This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

too long to boot - set up screen appears [Solved]

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Good job getting all of this done. Just so you know, the infection that was on your system is the "real deal" but has been neutralized. Now we may need to fix up some of the damage that it has created. By the way…great work getting your passwords changed and having your daughter help you out too is fantastic. :)
———-

Don't worry…your Firefox and Internet Explorer have not been deleted. We will get those back shortly. :) Do me a favor and look in Start >> Control Panel >> Programs and Features and let me know how many versions of Internet Explorer you have and what versions?
———

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
———-
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    uStart Page = hxxp://mystart.incredimail.com/mb57?a=DgVbUgHIqP
    uLocal Page = c:\windows\system32\blank.htm
    mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=nv79&r=27360310n935l0454z105a4482y249
    mLocal Page = c:\windows\SysWOW64\blank.htm
    
    File::
    c:\program files\Web Assistant\ExtensionUpdaterService.exe
    c:\program files\Web Assistant\Extension64.dll
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
    
    Driver::
    Web Assistant Updater
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

Hi,

Good job getting all of this done. Just so you know, the infection that was on your system is the "real deal" but has been neutralized. Now we may need to fix up some of the damage that it has created. By the way…great work getting your passwords changed and having your daughter help you out too is fantastic. :)
———-

Don't worry…your Firefox and Internet Explorer have not been deleted. We will get those back shortly. :) Do me a favor and look in Start >> Control Panel >> Programs and Features and let me know how many versions of Internet Explorer you have and what versions?
———

Please download Farbar Service Scanner and run it on the computer with the issue.

  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
———-
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    uStart Page = hxxp://mystart.incredimail.com/mb57?a=DgVbUgHIqP
    uLocal Page = c:\windows\system32\blank.htm
    mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l;=0409&m;=nv79&r;=27360310n935l0454z105a4482y249
    mLocal Page = c:\windows\SysWOW64\blank.htm
    
    File::
    c:\program files\Web Assistant\ExtensionUpdaterService.exe
    c:\program files\Web Assistant\Extension64.dll
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
    
    Driver::
    Web Assistant Updater
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-


OK - I'm home!!! and I'm on MY LAPTOP too!!! Soooooo happy!! But there is still work to be done, I know.

Here is the FSS.txt file:

Farbar Service Scanner Version: 08-07-2012
Ran by [removed] (administrator) on 16-07-2012 at 19:09:25
Running from "C:\Users\DARLENE'S\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is OK.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

I also tried to find out how many IE's I have….sad to say - I cannot locate it on that screen - but I did click on it, and it came up. I clicked on ABOUT and here it is:

Ver 9.0.8112.16421 64 bit


Now I'm on to running combo fix by dragging CFScript.txt…

thanks so much for all your help. so glad this sight is here! I think the morons that credit these viruses\trojans should be shot.

I'll be back.

Dar
Jeff I'm a little sad….I'm back on hubbys pc….IE and firefox are not available now on my laptop. So I saved the file to my hubby's desktop thru the network. Here it is: ComboFix 12-07-16.01 - DARLENE'S 07/16/2012 19:39:13.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3767.2157 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\DARLENE'S\Desktop\CFScript.txt AV: Trend Micro AntiVirus *Enabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902} SP: Trend Micro AntiVirus *Enabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\program files\Web Assistant\Extension64.dll" "c:\program files\Web Assistant\ExtensionUpdaterService.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_Web Assistant Updater . . ((((((((((((((((((((((((( Files Created from 2012-06-16 to 2012-07-16 ))))))))))))))))))))))))))))))) . . 2012-07-16 23:53 . 2012-07-16 23:53 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2012-07-16 23:53 . 2012-07-16 23:53 ——– d—–w- c:\users\QUEEN OF THE ROAD\AppData\Local\temp 2012-07-16 23:53 . 2012-07-16 23:53 ——– d—–w- c:\users\Guest\AppData\Local\temp 2012-07-16 23:53 . 2012-07-16 23:53 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-16 23:53 . 2012-07-16 23:53 ——– d—–w- c:\users\Administrator\AppData\Local\temp 2012-07-15 00:21 . 2012-07-15 00:21 ——– d—–w- c:\program files (x86)\ERUNT 2012-07-13 21:34 . 2012-07-13 21:34 ——– d-sh–w- c:\windows\SysWow64\%APPDATA% 2012-07-13 00:38 . 2012-06-05 07:37 256904 —-a-w- c:\windows\SysWow64\drivers\tmcomm.sys 2012-07-12 23:36 . 2012-07-15 22:49 21520 —-a-w- c:\windows\DCEBoot64.exe 2012-07-12 11:42 . 2012-07-13 10:04 129024 —-a-w- c:\windows\RegBootClean64.exe 2012-07-12 11:42 . 2012-07-12 21:39 102400 —-a-w- c:\windows\RegBootClean.exe 2012-07-11 10:12 . 2012-06-12 03:08 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-11 09:56 . 2012-06-06 06:06 2004480 —-a-w- c:\windows\system32\msxml6.dll 2012-07-11 09:56 . 2012-06-06 06:06 1881600 —-a-w- c:\windows\system32\msxml3.dll 2012-07-11 09:56 . 2012-06-06 05:05 1390080 —-a-w- c:\windows\SysWow64\msxml6.dll 2012-07-11 09:56 . 2012-06-06 05:05 1236992 —-a-w- c:\windows\SysWow64\msxml3.dll 2012-07-11 09:56 . 2010-06-26 03:55 2048 —-a-w- c:\windows\system32\msxml3r.dll 2012-07-11 09:56 . 2010-06-26 03:24 2048 —-a-w- c:\windows\SysWow64\msxml3r.dll 2012-06-23 09:36 . 2012-06-23 09:36 ——– d—–w- c:\users\DARLENE'S\AppData\Local\Macromedia 2012-06-21 21:41 . 2012-06-02 22:19 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-21 21:41 . 2012-06-02 22:19 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-21 21:41 . 2012-06-02 22:19 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-21 21:41 . 2012-06-02 22:15 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-21 21:40 . 2012-06-02 22:19 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-21 21:40 . 2012-06-02 22:19 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-21 21:40 . 2012-06-02 22:15 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-06-21 21:38 . 2012-06-02 19:19 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-21 21:38 . 2012-06-02 19:15 36864 —-a-w- c:\windows\system32\wuapp.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-15 12:29 . 2010-03-31 12:52 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2012-07-14 00:51 . 2010-03-28 22:27 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2012-07-14 00:50 . 2010-03-28 22:26 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-07-14 00:50 . 2010-05-18 21:24 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2012-07-12 00:07 . 2012-05-28 10:48 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-12 00:07 . 2011-05-14 15:12 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-08 11:19 . 2011-03-30 09:45 101464 —-a-w- c:\windows\system32\drivers\RapportKE64.sys 2012-07-05 21:43 . 2010-04-09 13:51 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2012-07-05 21:42 . 2010-04-09 13:51 4283672 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2012-07-05 21:42 . 2010-06-03 09:36 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-05-04 11:06 . 2012-06-12 21:38 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 10:03 . 2012-06-12 21:38 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03 . 2012-06-12 21:38 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-01 05:40 . 2012-06-12 21:38 209920 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:55 . 2012-06-12 21:38 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 05:41 . 2012-06-12 21:39 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 05:41 . 2012-06-12 21:39 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 05:34 . 2012-06-12 21:39 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-24 05:37 . 2012-06-12 21:38 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2012-04-24 05:37 . 2012-06-12 21:38 140288 —-a-w- c:\windows\system32\cryptnet.dll 2012-04-24 05:37 . 2012-06-12 21:38 1462272 —-a-w- c:\windows\system32\crypt32.dll 2012-04-24 04:36 . 2012-06-12 21:38 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2012-04-24 04:36 . 2012-06-12 21:38 1158656 —-a-w- c:\windows\SysWow64\crypt32.dll 2012-04-24 04:36 . 2012-06-12 21:38 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2012-04-19 00:56 . 2012-04-19 00:56 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2012-04-19 00:56 . 2012-04-19 00:56 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts . . ((((((((((((((((((((((((((((( SnapShot@2012-07-16_02.01.31 ))))))))))))))))))))))))))))))))))))))))) . + 2010-08-19 00:23 . 2012-07-17 00:01 32768 c:\windows\Temp\Temporary Internet Files\Content.IE5\index.dat - 2010-08-19 00:23 . 2012-07-16 02:01 32768 c:\windows\Temp\Temporary Internet Files\Content.IE5\index.dat - 2010-08-19 00:23 . 2012-07-16 02:00 16384 c:\windows\Temp\History\History.IE5\index.dat + 2010-08-19 00:23 . 2012-07-17 00:01 16384 c:\windows\Temp\History\History.IE5\index.dat - 2010-08-19 00:23 . 2012-07-16 02:00 16384 c:\windows\Temp\Cookies\index.dat + 2010-08-19 00:23 . 2012-07-17 00:01 16384 c:\windows\Temp\Cookies\index.dat + 2009-07-14 05:10 . 2012-07-16 23:59 38576 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-03-28 06:07 . 2012-07-16 23:59 21284 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-717187791-2577701650-807877497-1001_UserData.bin + 2012-07-16 10:17 . 2012-07-16 10:17 25600 c:\windows\Installer\1cbc7c0.msi - 2012-07-16 02:00 . 2012-07-16 02:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-07-16 23:55 . 2012-07-16 23:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-07-16 02:00 . 2012-07-16 02:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-07-16 23:55 . 2012-07-16 23:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-03-30 09:45 . 2012-07-17 00:00 5430 c:\windows\Installer\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}\RapportServiceStopShortcut.exe - 2011-03-30 09:45 . 2012-06-18 09:54 5430 c:\windows\Installer\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}\RapportServiceStopShortcut.exe + 2011-03-30 09:45 . 2012-07-17 00:00 5430 c:\windows\Installer\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}\RapportServiceStartShortcut.exe - 2011-03-30 09:45 . 2012-06-18 09:54 5430 c:\windows\Installer\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}\RapportServiceStartShortcut.exe + 2011-03-30 09:45 . 2012-07-17 00:00 5430 c:\windows\Installer\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}\RapportServiceConsoleShortcut.exe - 2011-03-30 09:45 . 2012-06-18 09:54 5430 c:\windows\Installer\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}\RapportServiceConsoleShortcut.exe - 2009-07-14 02:36 . 2012-07-15 02:03 660530 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-07-16 09:46 660530 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2012-07-15 02:03 121426 c:\windows\system32\perfc009.dat + 2009-07-14 02:36 . 2012-07-16 09:46 121426 c:\windows\system32\perfc009.dat + 2009-07-14 05:01 . 2012-07-16 23:54 405992 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2012-07-16 01:59 405992 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2010-04-04 04:58 . 2012-07-16 23:54 42882300 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-717187791-2577701650-807877497-1001-8192.dat - 2010-04-04 04:58 . 2012-07-16 01:59 42882300 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-717187791-2577701650-807877497-1001-8192.dat - 2010-07-30 11:54 . 2012-07-14 09:55 16997908 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-717187791-2577701650-807877497-1001-4096.dat + 2010-07-30 11:54 . 2012-07-16 23:54 16997908 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-717187791-2577701650-807877497-1001-4096.dat + 2012-07-16 23:55 . 2012-07-16 23:55 31225856 c:\windows\Installer\d1ee.msi . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn1\YTNavAssist.dll" [2011-01-21 213816] . [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}] [HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IncrediMail"="c:\program files (x86)\IncrediMail\bin\IncMail.exe" [2012-06-18 366536] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-17 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-09-17 1157640] "RemoteControl8"="c:\program files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [2009-04-16 91432] "PDVD8LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [2009-04-16 50472] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2011-06-16 2922496] "Conime"="c:\windows\system32\conime.exe" [BU] . c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy Software Installer.lnk - c:\program files\Best Buy Software Installer\Best Buy Software Installer.exe [2009-10-28 1132984] . c:\users\QUEEN OF THE ROAD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy Software Installer.lnk - c:\program files\Best Buy Software Installer\Best Buy Software Installer.exe [2009-10-28 1132984] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-29 136176] R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-12 250056] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-29 136176] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-17 113120] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-02 225280] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-31 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280] S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys [2012-07-08 101464] S1 RapportCerberus_34302;RapportCerberus_34302;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_34302.sys [2012-06-18 397520] S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2012-07-08 55096] S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2012-07-08 297048] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 ePowerSvc;Acer ePower Service;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe [2009-10-29 844320] S2 Greg_Service;GRegService;c:\program files (x86)\Gateway\Registration\GregHSRW.exe [2009-08-28 1150496] S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 27136] S2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [2011-07-27 14952] S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files (x86)\Kodak\AiO\Center\EKAiOHostService.exe [2011-12-19 394672] S2 McciCMService64;McciCMService64;c:\program files\Common Files\Motive\McciCMService.exe [2010-03-17 517632] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [2010-05-24 255744] S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2012-07-08 976728] S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2011-07-12 42768] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2009-11-02 13784] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-09-30 2320920] S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2009-07-04 240160] S2 WajamUpdater;WajamUpdater;c:\program files\Wajam\Updater\WajamUpdater.exe [2012-03-09 109064] S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [2009-02-12 292864] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 151936] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2009-10-29 244736] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-08-05 320040] S3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2010-03-30 917768] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . Contents of the 'Scheduled Tasks' folder . 2012-07-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-28 00:07] . 2012-07-15 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-717187791-2577701650-807877497-1001Core.job - c:\users\DARLENE'S\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-08-31 21:48] . 2012-07-16 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-717187791-2577701650-807877497-1001UA.job - c:\users\DARLENE'S\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-08-31 21:48] . 2012-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-29 02:22] . 2012-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-03-29 02:22] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\DARLENE'S\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904] "Acer ePower Management"="c:\program files\Gateway\Gateway Power Management\ePowerTray.exe" [2009-10-29 822816] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-20 8306208] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-03-30 1022368] "DriverAccess"="c:\program files (x86)\Driver Assure Corp\DriverAccess\DriverAccess.exe" [BU] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256] "EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe" [2011-06-16 2922496] "combofix"="c:\combofix\CF15212.3XE" [2010-11-20 345088] . ——- Supplementary Scan ——- . uLocal Page = %SystemRoot%\system32\blank.htm mLocal Page = %SystemRoot%\system32\blank.htm uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &Add animation to IncrediMail Style Box - c:\program files (x86)\IncrediMail\bin\resources\WebMenuImg.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Easy-WebPrint Add To Print List - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html IE: Easy-WebPrint High Speed Print - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html IE: Easy-WebPrint Preview - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html IE: Easy-WebPrint Print - c:\program files (x86)\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.1.1 [removed] DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB FF - ProfilePath - c:\users\DARLENE'S\AppData\Roaming\Mozilla\Firefox\Profiles\rs6a0nlk.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://forums.whatthetech.com/index.php?act=UserCP&CODE=26 FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Be4dcb1dd-7e64-4ac9-a5b3-74f0e7ab7eb8%7D&mid=469dad1e907047d0b4bea113f0f38de2-99689a59add06bdedde022257a874a8682ddc4d9&ds=od011&v=11.0.0.9&lang=en&pr=sa&d=2012-05-15%2005%3A44%3A51&sap=ku&q= FF - prefs.js: network.proxy.type - 0 FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . - - - - ORPHANS REMOVED - - - - . Toolbar-{06C7AD57-B655-418D-9AB8-9526A6D2E052} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Common Files\Motive\McciCMService.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files (x86)\Trusteer\Rapport\bin\RapportService.exe c:\program files (x86)\Internet Explorer\IELowutil.exe . ************************************************************************** . Completion time: 2012-07-16 20:14:46 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-17 00:14 ComboFix2.txt 2012-07-16 02:16 . Pre-Run: 55,389,839,360 bytes free Post-Run: 58,196,590,592 bytes free . - - End Of File - - D9D029182BDB5ACF2A6E8F106A8B4F28 Can I get my laptop back tonight? I'm so sad… I was so happy an hour ago! Dar
B) - I rebooted after I thought about what I read in the blue box….dah……..that combofix is set up to not let anyone click the mouse and use anything….idiot proofs itself.. Breathe deep - I'm ok…. dar
Hi,

So I just want to clarify….are you still not able to get onto IE and FF on your computer?
————

Download Windows Repair (all in one) from this site

Install and then run the program.

On the Start Repairs tab, select Advanced Mode and click Start
[external image: Posted Image]


Select the items Checked in the screen shot below (remove the checks from the rest ) and check Restart System When Finished.

[external image: Posted Image]
———-

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-
Good Morning! Once I rebooted, I can load FF and IE - no problem! so, not sure if you want me to continue with the instructions you just sent me. Please advise. I want to make sure I do everything you need me to do! this laptop seems to be running a tad faster too - always a good thing! Dar
Great!

Yes please follow the instructions that I provided as well as the following now that your IE is working…

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats is NOT selected and the option Scan unwanted applications is selected.
  • Click Scan (This scan can take several hours, so please be patient)
  • If there are threats that are found, please press List of found threats and then in the next window that opens press Export to text file…
  • Copy and paste/or attach that log as a reply to this topic
**Note** If not threats are found there will not be a log created.
———-

In your next reply please post the logs made by Malwarebytes and ESET. :)
Good Morning! I must leave for work in 10 minutes, so I don't have the time to do all that is needed. I will follow your instructions after dinner tonight! Have a great day and stay cool! Darlene
Here is Malaware bytes log: Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.17.14 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 DARLENE'S :: DARLENES-PC [administrator] 7/17/2012 6:32:39 PM mbam-log-2012-07-17 (18-53-22).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 279528 Time elapsed: 19 minute(s), 48 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 16 HKCR\Typelib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLab) -> No action taken. HKCR\Interface\{55555555-5555-5555-5555-550055225558} (Adware.GamePlayLab) -> No action taken. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65bcd620-07dd-012f-819f-073cf1b8f7c6} (Adware.GamePlayLab) -> No action taken. HKCR\CrossriderApp0002258.Sandbox (Adware.GamePlayLab) -> No action taken. HKCR\CrossriderApp0002258.FBApi (Adware.GamePlayLab) -> No action taken. HKCR\CrossriderApp0002258.BHO (Adware.GamePlayLab) -> No action taken. HKCR\CrossriderApp0002258.BHO (PUP.CrossFire.Gen) -> No action taken. HKCR\CrossriderApp0002258.BHO.1 (PUP.CrossFire.Gen) -> No action taken. HKCR\CrossriderApp0002258.FBApi (PUP.CrossFire.Gen) -> No action taken. HKCR\CrossriderApp0002258.FBApi.1 (PUP.CrossFire.Gen) -> No action taken. HKCR\CrossriderApp0002258.Sandbox (PUP.CrossFire.Gen) -> No action taken. HKCR\CrossriderApp0002258.Sandbox.1 (PUP.CrossFire.Gen) -> No action taken. HKCU\Software\Cr_Installer\2258 (Adware.GamePlayLab) -> No action taken. HKLM\SOFTWARE\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken. HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\I WANT THIS (Adware.GamePlayLab) -> No action taken. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken. Registry Values Detected: 1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\I Want This|Publisher (Adware.GamePlayLab) -> Data: 215 Apps -> No action taken. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) Where does this carp** come from? How can I stop it from coming on board?? Off to run the next one.. dar
Good Morning Jeff! After more than 6 hours of scanning… Here is the ESET log file! C:\Program Files (x86)\FoxTabPDFReader\Uninstall\Uninstall.exe a variant of Win32/InstallCore.M application C:\Qoobox\Quarantine\C\Users\DARLENE'S\AppData\Local\assembly\Applications\gqqpr.dll.vir a variant of Win32/Kryptik.AIGL trojan C:\_OTL\MovedFiles\07142012_202518\C_Windows\Installer\{4d69ce62-0186-2acc-f4de-bc14bad586a2}\U\80000032.@ a variant of Win32/Sirefef.FD trojan I can see by the 3 trojans found, that your work is not done.! I await your next set of instructions! Darlene
Good morning!!

Actually the ESET scan looks ok. We will remove one of the entries but the other two are already quarantined by the tools we have been using so they are alright.

I noticed that you did not remove the items that Malwarebytes found? Go ahead and remove those and then do the following.

First open an elevated command prompt > Click Start and type cmd in Start Search.
When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.

Copy the contents of the code box > right click in the command window and select paste >> Press Enter (do one line at a time if there are more than one)
del "C:\Program Files (x86)\FoxTabPDFReader\Uninstall\Uninstall.exe"
Close the Command Prompt box.

In your next reply please post the new Malwarebytes log and let me know how your system is running. :)
Morning Jeff! Your instructions didn't say to delete anything in Malaware…I was afraid to do anything unless you said to!! I will follow your instructions tonight after dinner. I have to leave for work here in 10 minutes. Thanks again for all your help! Will post tonight! dar
got sent home early today! Big storm came thru the area and knocked out the power!! here is the new malawarebytes log and I deleted all 16 nasties!! Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.17.15 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 DARLENE'S :: DARLENES-PC [administrator] 7/18/2012 3:51:40 PM mbam-log-2012-07-18 (16-12-22).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 279971 Time elapsed: 20 minute(s), 19 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 16 HKCR\Typelib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLab) -> No action taken. HKCR\Interface\{55555555-5555-5555-5555-550055225558} (Adware.GamePlayLab) -> No action taken. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65bcd620-07dd-012f-819f-073cf1b8f7c6} (Adware.GamePlayLab) -> No action taken. HKCR\CrossriderApp0002258.Sandbox (Adware.GamePlayLab) -> No action taken. HKCR\CrossriderApp0002258.FBApi (Adware.GamePlayLab) -> No action taken. HKCR\CrossriderApp0002258.BHO (Adware.GamePlayLab) -> No action taken. HKCR\CrossriderApp0002258.BHO (PUP.CrossFire.Gen) -> No action taken. HKCR\CrossriderApp0002258.BHO.1 (PUP.CrossFire.Gen) -> No action taken. HKCR\CrossriderApp0002258.FBApi (PUP.CrossFire.Gen) -> No action taken. HKCR\CrossriderApp0002258.FBApi.1 (PUP.CrossFire.Gen) -> No action taken. HKCR\CrossriderApp0002258.Sandbox (PUP.CrossFire.Gen) -> No action taken. HKCR\CrossriderApp0002258.Sandbox.1 (PUP.CrossFire.Gen) -> No action taken. HKCU\Software\Cr_Installer\2258 (Adware.GamePlayLab) -> No action taken. HKLM\SOFTWARE\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken. HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\I WANT THIS (Adware.GamePlayLab) -> No action taken. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken. Registry Values Detected: 1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\I Want This|Publisher (Adware.GamePlayLab) -> Data: 215 Apps -> No action taken. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) dar

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI