Ok…still not working.
Let's get out the big boy!
Download
Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————–
IMPORTANT -
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
here
——————————————————————–
Right-Click and Run as Administrator on
ComboFix.exe & follow the prompts.
When finished, it will produce a report for you. Please post the C:\ComboFix.txt for further review.
ok so it says to turn off my antivirus and antispyware. but the link doesn't say how to turn of mcafee security suite that comes from at&t. what features need to be off? i'm assuming real time scanning and the firewall right?
yes….if you can turn off your antivirus and firewall.
If you aren't able just continue on….it shouldn't be a problem.
ok here we go. combofix log
ComboFix 12-04-26.01 - Jeffrey 04/26/2012 15:22:29.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8183.6476 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\XkFcjVGVgWJhiQK.exe
c:\windows\svchost.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-03-26 to 2012-04-26 )))))))))))))))))))))))))))))))
.
.
2012-04-26 18:36 . 2012-04-26 18:37 ——– d—–w- c:\program files (x86)\ERUNT
2012-04-26 16:24 . 2012-04-26 16:24 ——– d—–w- c:\windows\Sun
2012-04-26 15:53 . 2012-04-26 18:23 ——– d—–w- C:\TDSSKiller_Quarantine
2012-04-26 14:54 . 2008-07-31 14:41 68616 —-a-w- c:\windows\SysWow64\XAPOFX1_1.dll
2012-04-26 14:54 . 2008-07-31 14:40 509448 —-a-w- c:\windows\SysWow64\XAudio2_2.dll
2012-04-26 14:54 . 2008-07-12 12:18 467984 —-a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-04-26 14:54 . 2008-07-12 12:18 3851784 —-a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-04-26 14:54 . 2008-07-12 12:18 1493528 —-a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-04-26 14:52 . 2012-04-26 14:52 ——– d—–w- C:\Riot Games
2012-04-26 10:43 . 2012-04-26 18:36 ——– d—–w- c:\programdata\PMB Files
2012-04-26 10:42 . 2012-04-26 10:42 ——– d—–w- c:\program files (x86)\Pando Networks
2012-04-26 10:36 . 2012-04-26 10:36 ——– d—–w- c:\program files (x86)\Mozilla Maintenance Service
2012-04-26 10:29 . 2012-04-26 10:29 ——– d—–w- c:\program files (x86)\Common Files\McAfee
2012-04-26 10:29 . 2012-02-22 17:29 10248 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2012-04-26 10:29 . 2012-02-22 17:29 75936 —-a-w- c:\windows\system32\drivers\mfenlfk.sys
2012-04-26 10:29 . 2012-02-22 17:29 65264 —-a-w- c:\windows\system32\drivers\cfwids.sys
2012-04-26 10:29 . 2012-02-22 17:29 487296 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2012-04-26 10:29 . 2012-02-22 17:29 289664 —-a-w- c:\windows\system32\drivers\mfewfpk.sys
2012-04-26 10:29 . 2012-02-22 17:29 229528 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2012-04-26 10:29 . 2012-02-22 17:29 100912 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2012-04-26 10:29 . 2012-04-26 10:29 ——– d—–w- c:\program files\Common Files\McAfee
2012-04-26 10:29 . 2012-04-26 10:30 ——– d—–w- c:\program files\McAfee
2012-04-26 10:29 . 2012-04-26 15:54 ——– d—–w- c:\program files (x86)\McAfee
2012-04-26 10:13 . 2012-03-20 17:11 162192 —-a-w- c:\windows\system32\mfevtps.exe
2012-04-26 10:13 . 2012-04-26 13:29 ——– d—–w- c:\programdata\McAfee
2012-04-26 10:08 . 2012-04-26 10:08 ——– d—–w- c:\program files (x86)\Compact Wireless-G USB Adapter Wireless Network Monitor
2012-04-26 10:08 . 2001-09-05 08:18 77824 —-a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2012-04-26 10:08 . 2001-09-05 08:18 225280 ——w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2012-04-26 10:08 . 2001-09-05 08:14 176128 ——w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2012-04-26 10:08 . 2001-09-05 08:13 32768 ——w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2012-04-26 10:02 . 2012-04-26 10:04 ——– d—–w- c:\users\Jeffrey
2012-04-26 09:45 . 2012-04-18 08:03 8917360 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2E70F480-88C1-4FEF-A7D6-4A31B65AAC75}\mpengine.dll
2012-04-26 09:45 . 2012-02-23 15:18 279656 ——w- c:\windows\system32\MpSigStub.exe
2012-04-26 09:12 . 2012-02-15 06:27 1031680 —-a-w- c:\windows\system32\rdpcore.dll
2012-04-26 09:12 . 2012-02-15 05:44 826368 —-a-w- c:\windows\SysWow64\rdpcore.dll
2012-04-26 09:12 . 2012-02-15 04:47 204800 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 09:12 . 2012-02-15 04:46 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys
2012-04-26 09:12 . 2012-01-25 06:27 76288 —-a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 09:12 . 2012-01-25 06:27 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 09:12 . 2012-01-25 06:20 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-26 09:12 . 2010-01-09 07:19 139264 —-a-w- c:\windows\system32\cabview.dll
2012-04-26 09:12 . 2010-01-09 06:52 132608 —-a-w- c:\windows\SysWow64\cabview.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-22 17:29 . 2012-02-22 17:29 647208 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2012-02-22 17:29 . 2012-02-22 17:29 160792 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Java\jre6\bin\jusched.exe" [2009-10-26 148888]
"ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2009-07-17 237568]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"DellComms"="c:\program files (x86)\Dell\DellComms\bin\sprtcmd.exe" [2009-05-05 206064]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160]
.
c:\users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-03-31 92160]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
S2 sprtsvc_DellComms;SupportSoft Sprocket Service (DellComms);c:\program files (x86)\Dell\DellComms\bin\sprtsvc.exe [2009-05-05 206064]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
S3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
*Deregistered* - mfeavfk01
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-05-23 7833120]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-26 16327712]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Jeffrey\AppData\Roaming\Mozilla\Firefox\Profiles\olkt1xwk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-Skytel - c:\program files\Realtek\Audio\HDA\Skytel.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\SysWOW64\rundll32.exe
c:\\.\globalroot\systemroot\svchost.exe
.
**************************************************************************
.
Completion time: 2012-04-26 15:28:33 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-26 19:28
.
Pre-Run: 948,807,012,352 bytes free
Post-Run: 948,911,742,976 bytes free
.
- - End Of File - - ED464CD552EDD63B4C38337F91679FBF
Ok…
CAUTION : Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
ok log
ComboFix 12-04-26.01 - Jeffrey 04/26/2012 15:44:21.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8183.6646 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Jeffrey\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Pando Networks
c:\program files (x86)\Pando Networks\Media Booster\BsSndRpt.exe
c:\program files (x86)\Pando Networks\Media Booster\BugSplat.dll
c:\program files (x86)\Pando Networks\Media Booster\BugSplatRc.dll
c:\program files (x86)\Pando Networks\Media Booster\freebl3.dll
c:\program files (x86)\Pando Networks\Media Booster\Media Booster FAQs.url
c:\program files (x86)\Pando Networks\Media Booster\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest
c:\program files (x86)\Pando Networks\Media Booster\Microsoft.VC90.CRT\msvcp90.dll
c:\program files (x86)\Pando Networks\Media Booster\Microsoft.VC90.CRT\msvcr90.dll
c:\program files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
c:\program files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll.2.config
c:\program files (x86)\Pando Networks\Media Booster\nspr4.dll
c:\program files (x86)\Pando Networks\Media Booster\nss3.dll
c:\program files (x86)\Pando Networks\Media Booster\nssckbi.dll
c:\program files (x86)\Pando Networks\Media Booster\plc4.dll
c:\program files (x86)\Pando Networks\Media Booster\plds4.dll
c:\program files (x86)\Pando Networks\Media Booster\PMB.cpl
c:\program files (x86)\Pando Networks\Media Booster\PMB.exe
c:\program files (x86)\Pando Networks\Media Booster\PMB.exe.config
c:\program files (x86)\Pando Networks\Media Booster\smime3.dll
c:\program files (x86)\Pando Networks\Media Booster\softokn3.dll
c:\program files (x86)\Pando Networks\Media Booster\ssl3.dll
c:\program files (x86)\Pando Networks\Media Booster\uninst.exe
c:\windows\svchost.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-03-26 to 2012-04-26 )))))))))))))))))))))))))))))))
.
.
2012-04-26 19:47 . 2012-04-26 19:47 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-04-26 18:36 . 2012-04-26 18:37 ——– d—–w- c:\program files (x86)\ERUNT
2012-04-26 16:24 . 2012-04-26 16:24 ——– d—–w- c:\windows\Sun
2012-04-26 15:53 . 2012-04-26 18:23 ——– d—–w- C:\TDSSKiller_Quarantine
2012-04-26 14:54 . 2008-07-31 14:41 68616 —-a-w- c:\windows\SysWow64\XAPOFX1_1.dll
2012-04-26 14:54 . 2008-07-31 14:40 509448 —-a-w- c:\windows\SysWow64\XAudio2_2.dll
2012-04-26 14:54 . 2008-07-12 12:18 467984 —-a-w- c:\windows\SysWow64\d3dx10_39.dll
2012-04-26 14:54 . 2008-07-12 12:18 3851784 —-a-w- c:\windows\SysWow64\D3DX9_39.dll
2012-04-26 14:54 . 2008-07-12 12:18 1493528 —-a-w- c:\windows\SysWow64\D3DCompiler_39.dll
2012-04-26 14:52 . 2012-04-26 14:52 ——– d—–w- C:\Riot Games
2012-04-26 10:43 . 2012-04-26 18:36 ——– d—–w- c:\programdata\PMB Files
2012-04-26 10:36 . 2012-04-26 10:36 ——– d—–w- c:\program files (x86)\Mozilla Maintenance Service
2012-04-26 10:29 . 2012-04-26 10:29 ——– d—–w- c:\program files (x86)\Common Files\McAfee
2012-04-26 10:29 . 2012-02-22 17:29 10248 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2012-04-26 10:29 . 2012-02-22 17:29 75936 —-a-w- c:\windows\system32\drivers\mfenlfk.sys
2012-04-26 10:29 . 2012-02-22 17:29 65264 —-a-w- c:\windows\system32\drivers\cfwids.sys
2012-04-26 10:29 . 2012-02-22 17:29 487296 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2012-04-26 10:29 . 2012-02-22 17:29 289664 —-a-w- c:\windows\system32\drivers\mfewfpk.sys
2012-04-26 10:29 . 2012-02-22 17:29 229528 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2012-04-26 10:29 . 2012-02-22 17:29 100912 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2012-04-26 10:29 . 2012-04-26 10:29 ——– d—–w- c:\program files\Common Files\McAfee
2012-04-26 10:29 . 2012-04-26 10:30 ——– d—–w- c:\program files\McAfee
2012-04-26 10:29 . 2012-04-26 15:54 ——– d—–w- c:\program files (x86)\McAfee
2012-04-26 10:13 . 2012-03-20 17:11 162192 —-a-w- c:\windows\system32\mfevtps.exe
2012-04-26 10:13 . 2012-04-26 13:29 ——– d—–w- c:\programdata\McAfee
2012-04-26 10:08 . 2012-04-26 10:08 ——– d—–w- c:\program files (x86)\Compact Wireless-G USB Adapter Wireless Network Monitor
2012-04-26 10:08 . 2001-09-05 08:18 77824 —-a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2012-04-26 10:08 . 2001-09-05 08:18 225280 ——w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2012-04-26 10:08 . 2001-09-05 08:14 176128 ——w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2012-04-26 10:08 . 2001-09-05 08:13 32768 ——w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2012-04-26 10:02 . 2012-04-26 10:04 ——– d—–w- c:\users\Jeffrey
2012-04-26 09:45 . 2012-04-18 08:03 8917360 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2E70F480-88C1-4FEF-A7D6-4A31B65AAC75}\mpengine.dll
2012-04-26 09:45 . 2012-02-23 15:18 279656 ——w- c:\windows\system32\MpSigStub.exe
2012-04-26 09:12 . 2012-02-15 06:27 1031680 —-a-w- c:\windows\system32\rdpcore.dll
2012-04-26 09:12 . 2012-02-15 05:44 826368 —-a-w- c:\windows\SysWow64\rdpcore.dll
2012-04-26 09:12 . 2012-02-15 04:47 204800 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 09:12 . 2012-02-15 04:46 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys
2012-04-26 09:12 . 2012-01-25 06:27 76288 —-a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 09:12 . 2012-01-25 06:27 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 09:12 . 2012-01-25 06:20 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-26 09:12 . 2010-01-09 07:19 139264 —-a-w- c:\windows\system32\cabview.dll
2012-04-26 09:12 . 2010-01-09 06:52 132608 —-a-w- c:\windows\SysWow64\cabview.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-22 17:29 . 2012-02-22 17:29 647208 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2012-02-22 17:29 . 2012-02-22 17:29 160792 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-26_19.26.30 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-26 10:05 . 2012-04-26 19:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2012-04-26 10:05 . 2012-04-26 19:10 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2012-04-26 19:32 . 2012-04-26 19:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
- 2012-04-26 09:11 . 2012-04-26 19:10 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012042620120427\index.dat
+ 2012-04-26 09:11 . 2012-04-26 19:27 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012042620120427\index.dat
- 2012-04-26 09:09 . 2012-04-26 19:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
+ 2012-04-26 09:09 . 2012-04-26 19:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
+ 2009-10-26 23:35 . 2012-04-26 19:27 25246 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-04-26 19:27 24328 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-04-26 09:58 . 2012-04-26 19:26 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-04-26 09:58 . 2012-04-26 19:03 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-04-26 09:58 . 2012-04-26 19:03 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-04-26 09:58 . 2012-04-26 19:26 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-26 19:26 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-04-26 19:03 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-04-26 09:58 . 2012-04-26 19:47 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-04-26 09:58 . 2012-04-26 19:26 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-04-26 10:09 . 2012-04-26 19:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2012-04-26 10:09 . 2012-04-26 19:26 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2012-04-26 10:09 . 2012-04-26 19:26 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2012-04-26 10:09 . 2012-04-26 19:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2012-04-26 10:09 . 2012-04-26 19:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
- 2012-04-26 10:09 . 2012-04-26 19:26 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
- 2012-04-26 09:58 . 2012-04-26 19:26 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-04-26 09:58 . 2012-04-26 19:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-04-26 09:58 . 2012-04-26 19:47 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-04-26 09:58 . 2012-04-26 19:26 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-04-26 09:19 . 2012-04-26 19:27 3930 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1896610987-2083587572-4140636840-1000_UserData.bin
- 2012-04-26 19:26 . 2012-04-26 19:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-04-26 19:47 . 2012-04-26 19:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 04:54 . 2012-04-26 19:26 212992 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-04-26 19:48 212992 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-04-26 19:48 753664 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 02:36 . 2012-04-26 19:30 615122 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-04-26 19:10 615122 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-04-26 19:10 103496 c:\windows\system32\perfc009.dat
+ 2009-07-14 02:36 . 2012-04-26 19:30 103496 c:\windows\system32\perfc009.dat
+ 2009-07-14 05:01 . 2012-04-26 19:47 328644 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-04-26 19:25 328644 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-04-26 15:53 . 2012-04-26 19:47 328644 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1896610987-2083587572-4140636840-1000-8192.dat
- 2012-04-26 15:53 . 2012-04-26 19:25 328644 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1896610987-2083587572-4140636840-1000-8192.dat
- 2009-07-14 04:54 . 2012-04-26 19:26 4947968 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-04-26 19:48 4947968 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 02:34 . 2012-04-26 19:16 9699328 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:34 . 2012-04-26 19:39 9699328 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Java\jre6\bin\jusched.exe" [2009-10-26 148888]
"ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2009-07-17 237568]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"DellComms"="c:\program files (x86)\Dell\DellComms\bin\sprtcmd.exe" [2009-05-05 206064]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160]
.
c:\users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-03-31 92160]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
S2 sprtsvc_DellComms;SupportSoft Sprocket Service (DellComms);c:\program files (x86)\Dell\DellComms\bin\sprtsvc.exe [2009-05-05 206064]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
S3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-05-23 7833120]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [BU]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-26 16327712]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960]
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Jeffrey\AppData\Roaming\Mozilla\Firefox\Profiles\olkt1xwk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
AddRemove-{980A182F-E0A2-4A40-94C1-AE0C1235902E} - c:\program files (x86)\Pando Networks\Media Booster\uninst.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\SysWOW64\rundll32.exe
c:\\.\globalroot\systemroot\svchost.exe
.
**************************************************************************
.
Completion time: 2012-04-26 15:50:10 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-26 19:50
ComboFix2.txt 2012-04-26 19:28
.
Pre-Run: 948,919,439,360 bytes free
Post-Run: 948,872,486,912 bytes free
.
- - End Of File - - AC4A70DEE6A83B9185851DC16FEA2389
i noticed the pando media booster files were deleted. are they infected? because if they are, they come prepackaged with league of legends and someone should let riot games know they're handing out infected files. also my dell dock is gone though i'm not terribly broken up about it, i'm wondering if thats another virus.
i noticed the pando media booster files were deleted
Portions of it were…if you would like to reinstall it after we are done that would be fine.
———-
Please download
Malwarebytes' Anti-Malware to your desktop.
Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program. At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware , then click Finish . If an update is found, it will download and install the latest version. Once the program has loaded, select Perform quick scan , then click Scan as shown below.
[external image: Posted Image]
When the scan is complete, click OK , then Show Results to view the results. Be sure that everything is checked, and click Remove Selected . When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-
ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan
Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.
As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
Do not use this instance of your browser for anything besides doing this scan When the scan is complete and the results saved, close that instance of your browser Open a new one the usual way and post the results in this topic.
Right-click and Run as Administartor on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan Click the [external image: Posted Image] button. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop. Double click on the [external image: Posted Image] icon on your desktop. Check [external image: Posted Image] Click the Start button. Accept any security warnings from your browser. Check [external image: Posted Image] Make sure that the option "Remove found threats" is Unchecked Push the Start button. ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time. When the scan completes, push [external image: Posted Image] Push [external image: Posted Image] , and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply. Push the Back button. Push Finish
http://www.eset.com/onlinescan/
———-
In your next reply please post the logs made by Malwarebytes and ESET.
ok malewarebytes log
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.04.26.04
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Jeffrey :: JEFFREY-PC [administrator]
Protection: Enabled
4/26/2012 4:08:10 PM
mbam-log-2012-04-26 (16-08-10).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204022
Time elapsed: 48 second(s)
Memory Processes Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> 4332 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.
(end)
and eset log
C:\Qoobox\Quarantine\C\ProgramData\XkFcjVGVgWJhiQK.exe.vir a variant of Win32/Kryptik.AEUQ trojan
btw while running the eset scan malwarebytes popped up a little thing about scvhost trying to run something or other so i clicked quarantine.
also i have to run some errands in about an hour so if i suddenly dissapear thats why. i'll be back in like an hour though.
Good…How is your system running?
its running fine. i'm a little concerned about the svchost pick up though. should i run another malwarebytes scan to see if its gone? i also wondered if you could recommend a good internet security program for someone who likes to watch a lot of anime episodes online. either one with an add blocker or if there isn't one with those maybe suggest a separate add blocker and popup blocker.
Hi,
Sure you can run another Malwarebytes Quick Scan and post the log.
I really like
Avast myself. It is free and is just plain good!!
Or you could try
Microsoft Security Essentials which is good too, but be sure to choose only one.
here's the log. it found it and now i need to restart it says so..restarting
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.04.26.04
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Jeffrey :: JEFFREY-PC [administrator]
Protection: Enabled
4/26/2012 9:21:27 PM
mbam-log-2012-04-26 (21-21-27).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204017
Time elapsed: 35 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
(end)
ok rebooted and malwarebytes keeps blocking svchost from acessing a melicious site and now things keep popping up for me to quarintine
ok its like the stuff hit the fan all of a sudden i've gotten like 10 quarentines and a bunch of malicious site blocks
Hi,
Run a new scan with OTL
In Custom Scans/Fixes put the following:
netsvcs
/md5start
consrv.dll
/md5stop
createrestorepoint
Press the Run Scan button and post the newly made log to your next reply.
none of my desktop icons are showing up
nor will anything in my start menue