-quarantined-files.txt 2012-04-11 22:42 ComboFix2.txt 2011-11-24 08:17 . Pre-Run: 1,420,488,904,704 bytes free Post-Run: 1,420,377,120,768 bytes free . - - End Of File - - 2AC2FCE03342C522F1AE026415B7A334
Hi,
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    uInternet Settings,ProxyOverride = 127.0.0.1:9421
    uURLSearchHooks: H - No File
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
    BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
    BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
    
    File::
    c:\progra~1\mcafee\msc\mcawfwk.exe
    
    Driver::
    McAWFwk
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI