This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

back door trojan [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hii guys….since last few hours my laptop is acting funny…everytime i open any browser it automatically opens a pop up ( singles in your area/porn ) n its a same pop up everytime… LINK REMOVED that made me run malwarebytes…n it shows one file found which is trojan.dropper.bcminer….i removed it but it keeps coming back n pop doesnt stop…i close it comes back after 5-10 mins…i read few stuff about this trojan type n it looks bad…please help me out if you can..thanks.. here are the OTL reports..
can anyone help me with this? or should i close this topic? even if someone is looking to help me..please let me know so i can wait.. THANKS..
Hello ankitt and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

P2P - I see you have P2P software, (BitTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\windows._cacheinvalidation.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._gdi_.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\pysqlite2._sqlite.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32com.shell.shell.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\pyexpat.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32api.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\_elementtree.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\_ctypes.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._html2.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\_socket.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32crypt.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._core_.pyd () – supposed to be \_MEI34842\wx._core_.pyd- http://systemexplorer.net/filereviews.php?fid=11587646 – can be anything as another was MEI21082
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._controls_.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._windows_.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._misc_.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\_ssl.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\unicodedata.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\pythoncom26.dll ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\_hashlib.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._wizard.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32file.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\PyWinTypes26.dll ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32inet.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32process.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32pdh.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32event.pyd ()
    MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\select.pyd ()
    MOD - \\?\globalroot\systemroot\syswow64\mswsock.DLL ()
    MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
    O3 - HKLM\..\Toolbar: (no name) - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - No CLSID value found.
    O4:[b]64bit:[/b] - HKLM..\Run: []  File not found
    O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
    O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
    O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
    O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
    O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
    O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
    O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
    O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
    O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
    O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
    O16:[b]64bit:[/b] - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Reg Error: Key error.)
    
    :Commands
    [purity]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
===================================================

Run TDSSKiller

Please download TDSSKiller.zip
  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan

    only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.

  • click Continue > Reboot now

  • copy and paste the log in your next reply
  • a copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)

======================================================

Download and run ComboFix

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It MUST be saved directly to your desktop. Choose save as and then make sure you choose Desktop

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • when finished, it will produce a report for you.
  • please post the C:\ComboFix.txt for further review.

Logs to include in the next post:

OTL fix log
TDSSKiller log
ComboFix.txt


Thanks

Satchfan

thanks for your help..

foe tddskiller..found one treat..but as you said to cure..none of that option came..all i had to pick from is skip..delete or quar…so i skip..it said treat was locked..anyways report is here for all 3..


i went to c driven \otl to get this log..as nothing has opened like last time..let me know if any changes needs to be made..thanks..

Submit a file to VirusTotal

Go to VirusTotal and submit this file for analysis:

c:\windows\system32\drivers\bocysgvh.sys
  • click on Browse
  • click on the arrow and choose Local Disc (C:)
    🖼Click to load external image (Posted Image)
  • below, double-click on Windows
  • double-click on the System32folder and then the Drivers folder
  • locate the file bocysgvh.sys click on it and then on Open
  • click on Send File.
You will get a report back; post the report into this thread for me to see.

========================================

Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Satchfan
hey the file you wanted me to find on virus total…doesnt exist when i went ahead n did windows/system32/drivers… here the report from cks CKScanner - Additional Security Risks - These are not necessarily bad c:\qoobox\quarantine\c\users\owner\microsoft office 2007 keygen –coded by melinda–.exe.vir scanner sequence 3.NA.11.TKAPJH —– EOF —–

the file you wanted me to find on virus total…doesnt exist

Show hidden Files and Folders
  • open Windows Explorer, (Windows key+E)
  • at the top, click on Organise, >Folder and search options
  • click on the “View” tab
  • under “Files and Folders”, place a check in Show hidden files, folders and drives
When you've done that, try searching for the file again.
Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
C:\windows\system32\drivers\bocysgvh.sys

Driver::
Bocysgvh

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

Please tell me how your computer is running

Satchfan
hey here is the report after the last combofix scan… in terms of my laptop…since this morning i havent seen that auto pop up coming up….so i guess its a good thing… let me know what needs to be done if any after you see the report…

Attachments:

Good news about the popups but we’ll need a few more scans before deciding that all’s well.

Please do these in the order given and copy/paste the results, not attach them. Thanks.

Download TFC to your desktop
  • close any open windows.
  • double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • click the Start button to begin the process.
  • allow TFC to run uninterrupted.
  • the program should not take long to finish it's job
  • once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

===================================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

===================================================

Please run ComboFix again.

Logs to include with the next post:

ComboFix.txt
Mbam.txt


Satchfan
here is the MBNA LOG Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.24.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Owner :: OWNER-PC [administrator] Protection: Enabled 24/07/2012 1:25:22 PM mbam-log-2012-07-24 (13-25-22).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 196642 Time elapsed: 3 minute(s), 24 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
combo fix log ComboFix 12-07-21.01 - Owner 24/07/2012 13:33:18.3.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.3894.2301 [GMT -4:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Outdated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D} SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Owner\AppData\Local\Temp\_MEI37242\_ctypes.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\_elementtree.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\_hashlib.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\_socket.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\_ssl.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\pyexpat.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\pysqlite2._sqlite.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\python26.dll c:\users\Owner\AppData\Local\Temp\_MEI37242\pythoncom26.dll c:\users\Owner\AppData\Local\Temp\_MEI37242\PyWinTypes26.dll c:\users\Owner\AppData\Local\Temp\_MEI37242\select.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\unicodedata.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\win32api.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\win32com.shell.shell.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\win32crypt.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\win32event.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\win32file.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\win32inet.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\win32pdh.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\win32process.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\windows._cacheinvalidation.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\wx._controls_.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\wx._core_.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\wx._gdi_.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\wx._html2.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\wx._misc_.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\wx._windows_.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\wx._wizard.pyd c:\users\Owner\AppData\Local\Temp\_MEI37242\wxbase293u_net_vc.dll c:\users\Owner\AppData\Local\Temp\_MEI37242\wxbase293u_vc.dll c:\users\Owner\AppData\Local\Temp\_MEI37242\wxmsw293u_adv_vc.dll c:\users\Owner\AppData\Local\Temp\_MEI37242\wxmsw293u_core_vc.dll c:\users\Owner\AppData\Local\Temp\_MEI37242\wxmsw293u_html_vc.dll c:\users\Owner\AppData\Local\Temp\_MEI37242\wxmsw293u_webview_vc.dll . . ((((((((((((((((((((((((( Files Created from 2012-06-24 to 2012-07-24 ))))))))))))))))))))))))))))))) . . 2012-07-24 17:46 . 2012-07-24 17:46 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-21 14:14 . 2012-07-21 14:14 ——– d—–w- C:\_OTL 2012-07-20 02:55 . 2012-07-20 02:55 ——– d—–w- c:\users\Owner\AppData\Local\Macromedia 2012-07-19 19:09 . 2012-07-19 19:09 ——– d-sh–w- c:\windows\SysWow64\%APPDATA% 2012-07-17 02:12 . 2012-07-17 02:33 ——– d—–w- c:\program files (x86)\PKR 2012-07-12 17:27 . 2012-06-12 03:08 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-10 23:26 . 2012-06-06 06:06 2004480 —-a-w- c:\windows\system32\msxml6.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-20 02:53 . 2012-04-29 19:40 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-20 02:53 . 2011-08-12 02:10 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-12 17:24 . 2011-05-12 14:24 59701280 —-a-w- c:\windows\system32\MRT.exe 2012-07-03 17:46 . 2011-09-01 19:56 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-06-02 22:19 . 2012-06-21 23:25 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-21 23:25 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-21 23:25 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-21 23:25 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-21 23:25 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-21 23:25 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-21 23:25 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-06-02 19:19 . 2012-06-21 23:25 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 19:15 . 2012-06-21 23:25 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-05-31 16:25 . 2011-05-11 20:36 279656 ——w- c:\windows\system32\MpSigStub.exe 2012-05-04 11:06 . 2012-06-13 22:27 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 10:03 . 2012-06-13 22:27 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03 . 2012-06-13 22:27 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-01 05:40 . 2012-06-13 22:27 209920 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:55 . 2012-06-13 22:27 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 05:41 . 2012-06-13 22:27 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 05:41 . 2012-06-13 22:27 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 05:34 . 2012-06-13 22:27 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-25 18:29 . 2011-11-11 00:50 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll . . ((((((((((((((((((((((((((((( SnapShot@2012-07-21_14.46.43 ))))))))))))))))))))))))))))))))))))))))) . + 2012-07-24 17:20 . 2012-07-24 17:20 13318 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat - 2012-07-20 04:10 . 2012-07-20 04:10 13318 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat + 2012-07-21 14:34 . 2012-07-24 01:19 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-07-21 14:34 . 2012-07-21 14:46 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-07-07 01:38 . 2012-07-21 14:55 44652 c:\windows\system64\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-07-24 17:22 41256 c:\windows\system64\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-05-11 20:03 . 2012-07-24 17:22 11134 c:\windows\system64\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3325534984-3842535646-1169382596-1000_UserData.bin - 2011-05-12 10:55 . 2012-07-21 14:17 16384 c:\windows\system64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-05-12 10:55 . 2012-07-24 17:48 16384 c:\windows\system64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-05-12 10:55 . 2012-07-21 14:17 32768 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-07-24 17:21 . 2012-07-24 17:48 32768 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-07-21 14:17 16384 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-07-24 17:48 16384 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-07-07 01:38 . 2012-07-21 14:55 44652 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-07-24 17:22 41256 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-05-11 20:03 . 2012-07-24 17:22 11134 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3325534984-3842535646-1169382596-1000_UserData.bin - 2011-05-12 10:55 . 2012-07-21 14:17 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-05-12 10:55 . 2012-07-24 17:48 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-05-12 10:55 . 2012-07-21 14:17 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-07-24 17:21 . 2012-07-24 17:48 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-07-21 14:17 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-07-24 17:48 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-08-02 05:34 . 2012-07-24 01:18 1604 c:\windows\system64\wdi\ERCQueuedResolutions.dat + 2011-08-02 05:34 . 2012-07-24 01:18 1604 c:\windows\system32\wdi\ERCQueuedResolutions.dat - 2012-07-21 14:46 . 2012-07-21 14:46 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-07-24 17:20 . 2012-07-24 17:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-07-24 17:20 . 2012-07-24 17:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-07-21 14:46 . 2012-07-21 14:46 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-07-14 04:54 . 2012-07-21 14:46 983040 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-07-24 01:19 983040 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-06-03 03:31 . 2012-07-24 03:51 294720 c:\windows\system64\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin + 2011-06-02 20:28 . 2012-07-24 17:17 365840 c:\windows\system64\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin + 2009-07-14 02:36 . 2012-07-23 00:43 638094 c:\windows\system64\perfh009.dat - 2009-07-14 02:36 . 2012-07-20 01:41 638094 c:\windows\system64\perfh009.dat + 2009-07-14 02:36 . 2012-07-23 00:43 115246 c:\windows\system64\perfc009.dat - 2009-07-14 02:36 . 2012-07-20 01:41 115246 c:\windows\system64\perfc009.dat + 2011-06-03 03:31 . 2012-07-24 03:51 294720 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin + 2011-06-02 20:28 . 2012-07-24 17:17 365840 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2009-07-14 02:36 . 2012-07-20 01:41 638094 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-07-23 00:43 638094 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2012-07-20 01:41 115246 c:\windows\system32\perfc009.dat + 2009-07-14 02:36 . 2012-07-23 00:43 115246 c:\windows\system32\perfc009.dat - 2009-07-14 05:01 . 2012-07-20 04:10 503668 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2012-07-24 17:20 503668 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2011-06-08 18:04 . 2012-07-20 04:10 1405836 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3325534984-3842535646-1169382596-1000-8192.dat + 2011-06-08 18:04 . 2012-07-24 17:20 1405836 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3325534984-3842535646-1169382596-1000-8192.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960] "AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120] "Facebook Update"="c:\users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-12 138096] "GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2012-06-20 12163848] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2007-08-24 240112] "AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-05-07 344736] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~2\KASPER~1\KASPER~1\sbhook.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-05-07 460888] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-11 135664] R2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [2007-08-24 362992] R2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2007-08-24 309744] R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2007-08-24 166384] R2 SessionLauncher;SessionLauncher;c:\users\Owner\AppData\Local\Temp\DX9\SessionLauncher.exe [x] R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-03-15 6403072] R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-15 188928] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-11 135664] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2007-08-24 72176] R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2007-08-24 1083888] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-02-01 232992] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-24 835952] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-05-12 1255736] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2007-07-26 53488] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-10-21 503352] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 27736] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-15 202752] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-29 249200] S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-18 258928] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 14472] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-10 158720] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-02-03 271872] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-03 22544] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-02-23 75304] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [2009-06-23 35008] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [2010-04-27 1103904] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] . . Contents of the 'Scheduled Tasks' folder . 2012-07-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3325534984-3842535646-1169382596-1000Core.job - c:\users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-16 01:43] . 2012-07-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3325534984-3842535646-1169382596-1000UA.job - c:\users\Owner\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-16 01:43] . 2012-07-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-11 20:20] . 2012-07-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-05-11 20:20] . 2012-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3325534984-3842535646-1169382596-1000Core.job - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-10 00:59] . 2012-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3325534984-3842535646-1169382596-1000UA.job - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-10 00:59] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2012-06-20 23:02 755224 —-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}] 2012-06-20 23:02 755224 —-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2012-06-20 23:02 755224 —-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2012-06-20 23:02 755224 —-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-02-26 166424] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-02-26 391192] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-02-26 410648] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272] "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768] "TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU] "HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU] "SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU] "00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976] "Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU] "TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1\x64\kloehk.dll c:\progra~2\KASPER~1\KASPER~1\x64\sbhook64.dll . ——- Supplementary Scan ——- . uStart Page = hxxp://www.toshiba.ca/welcome uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://www.toshiba.ca/welcome mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\gojmlcs7.default\ FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-10 - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe . ************************************************************************** . Completion time: 2012-07-24 13:59:09 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-24 17:59 ComboFix2.txt 2012-07-24 01:15 ComboFix3.txt 2012-07-21 14:51 . Pre-Run: 495,463,993,344 bytes free Post-Run: 494,994,644,992 bytes free . - - End Of File - - 13EE9B2D10EB85DA017B3C13935FF3BD
Hi ankitt. You've done good but although it all seems OK, I'd like another scan.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

NOTE. If Eset doesn't find any threats, it won't produce a log.

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI