Great.
Let's see if we can get an online scan. Be prepared as this will probably take hours to complete.
Go
here to run an online scanner from
ESET.
Turn off the real time scanner of any existing antivirus program while performing the online scan Tick the box next to YES, I accept the Terms of Use. Click Start When asked, allow the activeX control to install Click Start Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked. Click on Advanced Settings, ensure the options Scan for potentially unwanted applications , Scan for potentially unsafe applications , and Enable Anti-Stealth Technology are ticked. Click Scan Wait for the scan to finish When the scan completes, press the LIST OF THREATS FOUND button Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop Include the contents of this report in your next reply. Press the BACK button. Press Finish
A window came up after I finished the scan. See attachment.
Scan Results
C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe a variant of Win32/HiddenStart.A application
C:\Users\Sheila\Documents\Downloads\InternationalPrimoPDF.exe Win32/OpenCandy application
C:\Users\Sheila\Documents\Downloads\KeyFinderInstaller.exe Win32/OpenCandy application
C:\Users\Sheila\Documents\Downloads\knit_visualizer.rar_downloader_224.exe a variant of Win32/ExpressFiles application
C:\Users\Sheila\Documents\My Programs\DTLite4454-0315.exe Win32/OpenCandy application
C:\Users\Sheila\Documents\My Programs\InternationalPrimoPDF.exe Win32/OpenCandy application
Go ahead and cancel that window if you haven't yet. We got the report so we don't really care about the warning anymore.
COMBOFIX-Script
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Then give it a bit of a test drive and let me know what issues you are still having.
Control of internet functions have returned. Definite speed improvement.
The firewall is up and running. I can turn it off and on as I please. The advanced settings have reappeared.
Downloads window show up and function. No more tiny little boxes.
No more blank windows when opening files.
All functions and menus show up in start menu as they should.
Unicorn horns are properly sharpened and dog barking is at the proper sound level (my game is running right, no freezing or minimizing to bar)
I do however have two FlashPlayerPlugin_11_3_300_268.exe running in task manager now.
ComboFix 12-07-29.02 - Sheila 07/30/2012 10:54:09.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6031.4440 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Sheila\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\program files (x86)\Dell DataSafe Local Backup\hstart.exe"
"c:\users\Sheila\Documents\Downloads\InternationalPrimoPDF.exe"
"c:\users\Sheila\Documents\Downloads\KeyFinderInstaller.exe"
"c:\users\Sheila\Documents\Downloads\knit_visualizer.rar_downloader_224.exe"
"c:\users\Sheila\Documents\My Programs\DTLite4454-0315.exe"
"c:\users\Sheila\Documents\My Programs\InternationalPrimoPDF.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Dell DataSafe Local Backup\hstart.exe
c:\users\Sheila\Documents\Downloads\InternationalPrimoPDF.exe
c:\users\Sheila\Documents\Downloads\KeyFinderInstaller.exe
c:\users\Sheila\Documents\Downloads\knit_visualizer.rar_downloader_224.exe
c:\users\Sheila\Documents\My Programs\DTLite4454-0315.exe
c:\users\Sheila\Documents\My Programs\InternationalPrimoPDF.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-06-28 to 2012-07-30 )))))))))))))))))))))))))))))))
.
.
2012-07-30 14:59 . 2012-07-30 14:59 โโโ dโโw- c:\users\Default\AppData\Local\temp
2012-07-25 03:55 . 2012-07-25 03:55 โโโ d-shโw- c:\windows\SysWow64\%APPDATA%
2012-07-25 02:40 . 2012-07-25 02:40 โโโ dโโw- c:\programdata\FLEXnet
2012-07-23 01:40 . 2012-07-23 01:40 โโโ dโโw- c:\program files\s3pe
2012-07-22 22:58 . 2012-07-22 22:58 โโโ dโโw- c:\program files (x86)\Common Files\Control Panels
2012-07-22 22:55 . 2012-07-22 22:55 โโโ dโโw- c:\programdata\ALM
2012-07-22 22:53 . 2007-02-20 20:04 190696 โ-a-w- c:\windows\SysWow64\NPSWF32_FlashUtil.exe
2012-07-22 22:53 . 2007-02-20 20:04 2463976 โ-a-w- c:\windows\SysWow64\NPSWF32.dll
2012-07-22 22:49 . 2012-07-22 22:49 โโโ dโโw- c:\windows\SysWow64\spool
2012-07-22 22:48 . 2012-07-22 22:48 โโโ dโโw- c:\program files (x86)\Bonjour
2012-07-22 12:42 . 2012-07-22 12:42 โโโ dโโw- c:\program files\Blender Foundation
2012-07-22 12:32 . 2012-07-29 17:15 โโโ dโโw- c:\program files (x86)\MilkShape 3D 1.8.5
2012-07-22 01:57 . 2012-07-22 01:57 โโโ dโโw- c:\program files\Microsoft Silverlight
2012-07-20 23:06 . 2012-07-20 23:06 โโโ dโโw- c:\program files (x86)\Oracle
2012-07-20 23:03 . 2012-07-06 02:06 772544 โ-a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-07-20 18:01 . 2012-07-20 18:01 โโโ dโโw- c:\windows\Sun
2012-07-19 20:28 . 2012-05-25 21:09 29312 โ-a-w- c:\program files (x86)\Mozilla Firefox\ScriptFF.dll
2012-07-19 19:52 . 2012-07-19 19:52 โโโ dโโw- c:\program files (x86)\Mozilla Maintenance Service
2012-07-19 19:52 . 2012-07-14 00:17 136672 โ-a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2012-07-19 00:23 . 2012-07-19 00:23 โโโ dโโw- c:\program files (x86)\Bandicam
2012-07-19 00:23 . 2012-07-19 00:23 โโโ dโโw- c:\program files (x86)\BandiMPEG1
2012-07-16 15:08 . 2012-07-16 15:08 โโโ dโโw- c:\program files (x86)\Notepad++
2012-07-15 00:49 . 2012-07-15 00:49 โโโ dโโw- c:\program files\7-Zip
2012-07-15 00:23 . 2012-06-25 18:58 17936 โ-a-w- c:\windows\system32\nitrolocalui2.dll
2012-07-15 00:23 . 2012-06-25 18:58 29712 โ-a-w- c:\windows\system32\nitrolocalmon2.dll
2012-07-15 00:22 . 2012-07-15 00:22 โโโ dโโw- c:\program files\Common Files\Nitro PDF
2012-07-15 00:22 . 2012-07-15 00:22 โโโ dโโw- c:\program files (x86)\Common Files\Nitro PDF
2012-07-15 00:19 . 2012-07-15 00:19 โโโ dโโw- c:\programdata\Nitro PDF
2012-07-15 00:18 . 2011-02-28 22:37 95008 โ-a-w- c:\windows\system32\Primomonnt.dll
2012-07-13 00:24 . 2012-07-13 00:24 โโโ dโโw- c:\windows\SysWow64\Wat
2012-07-13 00:24 . 2012-07-13 00:24 โโโ dโโw- c:\windows\system32\Wat
2012-07-12 21:23 . 2012-07-12 21:23 โโโ dโโw- c:\programdata\regid.1986-12.com.adobe
2012-07-12 19:59 . 2012-07-12 19:59 โโโ dโโw- c:\program files (x86)\Adobe Story
2012-07-12 19:58 . 2012-07-12 19:58 โโโ dโโw- c:\program files (x86)\My Company Name
2012-07-12 16:30 . 2012-07-03 17:46 24904 โ-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-12 01:42 . 2012-07-12 01:42 โโโ dโโw- c:\programdata\EA Core
2012-07-12 00:47 . 2012-07-12 00:45 447752 โ-a-w- c:\windows\SysWow64\vp6vfw.dll
2012-07-12 00:46 . 2012-07-12 00:46 โโโ dโโw- c:\program files (x86)\Microsoft WSE
2012-07-11 16:18 . 2012-07-12 08:18 โโโ dโโw- c:\program files (x86)\Origin Games
2012-07-11 16:18 . 2012-07-13 01:01 โโโ dโโw- c:\programdata\Origin
2012-07-11 16:17 . 2012-07-11 16:17 โโโ dโโw- c:\programdata\Electronic Arts
2012-07-11 16:17 . 2012-07-11 16:18 โโโ dโโw- c:\program files (x86)\Origin
2012-07-11 15:36 . 2012-07-11 15:36 159744 โ-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-07-11 15:36 . 2012-07-11 15:36 159744 โ-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-07-11 15:36 . 2012-07-11 15:36 159744 โ-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-07-11 15:36 . 2012-07-11 15:36 159744 โ-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-07-11 15:36 . 2012-07-11 15:36 159744 โ-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-07-11 15:36 . 2012-07-11 15:36 159744 โ-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-07-11 15:36 . 2012-07-11 15:36 159744 โ-a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-07-11 15:36 . 2012-07-11 15:36 โโโ dโโw- c:\program files (x86)\QuickTime
2012-07-11 15:36 . 2012-07-11 15:36 โโโ dโโw- c:\programdata\Apple Computer
2012-07-11 15:35 . 2012-07-11 15:35 โโโ dโโw- c:\program files (x86)\Apple Software Update
2012-07-11 15:35 . 2012-07-11 15:35 โโโ dโโw- c:\programdata\Apple
2012-07-11 15:26 . 2012-07-30 14:45 426184 โ-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-11 14:21 . 2012-07-11 14:21 โโโ dโโw- c:\program files (x86)\Amazon
2012-07-11 14:02 . 2012-07-11 14:02 โโโ dโโw- c:\program files (x86)\Common Files\Skype
2012-07-11 13:44 . 2012-07-11 13:44 โโโ dโโw- c:\program files (x86)\PeaZip
2012-07-10 18:42 . 2012-06-12 03:08 3148800 โ-a-w- c:\windows\system32\win32k.sys
2012-07-10 18:34 . 2012-07-10 18:34 โโโ dโโw- c:\program files (x86)\MSXML 4.0
2012-07-10 18:23 . 2012-07-03 07:19 59701280 โ-a-w- c:\windows\system32\MRT.exe
2012-07-10 18:08 . 2012-05-04 11:00 366592 โ-a-w- c:\windows\system32\qdvd.dll
2012-07-10 18:08 . 2012-05-04 09:59 514560 โ-a-w- c:\windows\SysWow64\qdvd.dll
2012-07-10 17:35 . 2012-07-10 17:35 โโโ dโโw- c:\program files\Dell Support Center
2012-07-10 15:33 . 2011-03-12 12:08 1465344 โ-a-w- c:\windows\system32\XpsPrint.dll
2012-07-10 15:32 . 2011-12-16 08:46 634880 โ-a-w- c:\windows\system32\msvcrt.dll
2012-07-10 15:21 . 2012-02-17 06:38 1031680 โ-a-w- c:\windows\system32\rdpcore.dll
2012-07-10 15:21 . 2012-02-17 05:34 826880 โ-a-w- c:\windows\SysWow64\rdpcore.dll
2012-07-10 15:21 . 2012-02-17 04:57 23552 โ-a-w- c:\windows\system32\drivers\tdtcp.sys
2012-07-10 15:16 . 2012-06-02 22:19 2428952 โ-a-w- c:\windows\system32\wuaueng.dll
2012-07-10 15:16 . 2012-06-02 22:19 57880 โ-a-w- c:\windows\system32\wuauclt.exe
2012-07-10 15:16 . 2012-06-02 22:19 44056 โ-a-w- c:\windows\system32\wups2.dll
2012-07-10 15:16 . 2012-06-02 22:15 2622464 โ-a-w- c:\windows\system32\wucltux.dll
2012-07-10 15:16 . 2012-06-02 22:19 38424 โ-a-w- c:\windows\system32\wups.dll
2012-07-10 15:16 . 2012-06-02 22:19 701976 โ-a-w- c:\windows\system32\wuapi.dll
2012-07-10 15:16 . 2012-06-02 22:15 99840 โ-a-w- c:\windows\system32\wudriver.dll
2012-07-10 15:16 . 2012-06-02 19:19 186752 โ-a-w- c:\windows\system32\wuwebv.dll
2012-07-10 15:16 . 2012-06-02 19:15 36864 โ-a-w- c:\windows\system32\wuapp.exe
2012-07-07 21:28 . 2012-07-07 21:28 โโโ dโโw- c:\program files (x86)\Microsoft Synchronization Services
2012-07-07 21:27 . 2012-07-07 21:27 โโโ dโโw- c:\program files (x86)\Microsoft Sync Framework
2012-07-07 21:26 . 2012-07-07 21:26 โโโ dโโw- c:\program files (x86)\Microsoft Visual Studio 8
2012-07-07 21:26 . 2012-07-07 21:26 โโโ dโโw- c:\program files\Microsoft Office
2012-07-07 21:26 . 2012-07-07 21:26 โโโ dโโw- c:\program files (x86)\Microsoft Analysis Services
2012-07-07 21:25 . 2012-07-10 18:43 โโโ dโโw- c:\programdata\Microsoft Help
2012-07-07 21:25 . 2012-07-07 21:25 โโโ dโโr- C:\MSOCache
2012-07-07 16:51 . 2012-07-07 16:51 560184 โ-a-w- c:\windows\system32\drivers\sptd.sys
2012-07-07 16:50 . 2012-07-07 16:51 โโโ dโโw- c:\program files (x86)\DAEMON Tools Lite
2012-07-07 16:10 . 2012-07-07 21:15 โโโ dโโw- c:\programdata\DAEMON Tools Lite
2012-07-07 02:18 . 2012-07-07 02:18 โโโ dโโw- c:\programdata\Malwarebytes
2012-07-07 02:14 . 2012-07-07 02:14 โโโ dโโw- c:\program files\Pictus
2012-07-07 00:42 . 2012-07-07 00:42 โโโ dโโw- c:\program files (x86)\Adobe Reader 64-bit fixes
2012-07-07 00:00 . 2012-07-07 00:00 โโโ dโโw- c:\programdata\PCDr
2012-07-06 21:13 . 2012-07-08 18:11 โโโ dโโw- c:\users\Lotus
2012-07-06 07:06 . 2012-07-28 20:54 โโโ dโโw- c:\users\Sheila
2012-07-06 06:04 . 2012-07-06 06:36 โโโ dโโw- c:\windows\SMINST
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-30 14:45 . 2012-03-08 09:21 70344 โ-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-10 16:45 . 2010-06-24 17:33 19736 โ-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-07-06 02:06 . 2012-03-08 09:41 687544 โ-a-w- c:\windows\SysWow64\deployJava1.dll
2012-06-11 18:17 . 2012-06-11 18:17 71680 โ-a-w- c:\windows\system32\frapsv64.dll
2012-06-11 18:17 . 2012-06-11 18:17 65536 โ-a-w- c:\windows\SysWow64\frapsvid.dll
2012-05-25 21:13 . 2012-03-08 10:46 162224 โ-a-w- c:\windows\system32\mfevtps.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-30_04.08.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:54 . 2012-07-30 05:06 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54 . 2012-07-30 04:08 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 05:10 . 2012-07-30 05:05 38242 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2012-07-06 07:08 . 2012-07-30 03:59 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-07-06 07:08 . 2012-07-30 14:47 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-07-06 07:08 . 2012-07-30 03:59 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-07-06 07:08 . 2012-07-30 14:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-30 14:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-07-30 03:59 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-07-06 15:47 . 2012-07-30 05:05 7344 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2450799959-646583983-317965361-1000_UserData.bin
- 2012-07-30 04:05 . 2012-07-30 04:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-07-30 05:03 . 2012-07-30 05:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-07-30 05:03 . 2012-07-30 05:03 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-07-30 04:05 . 2012-07-30 04:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-07-30 14:45 . 2012-07-30 14:45 686792 c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_268_Plugin.exe
+ 2012-07-11 15:26 . 2012-07-30 14:45 250056 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2009-07-14 04:54 . 2012-07-30 05:06 966656 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-07-30 04:08 966656 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-07-07 02:48 . 2012-07-30 14:42 256736 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2012-07-06 15:45 . 2012-07-30 09:04 281370 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-07-14 02:36 . 2012-07-30 14:45 660318 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-07-30 03:54 660318 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-07-30 14:45 121214 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-07-30 03:54 121214 c:\windows\system32\perfc009.dat
+ 2012-07-30 14:45 . 2012-07-30 14:45 417992 c:\windows\system32\Macromed\Flash\FlashUtil64_11_3_300_268_Plugin.exe
+ 2009-07-14 05:01 . 2012-07-30 05:02 529016 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-07-30 04:04 529016 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-07-30 14:45 . 2012-07-30 14:45 9465032 c:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
+ 2012-07-30 14:45 . 2012-07-30 14:45 1536712 c:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_268.exe
- 2009-07-14 04:54 . 2012-07-30 04:08 2015232 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-07-30 05:06 2015232 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2012-07-30 14:45 . 2012-07-30 14:45 12315336 c:\windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll
+ 2012-07-06 07:43 . 2012-07-30 05:02 41074744 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2450799959-646583983-317965361-1000-8192.dat
- 2012-07-06 07:43 . 2012-07-30 04:04 41074744 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-2450799959-646583983-317965361-1000-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2011-04-13 503942]
"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1675160]
"NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2011-12-31 66872]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-11-03 957440]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
c:\users\Sheila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 DellDigitalDelivery;Dell Digital Delivery Service;c:\program files (x86)\Dell Digital Delivery\DeliveryService.exe [2011-10-26 162816]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944]
R3 AMPPALP;Intelยฎ Centrinoยฎ Wireless Bluetoothยฎ 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-10-19 195072]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-02-27 158976]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-05-17 34200]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2011-03-08 224704]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-02-22 100912]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-14 113120]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-11-01 340240]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-02 250984]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 TurboBoost;Intelยฎ Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-07-13 1255736]
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-09-30 169408]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S2 AMPPALR3;Intelยฎ Centrinoยฎ Wireless Bluetoothยฎ 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-10-19 661504]
S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-05-12 249648]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-10-18 936272]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-10-18 1001808]
S2 BTHSSecurityMgr;Intelยฎ Centrinoยฎ Wireless Bluetoothยฎ 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-10-21 135440]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe [2011-05-12 200320]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-28 249936]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-05-25 210616]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-05-25 162224]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-06-25 216080]
S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-09-22 1692480]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120]
S2 UNS;Intelยฎ Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760]
S3 AMPPAL;Intelยฎ Centrinoยฎ Wireless Bluetoothยฎ 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-10-19 195072]
S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-10-18 1354064]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-08-29 53760]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-11-15 327168]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096]
S3 CxUtilSvc;CxUtilSvc;c:\program files\Conexant\SA3\CxUtilSvc.exe [2011-08-12 109184]
S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-12-09 60416]
S3 IntcDAud;Intelยฎ Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-05-17 25496]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2011-03-23 77936]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 MCfilt;MCfilt;c:\windows\system32\drivers\MCfilt64.sys [2010-12-09 32344]
S3 MEIx64;Intelยฎ Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296]
S3 NETwNs64;___ Intelยฎ Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-12-02 8615936]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-09-14 95744]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-09-14 212992]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
โ Other Services/Drivers In Memory โ
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-12 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-05-22 07:16]
.
2012-07-30 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-05-22 07:16]
.
.
โโโ X64 Entries โโโโ
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-01 168216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-01 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-01 416024]
"SmartAudio"="c:\program files\CONEXANT\SA3\SACpl.exe" [2011-08-01 1574016]
"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-11-01 1935120]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-10-18 10357008]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-11-03 2190704]
.
โโ- Supplementary Scan โโ-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://xfinity.comcast.net/?cid=insDate07202012
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Download with &Media Finder - c:\program files (x86)\Media Finder\hook.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
FF - ProfilePath - c:\users\Sheila\AppData\Roaming\Mozilla\Firefox\Profiles\rdj6rf1t.default\
FF - prefs.js: browser.search.selectedEngine - XFINITY
FF - prefs.js: browser.startup.homepage - www.google.com
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
โโโโโโโ LOCKED REGISTRY KEYS โโโโโโโ
.
[HKEY_USERS\S-1-5-21-2450799959-646583983-317965361-1000\Software\SecuROM\License information*]
"datasecu"=hex:a7,e2,39,a5,10,e6,57,14,93,e1,fe,02,76,71,9c,c2,02,2b,67,26,46,
2e,c8,9f,80,17,e7,5d,ec,6d,6d,3f,8f,80,57,d1,6f,e7,4f,64,dd,fd,ae,17,63,25,\
"rkeysecu"=hex:6c,89,26,1e,ba,8e,8d,cc,46,64,d9,c2,1d,f8,13,71
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-30 11:01:25
ComboFix-quarantined-files.txt 2012-07-30 15:01
ComboFix2.txt 2012-07-30 04:18
.
Pre-Run: 297,455,407,104 bytes free
Post-Run: 297,396,871,168 bytes free
.
- - End Of File - - F6295041B85BB092230951F639ADD8FB
I'm not sure what is going on with FlashPlayer. I know that having multiple flashplayer plugins is normal in Chromeโฆ but I don't think it is on other browsers. If this gives you any troubleโฆ I suggest you seek help from the Tech Team in the
Windows Forum . They know much more about this than I do.
Meanwhile, let's clean you up.
Log looks good
Time for some housekeeping Click START then RUN Now type ComboFix /Uninstall in the runbox and click OK . Note the space between the X and the U , it needs to be there. [external image: Posted Image]
The above procedure will :
Implement some cleanup procedures. Reset System Restore.
Double click on OTL to run it. Click on CleanUp! When done, you will be prompted to restart your computer. Please restart your computer.
Please re-enable any security that was disabled.
The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.
Please take time to read
Preventing Malware - Tools and Practices for Safe Computing . Very important information for your consideration is contained therein.
I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Also:
"How to prevent malware"
by miekiemoes
Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved.
This showed up. I think maybe McAfee did not turn off because it wanted me to view some scan result on the test download file. Do I run again?
If combofix is still on your desktopโฆ then go ahead and try running the uninstall routine.
If it's not thereโฆ or if it fails again, go ahead and run the cleanup routine in OTL.
Went ahead and ran OTL clean up. Computer re-started. I have a question about additional protection. I want to get rid of McAfee and get Outpost Firewall. I already have the pro version of Malwarebytes. Do I still need a spyware protection as an added layer, or are those together sufficient? Oh, I will be using the mvps hosts files too.
Malwarebytes' is your spyware protectionโฆ you need an Anti-Virus.
Microsoft Security Essentials is a good choice. It has a small footprint and good results. I've been pretty happy with it.
Well in that case, it looks like I am all clear. I truly appreciate the help. You were literally an answer to my prayer. Thank you for all your help.
You are very welcome.
Good Luck and Be Well.
Since this issue appears to be resolved โฆ this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.