This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

80000032.@ RootKit Virus [Solved]

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please run the following:

download Farbar Recovery Scan Tool and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to the disclaimer.

[*]Place a check next to List Drivers MD5 as well as the default check marks that are already there

[*]Press Scan button.

[*]FRST will let you know when the scan is complete and has written the FRST.txt to file, close out this message, then type the following into the search box:

services.exe
[*]now press the search button

[*]when the search is complete, search.txt will also be written to your USB

[*]type exit and reboot the computer normally

[*]please copy and paste both logs in your reply.(FRST.txt and Search.txt)

FRST—BEGIN Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 25-07-2012 01 Ran by [removed] at 29-07-2012 12:14:46 Running from E:\ Windows Vista ™ Home Premium Service Pack 1 (X86) OS Language: English(US) The current controlset is ControlSet001 ========================== Registry (Whitelisted) ============= HKLM\…\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [292208 2010-06-04] (Alps Electric Co., Ltd.) HKLM\…\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM\…\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe [3563520 2008-08-05] (Dell Inc.) HKLM\…\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2 [438403 2008-02-19] (Creative Technology Ltd.) HKLM\…\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m [1742064 2008-10-03] () HKLM\…\Run: [dldtmon.exe] "C:\Program Files\Dell V305\dldtmon.exe" [672424 2010-02-10] () HKLM\…\Run: [dldtamon] "C:\Program Files\Dell V305\dldtamon.exe" [16040 2010-02-10] () HKLM\…\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe [442460 2008-08-25] (IDT, Inc.) HKLM\…\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui [4273976 2012-07-03] (AVAST Software) HKLM\…\Run: [NPSStartup] [x] HKLM\…\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.) HKLM\…\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2011-10-09] (Apple Inc.) HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated) HKLM\…\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.) HKLM\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.) HKU\Day\…\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation) HKU\Day\…\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\Day\…\Run: [PlayNC Launcher] [x] HKU\Day\…\Run: [] [x] HKU\Day\…\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash [487424 2010-10-14] (Gadwin Systems, Inc) HKU\Day\…\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation) HKU\Day\…\Run: [Akamai NetSession Interface] "C:\Users\Day\AppData\Local\Akamai\netsession_win.exe" [4327744 2012-05-26] (Akamai Technologies, Inc) HKU\Day\…\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe /minimized [22459984 2011-12-12] (ooVoo LLC) HKU\Day\…\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [95576 2010-07-04] (Samsung Electronics Co., Ltd.) HKU\Day\…\Run: [dhnsg] "C:\Windows\System32\rundll32.exe" "C:\Users\Day\AppData\Roaming\dhnsg.dll",Node_AddChild [432640 2012-07-27] (M-Audio) HKU\Default\…\Run: [ooVoo] C\ooVoo.exe /minimized [x] HKU\Default User\…\Run: [ooVoo] C\ooVoo.exe /minimized [x] Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [X] Tcpip\Parameters: [DhcpNameServer] 192.168.254.254 Startup: C:\Users\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation) Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickSet.lnk ShortcutTarget: QuickSet.lnk -> C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.) Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) ================================ Services (Whitelisted) ================== 2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe [73728 2008-08-25] (Andrea Electronics Corporation) 2 avast! Antivirus; "C:\Program Files\Alwil Software\Avast5\AvastSvc.exe" [44808 2012-07-03] (AVAST Software) 2 dldt_device; C:\Windows\system32\dldtcoms.exe -service [594600 2009-07-09] ( ) 2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-09-23] (Stardock Corporation) 2 Eventlog; C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [21504 2008-01-20] (Microsoft Corporation) 2 FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [238952 2010-07-04] (Teruten) 3 GoToAssist; "C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe" Start=service [16680 2008-11-26] (Citrix Online, a division of Citrix Systems, Inc.) 2 gupdate1ca31469181a180; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [133104 2009-09-09] (Google Inc.) 2 LPDSVC; C:\Windows\System32\lpdsvc.dll [35328 2008-01-20] (Microsoft Corporation) 3 npggsvc; C:\Windows\system32\GameMon.des -service [3251520 2009-07-14] (INCA Internet Co., Ltd.) 2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) 3 sdAuxService; C:\Program Files\Spyware Doctor\pctsAuxs.exe [365280 2009-12-09] (PC Tools) 3 sdCoreService; C:\Program Files\Spyware Doctor\pctsSvc.exe [1141712 2010-01-18] (PC Tools) 2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe [225362 2008-08-25] (IDT, Inc.) 2 Akamai; c:\program files\common files\akamai/netsession_win_4f7fccd.dll [x] 4 NetMsmqActivator; "c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator [x] 4 NetPipeActivator; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x] 4 NetTcpActivator; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x] 4 NetTcpPortSharing; c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [x] ========================== Drivers (Whitelisted) ============= 2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [21256 2012-07-03] (AVAST Software) 2 aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [57656 2012-07-03] (AVAST Software) 1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [35928 2012-07-03] (AVAST Software) 1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [721000 2012-07-03] (AVAST Software) 1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [353688 2012-07-03] (AVAST Software) 1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [54232 2012-07-03] (AVAST Software) 3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2008-08-05] (Broadcom Corporation) 3 FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [36608 2010-06-14] () 3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [54784 2008-08-25] (ITE Tech. Inc. ) 3 k57nd60x; C:\Windows\System32\DRIVERS\k57nd60x.sys [203264 2008-08-25] (Broadcom Corporation) 3 mferkdk; C:\Windows\System32\drivers\mferkdk.sys [34248 2009-09-16] (McAfee, Inc.) 3 mfesmfk; C:\Windows\System32\drivers\mfesmfk.sys [40552 2009-09-16] (McAfee, Inc.) 3 nmwcdnsu; C:\Windows\System32\drivers\nmwcdnsu.sys [137344 2010-02-26] (Nokia) 3 nmwcdnsuc; C:\Windows\System32\drivers\nmwcdnsuc.sys [8320 2010-02-26] (Nokia) 3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-08] (Microsoft Corporation) 4 NWADI; C:\Windows\system32\drivers\nwadienum.sys [213504 2008-08-25] (Novatel Wireless Inc) 3 NWDellModem; C:\Windows\System32\DRIVERS\nwdelmdm.sys [166144 2008-08-25] (Novatel Wireless Inc.) 3 NWDellPort; C:\Windows\System32\DRIVERS\nwdelser.sys [166144 2008-08-25] (Novatel Wireless Inc.) 4 NWDellPort2; C:\Windows\system32\drivers\nwdelser2.sys [166144 2008-08-25] (Novatel Wireless Inc.) 3 OA001Ufd; C:\Windows\System32\DRIVERS\OA001Ufd.sys [144672 2008-09-04] (Creative Technology Ltd.) 3 OA001Vid; C:\Windows\System32\DRIVERS\OA001Vid.sys [277632 2008-09-04] (Creative Technology Ltd.) 0 PCTCore; C:\Windows\System32\drivers\PCTCore.sys [207280 2009-09-23] (PC Tools) 3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [350720 2010-03-31] (Realtek Semiconductor Corporation ) 0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-04-09] (Duplex Secure Ltd.) 3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [x] 3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x] 3 Lavasoft Kernexplorer; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [x] 3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x] 3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x] ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-07-29 12:14 - 2012-07-29 12:14 - 00000000 ____D C:\FRST 2012-07-29 04:55 - 2012-07-29 04:55 - 00038480 ____A C:\Users\Day\Desktop\Extras.Txt 2012-07-29 04:53 - 2012-07-29 04:53 - 00140956 ____A C:\Users\Day\Desktop\OTL.Txt 2012-07-29 04:21 - 2012-07-29 04:07 - 00597504 ____A (OldTimer Tools) C:\Users\Day\Desktop\OTL.exe 2012-07-27 09:46 - 2012-07-27 09:46 - 00432640 ____A (M-Audio) C:\Users\Day\AppData\Roaming\dhnsg.dll 2012-07-27 09:45 - 2012-07-28 14:57 - 00000000 ____D C:\Users\Day\AppData\Roaming\xsecva 2012-07-26 06:37 - 2012-07-26 06:38 - 00000000 ___HD C:\Users\Day\AppData\AppDataEx 2012-07-26 06:31 - 2012-07-26 06:39 - 00000000 ____D C:\EOSRebelPics 2012-07-26 06:29 - 2012-07-26 06:29 - 00000000 ____D C:\Users\Day\AppData\Local\CANON_INC 2012-07-11 23:14 - 2012-06-13 05:40 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-07-11 23:02 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-07-11 23:02 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-07-11 23:02 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-07-11 23:02 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-07-11 23:02 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-07-11 23:02 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-07-11 23:02 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-07-11 23:02 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-07-11 23:02 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-07-11 23:02 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-07-11 23:02 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-07-11 23:02 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-07-11 23:02 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-07-11 23:02 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-07-11 05:37 - 2012-06-08 09:47 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-07-11 05:37 - 2012-06-05 08:47 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-07-11 05:37 - 2012-06-05 08:47 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-07-11 05:37 - 2012-06-04 07:26 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-07-11 05:37 - 2012-06-01 16:04 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-07-11 05:37 - 2012-06-01 16:03 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-07-10 15:35 - 2012-07-10 15:35 - 09187801 ____A C:\Users\Day\Downloads\Attachments_2012_07_10.zip 2012-07-04 05:23 - 2012-07-04 05:23 - 00000000 ____D C:\Program Files\Xvid 2012-07-04 05:23 - 2011-05-30 05:42 - 00240640 ____A C:\Windows\System32\xvidvfw.dll 2012-07-04 05:23 - 2011-05-23 01:52 - 00153088 ____A C:\Windows\System32\xvid.ax 2012-07-04 05:23 - 2011-05-22 23:46 - 00645632 ____A C:\Windows\System32\xvidcore.dll ============ 3 Months Modified Files ======================== 2012-07-29 08:08 - 2006-11-02 05:01 - 00032540 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-07-29 08:08 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-07-29 08:08 - 2006-11-02 04:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2012-07-29 08:08 - 2006-11-02 04:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2012-07-29 07:49 - 2009-09-09 04:07 - 00000868 ____A C:\Windows\Tasks\Google Software Updater.job 2012-07-29 07:41 - 2009-09-09 04:23 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-07-29 07:40 - 2012-04-01 16:26 - 00014992 ____A C:\Windows\PFRO.log 2012-07-29 07:19 - 2012-04-01 08:14 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-07-29 07:09 - 2009-09-09 04:23 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-07-29 04:55 - 2012-07-29 04:55 - 00038480 ____A C:\Users\Day\Desktop\Extras.Txt 2012-07-29 04:53 - 2012-07-29 04:53 - 00140956 ____A C:\Users\Day\Desktop\OTL.Txt 2012-07-29 04:24 - 2006-11-02 02:33 - 00755732 ____A C:\Windows\System32\PerfStringBackup.INI 2012-07-29 04:20 - 2012-05-13 09:10 - 00001590 ____A C:\Windows\setupact.log 2012-07-29 04:18 - 2010-11-06 03:51 - 00002519 ____A C:\Users\Day\Desktop\HiJackThis.lnk 2012-07-29 04:07 - 2012-07-29 04:21 - 00597504 ____A (OldTimer Tools) C:\Users\Day\Desktop\OTL.exe 2012-07-28 21:35 - 2008-11-26 10:13 - 01185116 ____A C:\Windows\WindowsUpdate.log 2012-07-27 12:09 - 2012-01-29 06:52 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-07-27 09:46 - 2012-07-27 09:46 - 00432640 ____A (M-Audio) C:\Users\Day\AppData\Roaming\dhnsg.dll 2012-07-26 23:19 - 2012-04-01 08:14 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2012-07-26 23:19 - 2011-06-27 17:26 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2012-07-26 16:49 - 2010-11-05 01:35 - 00000370 ____A C:\Windows\Tasks\Ad-Aware Update (Weekly).job 2012-07-26 06:35 - 2009-09-23 12:21 - 00003416 ___AH C:\Users\Day\Desktop\ZbThumbnail.info 2012-07-14 14:12 - 2006-11-02 02:23 - 00002577 ____A C:\Windows\System32\config.nt 2012-07-14 08:47 - 2009-07-15 10:59 - 00001972 ____A C:\Users\Day\Documents\acct stuff.txt 2012-07-13 12:16 - 2009-07-15 12:00 - 00033792 ____A C:\Users\Day\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-07-12 10:11 - 2009-09-09 04:13 - 00001973 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2012-07-11 23:35 - 2006-11-02 04:47 - 00283960 ____A C:\Windows\System32\FNTCACHE.DAT 2012-07-11 23:03 - 2006-11-02 02:24 - 57442464 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe 2012-07-10 15:35 - 2012-07-10 15:35 - 09187801 ____A C:\Users\Day\Downloads\Attachments_2012_07_10.zip 2012-07-03 09:46 - 2011-03-29 14:30 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-07-03 08:21 - 2011-07-30 04:58 - 00721000 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys 2012-07-03 08:21 - 2010-10-12 17:38 - 00353688 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys 2012-07-03 08:21 - 2010-10-12 17:38 - 00057656 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys 2012-07-03 08:21 - 2010-10-12 17:38 - 00054232 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys 2012-07-03 08:21 - 2010-10-12 17:38 - 00035928 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr.sys 2012-07-03 08:21 - 2010-10-12 17:38 - 00021256 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys 2012-07-03 08:21 - 2010-10-12 17:37 - 00227648 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe 2012-07-03 08:21 - 2010-10-12 17:37 - 00041224 ____A (AVAST Software) C:\Windows\avastSS.scr 2012-06-13 15:33 - 2012-06-13 15:33 - 00036878 ____A C:\Users\Day\Desktop\Confirmation - FAFSA on the Web - Federal Student Aid Fall 2012.htm 2012-06-13 05:40 - 2012-07-11 23:14 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-06-09 11:30 - 2009-11-03 15:22 - 00003490 ____A C:\Users\Day\AppData\Roaming\wklnhst.dat 2012-06-08 09:47 - 2012-07-11 05:37 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-06-05 08:47 - 2012-07-11 05:37 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-06-05 08:47 - 2012-07-11 05:37 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-06-04 07:26 - 2012-07-11 05:37 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-06-02 14:19 - 2012-06-18 20:27 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 14:19 - 2012-06-18 20:27 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 14:19 - 2012-06-18 20:27 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 14:19 - 2012-06-18 20:26 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 14:19 - 2012-06-18 20:26 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 14:12 - 2012-06-18 20:27 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 14:12 - 2012-06-18 20:26 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 11:19 - 2012-06-18 20:26 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 11:12 - 2012-06-18 20:26 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-06-02 01:07 - 2012-07-11 23:02 - 12314624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-02 00:43 - 2012-07-11 23:02 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-02 00:33 - 2012-07-11 23:02 - 01800192 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-06-02 00:26 - 2012-07-11 23:02 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-02 00:25 - 2012-07-11 23:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-06-02 00:25 - 2012-07-11 23:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-02 00:23 - 2012-07-11 23:02 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-02 00:21 - 2012-07-11 23:02 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-02 00:20 - 2012-07-11 23:02 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-06-02 00:19 - 2012-07-11 23:02 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-02 00:19 - 2012-07-11 23:02 - 00716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-02 00:17 - 2012-07-11 23:02 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-02 00:16 - 2012-07-11 23:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-02 00:14 - 2012-07-11 23:02 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-01 16:04 - 2012-07-11 05:37 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-06-01 16:03 - 2012-07-11 05:37 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-05-31 08:25 - 2010-03-20 18:13 - 00237072 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe 2012-05-26 14:29 - 2012-05-26 14:29 - 00476960 ____A (Sun Microsystems, Inc.) C:\Windows\System32\npdeployJava1.dll 2012-05-26 14:29 - 2012-05-26 14:29 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaws.exe 2012-05-26 14:29 - 2012-05-26 14:29 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\javaw.exe 2012-05-26 14:29 - 2012-05-26 14:29 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\System32\java.exe 2012-05-26 14:29 - 2012-02-02 15:55 - 00472864 ____A (Sun Microsystems, Inc.) C:\Windows\System32\deployJava1.dll 2012-05-19 05:50 - 2012-05-19 05:50 - 00011837 ____A C:\Users\Day\Desktop\RIDGID - LSA Registration Details.htm 2012-05-13 09:10 - 2012-05-13 09:10 - 00000000 ____A C:\Windows\setuperr.log 2012-05-01 06:03 - 2012-06-13 15:52 - 00180736 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys ZeroAccess: C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde} C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\@ C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\L C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\n C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\L\00000004.@ C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz1470.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz1D2D.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz2018.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz21B.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz29BF.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz2AAA.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz2E03.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz2E91.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz2FCB.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3030.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3080.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz31C9.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz33BD.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz33BF.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz344.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz34D4.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3556.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz360F.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz364D.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz378C.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz37A2.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3916.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3EAA.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3EB8.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3FF3.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz42E.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz461D.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz4B81.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz4FA1.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz52AE.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz562C.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz573F.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz5C9E.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz6350.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz648.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz6973.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz6D7A.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz7250.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz741D.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz759C.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz778F.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz7A77.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz7A7D.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz7A94.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz800C.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz81FD.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz848D.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz8BD4.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz97BA.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz985C.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz98E9.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz98EA.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz9C70.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz9E75.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzA1EC.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzAD22.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzAD27.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzB144.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzB17C.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzBA1C.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzBA8B.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzBBD2.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzBD0C.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzBFB9.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzC771.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzCCC0.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzD01.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzD198.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzD1BF.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzD232.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzD3C4.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzDA12.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzDBA1.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzDD29.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzE26.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzE4A.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzE8C1.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzEC76.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzEEDA.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzF053.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzF3E5.tmp C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzFDB0.tmp ZeroAccess: C:\Users\Day\AppData\Local\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde} C:\Users\Day\AppData\Local\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\@ C:\Users\Day\AppData\Local\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\L C:\Users\Day\AppData\Local\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\n C:\Users\Day\AppData\Local\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!. C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ========================= Memory info ====================== Percentage of memory in use: 10% Total physical RAM: 4059.98 MB Available physical RAM: 3633.78 MB Total Pagefile: 3929.29 MB Available Pagefile: 3788.96 MB Total Virtual: 2047.88 MB Available Virtual: 1974.31 MB ======================= Partitions ========================= 1 Drive c: (OS) (Fixed) (Total:287.95 GB) (Free:163.56 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 3 Drive e: () (Removable) (Total:7.45 GB) (Free:0.85 GB) FAT32 4 Drive x: (RECOVERY) (Fixed) (Total:10 GB) (Free:4.85 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ———- ——- ——- — — Disk 0 Online 298 GB 0 B Disk 1 Online 7634 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 OEM 141 MB 32 KB Partition 2 Primary 10 GB 142 MB Partition 3 Primary 288 GB 10 GB ================================================================================ == Disk: 0 Partition 1 Type : DE Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 4 FAT Partition 141 MB Healthy Hidden ================================================================================ == Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 X RECOVERY NTFS Partition 10 GB Healthy Boot ================================================================================ == Disk: 0 Partition 3 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C OS NTFS Partition 288 GB Healthy ================================================================================ == Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 7633 MB 16 KB ================================================================================ == Disk: 1 Partition 1 Type : 0B Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 E FAT32 Removable 7633 MB Healthy ================================================================================ == ========================================================== Last Boot: 2012-07-29 07:47 ======================= End Of Log ========================== FRST — END SEARCH—BEGIN Farbar Recovery Scan Tool Version: 25-07-2012 01 Ran by [removed] at 2012-07-29 12:17:01 Running from E:\ ================== Search: "services.exe" =================== C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe [2009-09-18 04:23] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) D4E6D91C1349B7BFB3599A6ADA56851B C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe [2008-01-20 18:24] - [2008-01-20 18:24] - 0279040 ____A (Microsoft Corporation) 2B336AB6286D6C81FA02CBAB914E3C6C C:\Windows\System32\services.exe [2009-09-18 04:23] - [2009-04-10 22:27] - 0279552 ____A (Microsoft Corporation) 8737764F4FD36D6808EE80578409C843 === End Of Search === SEARCH—END
Please do the following:


Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste). Save it on the flashdrive as fixlist.txt

start
HKU\Day\…\Run: [] [x]
HKU\Day\…\Run: [dhnsg] "C:\Windows\System32\rundll32.exe" "C:\Users\Day\AppData\Roaming\dhnsg.dll",Node_AddChild [432640 2012-07-27] (M-Audio)
2012-07-27 09:46 - 2012-07-27 09:46 - 00432640 ____A (M-Audio) C:\Users\Day\AppData\Roaming\dhnsg.dll
2012-07-27 09:45 - 2012-07-28 14:57 - 00000000 ____D C:\Users\Day\AppData\Roaming\xsecva
C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}
C:\Users\Day\AppData\Local\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}
replace: C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe C:\Windows\System32\services.exe
end

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system

Now please enter System Recovery Options then select Command Prompt

Run FRST and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Reboot Normally.


NEXT


Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
FIXLOG—BEGIN
Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by [removed] at 2012-07-29 12:56:09 Run:1
Running from E:\

==============================================

HKEY_USERS\Day\Software\Microsoft\Windows\CurrentVersion\Run\\dhnsg Value deleted successfully.
C:\Users\Day\AppData\Roaming\dhnsg.dll moved successfully.
C:\Users\Day\AppData\Roaming\xsecva moved successfully.
C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde} moved successfully.
C:\Users\Day\AppData\Local\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde} moved successfully.
C:\Windows\System32\services.exe moved successfully.
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe copied successfully to C:\Windows\System32\services.exe

==== End of Fixlog ====
FIXLOG—END
COMBOFIX—BEGIN

ComboFix 12-07-29.02 - Day 07/29/2012 13:13:42.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3036.1822 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
C:\LHT2761.tmp
c:\programdata\SPL4624.tmp
c:\programdata\SPL8E3A.tmp
c:\programdata\SPL9A62.tmp
c:\programdata\SPLEBE7.tmp
c:\users\Day\AppData\Local\assembly\tmp
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome.manifest
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\background.html
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\browser.xul
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\crossrider.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\crossriderapi.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\dialog.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\facebox.css
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\facebox.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\b.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\bl.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\br.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\closelabel.gif
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\loading.gif
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\tl.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\tr.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\faye-browser-min.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\jquery-1.4.2.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\manage-apps-style.css
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\manage-apps.html
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\messaging.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\options.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\options.xul
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\push.html
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\search_dialog.xul
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\socialapi.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\update.html
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\utilityapi.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\workers_chain.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\defaults\preferences\prefs.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\install.rdf
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\locale\en-US\translations.dtd
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\button1.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\button2.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\button3.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\button4.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\button5.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\crossrider_statusbar.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\icon128.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\icon16.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\icon24.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\icon48.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\panelarrow-up.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\popup.css
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\popup.html
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\popup_binding.xml
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\skin.css
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\update.css
c:\users\Day\Documents\~WRL0001.tmp
c:\windows\assembly\GAC\Desktop.ini
c:\windows\SwSys1.bmp
c:\windows\SwSys2.bmp
.
.
((((((((((((((((((((((((( Files Created from 2012-06-28 to 2012-07-29 )))))))))))))))))))))))))))))))
.
.
2012-07-29 20:14 . 2012-07-29 20:14 ——– d—–w- C:\FRST
2012-07-29 17:23 . 2012-07-29 17:28 ——– d—–w- c:\users\Day\AppData\Local\temp
2012-07-26 14:31 . 2012-07-26 14:39 ——– d—–w- C:\EOSRebelPics
2012-07-26 14:29 . 2012-07-26 14:29 ——– d—–w- c:\users\Day\AppData\Local\CANON_INC
2012-07-12 07:14 . 2012-06-13 13:40 2047488 —-a-w- c:\windows\system32\win32k.sys
2012-07-11 13:37 . 2012-06-05 16:47 708608 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 13:37 . 2012-06-05 16:47 1401856 —-a-w- c:\windows\system32\msxml6.dll
2012-07-11 13:37 . 2012-06-05 16:47 1248768 —-a-w- c:\windows\system32\msxml3.dll
2012-07-11 13:37 . 2012-06-04 15:26 440704 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-11 13:37 . 2012-06-02 00:04 278528 —-a-w- c:\windows\system32\schannel.dll
2012-07-11 13:37 . 2012-06-02 00:03 204288 —-a-w- c:\windows\system32\ncrypt.dll
2012-07-04 13:23 . 2011-05-23 09:52 153088 —-a-w- c:\windows\system32\xvid.ax
2012-07-04 13:23 . 2011-05-23 07:46 645632 —-a-w- c:\windows\system32\xvidcore.dll
2012-07-04 13:23 . 2011-05-30 13:42 240640 —-a-w- c:\windows\system32\xvidvfw.dll
2012-07-04 13:23 . 2012-07-04 13:23 ——– d—–w- c:\program files\Xvid
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-27 07:19 . 2012-04-01 16:14 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-27 07:19 . 2011-06-28 01:26 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-03 17:46 . 2011-03-29 22:30 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-03 16:21 . 2010-10-13 01:38 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2011-07-30 12:58 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2010-10-13 01:38 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2010-10-13 01:38 353688 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2010-10-13 01:38 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-03 16:21 . 2010-10-13 01:38 57656 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-07-03 16:21 . 2010-10-13 01:37 41224 —-a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2010-10-13 01:37 227648 —-a-w- c:\windows\system32\aswBoot.exe
2012-06-29 08:44 . 2012-07-27 10:05 6891424 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F5B99034-0954-4DF4-892A-9471986FE45A}\mpengine.dll
2012-06-02 22:19 . 2012-06-19 04:27 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 04:27 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 04:26 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 04:26 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-19 04:27 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-19 04:27 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-19 04:26 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-02 19:19 . 2012-06-19 04:26 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-02 19:12 . 2012-06-19 04:26 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-05-31 16:25 . 2010-03-21 02:13 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-05-26 22:29 . 2012-05-26 22:29 476960 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-05-26 22:29 . 2012-02-02 23:55 472864 —-a-w- c:\windows\system32\deployJava1.dll
2012-05-01 14:03 . 2012-06-13 23:52 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn1\YTNavAssist.dll" [2011-03-16 214840]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2010-10-14 487424]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Akamai NetSession Interface"="c:\users\Day\AppData\Local\Akamai\netsession_win.exe" [2012-05-26 4327744]
"ooVoo.exe"="c:\program files\ooVoo\oovoo.exe" [2011-12-12 22459984]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-06-04 292208]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-08-05 3563520]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-02-19 438403]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2008-10-03 1742064]
"dldtmon.exe"="c:\program files\Dell V305\dldtmon.exe" [2010-02-10 672424]
"dldtamon"="c:\program files\Dell V305\dldtamon.exe" [2010-02-10 16040]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-08-25 442460]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-31 1616976]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-24 1295656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-11-27 00:51 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Day^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
path=c:\users\Day\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
backup=c:\windows\pss\Dell Dock.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 —-a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2008-03-11 18:44 16384 —-a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2010-09-02 14:26 672632 —-a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2010-04-18 03:21 2938552 —-a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-09-02 19:15 13351304 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
LPDService REG_MULTI_SZ LPDSVC
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2012-02-03 00:25 114176 —-a-w- c:\windows\System32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 07:19]
.
2012-07-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-09 14:45]
.
2012-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-09 12:10]
.
2012-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-09 12:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
TCP: DhcpNameServer = 192.168.254.254
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-PlayNC Launcher - (no file)
HKLM-Run-NPSStartup - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-29 13:26
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_4f7fccd.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe
c:\program files\Dell\DellDock\DockLogin.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dldtcoms.exe
c:\windows\system32\FsUsbExService.Exe
c:\windows\system32\WUDFHost.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Spybot - Search & Destroy\SDWinSec.exe
c:\program files\Dell V305\dldtMsdMon.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2012-07-29 13:35:18 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-29 17:35
.
Pre-Run: 175,524,311,040 bytes free
Post-Run: 175,825,031,168 bytes free
.
- - End Of File - - A6D9A33AD2DCDCAC19E678AC41A2646B
COMBOFIX—END
Please run the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish


NEXT

  • Please download MiniToolBox and save it to your desktop and run it.

    Checkmark following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List installed programs.

Click Go and post the result (Result.txt) that pops up. A copy of result.txt will be saved in the same directory the tool is run.

NEXT

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
MALWAREBYTES—BEGIN Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.27.09 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Day :: DAY-PC [administrator] 7/29/2012 3:59:42 PM mbam-log-2012-07-29 (15-59-42).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 195690 Time elapsed: 9 minute(s), 40 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) MALWAREBYTES—END ESET—BEGIN C:\FRST\Quarantine\dhnsg.dll a variant of Win32/Medfos.BL trojan C:\FRST\Quarantine\services.exe Win32/Sirefef.FB.Gen trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\n Win32/Sirefef.EV trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz1470.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz1D2D.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz29BF.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz2E91.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3030.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz31C9.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz33BF.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz344.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3556.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz360F.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz364D.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz378C.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz37A2.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3916.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3EAA.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3EB8.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz3FF3.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz42E.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz4B81.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz52AE.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz562C.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz573F.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz6350.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz648.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz6D7A.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz7250.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz759C.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz7A77.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz7A7D.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz7A94.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz800C.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz848D.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz8BD4.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz97BA.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz985C.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz98E9.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz98EA.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trz9E75.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzA1EC.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzAD22.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzB17C.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzBA1C.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzBD0C.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzCCC0.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzD232.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzD3C4.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzDA12.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzDD29.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzE26.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzE4A.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzE8C1.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzEC76.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzF053.tmp a variant of Win32/Sirefef.FA trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\U\trzF3E5.tmp a variant of Win32/Sirefef.FD trojan C:\FRST\Quarantine\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde}\n Win32/Sirefef.EV trojan C:\ProgramData\{559F25A3-87D2-4D88-ADC5-DF4C277CDD45}\setup.res a variant of Win32/HiddenStart.A application C:\Users\All Users\{559F25A3-87D2-4D88-ADC5-DF4C277CDD45}\setup.res a variant of Win32/HiddenStart.A application ESET—END MINI—BEGIN (RESULT.TXT0 MiniToolBox by Farbar Version: 23-07-2012 Ran by [removed] (administrator) on 29-07-2012 at 18:55:01 Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. ========================= FF Proxy Settings: ============================== ========================= Hosts content: ================================= 127.0.0.1 localhost =========================== Installed Programs ============================ µTorrent (Version: 2.0.4) 7-Zip 4.65 Acrobat.com (Version: 0.0.0) Acrobat.com (Version: 1.1.377) Adobe AIR (Version: 2.0.2.12610) Adobe Flash Player 11 ActiveX (Version: 11.3.300.268) Adobe Flash Player 11 Plugin (Version: 11.3.300.268) Adobe Reader X (10.1.2) (Version: 10.1.2) Adobe Shockwave Player 11.5 (Version: 11.5.9.615) Advanced Audio FX Engine AGEIA PhysX v7.09.13 (Version: 7.09.13) Akamai NetSession Interface Service Apple Application Support (Version: 2.1.7) Apple Mobile Device Support (Version: 4.0.0.96) Apple Software Update (Version: 2.1.3.127) ATI Catalyst Control Center (Version: 2.008.0703.2235) avast! Free Antivirus (Version: 7.0.1456.0) Banctec Service Agreement (Version: 2.0.0) Bejeweled 3 Bonjour (Version: 3.0.0.10) Browser Address Error Redirector (Version: 1.00.0000) CamStudio Canon RAW Image Task for ZoomBrowser EX (Version: 2.6.0.13) Canon Utilities Digital Photo Professional 3.0 (Version: 3.0.2.6) Canon Utilities EOS Utility (Version: 2.0.2.26) Canon Utilities Original Data Security Tools (Version: 1.0.1.4) Canon Utilities PhotoStitch (Version: 3.1.19.43) Canon Utilities WFT-E1/E2 Utility (Version: 3.0.1.14) Canon Utilities ZoomBrowser EX (Version: 5.8.0.74) Catalyst Control Center - Branding (Version: 1.00.0000) Catalyst Control Center Core Implementation (Version: 2008.0703.2236.38526) Catalyst Control Center Graphics Full Existing (Version: 2008.0703.2236.38526) Catalyst Control Center Graphics Full New (Version: 2008.0703.2236.38526) Catalyst Control Center Graphics Light (Version: 2008.0703.2236.38526) Catalyst Control Center Graphics Previews Common (Version: 2008.0703.2236.38526) Catalyst Control Center Graphics Previews Vista (Version: 2008.0703.2236.38526) Catalyst Control Center InstallProxy (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Chinese Standard (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Chinese Traditional (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Danish (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Dutch (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Finnish (Version: 2008.0703.2236.38526) Catalyst Control Center Localization French (Version: 2008.0703.2236.38526) Catalyst Control Center Localization German (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Italian (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Japanese (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Korean (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Norwegian (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Portuguese (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Russian (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Spanish (Version: 2008.0703.2236.38526) Catalyst Control Center Localization Swedish (Version: 2008.0703.2236.38526) ccc-core-static (Version: 2008.0703.2236.38526) ccc-utility (Version: 2008.0703.2236.38526) CCC Help Chinese Standard (Version: 2008.0703.2235.38526) CCC Help Chinese Traditional (Version: 2008.0703.2235.38526) CCC Help Danish (Version: 2008.0703.2235.38526) CCC Help Dutch (Version: 2008.0703.2235.38526) CCC Help English (Version: 2008.0703.2235.38526) CCC Help Finnish (Version: 2008.0703.2235.38526) CCC Help French (Version: 2008.0703.2235.38526) CCC Help German (Version: 2008.0703.2235.38526) CCC Help Italian (Version: 2008.0703.2235.38526) CCC Help Japanese (Version: 2008.0703.2235.38526) CCC Help Korean (Version: 2008.0703.2235.38526) CCC Help Norwegian (Version: 2008.0703.2235.38526) CCC Help Portuguese (Version: 2008.0703.2235.38526) CCC Help Russian (Version: 2008.0703.2235.38526) CCC Help Spanish (Version: 2008.0703.2235.38526) CCC Help Swedish (Version: 2008.0703.2235.38526) CCleaner (Version: 3.17) Cisco EAP-FAST Module (Version: 2.1.3) Cisco LEAP Module (Version: 1.0.12) Cisco PEAP Module (Version: 1.0.13) Compatibility Pack for the 2007 Office system (Version: 12.0.4518.1014) Dell DataSafe Online (Version: 1.1.0019) Dell Dock (Version: 1.0.0) Dell Driver Download Manager (Version: 2.1.0.0) Dell Getting Started Guide (Version: 1.00.0000) Dell Mobile Broadband Card Utility (Version: 2.09.01.023) Dell Support Center (Version: 2.1.08060) Dell Touchpad (Version: 7.1007.101.209) Dell V305 Dell Video Chat (remove only) (Version: 6.0 (6551)) Dell Webcam Central Dell Wireless WLAN Card Utility (Version: 4.170.77.13) EDocs Encrypt Files v1.5 EOS IEEE1394 WIA Driver (Version: 6.0.0.4) EOS USB WIA Driver (Version: 6.0.0.4) ESET Online Scanner v3 Facebook Plug-In Fallen Earth (Version: 1.00.0000) Family Tree Maker 2012 (Version: 21.0.452) File Wipe Pro 2.0 (Version: 2.0) Gadwin PrintScreen (Version: 4.5) Google Chrome (Version: 20.0.1132.57) Google Earth (Version: 5.2.0.5932) Google Earth (Version: 6.1.0.5001) Google Update Helper (Version: 1.3.21.115) Google Updater (Version: 2.4.2432.1652) GoToAssist 8.0.0.514 HiJackThis (Version: 1.0.0) ImgBurn (Version: 2.5.1.0) Integrated Webcam Driver (1.03.01.0825) ITECIR (Version: 1.9) iTunes (Version: 10.5.0.142) JAP (Version: 00.13.001) Java Auto Updater (Version: 2.0.7.1) Java™ 6 Update 32 (Version: 6.0.320) LEGO Universe Malwarebytes Anti-Malware version 1.62.0.1300 (Version: 1.62.0.1300) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.4518.1014) Microsoft Office XP Professional with FrontPage (Version: 10.0.2627.01) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Works (Version: 9.7.0621) Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0) MSVC80_x86_v2 (Version: 1.0.3.0) MSVC90_x86 (Version: 1.0.1.2) MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) NCsoft Launcher (Version: 1.5.4.2) Nexon Game Manager Nokia Connectivity Cable Driver (Version: 7.1.31.0) Nokia Ovi Suite (Version: 2.2.1.23) Nokia Ovi Suite Software Updater (Version: 02.05.008.43342) ooVoo (Version: 3.0.7031) Ovi Desktop Sync Engine (Version: 1.4.92.0) OviMPlatform (Version: 2.6.221.2) Pando Media Booster (Version: 2.3.3.9) PC Connectivity Solution (Version: 10.33.1.0) QuickPar 0.9 (Version: 0.9) QuickSet (Version: 9.2.8) QuickTime (Version: 7.71.80.42) Roblox for Day Roller Coaster Tycoon 3 Platinum - CarlesNeo ! Roxio Creator Audio (Version: 3.7.0) Roxio Creator Copy (Version: 3.7.0) Roxio Creator Data (Version: 3.7.0) Roxio Creator DE (Version: 10.1) Roxio Creator DE (Version: 3.7.0) Roxio Creator Tools (Version: 3.7.0) Roxio Express Labeler 3 (Version: 3.2.1) Roxio Update Manager (Version: 6.0.0) Samsung New PC Studio (Version: 1.00.0000) SAMSUNG USB Driver for Mobile Phones (Version: 1.3.650.0) Skins (Version: 2008.0703.2236.38526) Skype™ 4.2 (Version: 4.2.187) Spybot - Search & Destroy (Version: 1.6.2) Spyware Doctor 7.0 (Version: 7.0) The Sims™ 3 (Version: 1.12.70) The Sims™ 3 Ambitions (Version: 4.0.87) Torchlight (Version: 0.0.66.192) Unity Web Player (Version: 2.5.1f5_24931) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01) VLC media player 1.1.4 (Version: 1.1.4) Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) (Version: 08/22/2008 7.0.0.0) Windows Media Encoder 9 Series Windows Media Encoder 9 Series (Version: 9.00.3374) Windows Resource Kit Tools - SubInAcl.exe (Version: 5.2.3790.1164) WinRAR archiver World of Warcraft (Version: 4.0.1.13164) Xvid Video Codec (Version: 1.3.2) Yahoo! Software Update Yahoo! Toolbar yEnc32 (remove only) **** End of log **** MINI—END(RESULT.TXT) FSS–BEGIN Farbar Service Scanner Version: 26-07-2012 Ran by [removed] (administrator) on 29-07-2012 at 18:56:07 Running from "C:\Users\Day\Desktop" Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. There is no connection to network. Attempt to access Google IP returned error: Google IP is unreachable Attempt to access Google.com returned error: Other errors Attempt to access Yahoo IP returned error: Yahoo IP is unreachable Attempt to access Yahoo.com returned error: Other errors Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ BITS Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to retrieve start type of BITS. The value does not exist. The ImagePath of BITS service is OK. The ServiceDll of BITS service is OK. Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Other Services: ============== sharedaccess Service is not running. Checking service configuration: The start type of sharedaccess service is set to Auto The ImagePath of sharedaccess service is OK. The ServiceDll of sharedaccess service is OK. File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys [2012-05-09 01:25] - [2012-03-30 08:39] - 0905600 ____A (Microsoft Corporation) 27D470DABC77BC60D0A3B0E4DEB6CB91 C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log **** FSS—END
The detections by ESET are in quarantine already and can't hurt your computer, the other two are nothing to be concerned about.

Windows update is broken because BITS registry key is missing, so we need to replace that:

please do the following:


download the attached reg fix and save it to your desktop, extract the registry fix then double click it and allow it to merge into your registry

reboot your machine, then right click and delete the file as you wont need it any more.


[attachment removed]



NEXT



Your Java is out of date, so go to Start > Control Panel > Programs and Features > scroll down to the Java installation and Remove it, now download the latest Java version 7 update 5 and install it: http://java.com/en/download/index.jsp

NEXT

Please post a fresh FarbarServiceScanner log and advise how the computer is running now and if there are any outstanding issues
This is the new FSS. And things seem to be running fine. I will do more surfing tomorrow and let you know, but I am not getting any TROJAN popups from avast now. FSS—BEGIN Farbar Service Scanner Version: 26-07-2012 Ran by [removed] (administrator) on 29-07-2012 at 21:34:28 Running from "C:\Users\Day\Desktop" Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Other Services: ============== sharedaccess Service is not running. Checking service configuration: The start type of sharedaccess service is set to Auto The ImagePath of sharedaccess service is OK. The ServiceDll of sharedaccess service is OK. File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys [2012-05-09 01:25] - [2012-03-30 08:39] - 0905600 ____A (Microsoft Corporation) 27D470DABC77BC60D0A3B0E4DEB6CB91 C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log **** FSS—END THANKS!!!!!
we just have some housekeeping to do now,

please do the following:

P2P - I see you have P2P software utorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.

I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Programs and Features.


NEXT


You can delete the DDS, Mini Tool Box, Farbar Service Scanner and FRST logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Press the WinKey +R to open a run box
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT


Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI