This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

some trojan. plz help! [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

FixMBR was the only option here. The FIX button was greyed out after the scan. I did nothing but save the log. ############################################## aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-08-03 10:49:30 —————————– 10:49:30.631 OS Version: Windows x64 6.1.7601 Service Pack 1 10:49:30.631 Number of processors: 4 586 0x2A07 10:49:30.631 ComputerName: STEPHEN-HP UserName: Stephen 10:49:31.146 Initialize success 10:53:58.857 AVAST engine defs: 12080201 10:54:58.870 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 10:54:58.870 Disk 0 Vendor: Intel___ 1.0. Size: 476937MB BusType: 8 10:54:58.886 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-1 10:54:58.886 Disk 1 Vendor: Intel___ 1.0. Size: 4096MB BusType: 8 10:54:58.886 Disk 0 MBR read successfully 10:54:58.902 Disk 0 MBR scan 10:54:58.902 Disk 0 Windows 7 default MBR code 10:54:58.902 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 10:54:58.902 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 456629 MB offset 409600 10:54:58.917 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 19999 MB offset 935585792 10:54:58.917 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 108 MB offset 976543744 10:54:58.917 Disk 0 scanning C:\Windows\system32\drivers 10:55:03.051 Service scanning 10:55:11.600 Modules scanning 10:55:11.616 Disk 0 trace - called modules: 10:55:11.631 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll 10:55:11.631 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80050ea060] 10:55:11.631 3 CLASSPNP.SYS[fffff88001a5143f] -> nt!IofCallDriver -> [0xfffffa8004f8bb10] 10:55:11.631 5 hpdskflt.sys[fffff88001ddd189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0xfffffa8004bae050] 10:55:12.068 AVAST engine scan C:\Windows 10:55:13.066 AVAST engine scan C:\Windows\system32 10:56:37.979 AVAST engine scan C:\Windows\system32\drivers 10:56:42.519 AVAST engine scan C:\Users\Stephen 10:57:40.644 File: C:\Users\Stephen\Old Files\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8B7CO0E\Installer.playbryte-iwt[1] **INFECTED** Win32:Trojan-gen 10:57:41.346 File: C:\Users\Stephen\Old Files\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KJGM8XBJ\VLC_Setup.exe **INFECTED** Win32:Rootkit-gen [Rtk] 10:59:54.836 File: C:\Users\Stephen\Old Files\AppData\LocalLow\Playbryte\Assemblies\1\BrowserObjects.dll **INFECTED** MSIL:BHO-A [Trj] 10:59:54.867 File: C:\Users\Stephen\Old Files\AppData\LocalLow\Playbryte\Assemblies\1\Inline.dll **INFECTED** MSIL:BHO-B [Trj] 11:04:01.238 AVAST engine scan C:\ProgramData 11:05:18.068 Scan finished successfully 11:08:25.610 Disk 0 MBR has been saved successfully to "C:\Users\Stephen\Documents\MBR.dat" 11:08:25.626 The log file has been saved successfully to "C:\Users\Stephen\Documents\aswMBR.txt" ################################################################################ #################################################################### DDS Log: . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1 Run by [removed] at 12:03:26 on 2012-08-03 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3996.1952 [GMT 10:00] . AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\IDT\WDM\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Hpservice.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe C:\Program Files\Intel\iCLS Client\HeciServer.exe C:\Windows\SysWOW64\irstrtsv.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files (x86)\Boost Mobile Wireless Broadband\Boost Mobile Wireless Broadband.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Glance27\Glance.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\SysWOW64\RunDll32.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted c:\program files (x86)\teamviewer\version7\TeamViewer_Desktop.exe C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil64_11_2_202_197_ActiveX.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskhost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\svchost.exe -k AxInstSVGroup C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com.au/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll" TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File uRun: [Mobile Partner] "C:\Program Files (x86)\Boost Mobile Wireless Broadband\Boost Mobile Wireless Broadband.exe" uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Glance.lnk - C:\Program Files (x86)\Glance27\Glance.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll Trusted Zone: samsungsetup.com\www TCP: Interfaces\{4E12AEE6-86B3-4ED6-A08A-3C5B76BBC570} : DhcpNameServer = 10.0.0.138 TCP: Interfaces\{9FBBB31C-479D-44B5-BCCB-2221878B96EC} : DhcpNameServer = [removed] TCP: Interfaces\{A80FB3A3-A282-44A6-8C3C-56E9F32904E5} : NameServer = 211.29.132.12 61.88.88.88 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll" TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File mRun-x64: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" mRun-x64: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe mRun-x64: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" IE-X64: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 . ============= SERVICES / DRIVERS =============== . R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\system32\drivers\iusb3hcs.sys –> C:\Windows\system32\drivers\iusb3hcs.sys [?] R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys –> C:\Windows\system32\DRIVERS\MpFilter.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928] R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-10 86072] R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-17 682040] R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe –> C:\Windows\system32\Hpservice.exe [?] R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-6 35200] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-5-4 13592] R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-2-3 628448] R2 irstrtsv;Intel® Rapid Start Technology Service;C:\Windows\SysWOW64\irstrtsv.exe [2012-5-4 193536] R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-5-4 161560] R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-6-21 2666880] R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-5-4 363800] R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.EXE [2012-2-14 240408] R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\system32\drivers\bcbtums.sys –> C:\Windows\system32\drivers\bcbtums.sys [?] R3 btwampfl;btwampfl Bluetooth filter driver;\??\C:\Windows\system32\drivers\btwampfl.sys –> C:\Windows\system32\drivers\btwampfl.sys [?] R3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\system32\DRIVERS\btwdpan.sys –> C:\Windows\system32\DRIVERS\btwdpan.sys [?] R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys –> C:\Windows\system32\DRIVERS\btwl2cap.sys [?] R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\system32\DRIVERS\clwvd.sys –> C:\Windows\system32\DRIVERS\clwvd.sys [?] R3 ewusbnet;HUAWEI USB-NDIS miniport;C:\Windows\system32\DRIVERS\ewusbnet.sys –> C:\Windows\system32\DRIVERS\ewusbnet.sys [?] R3 glancedrv;glancedrv;C:\Windows\system32\DRIVERS\glancedrv.sys –> C:\Windows\system32\DRIVERS\glancedrv.sys [?] R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys –> C:\Windows\system32\DRIVERS\IntcDAud.sys [?] R3 irstrtdv;Intel® Rapid Start Technology Driver;C:\Windows\system32\drivers\irstrtdv.sys –> C:\Windows\system32\drivers\irstrtdv.sys [?] R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\system32\drivers\iusb3hub.sys –> C:\Windows\system32\drivers\iusb3hub.sys [?] R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\system32\drivers\iusb3xhc.sys –> C:\Windows\system32\drivers\iusb3xhc.sys [?] R3 MEIx64;Intel® Management Engine Interface ;C:\Windows\system32\drivers\HECIx64.sys –> C:\Windows\system32\drivers\HECIx64.sys [?] R3 RSBASTOR;Realtek PCIE CardReader Driver - BA;C:\Windows\system32\DRIVERS\RtsBaStor.sys –> C:\Windows\system32\DRIVERS\RtsBaStor.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 SmbDrv;SmbDrv;C:\Windows\system32\drivers\Smb_driver.sys –> C:\Windows\system32\drivers\Smb_driver.sys [?] S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.EXE [2012-2-14 193816] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-6-28 116648] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-25 253600] S3 cphs;Intel® Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-2-22 276248] S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-13 206072] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-6-28 116648] S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys –> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?] S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS –> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?] S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS –> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS –> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184] . =============== Created Last 30 ================ . 2012-08-03 02:02:49 ——– d—–w- C:\Program Files (x86)\ESET 2012-08-03 02:02:30 ——– d–h–w- C:\Windows\AxInstSV 2012-08-03 01:39:58 ——– d-sh–w- C:\$RECYCLE.BIN 2012-08-03 01:14:56 98816 —-a-w- C:\Windows\sed.exe 2012-08-03 01:14:56 518144 —-a-w- C:\Windows\SWREG.exe 2012-08-03 01:14:56 256000 —-a-w- C:\Windows\PEV.exe 2012-08-03 01:14:56 208896 —-a-w- C:\Windows\MBR.exe 2012-08-03 00:38:44 69000 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F757F831-C14C-4594-889C-03033D632EB1}\offreg.dll 2012-08-02 22:48:44 9133488 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F757F831-C14C-4594-889C-03033D632EB1}\mpengine.dll 2012-08-02 02:05:59 ——– d—–w- C:\Users\Stephen\AppData\Local\LogMeIn Rescue Applet 2012-08-01 03:44:38 9133488 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-07-18 23:25:43 336208 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2012-07-11 05:13:14 3148800 —-a-w- C:\Windows\System32\win32k.sys 2012-07-10 23:10:47 2048 —-a-w- C:\Windows\SysWow64\msxml3r.dll 2012-07-04 23:21:56 927800 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2012-07-04 23:21:56 927800 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{36FCE286-60DE-4CDC-8485-3F1DAC3A4D2E}\gapaengine.dll . ==================== Find3M ==================== . 2012-06-06 06:06:16 2004480 —-a-w- C:\Windows\System32\msxml6.dll 2012-06-06 06:06:16 1881600 —-a-w- C:\Windows\System32\msxml3.dll 2012-06-06 06:02:54 1133568 —-a-w- C:\Windows\System32\cdosys.dll 2012-06-06 05:05:52 1390080 —-a-w- C:\Windows\SysWow64\msxml6.dll 2012-06-06 05:05:52 1236992 —-a-w- C:\Windows\SysWow64\msxml3.dll 2012-06-06 05:03:06 805376 —-a-w- C:\Windows\SysWow64\cdosys.dll 2012-06-02 22:15:31 2622464 —-a-w- C:\Windows\System32\wucltux.dll 2012-06-02 22:15:08 99840 —-a-w- C:\Windows\System32\wudriver.dll 2012-06-02 12:12:17 2311680 —-a-w- C:\Windows\System32\jscript9.dll 2012-06-02 12:05:28 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-06-02 12:04:50 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-06-02 12:01:40 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-06-02 11:57:08 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-06-02 08:33:25 1800192 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-06-02 08:25:08 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-06-02 08:25:03 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-06-02 08:20:33 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-06-02 08:16:52 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-06-02 05:50:10 458704 —-a-w- C:\Windows\System32\drivers\cng.sys 2012-06-02 05:48:16 95600 —-a-w- C:\Windows\System32\drivers\ksecdd.sys 2012-06-02 05:48:16 151920 —-a-w- C:\Windows\System32\drivers\ksecpkg.sys 2012-06-02 05:45:31 340992 —-a-w- C:\Windows\System32\schannel.dll 2012-06-02 05:44:21 307200 —-a-w- C:\Windows\System32\ncrypt.dll 2012-06-02 05:19:42 186752 —-a-w- C:\Windows\System32\wuwebv.dll 2012-06-02 05:15:12 36864 —-a-w- C:\Windows\System32\wuapp.exe 2012-06-02 04:40:42 22016 —-a-w- C:\Windows\SysWow64\secur32.dll 2012-06-02 04:40:39 225280 —-a-w- C:\Windows\SysWow64\schannel.dll 2012-06-02 04:39:10 219136 —-a-w- C:\Windows\SysWow64\ncrypt.dll 2012-06-02 04:34:09 96768 —-a-w- C:\Windows\SysWow64\sspicli.dll . ============= FINISH: 12:03:42.42 =============== Your Help Much Appreciated!
Hi, and welcome to our malware removal forum!

My name is Richard and I'll be happy to help you with your computer problems.

Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.

Please note the following:
  • The cleaning process is not instant as logs can take time to research. Sit tight and please be patient.
  • I will be working on your malware issues. This may or may not solve other issues you may have with your system.
  • While we are fixing your problems, do NOT install/re-install any programs or run any fixes or scanners unless told to do so.
  • Ensure that your anti-virus definitions are up-to-date.
  • I would advise backing up all your important documents, personal data files and photos to a CD or DVD drive.
  • Do not back up any Applications (programs). These should be re-installed from the original source CD(s) or website(s).
  • During the course of our cleanup, please do not do any additional online work or surfing until we have verified that your system is clean.
  • I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier.
  • Be sure to follow the directions and run tools/scans in the order listed.
  • If you do not reply to your topic, it will be closed after 3 days.
I will return as soon as possible with more instructions.



Regards,

Richard :wavey:
Please post the contents of attach.txt too :thumbup: .

Next

Please download OTM by OldTimer.
  • Save it to your Desktop.
  • Please right click OTM.exe and then select Run as Administrator.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Files
C:\Users\Stephen\Old Files\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F8B7CO0E\Installer.playbryte-iwt[1]
C:\Users\Stephen\Old Files\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KJGM8XBJ\VLC_Setup.exe
C:\Users\Stephen\Old Files\AppData\LocalLow\Playbryte\

:Commands
[purity]
[resethosts]
[emptytemp]
[start explorer]
[Reboot]

  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Next

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then press on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file in your next reply.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file in your next reply.
In your next reply, please provide the following:
  • OTM log.
  • attach.txt log.
  • TDSSKiller log.
  • Update on how your PC is running.



Regards,

Richard :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI