This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

malware removal [Solved]

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ComboFix 12-07-14.01 - Christina 16/07/2012 11:03:36.3.1 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.956.326 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\I Want This c:\program files (x86)\I Want This\I Want ThisInstaller.log c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed] c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome.manifest c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\background.html c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\browser.xul c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\crossrider.js c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\crossriderapi.js c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\dialog.js c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\options.js c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\options.xul c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\search_dialog.xul c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\update.html c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\defaults\preferences\prefs.js c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\install.rdf c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\locale\en-US\translations.dtd c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\button1.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\button2.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\button3.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\button4.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\button5.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\crossrider_statusbar.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\icon128.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\icon16.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\icon24.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\icon48.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\panelarrow-up.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\popup.css c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\popup.html c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\popup_binding.xml c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\skin.css c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\update.css . . ((((((((((((((((((((((((( Files Created from 2012-06-16 to 2012-07-16 ))))))))))))))))))))))))))))))) . . 2012-07-16 10:16 . 2012-07-16 10:16 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2012-07-16 10:16 . 2012-07-16 10:16 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-07-16 10:16 . 2012-07-16 10:16 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-16 08:54 . 2012-07-16 08:54 ——– d—–w- c:\programdata\AVG Secure Search 2012-07-15 21:32 . 2012-07-15 21:32 ——– d—–w- C:\_OTL 2012-07-15 21:01 . 2012-07-15 21:01 ——– d—–w- c:\users\Christina\AppData\Roaming\Avira 2012-07-15 20:52 . 2012-05-02 14:24 27760 —-a-w- c:\windows\system32\drivers\avkmgr.sys 2012-07-15 20:52 . 2012-04-27 09:20 132832 —-a-w- c:\windows\system32\drivers\avipbb.sys 2012-07-15 20:52 . 2012-04-24 23:32 98848 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2012-07-15 20:52 . 2012-07-16 09:13 ——– d—–w- c:\programdata\Avira 2012-07-15 20:52 . 2012-07-15 20:52 ——– d—–w- c:\program files (x86)\Avira 2012-07-14 06:34 . 2012-07-14 06:34 ——– d—–w- c:\users\Christina\AppData\Local\MapsGalaxy_39 2012-07-11 12:56 . 2012-06-12 03:08 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-11 09:33 . 2012-06-06 06:05 1499136 —-a-w- c:\program files\Common Files\System\ado\msado15.dll 2012-07-11 09:33 . 2012-06-06 05:05 1019904 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll 2012-07-11 09:33 . 2012-06-06 06:05 466944 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll 2012-07-11 09:33 . 2012-06-06 06:05 258048 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll 2012-07-11 09:33 . 2012-06-06 05:03 805376 —-a-w- c:\windows\SysWow64\cdosys.dll 2012-07-11 09:33 . 2012-06-06 06:05 495616 —-a-w- c:\program files\Common Files\System\ado\msadox.dll 2012-07-11 09:33 . 2012-06-06 06:05 61440 —-a-w- c:\program files\Common Files\System\ado\msador15.dll 2012-07-11 09:33 . 2012-06-06 05:05 143360 —-a-w- c:\program files (x86)\Common Files\System\ado\msjro.dll 2012-07-11 09:33 . 2012-06-06 05:05 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll 2012-07-11 09:33 . 2012-06-06 05:05 57344 —-a-w- c:\program files (x86)\Common Files\System\ado\msador15.dll 2012-07-11 09:33 . 2012-06-06 05:05 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll 2012-07-11 09:33 . 2012-06-06 05:05 212992 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll 2012-07-11 09:33 . 2012-06-06 06:02 1133568 —-a-w- c:\windows\system32\cdosys.dll 2012-07-08 20:53 . 2012-07-08 20:53 ——– d—–w- c:\users\Christina\AppData\Local\APN 2012-06-29 23:25 . 2012-06-29 23:25 770384 —-a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll 2012-06-29 23:25 . 2012-06-29 23:25 421200 —-a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll 2012-06-23 16:22 . 2012-06-23 16:22 ——– d—–w- c:\program files (x86)\MapsGalaxy_39 2012-06-21 11:51 . 2012-06-21 11:51 15712 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\25d79a0f1cd4fa40c\MeshBetaRemover.exe 2012-06-21 09:19 . 2012-06-02 22:19 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-21 09:19 . 2012-06-02 22:19 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-21 09:19 . 2012-06-02 22:19 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-21 09:19 . 2012-06-02 22:15 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-21 09:18 . 2012-06-02 22:19 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-21 09:18 . 2012-06-02 22:19 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-21 09:18 . 2012-06-02 22:15 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-06-21 09:18 . 2012-06-02 14:19 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-21 09:18 . 2012-06-02 14:15 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-06-20 20:14 . 2012-06-20 20:14 89944 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\4acc79ad1cd4f2102\DSETUP.dll 2012-06-20 20:14 . 2012-06-20 20:14 537432 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\4acc79ad1cd4f2102\DXSETUP.exe 2012-06-20 20:14 . 2012-06-20 20:14 1801048 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\4acc79ad1cd4f2102\dsetup32.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-12 13:58 . 2012-04-02 08:54 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-12 13:58 . 2011-09-27 17:52 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-05-31 04:04 . 2012-07-06 20:36 9013136 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2AB86CB7-31AE-47DD-B7E5-78CBD64E26E0}\mpengine.dll 2012-05-14 16:33 . 2011-03-28 17:36 19352 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-05-04 11:06 . 2012-06-12 21:33 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 10:03 . 2012-06-12 21:33 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03 . 2012-06-12 21:33 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-03 23:20 . 2012-05-03 23:20 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-05-03 23:20 . 2012-05-03 23:20 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2012-05-03 23:20 . 2012-05-03 23:20 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2012-05-03 23:20 . 2012-05-03 23:20 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-05-03 23:20 . 2012-05-03 23:20 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2012-05-03 23:20 . 2012-05-03 23:20 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-05-03 23:20 . 2012-05-03 23:20 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2012-05-03 23:20 . 2012-05-03 23:20 367104 —-a-w- c:\windows\SysWow64\html.iec 2012-05-03 23:19 . 2012-05-03 23:19 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2012-05-03 23:19 . 2012-05-03 23:19 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-05-03 23:19 . 2012-05-03 23:19 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2012-05-03 23:19 . 2012-05-03 23:19 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2012-05-03 23:19 . 2012-05-03 23:19 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2012-05-03 23:19 . 2012-05-03 23:19 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2012-05-03 23:19 . 2012-05-03 23:19 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2012-05-03 23:19 . 2012-05-03 23:19 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2012-05-03 23:19 . 2012-05-03 23:19 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-05-03 23:19 . 2012-05-03 23:19 222208 —-a-w- c:\windows\system32\msls31.dll 2012-05-03 23:19 . 2012-05-03 23:19 49664 —-a-w- c:\windows\system32\imgutil.dll 2012-05-03 23:19 . 2012-05-03 23:19 12288 —-a-w- c:\windows\system32\mshta.exe 2012-05-03 23:19 . 2012-05-03 23:19 114176 —-a-w- c:\windows\system32\admparse.dll 2012-05-03 23:19 . 2012-05-03 23:19 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-05-03 23:19 . 2012-05-03 23:19 76800 —-a-w- c:\windows\system32\tdc.ocx 2012-05-03 23:19 . 2012-05-03 23:19 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-05-03 23:19 . 2012-05-03 23:19 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-05-03 23:19 . 2012-05-03 23:19 111616 —-a-w- c:\windows\system32\iesysprep.dll 2012-05-03 23:19 . 2012-05-03 23:19 448512 —-a-w- c:\windows\system32\html.iec 2012-05-03 23:19 . 2012-05-03 23:19 85504 —-a-w- c:\windows\system32\iesetup.dll 2012-05-03 23:19 . 2012-05-03 23:19 603648 —-a-w- c:\windows\system32\vbscript.dll 2012-05-03 23:19 . 2012-05-03 23:19 30720 —-a-w- c:\windows\system32\licmgr10.dll 2012-05-03 23:19 . 2012-05-03 23:19 165888 —-a-w- c:\windows\system32\iexpress.exe 2012-05-03 23:19 . 2012-05-03 23:19 160256 —-a-w- c:\windows\system32\wextract.exe 2012-05-01 05:40 . 2012-06-12 21:33 209920 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:55 . 2012-06-12 21:33 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 05:41 . 2012-06-12 21:34 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 05:41 . 2012-06-12 21:34 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 05:34 . 2012-06-12 21:34 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-24 05:37 . 2012-06-12 21:33 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2012-04-24 05:37 . 2012-06-12 21:33 140288 —-a-w- c:\windows\system32\cryptnet.dll 2012-04-24 05:37 . 2012-06-12 21:33 1462272 —-a-w- c:\windows\system32\crypt32.dll 2012-04-24 04:36 . 2012-06-12 21:33 1158656 —-a-w- c:\windows\SysWow64\crypt32.dll 2012-04-24 04:36 . 2012-06-12 21:33 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2012-04-24 04:36 . 2012-06-12 21:33 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2012-04-23 09:04 . 2011-10-09 13:11 9728 —-a-w- c:\windows\system32\Native.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-03-16 214840] . [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6}] 2012-02-10 10:28 1307928 —-a-w- c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-04-18 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files (x86)\Toshiba\TRDCReminder\TRDCReminder.exe [2009-9-1 481184] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0native.exe . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-18 136176] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-12 250056] R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-18 136176] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-29 113120] R3 RapportKE64;RapportKE64;c:\windows\system32\Drivers\RapportKE64.sys [2011-08-21 64272] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-02-01 232992] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 31232] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-18 1255736] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-05-02 27760] S1 RapportCerberus_32029;RapportCerberus_32029;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\32029\RapportCerberus64_32029.sys [2011-10-18 396816] S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2011-08-21 52496] S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2011-08-21 61200] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-02 86224] S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200] S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448] S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-08-21 870200] S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144] S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2011-02-10 112080] S2 vToolbarUpdater;vToolbarUpdater;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe [2012-01-16 909152] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-09-27 76912] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2012-07-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 13:58] . 2012-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-18 00:04] . 2012-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-18 00:04] . 2012-07-16 c:\windows\Tasks\Updater.job - c:\programdata\WombatUpdater\WombatUpdater.exe [2010-12-30 09:26] . . ——— X64 Entries ———– . . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download all with Free Download Manager IE: Download selected with Free Download Manager IE: Download video with Free Download Manager IE: Download with Free Download Manager IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000 Trusted Zone: internet Trusted Zone: mcafee.com TCP: DhcpNameServer = 192.168.0.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll FF - ProfilePath - c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\ FF - prefs.js: browser.search.selectedEngine - Ask.com FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe c:\program files (x86)\Trusteer\Rapport\bin\RapportService.exe c:\program files (x86)\TOSHIBA\ConfigFree\NDSTray.exe c:\program files (x86)\TeamViewer\Version6\tv_w32.exe . ************************************************************************** . Completion time: 2012-07-16 12:56:03 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-16 11:56 ComboFix2.txt 2012-05-04 08:37 . Pre-Run: 58,997,616,640 bytes free Post-Run: 58,329,444,352 bytes free . - - End Of File - - FD96CD276EB15DD1700E556C1AB42535
Hi I had no internet access all day, apparently Virgin (my provider) had internet problems in my district in London. I managed to send Combo log in the morning but now I see it is not here so I am sending it again. Kind regards. ComboFix 12-07-14.01 - Christina 16/07/2012 11:03:36.3.1 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.956.326 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\I Want This c:\program files (x86)\I Want This\I Want ThisInstaller.log c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed] c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome.manifest c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\background.html c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\browser.xul c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\crossrider.js c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\crossriderapi.js c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\dialog.js c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\options.js c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\options.xul c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\search_dialog.xul c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\chrome\content\update.html c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\defaults\preferences\prefs.js c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\install.rdf c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\locale\en-US\translations.dtd c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\button1.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\button2.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\button3.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\button4.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\button5.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\crossrider_statusbar.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\icon128.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\icon16.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\icon24.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\icon48.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\panelarrow-up.png c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\popup.css c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\popup.html c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\popup_binding.xml c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\skin.css c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\extensions\[removed]\skin\update.css . . ((((((((((((((((((((((((( Files Created from 2012-06-16 to 2012-07-16 ))))))))))))))))))))))))))))))) . . 2012-07-16 10:16 . 2012-07-16 10:16 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2012-07-16 10:16 . 2012-07-16 10:16 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-07-16 10:16 . 2012-07-16 10:16 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-16 08:54 . 2012-07-16 08:54 ——– d—–w- c:\programdata\AVG Secure Search 2012-07-15 21:32 . 2012-07-15 21:32 ——– d—–w- C:\_OTL 2012-07-15 21:01 . 2012-07-15 21:01 ——– d—–w- c:\users\Christina\AppData\Roaming\Avira 2012-07-15 20:52 . 2012-05-02 14:24 27760 —-a-w- c:\windows\system32\drivers\avkmgr.sys 2012-07-15 20:52 . 2012-04-27 09:20 132832 —-a-w- c:\windows\system32\drivers\avipbb.sys 2012-07-15 20:52 . 2012-04-24 23:32 98848 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2012-07-15 20:52 . 2012-07-16 09:13 ——– d—–w- c:\programdata\Avira 2012-07-15 20:52 . 2012-07-15 20:52 ——– d—–w- c:\program files (x86)\Avira 2012-07-14 06:34 . 2012-07-14 06:34 ——– d—–w- c:\users\Christina\AppData\Local\MapsGalaxy_39 2012-07-11 12:56 . 2012-06-12 03:08 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-11 09:33 . 2012-06-06 06:05 1499136 —-a-w- c:\program files\Common Files\System\ado\msado15.dll 2012-07-11 09:33 . 2012-06-06 05:05 1019904 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll 2012-07-11 09:33 . 2012-06-06 06:05 466944 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll 2012-07-11 09:33 . 2012-06-06 06:05 258048 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll 2012-07-11 09:33 . 2012-06-06 05:03 805376 —-a-w- c:\windows\SysWow64\cdosys.dll 2012-07-11 09:33 . 2012-06-06 06:05 495616 —-a-w- c:\program files\Common Files\System\ado\msadox.dll 2012-07-11 09:33 . 2012-06-06 06:05 61440 —-a-w- c:\program files\Common Files\System\ado\msador15.dll 2012-07-11 09:33 . 2012-06-06 05:05 143360 —-a-w- c:\program files (x86)\Common Files\System\ado\msjro.dll 2012-07-11 09:33 . 2012-06-06 05:05 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll 2012-07-11 09:33 . 2012-06-06 05:05 57344 —-a-w- c:\program files (x86)\Common Files\System\ado\msador15.dll 2012-07-11 09:33 . 2012-06-06 05:05 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll 2012-07-11 09:33 . 2012-06-06 05:05 212992 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll 2012-07-11 09:33 . 2012-06-06 06:02 1133568 —-a-w- c:\windows\system32\cdosys.dll 2012-07-08 20:53 . 2012-07-08 20:53 ——– d—–w- c:\users\Christina\AppData\Local\APN 2012-06-29 23:25 . 2012-06-29 23:25 770384 —-a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll 2012-06-29 23:25 . 2012-06-29 23:25 421200 —-a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll 2012-06-23 16:22 . 2012-06-23 16:22 ——– d—–w- c:\program files (x86)\MapsGalaxy_39 2012-06-21 11:51 . 2012-06-21 11:51 15712 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\25d79a0f1cd4fa40c\MeshBetaRemover.exe 2012-06-21 09:19 . 2012-06-02 22:19 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-21 09:19 . 2012-06-02 22:19 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-21 09:19 . 2012-06-02 22:19 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-21 09:19 . 2012-06-02 22:15 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-21 09:18 . 2012-06-02 22:19 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-21 09:18 . 2012-06-02 22:19 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-21 09:18 . 2012-06-02 22:15 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-06-21 09:18 . 2012-06-02 14:19 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-21 09:18 . 2012-06-02 14:15 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-06-20 20:14 . 2012-06-20 20:14 89944 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\4acc79ad1cd4f2102\DSETUP.dll 2012-06-20 20:14 . 2012-06-20 20:14 537432 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\4acc79ad1cd4f2102\DXSETUP.exe 2012-06-20 20:14 . 2012-06-20 20:14 1801048 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\4acc79ad1cd4f2102\dsetup32.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-12 13:58 . 2012-04-02 08:54 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-12 13:58 . 2011-09-27 17:52 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-05-31 04:04 . 2012-07-06 20:36 9013136 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2AB86CB7-31AE-47DD-B7E5-78CBD64E26E0}\mpengine.dll 2012-05-14 16:33 . 2011-03-28 17:36 19352 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-05-04 11:06 . 2012-06-12 21:33 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 10:03 . 2012-06-12 21:33 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03 . 2012-06-12 21:33 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-03 23:20 . 2012-05-03 23:20 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-05-03 23:20 . 2012-05-03 23:20 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2012-05-03 23:20 . 2012-05-03 23:20 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2012-05-03 23:20 . 2012-05-03 23:20 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-05-03 23:20 . 2012-05-03 23:20 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2012-05-03 23:20 . 2012-05-03 23:20 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-05-03 23:20 . 2012-05-03 23:20 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2012-05-03 23:20 . 2012-05-03 23:20 367104 —-a-w- c:\windows\SysWow64\html.iec 2012-05-03 23:19 . 2012-05-03 23:19 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2012-05-03 23:19 . 2012-05-03 23:19 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-05-03 23:19 . 2012-05-03 23:19 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2012-05-03 23:19 . 2012-05-03 23:19 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2012-05-03 23:19 . 2012-05-03 23:19 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2012-05-03 23:19 . 2012-05-03 23:19 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2012-05-03 23:19 . 2012-05-03 23:19 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2012-05-03 23:19 . 2012-05-03 23:19 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2012-05-03 23:19 . 2012-05-03 23:19 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-05-03 23:19 . 2012-05-03 23:19 222208 —-a-w- c:\windows\system32\msls31.dll 2012-05-03 23:19 . 2012-05-03 23:19 49664 —-a-w- c:\windows\system32\imgutil.dll 2012-05-03 23:19 . 2012-05-03 23:19 12288 —-a-w- c:\windows\system32\mshta.exe 2012-05-03 23:19 . 2012-05-03 23:19 114176 —-a-w- c:\windows\system32\admparse.dll 2012-05-03 23:19 . 2012-05-03 23:19 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-05-03 23:19 . 2012-05-03 23:19 76800 —-a-w- c:\windows\system32\tdc.ocx 2012-05-03 23:19 . 2012-05-03 23:19 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-05-03 23:19 . 2012-05-03 23:19 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-05-03 23:19 . 2012-05-03 23:19 111616 —-a-w- c:\windows\system32\iesysprep.dll 2012-05-03 23:19 . 2012-05-03 23:19 448512 —-a-w- c:\windows\system32\html.iec 2012-05-03 23:19 . 2012-05-03 23:19 85504 —-a-w- c:\windows\system32\iesetup.dll 2012-05-03 23:19 . 2012-05-03 23:19 603648 —-a-w- c:\windows\system32\vbscript.dll 2012-05-03 23:19 . 2012-05-03 23:19 30720 —-a-w- c:\windows\system32\licmgr10.dll 2012-05-03 23:19 . 2012-05-03 23:19 165888 —-a-w- c:\windows\system32\iexpress.exe 2012-05-03 23:19 . 2012-05-03 23:19 160256 —-a-w- c:\windows\system32\wextract.exe 2012-05-01 05:40 . 2012-06-12 21:33 209920 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:55 . 2012-06-12 21:33 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 05:41 . 2012-06-12 21:34 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 05:41 . 2012-06-12 21:34 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 05:34 . 2012-06-12 21:34 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-24 05:37 . 2012-06-12 21:33 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2012-04-24 05:37 . 2012-06-12 21:33 140288 —-a-w- c:\windows\system32\cryptnet.dll 2012-04-24 05:37 . 2012-06-12 21:33 1462272 —-a-w- c:\windows\system32\crypt32.dll 2012-04-24 04:36 . 2012-06-12 21:33 1158656 —-a-w- c:\windows\SysWow64\crypt32.dll 2012-04-24 04:36 . 2012-06-12 21:33 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2012-04-24 04:36 . 2012-06-12 21:33 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2012-04-23 09:04 . 2011-10-09 13:11 9728 —-a-w- c:\windows\system32\Native.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-03-16 214840] . [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6}] 2012-02-10 10:28 1307928 —-a-w- c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-04-18 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files (x86)\Toshiba\TRDCReminder\TRDCReminder.exe [2009-9-1 481184] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0native.exe . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-18 136176] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-12 250056] R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-18 136176] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-29 113120] R3 RapportKE64;RapportKE64;c:\windows\system32\Drivers\RapportKE64.sys [2011-08-21 64272] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-02-01 232992] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 31232] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-04-18 1255736] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-05-02 27760] S1 RapportCerberus_32029;RapportCerberus_32029;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\32029\RapportCerberus64_32029.sys [2011-10-18 396816] S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2011-08-21 52496] S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2011-08-21 61200] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-02 86224] S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200] S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448] S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-08-21 870200] S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144] S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2011-02-10 112080] S2 vToolbarUpdater;vToolbarUpdater;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe [2012-01-16 909152] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-09-27 76912] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [2009-06-22 35008] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2012-07-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 13:58] . 2012-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-18 00:04] . 2012-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-18 00:04] . 2012-07-16 c:\windows\Tasks\Updater.job - c:\programdata\WombatUpdater\WombatUpdater.exe [2010-12-30 09:26] . . ——— X64 Entries ———– . . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download all with Free Download Manager IE: Download selected with Free Download Manager IE: Download video with Free Download Manager IE: Download with Free Download Manager IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000 Trusted Zone: internet Trusted Zone: mcafee.com TCP: DhcpNameServer = 192.168.0.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll FF - ProfilePath - c:\users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\me606ewo.default\ FF - prefs.js: browser.search.selectedEngine - Ask.com FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe c:\program files (x86)\Trusteer\Rapport\bin\RapportService.exe c:\program files (x86)\TOSHIBA\ConfigFree\NDSTray.exe c:\program files (x86)\TeamViewer\Version6\tv_w32.exe . ************************************************************************** . Completion time: 2012-07-16 12:56:03 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-16 11:56 ComboFix2.txt 2012-05-04 08:37 . Pre-Run: 58,997,616,640 bytes free Post-Run: 58,329,444,352 bytes free . - - End Of File - - FD96CD276EB15DD1700E556C1AB42535
If Virgin was the problem, (which seems to be a regular occurance), there is no way of knowing until they sort themselves out.

Meanwhile, we'll run a couple of scans, one which will check some of your Internet settings.


Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

==============================================

Run MiniToolBox

Please download MiniToolBox, save it to your desktop and run it.

Place a checkmark in the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List last 10 Event Viewer log
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Logs to include with the next post:

Mbam.txt
Result.txt


Can you tell me if there is any progress yet.

Satchfan
There is an improvement: Explorer now works. Messenger still tells me to update otherwise I can't use it. I did not try to download their new version yet. Will do asap although I resent their new versions. I often lose my internet connection and need to reset modem. This lap top is very slow and has problems with browser launcher. I do regular scans by MB and receive confirmation of no malicious items but I do not trust it completely because it had not detected any malware before in the course of repairs by your specialists and only did so after many diagnostic scans by Combo,OTL and others cleared the path to detection. MiniToolBox by Farbar Version: 15-07-2012 Ran by [removed] (administrator) on 17-07-2012 at 10:56:13 Microsoft Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. ========================= FF Proxy Settings: ============================== "network.proxy.type", 0 ========================= Hosts content: ================================= 127.0.0.1 localhost ========================= IP Configuration: ================================ Atheros AR9285 Wireless Network Adapter = Wireless Network Connection (Connected) Atheros AR8152/8158 PCI-E Fast Ethernet Controller (NDIS 6.20) = Local Area Connection (Media disconnected) Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected) # ———————————- # IPv4 Configuration # ———————————- pushd interface ipv4 reset set global popd # End of IPv4 configuration Windows IP Configuration Host Name . . . . . . . . . . . . : Christina-TOSH Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : cable.virginmedia.net Wireless LAN adapter Wireless Network Connection 2: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter Physical Address. . . . . . . . . : 76-F1-A1-D7-52-49 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Ethernet adapter Local Area Connection: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Atheros AR8152/8158 PCI-E Fast Ethernet Controller (NDIS 6.20) Physical Address. . . . . . . . . : 00-26-6C-73-E9-C0 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Wireless LAN adapter Wireless Network Connection: Connection-specific DNS Suffix . : cable.virginmedia.net Description . . . . . . . . . . . : Atheros AR9285 Wireless Network Adapter Physical Address. . . . . . . . . : 70-F1-A1-D7-52-49 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::e95e:f38c:727:b0da%10(Preferred) IPv4 Address. . . . . . . . . . . : 192.168.0.2(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : 17 July 2012 10:33:39 Lease Expires . . . . . . . . . . : 20 July 2012 10:42:56 Default Gateway . . . . . . . . . : 192.168.0.1 DHCP Server . . . . . . . . . . . : 192.168.0.1 DHCPv6 IAID . . . . . . . . . . . : 191951265 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-30-BB-69-00-26-6C-73-E9-C0 DNS Servers . . . . . . . . . . . : 192.168.0.1 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adapter isatap.cable.virginmedia.net: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : cable.virginmedia.net Description . . . . . . . . . . . : Microsoft ISATAP Adapter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter isatap.{D466C98A-4698-47AA-9195-E8B7050F7CE6}: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3 Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter isatap.{A22D127C-938C-4DC7-8264-DF55CA381631}: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft ISATAP Adapter #4 Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Local Area Connection* 12: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes IPv6 Address. . . . . . . . . . . : 2001:0:5ef5:79fb:878:2572:3f57:fffd(Preferred) Link-local IPv6 Address . . . . . : fe80::878:2572:3f57:fffd%17(Preferred) Default Gateway . . . . . . . . . : :: NetBIOS over Tcpip. . . . . . . . : Disabled Server: UnKnown Address: 192.168.0.1 Name: google.com.cable.virginmedia.net Address: 81.200.64.50 Pinging google.com [173.194.41.99] with 32 bytes of data: Reply from 173.194.41.99: bytes=32 time=15ms TTL=56 Reply from 173.194.41.99: bytes=32 time=88ms TTL=56 Ping statistics for 173.194.41.99: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 15ms, Maximum = 88ms, Average = 51ms Server: UnKnown Address: 192.168.0.1 Name: yahoo.com.cable.virginmedia.net Address: 81.200.64.50 Pinging yahoo.com [72.30.38.140] with 32 bytes of data: Reply from 72.30.38.140: bytes=32 time=166ms TTL=48 Reply from 72.30.38.140: bytes=32 time=165ms TTL=48 Ping statistics for 72.30.38.140: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 165ms, Maximum = 166ms, Average = 165ms Server: UnKnown Address: 192.168.0.1 DNS request timed out. timeout was 2 seconds. Name: bleepingcomputer.com Address: 208.43.87.2 Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data: Request timed out. Request timed out. Ping statistics for 208.43.87.2: Packets: Sent = 2, Received = 0, Lost = 2 (100% loss), Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 13…76 f1 a1 d7 52 49 ……Microsoft Virtual WiFi Miniport Adapter 11…00 26 6c 73 e9 c0 ……Atheros AR8152/8158 PCI-E Fast Ethernet Controller (NDIS 6.20) 10…70 f1 a1 d7 52 49 ……Atheros AR9285 Wireless Network Adapter 1………………………Software Loopback Interface 1 18…00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter 19…00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3 20…00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #4 17…00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.2 30 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.0.0 255.255.255.0 On-link 192.168.0.2 286 192.168.0.2 255.255.255.255 On-link 192.168.0.2 286 192.168.0.255 255.255.255.255 On-link 192.168.0.2 286 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.0.2 286 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.0.2 286 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 17 58 ::/0 On-link 1 306 ::1/128 On-link 17 58 2001::/32 On-link 17 306 2001:0:5ef5:79fb:878:2572:3f57:fffd/128 On-link 10 286 fe80::/64 On-link 17 306 fe80::/64 On-link 17 306 fe80::878:2572:3f57:fffd/128 On-link 10 286 fe80::e95e:f38c:727:b0da/128 On-link 1 306 ff00::/8 On-link 17 306 ff00::/8 On-link 10 286 ff00::/8 On-link =========================================================================== Persistent Routes: None ========================= Event log errors: =============================== Application errors: ================== Error: (07/17/2012 09:13:37 AM) (Source: ESENT) (User: ) Description: wlcomm (2632) C:\Users\Christina\AppData\Local\Microsoft\Windows Live Contacts\{dc329d13-426b-4ba6-96af-9c6a09d6a6fd}\: The backup has been stopped because it was halted by the client or the connection with the client failed. Error: (07/16/2012 02:20:18 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 16396 Error: (07/16/2012 02:20:18 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 16396 Error: (07/16/2012 02:08:39 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/16/2012 00:06:17 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 31076 Error: (07/16/2012 00:06:17 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 31076 Error: (07/16/2012 00:06:17 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/16/2012 00:06:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15507 Error: (07/16/2012 00:06:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15507 Error: (07/16/2012 00:06:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (07/17/2012 10:33:44 AM) (Source: Service Control Manager) (User: ) Description: The Peer Name Resolution Protocol service terminated with the following error: %%-2140993535 Error: (07/17/2012 10:33:44 AM) (Source: Service Control Manager) (User: ) Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: %%-2140993535 Error: (07/17/2012 10:33:44 AM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (07/17/2012 10:30:04 AM) (Source: Service Control Manager) (User: ) Description: The Peer Name Resolution Protocol service terminated with the following error: %%-2140993535 Error: (07/17/2012 10:30:04 AM) (Source: Service Control Manager) (User: ) Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: %%-2140993535 Error: (07/17/2012 10:30:04 AM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (07/17/2012 09:17:55 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 4 Client Profile for Windows 7 x64-based Systems (KB982670). Error: (07/17/2012 09:12:38 AM) (Source: Service Control Manager) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the eventlog service. Error: (07/17/2012 09:11:38 AM) (Source: Service Control Manager) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the eventlog service. Error: (07/17/2012 09:11:01 AM) (Source: Service Control Manager) (User: ) Description: The Security Center service hung on starting. Microsoft Office Sessions: ========================= Error: (07/17/2012 09:13:37 AM) (Source: ESENT)(User: ) Description: wlcomm2632C:\Users\Christina\AppData\Local\Microsoft\Windows Live Contacts\{dc329d13-426b-4ba6-96af-9c6a09d6a6fd}\: Error: (07/16/2012 02:20:18 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 16396 Error: (07/16/2012 02:20:18 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 16396 Error: (07/16/2012 02:08:39 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/16/2012 00:06:17 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 31076 Error: (07/16/2012 00:06:17 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 31076 Error: (07/16/2012 00:06:17 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/16/2012 00:06:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15507 Error: (07/16/2012 00:06:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15507 Error: (07/16/2012 00:06:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second ========================= Minidump Files ================================== No minidump file found **** End of log **** Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.17.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Christina :: CHRISTINA-TOSH [administrator] 17/07/2012 10:43:50 mbam-log-2012-07-17 (10-43-50).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 218455 Time elapsed: 7 minute(s), 38 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Glad to hear that there is some improvement.

A few anomalies in that last log so let’s take a look with a different tool.

First:

Run McAfee Removal Tool

Next:

Run Farbar Service Scanner

Please download Farbar Service Scanner and run it on the computer with the issue.
  • make sure the following options are checked:
    • Internet Services
    • Windows Firewallsfc
    • System Restore
    • Security Center
    • Windows Update
  • press "Scan".
  • it will create a log (FSS.txt) in the same directory the tool is run.
  • please copy and paste the log to your reply.
Satchfan
McAffee removal done. The Log: Farbar Service Scanner Version: 08-07-2012 Ran by [removed] (administrator) on 17-07-2012 at 22:57:25 Running from "C:\Users\Christina\Desktop" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** ;)
Hi I shall check if I can upload WL Messenger. I deleted it yesterday because it did not work at all. It was compelling me download a new version as a necessity and when I had to agree and tried to download it was failing each time due to some error. This is why I uninstalled Winows Live Essentials. I would like to have it back and functioning. I understand I had no viruses, is that correct? :thumbup:
I would say that you are free from any infection but an online scan should confirm it.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

NOTE. If Eset doesn't find any threats, it won't produce a log.

===============================================

Have you actually uninstalled Windows Live Essentials?

To try to solve that problem, I need to know exactly how you have tried to remove and re-install WLM

Thanks

Satchfan
Esset found one virus , something to do with "slow computer". Maybe it was during past browsing through some instructions how to speed up computer. Unfortunately the file did not save itself despite my 100% performed steps as instructed. Virus is deleted anyway so repeating the scan is pointless. Its amazing that no other scan revealed this and only Esset did! As to WLM I uninstalled only WLEssentials with Revo uninstaller. I have been trying to install anew but installation reverses ab initio beacuse of error 0x80040609 Whatever that is! Thank you very much for your work, I believe WLM is the last problem. Christina
I uninstalled only on Thursday after many trials to upload updated version and :) receiving the same error so my uninstalling had no impact on the error.
It says that none of the WLE can be updated because of error (0x80040609) I don't understand why it refers to update when WLE have been uninstalled. It should refer to download. I uninmstalled only WLE because I was not sure what other associated programmes I should also uninstal. I would copy the message but I cant select it by highlighting and I don't know how otherwise to do it. It can't be highlighted unless there is some other method of doing so without the cursor.
This seems to be quite a common problem.

Go to C: Program Files and right click on Windows Live folder and delete it: then do the same for C: Program Files\Common Files\ Windows Live folder. Restart computer and try to install again.

If that didn't work, let’s see what is still installed on your computer..

Click the Windows “Start” button, select Run, then copy/paste the following bolded text into the run box and then click OK

C:\Qoobox\Add-Remove Programs.txt

Please post back with the list.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI