This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

rootkit.boot.pihar.b won't go away [Solved]

120 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok…still not working.

Let's get out the big boy! :)

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ok so it says to turn off my antivirus and antispyware. but the link doesn't say how to turn of mcafee security suite that comes from at&t. what features need to be off? i'm assuming real time scanning and the firewall right?
ok here we go. combofix log ComboFix 12-04-26.01 - Jeffrey 04/26/2012 15:22:29.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8183.6476 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\XkFcjVGVgWJhiQK.exe c:\windows\svchost.exe . . ((((((((((((((((((((((((( Files Created from 2012-03-26 to 2012-04-26 ))))))))))))))))))))))))))))))) . . 2012-04-26 18:36 . 2012-04-26 18:37 ——– d—–w- c:\program files (x86)\ERUNT 2012-04-26 16:24 . 2012-04-26 16:24 ——– d—–w- c:\windows\Sun 2012-04-26 15:53 . 2012-04-26 18:23 ——– d—–w- C:\TDSSKiller_Quarantine 2012-04-26 14:54 . 2008-07-31 14:41 68616 —-a-w- c:\windows\SysWow64\XAPOFX1_1.dll 2012-04-26 14:54 . 2008-07-31 14:40 509448 —-a-w- c:\windows\SysWow64\XAudio2_2.dll 2012-04-26 14:54 . 2008-07-12 12:18 467984 —-a-w- c:\windows\SysWow64\d3dx10_39.dll 2012-04-26 14:54 . 2008-07-12 12:18 3851784 —-a-w- c:\windows\SysWow64\D3DX9_39.dll 2012-04-26 14:54 . 2008-07-12 12:18 1493528 —-a-w- c:\windows\SysWow64\D3DCompiler_39.dll 2012-04-26 14:52 . 2012-04-26 14:52 ——– d—–w- C:\Riot Games 2012-04-26 10:43 . 2012-04-26 18:36 ——– d—–w- c:\programdata\PMB Files 2012-04-26 10:42 . 2012-04-26 10:42 ——– d—–w- c:\program files (x86)\Pando Networks 2012-04-26 10:36 . 2012-04-26 10:36 ——– d—–w- c:\program files (x86)\Mozilla Maintenance Service 2012-04-26 10:29 . 2012-04-26 10:29 ——– d—–w- c:\program files (x86)\Common Files\McAfee 2012-04-26 10:29 . 2012-02-22 17:29 10248 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2012-04-26 10:29 . 2012-02-22 17:29 75936 —-a-w- c:\windows\system32\drivers\mfenlfk.sys 2012-04-26 10:29 . 2012-02-22 17:29 65264 —-a-w- c:\windows\system32\drivers\cfwids.sys 2012-04-26 10:29 . 2012-02-22 17:29 487296 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2012-04-26 10:29 . 2012-02-22 17:29 289664 —-a-w- c:\windows\system32\drivers\mfewfpk.sys 2012-04-26 10:29 . 2012-02-22 17:29 229528 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2012-04-26 10:29 . 2012-02-22 17:29 100912 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-04-26 10:29 . 2012-04-26 10:29 ——– d—–w- c:\program files\Common Files\McAfee 2012-04-26 10:29 . 2012-04-26 10:30 ——– d—–w- c:\program files\McAfee 2012-04-26 10:29 . 2012-04-26 15:54 ——– d—–w- c:\program files (x86)\McAfee 2012-04-26 10:13 . 2012-03-20 17:11 162192 —-a-w- c:\windows\system32\mfevtps.exe 2012-04-26 10:13 . 2012-04-26 13:29 ——– d—–w- c:\programdata\McAfee 2012-04-26 10:08 . 2012-04-26 10:08 ——– d—–w- c:\program files (x86)\Compact Wireless-G USB Adapter Wireless Network Monitor 2012-04-26 10:08 . 2001-09-05 08:18 77824 —-a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll 2012-04-26 10:08 . 2001-09-05 08:18 225280 ——w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll 2012-04-26 10:08 . 2001-09-05 08:14 176128 ——w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll 2012-04-26 10:08 . 2001-09-05 08:13 32768 ——w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll 2012-04-26 10:02 . 2012-04-26 10:04 ——– d—–w- c:\users\Jeffrey 2012-04-26 09:45 . 2012-04-18 08:03 8917360 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2E70F480-88C1-4FEF-A7D6-4A31B65AAC75}\mpengine.dll 2012-04-26 09:45 . 2012-02-23 15:18 279656 ——w- c:\windows\system32\MpSigStub.exe 2012-04-26 09:12 . 2012-02-15 06:27 1031680 —-a-w- c:\windows\system32\rdpcore.dll 2012-04-26 09:12 . 2012-02-15 05:44 826368 —-a-w- c:\windows\SysWow64\rdpcore.dll 2012-04-26 09:12 . 2012-02-15 04:47 204800 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 09:12 . 2012-02-15 04:46 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-04-26 09:12 . 2012-01-25 06:27 76288 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 09:12 . 2012-01-25 06:27 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 09:12 . 2012-01-25 06:20 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-26 09:12 . 2010-01-09 07:19 139264 —-a-w- c:\windows\system32\cabview.dll 2012-04-26 09:12 . 2010-01-09 06:52 132608 —-a-w- c:\windows\SysWow64\cabview.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-22 17:29 . 2012-02-22 17:29 647208 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2012-02-22 17:29 . 2012-02-22 17:29 160792 —-a-w- c:\windows\system32\drivers\mfeapfk.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files (x86)\Java\jre6\bin\jusched.exe" [2009-10-26 148888] "ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2009-07-17 237568] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520] "DellComms"="c:\program files (x86)\Dell\DellComms\bin\sprtcmd.exe" [2009-05-05 206064] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160] . c:\users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192] ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936] R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976] R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-03-31 92160] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x] S2 sprtsvc_DellComms;SupportSoft Sprocket Service (DellComms);c:\program files (x86)\Dell\DellComms\bin\sprtsvc.exe [2009-05-05 206064] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x] S3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL *Deregistered* - mfeavfk01 . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-05-23 7833120] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-26 16327712] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\Jeffrey\AppData\Roaming\Mozilla\Firefox\Profiles\olkt1xwk.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) HKLM-Run-Skytel - c:\program files\Realtek\Audio\HDA\Skytel.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}] @Denied: (A 2) (Everyone) @="IFlashBroker2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\windows\SysWOW64\rundll32.exe c:\\.\globalroot\systemroot\svchost.exe . ************************************************************************** . Completion time: 2012-04-26 15:28:33 - machine was rebooted ComboFix-quarantined-files.txt 2012-04-26 19:28 . Pre-Run: 948,807,012,352 bytes free Post-Run: 948,911,742,976 bytes free . - - End Of File - - ED464CD552EDD63B4C38337F91679FBF
Ok…

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    Firefox::
    FF - ProfilePath - c:\users\Jeffrey\AppData\Roaming\Mozilla\Firefox\Profiles\olkt1xwk.default\
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    
    Folder::
    c:\program files (x86)\Pando Networks
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
ok log ComboFix 12-04-26.01 - Jeffrey 04/26/2012 15:44:21.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8183.6646 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Jeffrey\Desktop\CFScript.txt AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Pando Networks c:\program files (x86)\Pando Networks\Media Booster\BsSndRpt.exe c:\program files (x86)\Pando Networks\Media Booster\BugSplat.dll c:\program files (x86)\Pando Networks\Media Booster\BugSplatRc.dll c:\program files (x86)\Pando Networks\Media Booster\freebl3.dll c:\program files (x86)\Pando Networks\Media Booster\Media Booster FAQs.url c:\program files (x86)\Pando Networks\Media Booster\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest c:\program files (x86)\Pando Networks\Media Booster\Microsoft.VC90.CRT\msvcp90.dll c:\program files (x86)\Pando Networks\Media Booster\Microsoft.VC90.CRT\msvcr90.dll c:\program files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll c:\program files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll.2.config c:\program files (x86)\Pando Networks\Media Booster\nspr4.dll c:\program files (x86)\Pando Networks\Media Booster\nss3.dll c:\program files (x86)\Pando Networks\Media Booster\nssckbi.dll c:\program files (x86)\Pando Networks\Media Booster\plc4.dll c:\program files (x86)\Pando Networks\Media Booster\plds4.dll c:\program files (x86)\Pando Networks\Media Booster\PMB.cpl c:\program files (x86)\Pando Networks\Media Booster\PMB.exe c:\program files (x86)\Pando Networks\Media Booster\PMB.exe.config c:\program files (x86)\Pando Networks\Media Booster\smime3.dll c:\program files (x86)\Pando Networks\Media Booster\softokn3.dll c:\program files (x86)\Pando Networks\Media Booster\ssl3.dll c:\program files (x86)\Pando Networks\Media Booster\uninst.exe c:\windows\svchost.exe . . ((((((((((((((((((((((((( Files Created from 2012-03-26 to 2012-04-26 ))))))))))))))))))))))))))))))) . . 2012-04-26 19:47 . 2012-04-26 19:47 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-26 18:36 . 2012-04-26 18:37 ——– d—–w- c:\program files (x86)\ERUNT 2012-04-26 16:24 . 2012-04-26 16:24 ——– d—–w- c:\windows\Sun 2012-04-26 15:53 . 2012-04-26 18:23 ——– d—–w- C:\TDSSKiller_Quarantine 2012-04-26 14:54 . 2008-07-31 14:41 68616 —-a-w- c:\windows\SysWow64\XAPOFX1_1.dll 2012-04-26 14:54 . 2008-07-31 14:40 509448 —-a-w- c:\windows\SysWow64\XAudio2_2.dll 2012-04-26 14:54 . 2008-07-12 12:18 467984 —-a-w- c:\windows\SysWow64\d3dx10_39.dll 2012-04-26 14:54 . 2008-07-12 12:18 3851784 —-a-w- c:\windows\SysWow64\D3DX9_39.dll 2012-04-26 14:54 . 2008-07-12 12:18 1493528 —-a-w- c:\windows\SysWow64\D3DCompiler_39.dll 2012-04-26 14:52 . 2012-04-26 14:52 ——– d—–w- C:\Riot Games 2012-04-26 10:43 . 2012-04-26 18:36 ——– d—–w- c:\programdata\PMB Files 2012-04-26 10:36 . 2012-04-26 10:36 ——– d—–w- c:\program files (x86)\Mozilla Maintenance Service 2012-04-26 10:29 . 2012-04-26 10:29 ——– d—–w- c:\program files (x86)\Common Files\McAfee 2012-04-26 10:29 . 2012-02-22 17:29 10248 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2012-04-26 10:29 . 2012-02-22 17:29 75936 —-a-w- c:\windows\system32\drivers\mfenlfk.sys 2012-04-26 10:29 . 2012-02-22 17:29 65264 —-a-w- c:\windows\system32\drivers\cfwids.sys 2012-04-26 10:29 . 2012-02-22 17:29 487296 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2012-04-26 10:29 . 2012-02-22 17:29 289664 —-a-w- c:\windows\system32\drivers\mfewfpk.sys 2012-04-26 10:29 . 2012-02-22 17:29 229528 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2012-04-26 10:29 . 2012-02-22 17:29 100912 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-04-26 10:29 . 2012-04-26 10:29 ——– d—–w- c:\program files\Common Files\McAfee 2012-04-26 10:29 . 2012-04-26 10:30 ——– d—–w- c:\program files\McAfee 2012-04-26 10:29 . 2012-04-26 15:54 ——– d—–w- c:\program files (x86)\McAfee 2012-04-26 10:13 . 2012-03-20 17:11 162192 —-a-w- c:\windows\system32\mfevtps.exe 2012-04-26 10:13 . 2012-04-26 13:29 ——– d—–w- c:\programdata\McAfee 2012-04-26 10:08 . 2012-04-26 10:08 ——– d—–w- c:\program files (x86)\Compact Wireless-G USB Adapter Wireless Network Monitor 2012-04-26 10:08 . 2001-09-05 08:18 77824 —-a-w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll 2012-04-26 10:08 . 2001-09-05 08:18 225280 ——w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll 2012-04-26 10:08 . 2001-09-05 08:14 176128 ——w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll 2012-04-26 10:08 . 2001-09-05 08:13 32768 ——w- c:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll 2012-04-26 10:02 . 2012-04-26 10:04 ——– d—–w- c:\users\Jeffrey 2012-04-26 09:45 . 2012-04-18 08:03 8917360 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2E70F480-88C1-4FEF-A7D6-4A31B65AAC75}\mpengine.dll 2012-04-26 09:45 . 2012-02-23 15:18 279656 ——w- c:\windows\system32\MpSigStub.exe 2012-04-26 09:12 . 2012-02-15 06:27 1031680 —-a-w- c:\windows\system32\rdpcore.dll 2012-04-26 09:12 . 2012-02-15 05:44 826368 —-a-w- c:\windows\SysWow64\rdpcore.dll 2012-04-26 09:12 . 2012-02-15 04:47 204800 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 09:12 . 2012-02-15 04:46 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-04-26 09:12 . 2012-01-25 06:27 76288 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 09:12 . 2012-01-25 06:27 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 09:12 . 2012-01-25 06:20 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-26 09:12 . 2010-01-09 07:19 139264 —-a-w- c:\windows\system32\cabview.dll 2012-04-26 09:12 . 2010-01-09 06:52 132608 —-a-w- c:\windows\SysWow64\cabview.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-22 17:29 . 2012-02-22 17:29 647208 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2012-02-22 17:29 . 2012-02-22 17:29 160792 —-a-w- c:\windows\system32\drivers\mfeapfk.sys . . ((((((((((((((((((((((((((((( SnapShot@2012-04-26_19.26.30 ))))))))))))))))))))))))))))))))))))))))) . + 2012-04-26 10:05 . 2012-04-26 19:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat - 2012-04-26 10:05 . 2012-04-26 19:10 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2012-04-26 19:32 . 2012-04-26 19:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat - 2012-04-26 09:11 . 2012-04-26 19:10 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012042620120427\index.dat + 2012-04-26 09:11 . 2012-04-26 19:27 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012042620120427\index.dat - 2012-04-26 09:09 . 2012-04-26 19:10 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat + 2012-04-26 09:09 . 2012-04-26 19:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat + 2009-10-26 23:35 . 2012-04-26 19:27 25246 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-04-26 19:27 24328 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2012-04-26 09:58 . 2012-04-26 19:26 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-04-26 09:58 . 2012-04-26 19:03 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-04-26 09:58 . 2012-04-26 19:03 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-04-26 09:58 . 2012-04-26 19:26 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-04-26 19:26 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-04-26 19:03 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-04-26 09:58 . 2012-04-26 19:47 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-04-26 09:58 . 2012-04-26 19:26 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2012-04-26 10:09 . 2012-04-26 19:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat - 2012-04-26 10:09 . 2012-04-26 19:26 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat - 2012-04-26 10:09 . 2012-04-26 19:26 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat + 2012-04-26 10:09 . 2012-04-26 19:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat + 2012-04-26 10:09 . 2012-04-26 19:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat - 2012-04-26 10:09 . 2012-04-26 19:26 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat - 2012-04-26 09:58 . 2012-04-26 19:26 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-04-26 09:58 . 2012-04-26 19:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-04-26 09:58 . 2012-04-26 19:47 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2012-04-26 09:58 . 2012-04-26 19:26 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-04-26 09:19 . 2012-04-26 19:27 3930 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1896610987-2083587572-4140636840-1000_UserData.bin - 2012-04-26 19:26 . 2012-04-26 19:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-04-26 19:47 . 2012-04-26 19:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-07-14 04:54 . 2012-04-26 19:26 212992 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-04-26 19:48 212992 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-04-26 19:48 753664 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 02:36 . 2012-04-26 19:30 615122 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2012-04-26 19:10 615122 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2012-04-26 19:10 103496 c:\windows\system32\perfc009.dat + 2009-07-14 02:36 . 2012-04-26 19:30 103496 c:\windows\system32\perfc009.dat + 2009-07-14 05:01 . 2012-04-26 19:47 328644 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2012-04-26 19:25 328644 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2012-04-26 15:53 . 2012-04-26 19:47 328644 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1896610987-2083587572-4140636840-1000-8192.dat - 2012-04-26 15:53 . 2012-04-26 19:25 328644 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1896610987-2083587572-4140636840-1000-8192.dat - 2009-07-14 04:54 . 2012-04-26 19:26 4947968 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-04-26 19:48 4947968 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 02:34 . 2012-04-26 19:16 9699328 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT + 2009-07-14 02:34 . 2012-04-26 19:39 9699328 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files (x86)\Java\jre6\bin\jusched.exe" [2009-10-26 148888] "ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2009-07-17 237568] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520] "DellComms"="c:\program files (x86)\Dell\DellComms\bin\sprtcmd.exe" [2009-05-05 206064] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160] . c:\users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192] ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936] R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976] R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-03-31 92160] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-03-20 210584] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x] S2 sprtsvc_DellComms;SupportSoft Sprocket Service (DellComms);c:\program files (x86)\Dell\DellComms\bin\sprtsvc.exe [2009-05-05 206064] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x] S3 netr7364;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr7364.sys [x] . . — Other Services/Drivers In Memory — . *Deregistered* - mfeavfk01 . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-05-23 7833120] "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [BU] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-26 16327712] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\Jeffrey\AppData\Roaming\Mozilla\Firefox\Profiles\olkt1xwk.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) AddRemove-{980A182F-E0A2-4A40-94C1-AE0C1235902E} - c:\program files (x86)\Pando Networks\Media Booster\uninst.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}] @Denied: (A 2) (Everyone) @="IFlashBroker2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\windows\SysWOW64\rundll32.exe c:\\.\globalroot\systemroot\svchost.exe . ************************************************************************** . Completion time: 2012-04-26 15:50:10 - machine was rebooted ComboFix-quarantined-files.txt 2012-04-26 19:50 ComboFix2.txt 2012-04-26 19:28 . Pre-Run: 948,919,439,360 bytes free Post-Run: 948,872,486,912 bytes free . - - End Of File - - AC4A70DEE6A83B9185851DC16FEA2389 i noticed the pando media booster files were deleted. are they infected? because if they are, they come prepackaged with league of legends and someone should let riot games know they're handing out infected files. also my dell dock is gone though i'm not terribly broken up about it, i'm wondering if thats another virus.

i noticed the pando media booster files were deleted

Portions of it were…if you would like to reinstall it after we are done that would be fine.
———-

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.


  • Right-click and Run as Administartor on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs made by Malwarebytes and ESET. :)
ok malewarebytes log Malwarebytes Anti-Malware (Trial) 1.61.0.1400 www.malwarebytes.org Database version: v2012.04.26.04 Windows 7 x64 NTFS Internet Explorer 8.0.7600.16385 Jeffrey :: JEFFREY-PC [administrator] Protection: Enabled 4/26/2012 4:08:10 PM mbam-log-2012-04-26 (16-08-10).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 204022 Time elapsed: 48 second(s) Memory Processes Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> 4332 -> Delete on reboot. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot. (end) and eset log C:\Qoobox\Quarantine\C\ProgramData\XkFcjVGVgWJhiQK.exe.vir a variant of Win32/Kryptik.AEUQ trojan btw while running the eset scan malwarebytes popped up a little thing about scvhost trying to run something or other so i clicked quarantine. also i have to run some errands in about an hour so if i suddenly dissapear thats why. i'll be back in like an hour though.
its running fine. i'm a little concerned about the svchost pick up though. should i run another malwarebytes scan to see if its gone? i also wondered if you could recommend a good internet security program for someone who likes to watch a lot of anime episodes online. either one with an add blocker or if there isn't one with those maybe suggest a separate add blocker and popup blocker.
here's the log. it found it and now i need to restart it says so..restarting Malwarebytes Anti-Malware (Trial) 1.61.0.1400 www.malwarebytes.org Database version: v2012.04.26.04 Windows 7 x64 NTFS Internet Explorer 8.0.7600.16385 Jeffrey :: JEFFREY-PC [administrator] Protection: Enabled 4/26/2012 9:21:27 PM mbam-log-2012-04-26 (21-21-27).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 204017 Time elapsed: 35 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. (end) ok rebooted and malwarebytes keeps blocking svchost from acessing a melicious site and now things keep popping up for me to quarintine
Hi,

Run a new scan with OTL
In Custom Scans/Fixes put the following:

netsvcs
/md5start
consrv.dll
/md5stop
createrestorepoint


Press the Run Scan button and post the newly made log to your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI