This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow computer ... virus? [Closed]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi :). My computer is working as usual, except it's very slow. I've had this before (and been helped here), and it was a virus. Any help would be GREATLY appreciated. Thanks!
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

Please post the logs made by DDS and aswMBR to your next reply.
. DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31 Run by [removed] at 10:21:18 on 2012-05-04 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4044.1170 [GMT -4:00] . AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B} . ============== Running Processes =============== . C:\windows\system32\wininit.exe C:\windows\system32\lsm.exe C:\windows\system32\svchost.exe -k DcomLaunch C:\windows\system32\svchost.exe -k RPCSS C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\windows\system32\svchost.exe -k netsvcs C:\windows\system32\svchost.exe -k LocalService C:\windows\system32\svchost.exe -k NetworkService C:\windows\System32\spoolsv.exe C:\windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe C:\windows\system32\taskhost.exe C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\windows\system32\svchost.exe -k imgsvc C:\windows\system32\TODDSrv.exe C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Windows\System32\StikyNot.exe C:\Program Files (x86)\BitTorrent\BitTorrent.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\windows\system32\taskhost.exe C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe Q:\140066.enu\Office14\WINWORDC.EXE C:\windows\splwow64.exe Q:\140066.enu\Office14\OffSpon.EXE C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\windows\explorer.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files (x86)\VideoLAN\VLC\vlc.exe C:\windows\explorer.exe C:\windows\system32\mspaint.exe C:\windows\system32\mspaint.exe C:\windows\system32\mspaint.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Program Files (x86)\Windows Media Player\wmplayer.exe C:\windows\system32\calc.exe C:\windows\system32\calc.exe C:\windows\system32\SearchProtocolHost.exe C:\windows\system32\SearchFilterHost.exe C:\windows\SysWOW64\cmd.exe C:\windows\system32\conhost.exe C:\windows\SysWOW64\cscript.exe C:\windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://start.toshiba.com/?cid=C001B2Y uDefault_Page_URL = hxxp://start.toshiba.com/?cid=C001B2Y uInternet Settings,ProxyOverride = ;*.local mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe uRun: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe" /MINIMIZED uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Standby] "c:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -START mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab TCP: DhcpNameServer = 192.168.254.254 192.168.254.254 TCP: Interfaces\{3CA6EBC8-F765-490A-AC8C-51A57724CEE7} : DhcpNameServer = 192.168.254.254 192.168.254.254 TCP: Interfaces\{C65F7F64-9738-44C6-9E9A-C651FDF10295} : DhcpNameServer = [removed] [removed] Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [Standby] "c:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -START mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\9jna99sf.default\ FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;C:\windows\system32\DRIVERS\MpFilter.sys –> C:\windows\system32\DRIVERS\MpFilter.sys [?] R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\system32\DRIVERS\tos_sps64.sys –> C:\windows\system32\DRIVERS\tos_sps64.sys [?] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\windows\system32\DRIVERS\dtsoftbus01.sys –> C:\windows\system32\DRIVERS\dtsoftbus01.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys –> C:\windows\system32\DRIVERS\vwififlt.sys [?] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624] R2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe [2011-11-30 135608] R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [2011-11-30 126392] R3 FwLnk;FwLnk Driver;C:\windows\system32\DRIVERS\FwLnk.sys –> C:\windows\system32\DRIVERS\FwLnk.sys [?] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\windows\system32\DRIVERS\L1C62x64.sys –> C:\windows\system32\DRIVERS\L1C62x64.sys [?] R3 MEIx64;Intel® Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys –> C:\windows\system32\DRIVERS\HECIx64.sys [?] R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] R3 PGEffect;Pangu effect driver;C:\windows\system32\DRIVERS\pgeffect.sys –> C:\windows\system32\DRIVERS\pgeffect.sys [?] R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\windows\system32\DRIVERS\rtl8192Ce.sys –> C:\windows\system32\DRIVERS\rtl8192Ce.sys [?] R3 Sftfs;Sftfs;C:\windows\system32\DRIVERS\Sftfslh.sys –> C:\windows\system32\DRIVERS\Sftfslh.sys [?] R3 Sftplay;Sftplay;C:\windows\system32\DRIVERS\Sftplaylh.sys –> C:\windows\system32\DRIVERS\Sftplaylh.sys [?] R3 Sftredir;Sftredir;C:\windows\system32\DRIVERS\Sftredirlh.sys –> C:\windows\system32\DRIVERS\Sftredirlh.sys [?] R3 Sftvol;Sftvol;C:\windows\system32\DRIVERS\Sftvollh.sys –> C:\windows\system32\DRIVERS\Sftvollh.sys [?] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys –> C:\windows\system32\DRIVERS\vwifimp.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 136176] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-3 253088] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 136176] S3 NisDrv;Microsoft Network Inspection System;C:\windows\system32\DRIVERS\NisDrvWFP.sys –> C:\windows\system32\DRIVERS\NisDrvWFP.sys [?] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUStor.sys –> C:\windows\system32\Drivers\RtsUStor.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys –> C:\windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys –> C:\windows\system32\drivers\TsUsbGD.sys [?] . =============== Created Last 30 ================ . 2012-05-03 01:12:43 8917360 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{537056C2-9A11-4C08-BCEE-CE063FD3F234}\mpengine.dll 2012-05-02 13:45:24 8917360 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-05-01 07:01:22 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client 2012-04-30 18:48:51 ——– d—–w- C:\Users\Owner\AppData\Local\{555A315E-9D74-4EB9-901F-E5D9E156907F} 2012-04-30 18:48:39 ——– d—–w- C:\Users\Owner\AppData\Local\{8FB25D57-7E5B-4D0F-8B41-0C3BBFC95FEA} 2012-04-20 03:41:09 ——– d—–w- C:\Program Files\iPod 2012-04-20 03:41:08 ——– d—–w- C:\Program Files\iTunes 2012-04-20 03:41:08 ——– d—–w- C:\Program Files (x86)\iTunes 2012-04-17 20:30:46 ——– d—–w- C:\Users\Owner\AppData\Local\19th Parallel 2012-04-17 20:30:46 ——– d—–w- C:\Program Files (x86)\19th Parallel 2012-04-16 20:21:01 ——– d—–w- C:\Users\Owner\AppData\Local\{63DD4604-C8FC-4063-B4E0-619B02534593} 2012-04-14 18:25:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2012-04-14 18:25:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2012-04-14 18:25:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2012-04-14 18:25:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2012-04-14 18:25:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2012-04-14 18:25:43 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2012-04-14 18:25:43 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2012-04-12 09:42:25 81408 —-a-w- C:\windows\System32\imagehlp.dll 2012-04-12 09:42:25 23408 —-a-w- C:\windows\System32\drivers\fs_rec.sys 2012-04-12 09:42:25 159232 —-a-w- C:\windows\SysWow64\imagehlp.dll 2012-04-12 09:42:24 172544 —-a-w- C:\windows\SysWow64\wintrust.dll 2012-04-12 09:42:23 5120 —-a-w- C:\windows\SysWow64\wmi.dll 2012-04-12 09:42:23 5120 —-a-w- C:\windows\System32\wmi.dll 2012-04-12 09:42:23 220672 —-a-w- C:\windows\System32\wintrust.dll 2012-04-10 15:12:26 ——– d—–w- C:\Program Files (x86)\Common Files\Symantec Shared 2012-04-10 15:08:35 ——– d—–w- C:\ProgramData\Symantec 2012-04-05 00:56:39 ——– d—–w- C:\ProgramData\Spybot - Search & Destroy 2012-04-05 00:56:39 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy 2012-04-04 23:59:36 ——– d—–w- C:\Program Files\PeerBlock . ==================== Find3M ==================== . 2012-04-23 19:41:57 70304 —-a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-04-23 19:41:57 418464 —-a-w- C:\windows\SysWow64\FlashPlayerApp.exe 2012-04-19 01:57:09 472808 —-a-w- C:\windows\SysWow64\deployJava1.dll 2012-04-13 22:58:36 8741536 —-a-w- C:\windows\SysWow64\FlashPlayerInstaller.exe 2012-04-08 18:14:53 5642 –sha-w- C:\ProgramData\KGyGaAvL.sys 2012-03-21 00:44:12 98688 —-a-w- C:\windows\System32\drivers\NisDrvWFP.sys 2012-03-21 00:44:12 203888 —-a-w- C:\windows\System32\drivers\MpFilter.sys 2012-03-06 06:53:37 5559152 —-a-w- C:\windows\System32\ntoskrnl.exe 2012-03-06 05:59:47 3968368 —-a-w- C:\windows\SysWow64\ntkrnlpa.exe 2012-03-06 05:59:41 3913072 —-a-w- C:\windows\SysWow64\ntoskrnl.exe 2012-02-28 06:56:48 2311168 —-a-w- C:\windows\System32\jscript9.dll 2012-02-28 06:49:56 1390080 —-a-w- C:\windows\System32\wininet.dll 2012-02-28 06:48:57 1493504 —-a-w- C:\windows\System32\inetcpl.cpl 2012-02-28 06:42:55 2382848 —-a-w- C:\windows\System32\mshtml.tlb 2012-02-28 01:18:55 1799168 —-a-w- C:\windows\SysWow64\jscript9.dll 2012-02-28 01:11:21 1427456 —-a-w- C:\windows\SysWow64\inetcpl.cpl 2012-02-28 01:11:07 1127424 —-a-w- C:\windows\SysWow64\wininet.dll 2012-02-28 01:03:16 2382848 —-a-w- C:\windows\SysWow64\mshtml.tlb 2012-02-23 17:40:12 88 –sh–r- C:\ProgramData\B0545EB164.sys 2012-02-17 06:38:26 1031680 —-a-w- C:\windows\System32\rdpcore.dll 2012-02-17 05:34:22 826880 —-a-w- C:\windows\SysWow64\rdpcore.dll 2012-02-17 04:58:24 210944 —-a-w- C:\windows\System32\drivers\rdpwd.sys 2012-02-17 04:57:32 23552 —-a-w- C:\windows\System32\drivers\tdtcp.sys 2012-02-15 20:02:02 283200 —-a-w- C:\windows\System32\drivers\dtsoftbus01.sys 2012-02-10 06:36:07 1544192 —-a-w- C:\windows\System32\DWrite.dll 2012-02-10 05:38:43 1077248 —-a-w- C:\windows\SysWow64\DWrite.dll . ============= FINISH: 10:22:26.81 ===============

Attachments:

I downloaded the second program, aswMBR, and it did a blue screen thing mid-scan (I never have the blue screen thing). Should I continue with the scan? This is the error report … Problem signature: Problem Event Name: BlueScreen OS Version: 6.1.7601.2.1.0.768.3 Locale ID: 1033 Additional information about the problem: BCCode: d1 BCP1: 0000000000000000 BCP2: 0000000000000002 BCP3: 0000000000000008 BCP4: 0000000000000000 OS Version: 6_1_7601 Service Pack: 1_0 Product: 768_1 Files that help describe the problem: C:\Windows\Minidump\050412-39000-01.dmp C:\Users\Owner\AppData\Local\Temp\WER-89716-0.sysdata.xml
I went ahead and did the aswMBR scan again. aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-05-04 10:36:26 —————————– 10:36:26.130 OS Version: Windows x64 6.1.7601 Service Pack 1 10:36:26.130 Number of processors: 4 586 0x2A07 10:36:26.130 ComputerName: OWNER-PC UserName: Owner 10:36:27.459 Initialze error C000010E - driver not loaded 10:36:27.659 write error "aswCmnB.dll". The process cannot access the file because it is being used by another process. 10:36:33.350 Service scanning 10:37:06.843 Modules scanning 10:37:06.843 Disk 0 trace - called modules: 10:37:06.843 10:37:06.843 Scan finished successfully 10:37:22.758 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"
I had to download the Avast virus definitions before the aswMBR program would work (?). Anyway, this is the log … aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-05-04 13:28:05 —————————– 13:28:05.947 OS Version: Windows x64 6.1.7601 Service Pack 1 13:28:05.947 Number of processors: 4 586 0x2A07 13:28:05.948 ComputerName: OWNER-PC UserName: Owner 13:28:07.979 Initialize success 13:31:30.303 AVAST engine defs: 12050400 13:31:38.034 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 13:31:38.040 Disk 0 Vendor: TOSHIBA_ GT00 Size: 305245MB BusType: 3 13:31:38.046 Disk 0 MBR read successfully 13:31:38.053 Disk 0 MBR scan 13:31:38.079 Disk 0 Windows VISTA default MBR code 13:31:38.110 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048 13:31:38.172 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 289747 MB offset 3074048 13:31:38.227 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 13997 MB offset 596475904 13:31:38.329 Disk 0 scanning C:\windows\system32\drivers 13:31:50.025 Service scanning 13:32:34.441 Modules scanning 13:32:34.462 Disk 0 trace - called modules: 13:32:34.484 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 13:32:34.492 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800690c060] 13:32:34.715 3 CLASSPNP.SYS[fffff880018a643f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004a48050] 13:32:36.300 AVAST engine scan C:\windows 13:32:39.134 AVAST engine scan C:\windows\system32 13:36:58.165 AVAST engine scan C:\windows\system32\drivers 13:37:11.611 AVAST engine scan C:\Users\Owner 13:38:46.415 File: C:\Users\Owner\AppData\Roaming\Adobe\Flash Player\NativeCache\2B6D427C0AF6E92873BF2615668F421B\7df9b4e0\adobecp-200489-1.dll **INFECTED** Win32:Malware-gen 13:46:43.636 AVAST engine scan C:\ProgramData 13:48:40.228 Scan finished successfully 14:53:11.628 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat" 14:53:11.695 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt" 14:54:16.096 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat" 14:54:16.103 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR2.txt"
Hi,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.


Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
HELP!!!!!!!!!!!!! I did the ComboFix, it finished and the computer rebooted. Then when I tried to get back online Mozilla wouldn't work. The error message says … C:\Program Fils (x86)\Mozilla Firefox\firefox.exe Illegal operation attempted on a registry key that has been marked for deletion. It says the same thing when I try to get to system restore, and Internet Explorer and just about every program I have. I haven't tried everything, but almost everything I try has that same "illegal operation" message. HELP!!! How do I get this working again???
Just go ahead and reboot your system. It may take two tries but it is nothing to worry about. :) When you find the log that ComboFix has created be sure to post that as well.
OK, whew, it's all working again. Thanks :) Log is below. ComboFix 12-05-05.06 - Owner 05/05/2012 17:17:04.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4044.964 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6} SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Amazon.ico c:\programdata\MercadoLivre.ico c:\programdata\QuickStores.ico c:\users\Owner\AppData\Local\TempDIR c:\windows\system32\Thumbs.db . . ((((((((((((((((((((((((( Files Created from 2012-04-05 to 2012-05-05 ))))))))))))))))))))))))))))))) . . 2012-05-05 21:21 . 2012-05-05 21:21 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-05-05 19:31 . 2012-04-13 08:46 8917360 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{346A1163-0BD5-4739-BDCC-49655E000438}\mpengine.dll 2012-05-05 01:45 . 2012-04-13 08:46 8917360 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-05-01 07:01 . 2012-05-01 07:01 ——– d—–w- c:\program files (x86)\Microsoft Security Client 2012-04-24 00:00 . 2012-04-24 00:00 ——– d—–w- c:\windows\Sun 2012-04-20 03:41 . 2012-04-20 03:41 ——– d—–w- c:\program files\iPod 2012-04-20 03:41 . 2012-04-20 03:41 ——– d—–w- c:\program files\iTunes 2012-04-20 03:41 . 2012-04-20 03:41 ——– d—–w- c:\program files (x86)\iTunes 2012-04-19 01:57 . 2012-04-19 01:57 ——– d—–w- c:\program files (x86)\Common Files\Java 2012-04-19 01:57 . 2012-04-19 01:57 ——– d—–w- c:\program files (x86)\Java 2012-04-17 20:30 . 2012-04-17 20:31 ——– d—–w- c:\users\Owner\AppData\Local\19th Parallel 2012-04-17 20:30 . 2012-04-17 20:30 ——– d—–w- c:\program files (x86)\19th Parallel 2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2012-04-14 18:25 . 2012-04-14 18:25 ——– d—–w- c:\program files (x86)\QuickTime 2012-04-12 09:42 . 2012-03-01 06:46 23408 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-12 09:42 . 2012-03-01 06:33 81408 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-12 09:42 . 2012-03-01 05:33 159232 —-a-w- c:\windows\SysWow64\imagehlp.dll 2012-04-12 09:42 . 2012-03-01 05:37 172544 —-a-w- c:\windows\SysWow64\wintrust.dll 2012-04-12 09:42 . 2012-03-01 06:38 220672 —-a-w- c:\windows\system32\wintrust.dll 2012-04-12 09:42 . 2012-03-01 06:28 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-12 09:42 . 2012-03-01 05:29 5120 —-a-w- c:\windows\SysWow64\wmi.dll 2012-04-10 15:12 . 2012-04-10 15:12 ——– d—–w- c:\program files (x86)\Common Files\Symantec Shared 2012-04-10 15:08 . 2012-04-10 15:08 ——– d—–w- c:\programdata\Symantec . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-05 06:59 . 2012-04-03 05:09 419488 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-05-05 06:59 . 2011-10-31 02:34 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-05-05 06:59 . 2012-04-03 05:58 8744608 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2012-04-19 01:57 . 2012-01-14 14:03 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-04-08 18:14 . 2012-01-29 07:33 5642 –sha-w- c:\programdata\KGyGaAvL.sys 2012-03-21 00:44 . 2011-04-27 20:25 98688 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2012-03-21 00:44 . 2011-04-18 18:18 203888 —-a-w- c:\windows\system32\drivers\MpFilter.sys 2012-03-03 20:14 . 2012-03-03 20:14 927800 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1AF21C05-7682-4368-8699-7788662FA8AC}\gapaengine.dll 2012-02-23 17:40 . 2012-01-29 07:33 88 –sh–r- c:\programdata\B0545EB164.sys 2012-02-17 06:38 . 2012-03-14 14:26 1031680 —-a-w- c:\windows\system32\rdpcore.dll 2012-02-17 05:34 . 2012-03-14 14:26 826880 —-a-w- c:\windows\SysWow64\rdpcore.dll 2012-02-17 04:58 . 2012-03-14 14:26 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-02-17 04:57 . 2012-03-14 14:26 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-02-15 20:02 . 2012-02-15 19:54 283200 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2012-02-10 06:36 . 2012-03-14 14:29 1544192 —-a-w- c:\windows\system32\DWrite.dll 2012-02-10 05:38 . 2012-03-14 14:29 1077248 —-a-w- c:\windows\SysWow64\DWrite.dll 2012-02-08 07:13 . 2012-03-02 16:00 8643640 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BAA95D8C-2379-4DC4-A3DB-007A8822CF1F}\mpengine.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent"="c:\program files (x86)\BitTorrent\BitTorrent.exe" [2012-02-22 650104] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-01-24 3478336] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "Standby"="c:\program files (x86)\Common Files\Corel\Standby\Standby.exe" [2009-12-17 105632] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackupReminder] 2011-06-22 22:26 3218864 —-a-w- c:\program files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToshibaAppPlace] 2010-09-23 18:03 552960 —-a-w- c:\program files (x86)\TOSHIBA\Toshiba App Place\ToshibaAppPlace.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToshibaServiceStation] 2011-07-12 01:16 1298816 —-a-w- c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 136176] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 136176] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-07-12 57216] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-06-10 138152] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe [2012-03-19 135608] S2 PCCUJobMgr;Common Client Job Manager Service;c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [2011-07-19 126392] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-01 2656280] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-05-05 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 06:59] . 2012-05-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 22:45] . 2012-05-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 22:45] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://start.toshiba.com/?cid=C001B2Y mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = ;*.local TCP: DhcpNameServer = 192.168.254.254 192.168.254.254 FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\9jna99sf.default\ . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCCUJobMgr] "ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2012-05-05 17:26:30 - machine was rebooted ComboFix-quarantined-files.txt 2012-05-05 21:26 . Pre-Run: 152,984,195,072 bytes free Post-Run: 153,120,079,872 bytes free . - - End Of File - - 714AF4A5F9AF89250780AEA43D4D274A
Hi,

P2P - I see you have P2P software BitTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Programs and Features.
———-

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    uInternet Settings,ProxyOverride = ;*.local
    BHO-X64: AcroIEHelperStub - No File
    
    File::
    C:\ProgramData\B0545EB164.sys
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

In your next reply please post the new log made by ComboFix. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI