I'll be happy to take a look at the laptop. We can do that right in this thread. There is no need to open a new one. I would like to use a different tool than OTL to get a scan though.
Download and Run DDS by sUBs
Please download
DDS and save it to your desktop.
Disable any script blocking protection Double click dds.scr to run the tool. When done, DDS.txt will open. Save both reports to your desktop. —————————————————
Please Please copy / paste the scan reults.
DDS.txt and
Attach.txt
hi it just comes up as blank page when i click on the link
well a turn of events has occured. i can access the internet via my pc through Internet Explorer with no problems what so ever, infact i have been able to download DDS and transfer it to the laptop via usb stick. i am wondering if the problem with my pc is infact google chrome!! i shall post the logs from the scan on the laptop.
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 30/01/2012 10:00:36
System Uptime: 19/07/2012 16:09:41 (8 hours ago)
.
Motherboard: TOSHIBA | | NBWAE
Processor: AMD Sempron™ SI-42 | Socket M2/S1G1 | 1050/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 233 GiB total, 193.93 GiB free.
D: is Removable
E: is CDROM (CDFS)
F: is CDROM ()
G: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP39: 03/06/2012 19:21:17 - Removed Facebook Messenger 2.1.4520.0
RP40: 04/06/2012 13:14:55 - Windows Update
RP41: 07/06/2012 19:10:01 - Windows Update
RP42: 14/06/2012 00:29:18 - Windows Update
RP43: 14/06/2012 22:24:07 - Windows Update
RP44: 19/06/2012 16:10:22 - Windows Update
RP45: 19/06/2012 16:16:34 - Windows Update
RP46: 26/06/2012 22:31:55 - Windows Update
RP47: 01/07/2012 16:12:33 - Windows Update
RP48: 06/07/2012 22:18:49 - Windows Update
RP49: 12/07/2012 17:08:22 - Windows Update
RP50: 12/07/2012 23:47:31 - Windows Update
RP51: 18/07/2012 20:37:06 - Windows Update
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
Adobe AIR
Adobe Reader X (10.1.3)
Apple Application Support
Apple Mobile Device Support
Apple Software Update
avast! Free Antivirus
Bonjour
Facebook Video Calling 1.2.0.159
Google Chrome
iTunes
MagicDisc 2.7.106
Malwarebytes' Anti-Malware
McAfee Security Scan Plus
Microsoft .NET Framework 4 Client Profile
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Picasa 3
Realtek 8136 8168 8169 Ethernet Driver
Realtek WLAN Driver
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft Office 2007 suites (KB2596666) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition
TOSHIBA Web Camera Application
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2596598) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687310) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Yontoo 1.10.02
.
==== Event Viewer Messages From Past Week ========
.
20/07/2012 00:02:49, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR5.
19/07/2012 23:53:28, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR4.
19/07/2012 23:28:57, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Lisa-PC\Lisa SID (S-1-5-21-3561299463-2961446174-593319071-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
19/07/2012 18:56:21, Error: atikmdag [43029] - Display is not active
19/07/2012 13:58:11, Error: Service Control Manager [7023] - The Offline Files service terminated with the following error: The system cannot find the path specified.
19/07/2012 13:58:08, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
.
==== End Of File ===========================
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by [removed] at 0:03:49 on 2012-07-20
Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.766.56 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Media Finder\Media Finder.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.babylon.com/?affID=110819&babsrc=HP_ss&mntrId=fad6c701000000000000701a04ecee4d
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Yontoo: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo\YontooIEClient.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [Google Update] "c:\users\lisa\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Facebook Update] "c:\users\lisa\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver
uRun: [Media Finder] "c:\program files\media finder\Media Finder.exe" /opentotray
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download with &Media Finder - c:\program files\media finder\hook.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{3A38CA1A-8A0F-4B64-A7D2-74F5E09F122E} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}\35B4957383935383 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}\4514C4B44514C4B4D2436464449364 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}\C6963756E6564777F627B6 : DhcpNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-1-30 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-1-30 353688]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-1-30 21256]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-1-30 57656]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-7-10 44808]
R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2012-2-4 24064]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2012-1-30 167936]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2012-1-30 859136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-4-10 1343400]
.
=============== Created Last 30 ================
.
2012-07-18 19:39:21 6891424 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{d33eab24-1800-4f66-a649-be35f3ecec4e}\mpengine.dll
2012-07-12 22:50:16 2345984 —-a-w- c:\windows\system32\win32k.sys
2012-07-12 22:50:06 293376 —-a-w- c:\windows\system32\browserchoice.exe
2012-07-12 16:20:32 369336 —-a-w- c:\windows\system32\drivers\cng.sys
2012-07-12 16:20:32 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-07-12 16:20:31 219136 —-a-w- c:\windows\system32\ncrypt.dll
2012-07-12 16:20:30 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-12 16:20:30 225280 —-a-w- c:\windows\system32\schannel.dll
2012-07-12 16:20:16 1390080 —-a-w- c:\windows\system32\msxml6.dll
2012-07-12 16:20:14 1236992 —-a-w- c:\windows\system32\msxml3.dll
2012-07-12 16:20:13 2048 —-a-w- c:\windows\system32\msxml3r.dll
2012-07-12 16:20:03 1019904 —-a-w- c:\program files\common files\system\ado\msado15.dll
2012-07-12 16:20:00 805376 —-a-w- c:\windows\system32\cdosys.dll
2012-07-12 16:19:58 352256 —-a-w- c:\program files\common files\system\ado\msadomd.dll
2012-07-12 16:19:56 57344 —-a-w- c:\program files\common files\system\ado\msador15.dll
2012-07-12 16:19:54 212992 —-a-w- c:\program files\common files\system\msadc\msadco.dll
2012-07-12 16:19:53 372736 —-a-w- c:\program files\common files\system\ado\msadox.dll
2012-07-12 16:19:53 143360 —-a-w- c:\program files\common files\system\ado\msjro.dll
.
==================== Find3M ====================
.
2012-07-03 16:21:53 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21:53 57656 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-07-03 16:21:53 44784 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-07-03 16:21:32 41224 —-a-w- c:\windows\avastSS.scr
2012-06-02 22:12:32 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:13 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-02 14:19:42 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-02 14:12:20 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-06-02 08:33:25 1800192 —-a-w- c:\windows\system32\jscript9.dll
2012-06-02 08:25:08 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-06-02 08:25:03 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-06-02 08:20:33 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-06-02 08:16:52 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-05-31 11:25:14 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-05-01 04:44:12 164352 —-a-w- c:\windows\system32\profsvc.dll
2012-04-28 03:17:07 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 04:45:55 58880 —-a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 04:45:54 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 04:41:16 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-24 04:36:42 140288 —-a-w- c:\windows\system32\cryptsvc.dll
2012-04-24 04:36:42 1158656 —-a-w- c:\windows\system32\crypt32.dll
2012-04-24 04:36:42 103936 —-a-w- c:\windows\system32\cryptnet.dll
.
============= FINISH: 0:05:18.21 ===============
Fantastic! I know what files we need to target at this point. Let's go ahead and run Combofix and see which ones it removes for us and then we will remove what we need to. Media Finder is not good to have on your machine so we are giong to want to remove it. But let's see if Combofix removes it for us, if not we will do it with a script. We will do the Babylon with a script as well on the 2nd pass of Combofix as well
Download and Install Combofix
Download
ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your
Desktop
*
IMPORTANT -
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
here
Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you.
Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi, it didnt give me the chance to save to my desktop it just started to run without me accepting,so im not sure where its saved to. The laptop is running ok but just have this yontoo,media finder and babylon which i would very much like removing.
ComboFix 12-07-21.01 - Lisa 23/07/2012 0:27.1.1 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.766.248 [GMT 1:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\DEBUG.log
.
.
((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 )))))))))))))))))))))))))))))))
.
.
2012-07-22 23:36 . 2012-07-22 23:36 ——– d—–w- c:\users\Lisa\AppData\Local\temp
2012-07-22 23:36 . 2012-07-22 23:36 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-07-20 10:47 . 2012-06-29 08:44 6891424 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE4BBF0C-CB55-4F34-9C33-A7E07800E909}\mpengine.dll
2012-07-12 22:50 . 2012-06-12 02:40 2345984 —-a-w- c:\windows\system32\win32k.sys
2012-07-12 22:50 . 2010-02-11 07:10 293376 —-a-w- c:\windows\system32\browserchoice.exe
2012-07-12 16:20 . 2012-06-02 04:45 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-07-12 16:20 . 2012-06-02 04:40 369336 —-a-w- c:\windows\system32\drivers\cng.sys
2012-07-12 16:20 . 2012-06-02 04:39 219136 —-a-w- c:\windows\system32\ncrypt.dll
2012-07-12 16:20 . 2012-06-02 04:45 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-12 16:20 . 2012-06-02 04:40 225280 —-a-w- c:\windows\system32\schannel.dll
2012-07-12 16:20 . 2012-06-06 05:05 1390080 —-a-w- c:\windows\system32\msxml6.dll
2012-07-12 16:20 . 2012-06-06 05:05 1236992 —-a-w- c:\windows\system32\msxml3.dll
2012-07-12 16:20 . 2010-06-26 03:24 2048 —-a-w- c:\windows\system32\msxml3r.dll
2012-07-12 16:20 . 2012-06-06 05:05 1019904 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-12 16:20 . 2012-06-06 05:03 805376 —-a-w- c:\windows\system32\cdosys.dll
2012-07-12 16:19 . 2012-06-06 05:05 352256 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll
2012-07-12 16:19 . 2012-06-06 05:05 57344 —-a-w- c:\program files\Common Files\System\ado\msador15.dll
2012-07-12 16:19 . 2012-06-06 05:05 212992 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll
2012-07-12 16:19 . 2012-06-06 05:05 143360 —-a-w- c:\program files\Common Files\System\ado\msjro.dll
2012-07-12 16:19 . 2012-06-06 05:05 372736 —-a-w- c:\program files\Common Files\System\ado\msadox.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-03 16:21 . 2012-01-30 12:48 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2012-05-06 20:39 44784 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-07-03 16:21 . 2012-01-30 12:48 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2012-01-30 12:48 353688 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2012-01-30 12:48 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2012-01-30 12:48 57656 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-07-03 16:21 . 2012-01-30 12:47 41224 —-a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2012-01-30 12:47 227648 —-a-w- c:\windows\system32\aswBoot.exe
2012-06-02 22:19 . 2012-06-19 15:11 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 15:11 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 15:11 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 15:11 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-19 15:11 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-19 15:11 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-19 15:11 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-02 14:19 . 2012-06-19 15:10 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-02 14:12 . 2012-06-19 15:10 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-05-31 11:25 . 2012-02-12 16:07 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-05-27 21:51 . 2012-05-27 21:51 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-05-27 21:51 . 2012-05-27 21:51 161792 —-a-w- c:\windows\system32\msls31.dll
2012-05-27 21:51 . 2012-05-27 21:51 86528 —-a-w- c:\windows\system32\iesysprep.dll
2012-05-27 21:51 . 2012-05-27 21:51 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-05-27 21:51 . 2012-05-27 21:51 48640 —-a-w- c:\windows\system32\mshtmler.dll
2012-05-27 21:51 . 2012-05-27 21:51 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
2012-05-27 21:51 . 2012-05-27 21:51 63488 —-a-w- c:\windows\system32\tdc.ocx
2012-05-27 21:51 . 2012-05-27 21:51 367104 —-a-w- c:\windows\system32\html.iec
2012-05-27 21:51 . 2012-05-27 21:51 74752 —-a-w- c:\windows\system32\iesetup.dll
2012-05-27 21:51 . 2012-05-27 21:51 23552 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-27 21:51 . 2012-05-27 21:51 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-05-27 21:51 . 2012-05-27 21:51 152064 —-a-w- c:\windows\system32\wextract.exe
2012-05-27 21:51 . 2012-05-27 21:51 150528 —-a-w- c:\windows\system32\iexpress.exe
2012-05-27 21:51 . 2012-05-27 21:51 11776 —-a-w- c:\windows\system32\mshta.exe
2012-05-27 21:51 . 2012-05-27 21:51 101888 —-a-w- c:\windows\system32\admparse.dll
2012-05-27 21:51 . 2012-05-27 21:51 35840 —-a-w- c:\windows\system32\imgutil.dll
2012-05-01 04:44 . 2012-06-13 23:41 164352 —-a-w- c:\windows\system32\profsvc.dll
2012-04-28 03:17 . 2012-06-13 23:42 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 04:45 . 2012-06-13 23:41 58880 —-a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 04:45 . 2012-06-13 23:41 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 04:41 . 2012-06-13 23:41 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-24 04:36 . 2012-06-13 23:40 140288 —-a-w- c:\windows\system32\cryptsvc.dll
2012-04-24 04:36 . 2012-06-13 23:40 1158656 —-a-w- c:\windows\system32\crypt32.dll
2012-04-24 04:36 . 2012-06-13 23:40 103936 —-a-w- c:\windows\system32\cryptnet.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-12 138096]
"Media Finder"="c:\program files\Media Finder\Media Finder.exe" [2012-05-23 8630272]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job
- c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-01 16:20]
.
2012-07-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job
- c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-01 16:20]
.
2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job
- c:\users\Lisa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 11:49]
.
2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job
- c:\users\Lisa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 11:49]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.babylon.com/?affID=110819&babsrc=HP_ss&mntrId=fad6c701000000000000701a04ecee4d
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-23 00:40:39
ComboFix-quarantined-files.txt 2012-07-22 23:40
.
Pre-Run: 211,279,200,256 bytes free
Post-Run: 212,743,454,720 bytes free
If Combofix didn't save to your desktop, please go ahead and download it again and make sure it saves to your desktop (but don't run it again). That is going to be very important in order for you to complete the next steps.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open
notepad and copy/paste the text in the quotebox below into it:
File::
C:\Program Files\Media Finder\Media Finder.exe
Folder::
C:\Program Files\Media Finder
DDS::
uStart Page = hxxp://search.babylon.com/?affID=110819&babsrc=HP_ss&mntrId=fad6c701000000000000701a04ecee4d
uRun: [Media Finder] "c:\program files\media finder\Media Finder.exe" /opentotray
IE: Download with &Media Finder - c:\program files\media finder\hook.html
Save this as
"CFScript.txt" , and as Type: All Files (*.*) in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.
When finished, it shall produce a log for you at
C:\ComboFix.txt which I will require in your next reply.
hi it still gives me no option to save it anywhere, it automatically goes to downloads, ive tried to move it from there to the desktop but it only creates a shortcut. i thought it best to check with you first to see if i can change any settings to avoid it going straight to downloads
What browser are you using? That will help me to help you with the problem
Also, do you still have a copy on your USB? You could cut and paste the copy from the USB to your desktop. That would work as well.
Using chrome but will try windows and USB if still the same, Sry not quite with it today lol
If you are using Chrome, the default download automatically goes to your downloads folder. You can click on the arrow next to the download in the browser screen and have it open the location when done with the download (vs. clicking the actual download to run it) and CUT and paste to your desktop.
Alternatively, you can click on the little wrench in the top right corner of your screen and then choose downloads. Towards the upper portion of the screen should be a link to open your downloads folder. Once you do that you can find the Combofix download and CUT and paste it to your desktop.
Let me know if you are still having trouble getting it on your desktop.
I moved it over with IE , its running the scan now
ComboFix 12-07-21.01 - Lisa 23/07/2012 13:09:34.2.1 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.766.323 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Lisa\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files\Media Finder\Media Finder.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Media Finder
c:\program files\Media Finder\borlndmm.dat
c:\program files\Media Finder\borlndmm.dll
c:\program files\media finder\Media Finder.exe
c:\program files\Media Finder\Plugins\_4shared.dll
c:\program files\Media Finder\Plugins\depositfiles.dll
c:\program files\Media Finder\Plugins\extabit.dll
c:\program files\Media Finder\Plugins\filepost.dll
c:\program files\Media Finder\Plugins\furk.dll
c:\program files\Media Finder\Plugins\hotfile.dll
c:\program files\Media Finder\Plugins\letitbit.dll
c:\program files\Media Finder\Plugins\madshare.dll
c:\program files\Media Finder\Plugins\oron.dll
c:\program files\Media Finder\Plugins\rapidshare.dll
c:\program files\Media Finder\Plugins\turbobit.dll
c:\program files\Media Finder\Plugins\unibytes.dll
c:\program files\Media Finder\Plugins\uploading.dll
c:\program files\Media Finder\Plugins\uploadstation.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-06-23 to 2012-07-23 )))))))))))))))))))))))))))))))
.
.
2012-07-23 12:17 . 2012-07-23 12:17 ——– d—–w- c:\users\Lisa\AppData\Local\temp
2012-07-23 12:17 . 2012-07-23 12:17 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-07-23 02:13 . 2012-07-23 02:13 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE4BBF0C-CB55-4F34-9C33-A7E07800E909}\offreg.dll
2012-07-20 10:47 . 2012-06-29 08:44 6891424 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE4BBF0C-CB55-4F34-9C33-A7E07800E909}\mpengine.dll
2012-07-12 22:50 . 2012-06-12 02:40 2345984 —-a-w- c:\windows\system32\win32k.sys
2012-07-12 22:50 . 2010-02-11 07:10 293376 —-a-w- c:\windows\system32\browserchoice.exe
2012-07-12 16:20 . 2012-06-02 04:45 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-07-12 16:20 . 2012-06-02 04:40 369336 —-a-w- c:\windows\system32\drivers\cng.sys
2012-07-12 16:20 . 2012-06-02 04:39 219136 —-a-w- c:\windows\system32\ncrypt.dll
2012-07-12 16:20 . 2012-06-02 04:45 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-12 16:20 . 2012-06-02 04:40 225280 —-a-w- c:\windows\system32\schannel.dll
2012-07-12 16:20 . 2012-06-06 05:05 1390080 —-a-w- c:\windows\system32\msxml6.dll
2012-07-12 16:20 . 2012-06-06 05:05 1236992 —-a-w- c:\windows\system32\msxml3.dll
2012-07-12 16:20 . 2010-06-26 03:24 2048 —-a-w- c:\windows\system32\msxml3r.dll
2012-07-12 16:20 . 2012-06-06 05:05 1019904 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-12 16:20 . 2012-06-06 05:03 805376 —-a-w- c:\windows\system32\cdosys.dll
2012-07-12 16:19 . 2012-06-06 05:05 352256 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll
2012-07-12 16:19 . 2012-06-06 05:05 57344 —-a-w- c:\program files\Common Files\System\ado\msador15.dll
2012-07-12 16:19 . 2012-06-06 05:05 212992 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll
2012-07-12 16:19 . 2012-06-06 05:05 143360 —-a-w- c:\program files\Common Files\System\ado\msjro.dll
2012-07-12 16:19 . 2012-06-06 05:05 372736 —-a-w- c:\program files\Common Files\System\ado\msadox.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-03 16:21 . 2012-01-30 12:48 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2012-05-06 20:39 44784 —-a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-07-03 16:21 . 2012-01-30 12:48 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2012-01-30 12:48 353688 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2012-01-30 12:48 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2012-01-30 12:48 57656 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-07-03 16:21 . 2012-01-30 12:47 41224 —-a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2012-01-30 12:47 227648 —-a-w- c:\windows\system32\aswBoot.exe
2012-06-02 22:19 . 2012-06-19 15:11 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 15:11 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 15:11 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 15:11 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-19 15:11 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-19 15:11 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-19 15:11 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-02 14:19 . 2012-06-19 15:10 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-02 14:12 . 2012-06-19 15:10 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-05-31 11:25 . 2012-02-12 16:07 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-05-27 21:51 . 2012-05-27 21:51 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-05-27 21:51 . 2012-05-27 21:51 161792 —-a-w- c:\windows\system32\msls31.dll
2012-05-27 21:51 . 2012-05-27 21:51 86528 —-a-w- c:\windows\system32\iesysprep.dll
2012-05-27 21:51 . 2012-05-27 21:51 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-05-27 21:51 . 2012-05-27 21:51 48640 —-a-w- c:\windows\system32\mshtmler.dll
2012-05-27 21:51 . 2012-05-27 21:51 110592 —-a-w- c:\windows\system32\IEAdvpack.dll
2012-05-27 21:51 . 2012-05-27 21:51 63488 —-a-w- c:\windows\system32\tdc.ocx
2012-05-27 21:51 . 2012-05-27 21:51 367104 —-a-w- c:\windows\system32\html.iec
2012-05-27 21:51 . 2012-05-27 21:51 74752 —-a-w- c:\windows\system32\iesetup.dll
2012-05-27 21:51 . 2012-05-27 21:51 23552 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-27 21:51 . 2012-05-27 21:51 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-05-27 21:51 . 2012-05-27 21:51 152064 —-a-w- c:\windows\system32\wextract.exe
2012-05-27 21:51 . 2012-05-27 21:51 150528 —-a-w- c:\windows\system32\iexpress.exe
2012-05-27 21:51 . 2012-05-27 21:51 11776 —-a-w- c:\windows\system32\mshta.exe
2012-05-27 21:51 . 2012-05-27 21:51 101888 —-a-w- c:\windows\system32\admparse.dll
2012-05-27 21:51 . 2012-05-27 21:51 35840 —-a-w- c:\windows\system32\imgutil.dll
2012-05-01 04:44 . 2012-06-13 23:41 164352 —-a-w- c:\windows\system32\profsvc.dll
2012-04-28 03:17 . 2012-06-13 23:42 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 04:45 . 2012-06-13 23:41 58880 —-a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 04:45 . 2012-06-13 23:41 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 04:41 . 2012-06-13 23:41 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-22_23.36.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:55 . 2012-07-23 01:14 43956 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-01-30 00:54 . 2012-07-23 11:30 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-01-30 00:54 . 2012-07-22 23:31 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-01-30 00:54 . 2012-07-22 23:31 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-01-30 00:54 . 2012-07-23 11:30 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:41 . 2012-07-23 11:30 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2012-07-22 23:31 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-07-21 22:05 . 2012-07-21 22:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-07-23 01:13 . 2012-07-23 01:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-07-21 22:05 . 2012-07-21 22:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-07-23 01:13 . 2012-07-23 01:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:05 . 2012-07-23 09:53 628460 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2012-07-22 22:20 628460 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2012-07-22 22:20 110612 c:\windows\System32\perfc009.dat
+ 2009-07-14 02:05 . 2012-07-23 09:53 110612 c:\windows\System32\perfc009.dat
- 2009-07-14 04:47 . 2012-07-20 22:46 389820 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 04:47 . 2012-07-23 00:01 389820 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-12 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job
- c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-01 16:20]
.
2012-07-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job
- c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-01 16:20]
.
2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job
- c:\users\Lisa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 11:49]
.
2012-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job
- c:\users\Lisa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 11:49]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-23 13:21:37
ComboFix-quarantined-files.txt 2012-07-23 12:21
ComboFix2.txt 2012-07-22 23:40
.
Pre-Run: 211,860,103,168 bytes free
Post-Run: 211,563,491,328 bytes free
.
- - End Of File - - A3320245DEA7FB99B06C67A09D406E58
And can I just confirm that the pesky Babylon is GONE?!
By the way, if you haven't already done so, please reboot just to clear out any leftovers.