Hi :). My computer is working as usual, except it's very slow. I've had this before (and been helped here), and it was a virus. Any help would be GREATLY appreciated. Thanks!
Hi and Welcome!!
My name is
Jeff . I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision .
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
First we need to make all files and folders VISIBLE :
Go to start>control panel>folder options>view Choose to "show hidden files and folders ," Uncheck the "hide protected operating system files" and the "hide extensions for know file types " boxes. Close the window with OK
———
Please download
DDS from either of these links
LINK 1
LINK 2
and save it to your
desktop.
Disable any script blocking protection Right-click and Run as Administrator dds to run the tool. When done, two DDS.txt's will open. Save both reports to your desktop. —————————————————
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt
———-
Please download
aswMBR to your desktop.
Right click and Run as Administrator the aswMBR icon to run it. Click the Scan button to start scan. When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
Click the image to enlarge it
———-
Please post the logs made by DDS and aswMBR to your next reply.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
Run by [removed] at 10:21:18 on 2012-05-04
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4044.1170 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\BitTorrent\BitTorrent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\windows\system32\taskhost.exe
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe
Q:\140066.enu\Office14\WINWORDC.EXE
C:\windows\splwow64.exe
Q:\140066.enu\Office14\OffSpon.EXE
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\explorer.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\windows\explorer.exe
C:\windows\system32\mspaint.exe
C:\windows\system32\mspaint.exe
C:\windows\system32\mspaint.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\windows\system32\calc.exe
C:\windows\system32\calc.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\SysWOW64\cmd.exe
C:\windows\system32\conhost.exe
C:\windows\SysWOW64\cscript.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://start.toshiba.com/?cid=C001B2Y
uDefault_Page_URL = hxxp://start.toshiba.com/?cid=C001B2Y
uInternet Settings,ProxyOverride = ;*.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
uRun: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe" /MINIMIZED
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Standby] "c:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -START
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.254.254 192.168.254.254
TCP: Interfaces\{3CA6EBC8-F765-490A-AC8C-51A57724CEE7} : DhcpNameServer = 192.168.254.254 192.168.254.254
TCP: Interfaces\{C65F7F64-9738-44C6-9E9A-C651FDF10295} : DhcpNameServer = [removed] [removed]
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Standby] "c:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -START
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\9jna99sf.default\
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\windows\system32\DRIVERS\MpFilter.sys –> C:\windows\system32\DRIVERS\MpFilter.sys [?]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\system32\DRIVERS\tos_sps64.sys –> C:\windows\system32\DRIVERS\tos_sps64.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\windows\system32\DRIVERS\dtsoftbus01.sys –> C:\windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys –> C:\windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe [2011-11-30 135608]
R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [2011-11-30 126392]
R3 FwLnk;FwLnk Driver;C:\windows\system32\DRIVERS\FwLnk.sys –> C:\windows\system32\DRIVERS\FwLnk.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\windows\system32\DRIVERS\L1C62x64.sys –> C:\windows\system32\DRIVERS\L1C62x64.sys [?]
R3 MEIx64;Intel® Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys –> C:\windows\system32\DRIVERS\HECIx64.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 PGEffect;Pangu effect driver;C:\windows\system32\DRIVERS\pgeffect.sys –> C:\windows\system32\DRIVERS\pgeffect.sys [?]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\windows\system32\DRIVERS\rtl8192Ce.sys –> C:\windows\system32\DRIVERS\rtl8192Ce.sys [?]
R3 Sftfs;Sftfs;C:\windows\system32\DRIVERS\Sftfslh.sys –> C:\windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\windows\system32\DRIVERS\Sftplaylh.sys –> C:\windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\windows\system32\DRIVERS\Sftredirlh.sys –> C:\windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\windows\system32\DRIVERS\Sftvollh.sys –> C:\windows\system32\DRIVERS\Sftvollh.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys –> C:\windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-3 253088]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 136176]
S3 NisDrv;Microsoft Network Inspection System;C:\windows\system32\DRIVERS\NisDrvWFP.sys –> C:\windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUStor.sys –> C:\windows\system32\Drivers\RtsUStor.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys –> C:\windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys –> C:\windows\system32\drivers\TsUsbGD.sys [?]
.
=============== Created Last 30 ================
.
2012-05-03 01:12:43 8917360 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{537056C2-9A11-4C08-BCEE-CE063FD3F234}\mpengine.dll
2012-05-02 13:45:24 8917360 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-01 07:01:22 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client
2012-04-30 18:48:51 ——– d—–w- C:\Users\Owner\AppData\Local\{555A315E-9D74-4EB9-901F-E5D9E156907F}
2012-04-30 18:48:39 ——– d—–w- C:\Users\Owner\AppData\Local\{8FB25D57-7E5B-4D0F-8B41-0C3BBFC95FEA}
2012-04-20 03:41:09 ——– d—–w- C:\Program Files\iPod
2012-04-20 03:41:08 ——– d—–w- C:\Program Files\iTunes
2012-04-20 03:41:08 ——– d—–w- C:\Program Files (x86)\iTunes
2012-04-17 20:30:46 ——– d—–w- C:\Users\Owner\AppData\Local\19th Parallel
2012-04-17 20:30:46 ——– d—–w- C:\Program Files (x86)\19th Parallel
2012-04-16 20:21:01 ——– d—–w- C:\Users\Owner\AppData\Local\{63DD4604-C8FC-4063-B4E0-619B02534593}
2012-04-14 18:25:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-04-14 18:25:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-04-14 18:25:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-04-14 18:25:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-04-14 18:25:44 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-04-14 18:25:43 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-04-14 18:25:43 159744 —-a-w- C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-04-12 09:42:25 81408 —-a-w- C:\windows\System32\imagehlp.dll
2012-04-12 09:42:25 23408 —-a-w- C:\windows\System32\drivers\fs_rec.sys
2012-04-12 09:42:25 159232 —-a-w- C:\windows\SysWow64\imagehlp.dll
2012-04-12 09:42:24 172544 —-a-w- C:\windows\SysWow64\wintrust.dll
2012-04-12 09:42:23 5120 —-a-w- C:\windows\SysWow64\wmi.dll
2012-04-12 09:42:23 5120 —-a-w- C:\windows\System32\wmi.dll
2012-04-12 09:42:23 220672 —-a-w- C:\windows\System32\wintrust.dll
2012-04-10 15:12:26 ——– d—–w- C:\Program Files (x86)\Common Files\Symantec Shared
2012-04-10 15:08:35 ——– d—–w- C:\ProgramData\Symantec
2012-04-05 00:56:39 ——– d—–w- C:\ProgramData\Spybot - Search & Destroy
2012-04-05 00:56:39 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy
2012-04-04 23:59:36 ——– d—–w- C:\Program Files\PeerBlock
.
==================== Find3M ====================
.
2012-04-23 19:41:57 70304 —-a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-23 19:41:57 418464 —-a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2012-04-19 01:57:09 472808 —-a-w- C:\windows\SysWow64\deployJava1.dll
2012-04-13 22:58:36 8741536 —-a-w- C:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-08 18:14:53 5642 –sha-w- C:\ProgramData\KGyGaAvL.sys
2012-03-21 00:44:12 98688 —-a-w- C:\windows\System32\drivers\NisDrvWFP.sys
2012-03-21 00:44:12 203888 —-a-w- C:\windows\System32\drivers\MpFilter.sys
2012-03-06 06:53:37 5559152 —-a-w- C:\windows\System32\ntoskrnl.exe
2012-03-06 05:59:47 3968368 —-a-w- C:\windows\SysWow64\ntkrnlpa.exe
2012-03-06 05:59:41 3913072 —-a-w- C:\windows\SysWow64\ntoskrnl.exe
2012-02-28 06:56:48 2311168 —-a-w- C:\windows\System32\jscript9.dll
2012-02-28 06:49:56 1390080 —-a-w- C:\windows\System32\wininet.dll
2012-02-28 06:48:57 1493504 —-a-w- C:\windows\System32\inetcpl.cpl
2012-02-28 06:42:55 2382848 —-a-w- C:\windows\System32\mshtml.tlb
2012-02-28 01:18:55 1799168 —-a-w- C:\windows\SysWow64\jscript9.dll
2012-02-28 01:11:21 1427456 —-a-w- C:\windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07 1127424 —-a-w- C:\windows\SysWow64\wininet.dll
2012-02-28 01:03:16 2382848 —-a-w- C:\windows\SysWow64\mshtml.tlb
2012-02-23 17:40:12 88 –sh–r- C:\ProgramData\B0545EB164.sys
2012-02-17 06:38:26 1031680 —-a-w- C:\windows\System32\rdpcore.dll
2012-02-17 05:34:22 826880 —-a-w- C:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58:24 210944 —-a-w- C:\windows\System32\drivers\rdpwd.sys
2012-02-17 04:57:32 23552 —-a-w- C:\windows\System32\drivers\tdtcp.sys
2012-02-15 20:02:02 283200 —-a-w- C:\windows\System32\drivers\dtsoftbus01.sys
2012-02-10 06:36:07 1544192 —-a-w- C:\windows\System32\DWrite.dll
2012-02-10 05:38:43 1077248 —-a-w- C:\windows\SysWow64\DWrite.dll
.
============= FINISH: 10:22:26.81 ===============
I downloaded the second program, aswMBR, and it did a blue screen thing mid-scan (I never have the blue screen thing). Should I continue with the scan? This is the error report …
Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.1.7601.2.1.0.768.3
Locale ID: 1033
Additional information about the problem:
BCCode: d1
BCP1: 0000000000000000
BCP2: 0000000000000002
BCP3: 0000000000000008
BCP4: 0000000000000000
OS Version: 6_1_7601
Service Pack: 1_0
Product: 768_1
Files that help describe the problem:
C:\Windows\Minidump\050412-39000-01.dmp
C:\Users\Owner\AppData\Local\Temp\WER-89716-0.sysdata.xml
I went ahead and did the aswMBR scan again.
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-04 10:36:26
—————————–
10:36:26.130 OS Version: Windows x64 6.1.7601 Service Pack 1
10:36:26.130 Number of processors: 4 586 0x2A07
10:36:26.130 ComputerName: OWNER-PC UserName: Owner
10:36:27.459 Initialze error C000010E - driver not loaded
10:36:27.659 write error "aswCmnB.dll". The process cannot access the file because it is being used by another process.
10:36:33.350 Service scanning
10:37:06.843 Modules scanning
10:37:06.843 Disk 0 trace - called modules:
10:37:06.843
10:37:06.843 Scan finished successfully
10:37:22.758 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"
Hi,
Try and run aswMBR.exe once again. When the log is created post that to your next reply.
I had to download the Avast virus definitions before the aswMBR program would work (?). Anyway, this is the log …
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-04 13:28:05
—————————–
13:28:05.947 OS Version: Windows x64 6.1.7601 Service Pack 1
13:28:05.947 Number of processors: 4 586 0x2A07
13:28:05.948 ComputerName: OWNER-PC UserName: Owner
13:28:07.979 Initialize success
13:31:30.303 AVAST engine defs: 12050400
13:31:38.034 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
13:31:38.040 Disk 0 Vendor: TOSHIBA_ GT00 Size: 305245MB BusType: 3
13:31:38.046 Disk 0 MBR read successfully
13:31:38.053 Disk 0 MBR scan
13:31:38.079 Disk 0 Windows VISTA default MBR code
13:31:38.110 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048
13:31:38.172 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 289747 MB offset 3074048
13:31:38.227 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 13997 MB offset 596475904
13:31:38.329 Disk 0 scanning C:\windows\system32\drivers
13:31:50.025 Service scanning
13:32:34.441 Modules scanning
13:32:34.462 Disk 0 trace - called modules:
13:32:34.484 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
13:32:34.492 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800690c060]
13:32:34.715 3 CLASSPNP.SYS[fffff880018a643f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004a48050]
13:32:36.300 AVAST engine scan C:\windows
13:32:39.134 AVAST engine scan C:\windows\system32
13:36:58.165 AVAST engine scan C:\windows\system32\drivers
13:37:11.611 AVAST engine scan C:\Users\Owner
13:38:46.415 File: C:\Users\Owner\AppData\Roaming\Adobe\Flash Player\NativeCache\2B6D427C0AF6E92873BF2615668F421B\7df9b4e0\adobecp-200489-1.dll **INFECTED** Win32:Malware-gen
13:46:43.636 AVAST engine scan C:\ProgramData
13:48:40.228 Scan finished successfully
14:53:11.628 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat"
14:53:11.695 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"
14:54:16.096 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat"
14:54:16.103 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR2.txt"
Hi,
Download
Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————–
IMPORTANT -
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
here
——————————————————————–
Right-Click and Run as Administrator on
ComboFix.exe & follow the prompts.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.
When finished, it will produce a report for you. Please post the C:\ComboFix.txt for further review.
———-
HELP!!!!!!!!!!!!!
I did the ComboFix, it finished and the computer rebooted. Then when I tried to get back online Mozilla wouldn't work. The error message says …
C:\Program Fils (x86)\Mozilla Firefox\firefox.exe
Illegal operation attempted on a registry key that has been marked for deletion.
It says the same thing when I try to get to system restore, and Internet Explorer and just about every program I have. I haven't tried everything, but almost everything I try has that same "illegal operation" message.
HELP!!! How do I get this working again???
Just go ahead and reboot your system. It may take two tries but it is nothing to worry about.
When you find the log that ComboFix has created be sure to post that as well.
OK, whew, it's all working again. Thanks
Log is below.
ComboFix 12-05-05.06 - Owner 05/05/2012 17:17:04.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4044.964 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Amazon.ico
c:\programdata\MercadoLivre.ico
c:\programdata\QuickStores.ico
c:\users\Owner\AppData\Local\TempDIR
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2012-04-05 to 2012-05-05 )))))))))))))))))))))))))))))))
.
.
2012-05-05 21:21 . 2012-05-05 21:21 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-05-05 19:31 . 2012-04-13 08:46 8917360 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{346A1163-0BD5-4739-BDCC-49655E000438}\mpengine.dll
2012-05-05 01:45 . 2012-04-13 08:46 8917360 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-01 07:01 . 2012-05-01 07:01 ——– d—–w- c:\program files (x86)\Microsoft Security Client
2012-04-24 00:00 . 2012-04-24 00:00 ——– d—–w- c:\windows\Sun
2012-04-20 03:41 . 2012-04-20 03:41 ——– d—–w- c:\program files\iPod
2012-04-20 03:41 . 2012-04-20 03:41 ——– d—–w- c:\program files\iTunes
2012-04-20 03:41 . 2012-04-20 03:41 ——– d—–w- c:\program files (x86)\iTunes
2012-04-19 01:57 . 2012-04-19 01:57 ——– d—–w- c:\program files (x86)\Common Files\Java
2012-04-19 01:57 . 2012-04-19 01:57 ——– d—–w- c:\program files (x86)\Java
2012-04-17 20:30 . 2012-04-17 20:31 ——– d—–w- c:\users\Owner\AppData\Local\19th Parallel
2012-04-17 20:30 . 2012-04-17 20:30 ——– d—–w- c:\program files (x86)\19th Parallel
2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-04-14 18:25 . 2012-04-14 18:25 159744 —-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-04-14 18:25 . 2012-04-14 18:25 ——– d—–w- c:\program files (x86)\QuickTime
2012-04-12 09:42 . 2012-03-01 06:46 23408 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-12 09:42 . 2012-03-01 06:33 81408 —-a-w- c:\windows\system32\imagehlp.dll
2012-04-12 09:42 . 2012-03-01 05:33 159232 —-a-w- c:\windows\SysWow64\imagehlp.dll
2012-04-12 09:42 . 2012-03-01 05:37 172544 —-a-w- c:\windows\SysWow64\wintrust.dll
2012-04-12 09:42 . 2012-03-01 06:38 220672 —-a-w- c:\windows\system32\wintrust.dll
2012-04-12 09:42 . 2012-03-01 06:28 5120 —-a-w- c:\windows\system32\wmi.dll
2012-04-12 09:42 . 2012-03-01 05:29 5120 —-a-w- c:\windows\SysWow64\wmi.dll
2012-04-10 15:12 . 2012-04-10 15:12 ——– d—–w- c:\program files (x86)\Common Files\Symantec Shared
2012-04-10 15:08 . 2012-04-10 15:08 ——– d—–w- c:\programdata\Symantec
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-05 06:59 . 2012-04-03 05:09 419488 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-05 06:59 . 2011-10-31 02:34 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 06:59 . 2012-04-03 05:58 8744608 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-04-19 01:57 . 2012-01-14 14:03 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll
2012-04-08 18:14 . 2012-01-29 07:33 5642 –sha-w- c:\programdata\KGyGaAvL.sys
2012-03-21 00:44 . 2011-04-27 20:25 98688 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-21 00:44 . 2011-04-18 18:18 203888 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-03-03 20:14 . 2012-03-03 20:14 927800 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1AF21C05-7682-4368-8699-7788662FA8AC}\gapaengine.dll
2012-02-23 17:40 . 2012-01-29 07:33 88 –sh–r- c:\programdata\B0545EB164.sys
2012-02-17 06:38 . 2012-03-14 14:26 1031680 —-a-w- c:\windows\system32\rdpcore.dll
2012-02-17 05:34 . 2012-03-14 14:26 826880 —-a-w- c:\windows\SysWow64\rdpcore.dll
2012-02-17 04:58 . 2012-03-14 14:26 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:57 . 2012-03-14 14:26 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-15 20:02 . 2012-02-15 19:54 283200 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-02-10 06:36 . 2012-03-14 14:29 1544192 —-a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:38 . 2012-03-14 14:29 1077248 —-a-w- c:\windows\SysWow64\DWrite.dll
2012-02-08 07:13 . 2012-03-02 16:00 8643640 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BAA95D8C-2379-4DC4-A3DB-007A8822CF1F}\mpengine.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent"="c:\program files (x86)\BitTorrent\BitTorrent.exe" [2012-02-22 650104]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-01-24 3478336]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Standby"="c:\program files (x86)\Common Files\Corel\Standby\Standby.exe" [2009-12-17 105632]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackupReminder]
2011-06-22 22:26 3218864 —-a-w- c:\program files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToshibaAppPlace]
2010-09-23 18:03 552960 —-a-w- c:\program files (x86)\TOSHIBA\Toshiba App Place\ToshibaAppPlace.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToshibaServiceStation]
2011-07-12 01:16 1298816 —-a-w- c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 136176]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 136176]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-07-12 57216]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-06-10 138152]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe [2012-03-19 135608]
S2 PCCUJobMgr;Common Client Job Manager Service;c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [2011-07-19 126392]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 06:59]
.
2012-05-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 22:45]
.
2012-05-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 22:45]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.toshiba.com/?cid=C001B2Y
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = ;*.local
TCP: DhcpNameServer = 192.168.254.254 192.168.254.254
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\9jna99sf.default\
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCCUJobMgr]
"ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2012-05-05 17:26:30 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-05 21:26
.
Pre-Run: 152,984,195,072 bytes free
Post-Run: 153,120,079,872 bytes free
.
- - End Of File - - 714AF4A5F9AF89250780AEA43D4D274A
Hi,
P2P - I see you have
P2P software
BitTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly
Identity Theft . It likely contributed to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
I would strongly recommend that you uninstall these now. You can do so via
Control Panel >> Programs and Features .
———-
CAUTION : Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
In your next reply please post the new log made by ComboFix.
Hi,
Do you still need help?
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic