This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Got virus, trojan or whatever [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Great.

Let's see if we can get an online scan. Be prepared as this will probably take hours to complete.

Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
A window came up after I finished the scan. See attachment. Scan Results C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe a variant of Win32/HiddenStart.A application C:\Users\Sheila\Documents\Downloads\InternationalPrimoPDF.exe Win32/OpenCandy application C:\Users\Sheila\Documents\Downloads\KeyFinderInstaller.exe Win32/OpenCandy application C:\Users\Sheila\Documents\Downloads\knit_visualizer.rar_downloader_224.exe a variant of Win32/ExpressFiles application C:\Users\Sheila\Documents\My Programs\DTLite4454-0315.exe Win32/OpenCandy application C:\Users\Sheila\Documents\My Programs\InternationalPrimoPDF.exe Win32/OpenCandy application
Go ahead and cancel that window if you haven't yet. We got the report so we don't really care about the warning anymore.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe
    C:\Users\Sheila\Documents\Downloads\InternationalPrimoPDF.exe
    C:\Users\Sheila\Documents\Downloads\KeyFinderInstaller.exe
    C:\Users\Sheila\Documents\Downloads\knit_visualizer.rar_downloader_224.exe
    C:\Users\Sheila\Documents\My Programs\DTLite4454-0315.exe
    C:\Users\Sheila\Documents\My Programs\InternationalPrimoPDF.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then give it a bit of a test drive and let me know what issues you are still having.
Control of internet functions have returned. Definite speed improvement. The firewall is up and running. I can turn it off and on as I please. The advanced settings have reappeared. Downloads window show up and function. No more tiny little boxes. No more blank windows when opening files. All functions and menus show up in start menu as they should. Unicorn horns are properly sharpened and dog barking is at the proper sound level (my game is running right, no freezing or minimizing to bar) I do however have two FlashPlayerPlugin_11_3_300_268.exe running in task manager now. ComboFix 12-07-29.02 - Sheila 07/30/2012 10:54:09.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6031.4440 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Sheila\Desktop\CFScript.txt AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . FILE :: "c:\program files (x86)\Dell DataSafe Local Backup\hstart.exe" "c:\users\Sheila\Documents\Downloads\InternationalPrimoPDF.exe" "c:\users\Sheila\Documents\Downloads\KeyFinderInstaller.exe" "c:\users\Sheila\Documents\Downloads\knit_visualizer.rar_downloader_224.exe" "c:\users\Sheila\Documents\My Programs\DTLite4454-0315.exe" "c:\users\Sheila\Documents\My Programs\InternationalPrimoPDF.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Dell DataSafe Local Backup\hstart.exe c:\users\Sheila\Documents\Downloads\InternationalPrimoPDF.exe c:\users\Sheila\Documents\Downloads\KeyFinderInstaller.exe c:\users\Sheila\Documents\Downloads\knit_visualizer.rar_downloader_224.exe c:\users\Sheila\Documents\My Programs\DTLite4454-0315.exe c:\users\Sheila\Documents\My Programs\InternationalPrimoPDF.exe . . ((((((((((((((((((((((((( Files Created from 2012-06-28 to 2012-07-30 ))))))))))))))))))))))))))))))) . . 2012-07-30 14:59 . 2012-07-30 14:59 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp 2012-07-25 03:55 . 2012-07-25 03:55 โ€”โ€”โ€“ d-shโ€“w- c:\windows\SysWow64\%APPDATA% 2012-07-25 02:40 . 2012-07-25 02:40 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\FLEXnet 2012-07-23 01:40 . 2012-07-23 01:40 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\s3pe 2012-07-22 22:58 . 2012-07-22 22:58 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\Control Panels 2012-07-22 22:55 . 2012-07-22 22:55 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\ALM 2012-07-22 22:53 . 2007-02-20 20:04 190696 โ€”-a-w- c:\windows\SysWow64\NPSWF32_FlashUtil.exe 2012-07-22 22:53 . 2007-02-20 20:04 2463976 โ€”-a-w- c:\windows\SysWow64\NPSWF32.dll 2012-07-22 22:49 . 2012-07-22 22:49 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\SysWow64\spool 2012-07-22 22:48 . 2012-07-22 22:48 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Bonjour 2012-07-22 12:42 . 2012-07-22 12:42 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Blender Foundation 2012-07-22 12:32 . 2012-07-29 17:15 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\MilkShape 3D 1.8.5 2012-07-22 01:57 . 2012-07-22 01:57 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Microsoft Silverlight 2012-07-20 23:06 . 2012-07-20 23:06 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Oracle 2012-07-20 23:03 . 2012-07-06 02:06 772544 โ€”-a-w- c:\windows\SysWow64\npDeployJava1.dll 2012-07-20 18:01 . 2012-07-20 18:01 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\Sun 2012-07-19 20:28 . 2012-05-25 21:09 29312 โ€”-a-w- c:\program files (x86)\Mozilla Firefox\ScriptFF.dll 2012-07-19 19:52 . 2012-07-19 19:52 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Mozilla Maintenance Service 2012-07-19 19:52 . 2012-07-14 00:17 136672 โ€”-a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll 2012-07-19 00:23 . 2012-07-19 00:23 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Bandicam 2012-07-19 00:23 . 2012-07-19 00:23 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\BandiMPEG1 2012-07-16 15:08 . 2012-07-16 15:08 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Notepad++ 2012-07-15 00:49 . 2012-07-15 00:49 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\7-Zip 2012-07-15 00:23 . 2012-06-25 18:58 17936 โ€”-a-w- c:\windows\system32\nitrolocalui2.dll 2012-07-15 00:23 . 2012-06-25 18:58 29712 โ€”-a-w- c:\windows\system32\nitrolocalmon2.dll 2012-07-15 00:22 . 2012-07-15 00:22 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Common Files\Nitro PDF 2012-07-15 00:22 . 2012-07-15 00:22 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\Nitro PDF 2012-07-15 00:19 . 2012-07-15 00:19 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Nitro PDF 2012-07-15 00:18 . 2011-02-28 22:37 95008 โ€”-a-w- c:\windows\system32\Primomonnt.dll 2012-07-13 00:24 . 2012-07-13 00:24 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\SysWow64\Wat 2012-07-13 00:24 . 2012-07-13 00:24 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\system32\Wat 2012-07-12 21:23 . 2012-07-12 21:23 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\regid.1986-12.com.adobe 2012-07-12 19:59 . 2012-07-12 19:59 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Adobe Story 2012-07-12 19:58 . 2012-07-12 19:58 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\My Company Name 2012-07-12 16:30 . 2012-07-03 17:46 24904 โ€”-a-w- c:\windows\system32\drivers\mbam.sys 2012-07-12 01:42 . 2012-07-12 01:42 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\EA Core 2012-07-12 00:47 . 2012-07-12 00:45 447752 โ€”-a-w- c:\windows\SysWow64\vp6vfw.dll 2012-07-12 00:46 . 2012-07-12 00:46 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Microsoft WSE 2012-07-11 16:18 . 2012-07-12 08:18 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Origin Games 2012-07-11 16:18 . 2012-07-13 01:01 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Origin 2012-07-11 16:17 . 2012-07-11 16:17 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Electronic Arts 2012-07-11 16:17 . 2012-07-11 16:18 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Origin 2012-07-11 15:36 . 2012-07-11 15:36 159744 โ€”-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 โ€”-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 โ€”-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 โ€”-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 โ€”-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 โ€”-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll 2012-07-11 15:36 . 2012-07-11 15:36 159744 โ€”-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll 2012-07-11 15:36 . 2012-07-11 15:36 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\QuickTime 2012-07-11 15:36 . 2012-07-11 15:36 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Apple Computer 2012-07-11 15:35 . 2012-07-11 15:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Apple Software Update 2012-07-11 15:35 . 2012-07-11 15:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Apple 2012-07-11 15:26 . 2012-07-30 14:45 426184 โ€”-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-11 14:21 . 2012-07-11 14:21 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Amazon 2012-07-11 14:02 . 2012-07-11 14:02 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\Skype 2012-07-11 13:44 . 2012-07-11 13:44 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\PeaZip 2012-07-10 18:42 . 2012-06-12 03:08 3148800 โ€”-a-w- c:\windows\system32\win32k.sys 2012-07-10 18:34 . 2012-07-10 18:34 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\MSXML 4.0 2012-07-10 18:23 . 2012-07-03 07:19 59701280 โ€”-a-w- c:\windows\system32\MRT.exe 2012-07-10 18:08 . 2012-05-04 11:00 366592 โ€”-a-w- c:\windows\system32\qdvd.dll 2012-07-10 18:08 . 2012-05-04 09:59 514560 โ€”-a-w- c:\windows\SysWow64\qdvd.dll 2012-07-10 17:35 . 2012-07-10 17:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Dell Support Center 2012-07-10 15:33 . 2011-03-12 12:08 1465344 โ€”-a-w- c:\windows\system32\XpsPrint.dll 2012-07-10 15:32 . 2011-12-16 08:46 634880 โ€”-a-w- c:\windows\system32\msvcrt.dll 2012-07-10 15:21 . 2012-02-17 06:38 1031680 โ€”-a-w- c:\windows\system32\rdpcore.dll 2012-07-10 15:21 . 2012-02-17 05:34 826880 โ€”-a-w- c:\windows\SysWow64\rdpcore.dll 2012-07-10 15:21 . 2012-02-17 04:57 23552 โ€”-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-07-10 15:16 . 2012-06-02 22:19 2428952 โ€”-a-w- c:\windows\system32\wuaueng.dll 2012-07-10 15:16 . 2012-06-02 22:19 57880 โ€”-a-w- c:\windows\system32\wuauclt.exe 2012-07-10 15:16 . 2012-06-02 22:19 44056 โ€”-a-w- c:\windows\system32\wups2.dll 2012-07-10 15:16 . 2012-06-02 22:15 2622464 โ€”-a-w- c:\windows\system32\wucltux.dll 2012-07-10 15:16 . 2012-06-02 22:19 38424 โ€”-a-w- c:\windows\system32\wups.dll 2012-07-10 15:16 . 2012-06-02 22:19 701976 โ€”-a-w- c:\windows\system32\wuapi.dll 2012-07-10 15:16 . 2012-06-02 22:15 99840 โ€”-a-w- c:\windows\system32\wudriver.dll 2012-07-10 15:16 . 2012-06-02 19:19 186752 โ€”-a-w- c:\windows\system32\wuwebv.dll 2012-07-10 15:16 . 2012-06-02 19:15 36864 โ€”-a-w- c:\windows\system32\wuapp.exe 2012-07-07 21:28 . 2012-07-07 21:28 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Microsoft Synchronization Services 2012-07-07 21:27 . 2012-07-07 21:27 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Microsoft Sync Framework 2012-07-07 21:26 . 2012-07-07 21:26 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Microsoft Visual Studio 8 2012-07-07 21:26 . 2012-07-07 21:26 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Microsoft Office 2012-07-07 21:26 . 2012-07-07 21:26 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Microsoft Analysis Services 2012-07-07 21:25 . 2012-07-10 18:43 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Microsoft Help 2012-07-07 21:25 . 2012-07-07 21:25 โ€”โ€”โ€“ dโ€”โ€“r- C:\MSOCache 2012-07-07 16:51 . 2012-07-07 16:51 560184 โ€”-a-w- c:\windows\system32\drivers\sptd.sys 2012-07-07 16:50 . 2012-07-07 16:51 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\DAEMON Tools Lite 2012-07-07 16:10 . 2012-07-07 21:15 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\DAEMON Tools Lite 2012-07-07 02:18 . 2012-07-07 02:18 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Malwarebytes 2012-07-07 02:14 . 2012-07-07 02:14 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Pictus 2012-07-07 00:42 . 2012-07-07 00:42 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Adobe Reader 64-bit fixes 2012-07-07 00:00 . 2012-07-07 00:00 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\PCDr 2012-07-06 21:13 . 2012-07-08 18:11 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Lotus 2012-07-06 07:06 . 2012-07-28 20:54 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Sheila 2012-07-06 06:04 . 2012-07-06 06:36 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\SMINST . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-30 14:45 . 2012-03-08 09:21 70344 โ€”-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-10 16:45 . 2010-06-24 17:33 19736 โ€”-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-07-06 02:06 . 2012-03-08 09:41 687544 โ€”-a-w- c:\windows\SysWow64\deployJava1.dll 2012-06-11 18:17 . 2012-06-11 18:17 71680 โ€”-a-w- c:\windows\system32\frapsv64.dll 2012-06-11 18:17 . 2012-06-11 18:17 65536 โ€”-a-w- c:\windows\SysWow64\frapsvid.dll 2012-05-25 21:13 . 2012-03-08 10:46 162224 โ€”-a-w- c:\windows\system32\mfevtps.exe . . ((((((((((((((((((((((((((((( SnapShot@2012-07-30_04.08.58 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 04:54 . 2012-07-30 05:06 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-07-30 04:08 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 05:10 . 2012-07-30 05:05 38242 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin - 2012-07-06 07:08 . 2012-07-30 03:59 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2012-07-06 07:08 . 2012-07-30 14:47 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-07-06 07:08 . 2012-07-30 03:59 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-07-06 07:08 . 2012-07-30 14:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-07-30 14:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-07-30 03:59 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-07-06 15:47 . 2012-07-30 05:05 7344 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2450799959-646583983-317965361-1000_UserData.bin - 2012-07-30 04:05 . 2012-07-30 04:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-07-30 05:03 . 2012-07-30 05:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-07-30 05:03 . 2012-07-30 05:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-07-30 04:05 . 2012-07-30 04:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-07-30 14:45 . 2012-07-30 14:45 686792 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_268_Plugin.exe + 2012-07-11 15:26 . 2012-07-30 14:45 250056 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe + 2009-07-14 04:54 . 2012-07-30 05:06 966656 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-07-14 04:54 . 2012-07-30 04:08 966656 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2012-07-07 02:48 . 2012-07-30 14:42 256736 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin + 2012-07-06 15:45 . 2012-07-30 09:04 281370 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin + 2009-07-14 02:36 . 2012-07-30 14:45 660318 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2012-07-30 03:54 660318 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-07-30 14:45 121214 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2012-07-30 03:54 121214 c:\windows\system32\perfc009.dat + 2012-07-30 14:45 . 2012-07-30 14:45 417992 c:\windows\system32\Macromed\Flash\FlashUtil64_11_3_300_268_Plugin.exe + 2009-07-14 05:01 . 2012-07-30 05:02 529016 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2012-07-30 04:04 529016 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2012-07-30 14:45 . 2012-07-30 14:45 9465032 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll + 2012-07-30 14:45 . 2012-07-30 14:45 1536712 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe - 2009-07-14 04:54 . 2012-07-30 04:08 2015232 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-07-30 05:06 2015232 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-07-30 14:45 . 2012-07-30 14:45 12315336 c:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll + 2012-07-06 07:43 . 2012-07-30 05:02 41074744 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2450799959-646583983-317965361-1000-8192.dat - 2012-07-06 07:43 . 2012-07-30 04:04 41074744 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2450799959-646583983-317965361-1000-8192.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942] "Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528] "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112] "Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160] "NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2011-12-31 66872] "AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-11-03 957440] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] . c:\users\Sheila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 DellDigitalDelivery;Dell Digital Delivery Service;c:\program files (x86)\Dell Digital Delivery\DeliveryService.exe [2011-10-26 162816] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944] R3 AMPPALP;Intelยฎ Centrinoยฎ Wireless Bluetoothยฎ 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-10-19 195072] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-02-27 158976] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-05-17 34200] R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2011-03-08 224704] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-11-01 340240] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-02 250984] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 TurboBoost;Intelยฎ Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-07-13 1255736] R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928] S2 AMPPALR3;Intelยฎ Centrinoยฎ Wireless Bluetoothยฎ 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-10-19 661504] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-05-12 249648] S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-10-18 936272] S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-10-18 1001808] S2 BTHSSecurityMgr;Intelยฎ Centrinoยฎ Wireless Bluetoothยฎ 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-10-21 135440] S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe [2011-05-12 200320] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-28 249936] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-05-25 210616] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-05-25 162224] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400] S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-06-25 216080] S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-09-22 1692480] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120] S2 UNS;Intelยฎ Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe [2010-12-21 2656280] S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760] S3 AMPPAL;Intelยฎ Centrinoยฎ Wireless Bluetoothยฎ 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-10-19 195072] S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-10-18 1354064] S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-08-29 53760] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-11-15 327168] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096] S3 CxUtilSvc;CxUtilSvc;c:\program files\Conexant\SA3\CxUtilSvc.exe [2011-08-12 109184] S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-12-09 60416] S3 IntcDAud;Intelยฎ Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-05-17 25496] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2011-03-23 77936] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904] S3 MCfilt;MCfilt;c:\windows\system32\drivers\MCfilt64.sys [2010-12-09 32344] S3 MEIx64;Intelยฎ Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296] S3 NETwNs64;___ Intelยฎ Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-12-02 8615936] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-09-14 95744] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-09-14 212992] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . โ€” Other Services/Drivers In Memory โ€” . *Deregistered* - mfeavfk01 . Contents of the 'Scheduled Tasks' folder . 2012-07-12 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\Dell Support Center\uaclauncher.exe [2012-05-22 07:16] . 2012-07-30 c:\windows\Tasks\SystemToolsDailyTest.job - c:\program files\Dell Support Center\uaclauncher.exe [2012-05-22 07:16] . . โ€”โ€”โ€” X64 Entries โ€”โ€”โ€”โ€“ . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-01 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-01 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-01 416024] "SmartAudio"="c:\program files\CONEXANT\SA3\SACpl.exe" [2011-08-01 1574016] "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-11-01 1935120] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-10-18 10357008] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608] "DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-11-03 2190704] . โ€”โ€”- Supplementary Scan โ€”โ€”- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://xfinity.comcast.net/?cid=insDate07202012 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download with &Media Finder - c:\program files (x86)\Media Finder\hook.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Sheila\AppData\Roaming\Mozilla\Firefox\Profiles\rdj6rf1t.default\ FF - prefs.js: browser.search.selectedEngine - XFINITY FF - prefs.js: browser.startup.homepage - www.google.com . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) . . . โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€” . [HKEY_USERS\S-1-5-21-2450799959-646583983-317965361-1000\Software\SecuROM\License information*] "datasecu"=hex:a7,e2,39,a5,10,e6,57,14,93,e1,fe,02,76,71,9c,c2,02,2b,67,26,46, 2e,c8,9f,80,17,e7,5d,ec,6d,6d,3f,8f,80,57,d1,6f,e7,4f,64,dd,fd,ae,17,63,25,\ "rkeysecu"=hex:6c,89,26,1e,ba,8e,8d,cc,46,64,d9,c2,1d,f8,13,71 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-07-30 11:01:25 ComboFix-quarantined-files.txt 2012-07-30 15:01 ComboFix2.txt 2012-07-30 04:18 . Pre-Run: 297,455,407,104 bytes free Post-Run: 297,396,871,168 bytes free . - - End Of File - - F6295041B85BB092230951F639ADD8FB
I'm not sure what is going on with FlashPlayer. I know that having multiple flashplayer plugins is normal in Chromeโ€ฆ but I don't think it is on other browsers. If this gives you any troubleโ€ฆ I suggest you seek help from the Tech Team in the Windows Forum. They know much more about this than I do.

Meanwhile, let's clean you up. :D

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
If combofix is still on your desktopโ€ฆ then go ahead and try running the uninstall routine. If it's not thereโ€ฆ or if it fails again, go ahead and run the cleanup routine in OTL.
Went ahead and ran OTL clean up. Computer re-started. I have a question about additional protection. I want to get rid of McAfee and get Outpost Firewall. I already have the pro version of Malwarebytes. Do I still need a spyware protection as an added layer, or are those together sufficient? Oh, I will be using the mvps hosts files too.
Well in that case, it looks like I am all clear. I truly appreciate the help. You were literally an answer to my prayer. Thank you for all your help. :D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI