This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

All manner of viruses on PC (XP service pack 3) [Solved]

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm not sure if this is all the info you need: SHA256: 3c26c9272bdee1767a06c83cae196759ac6d3000863fcc42e671ee35c6d9f31d SHA1: f5061f226b1f7e5b3f646131416be24b86f9be88 MD5: 5ff0856b24470f5121dd22685f212c27 File size: 1.7 MB ( 1781984 bytes ) File name: tsassist.exe File type: Win32 EXE Detection ratio: 0 / 42 Analysis date: 2012-08-28 18:12:54 UTC ( 0 minutes ago )
Hi,

Yep…that will work.
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    File::
    c:\windows\system32\drivers\34552256.sys 
    c:\windows\system32\drivers\nmvowknv.sys
    c:\program files\Free_TV_Bar_c3\prxtbFre2.dll
    
    Folder::
    c:\documents and settings\Administrator\Local Settings\Application Data\Conduit
    c:\documents and settings\Administrator\Application Data\BabylonToolbar
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}"=-
    [-HKEY_CLASSES_ROOT\clsid\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{3EE8D0BE-F450-4EF2-97B9-AC2222D14DB3}"=-
    [-HKEY_CLASSES_ROOT\clsid\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}]
    
    Driver::
    43405483
    nmvowknv
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
ComboFix 12-08-28.03 - Office 08/28/2012 14:32:55.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3037.2478 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Office\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\program files\Free_TV_Bar_c3\prxtbFre2.dll"
"c:\windows\system32\drivers\34552256.sys"
"c:\windows\system32\drivers\nmvowknv.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Application Data\BabylonToolbar
c:\documents and settings\Administrator\Application Data\PriceGong
c:\documents and settings\Administrator\Application Data\PriceGong\Data\1.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\a.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\b.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\c.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\d.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\e.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\f.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\g.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\h.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\i.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\j.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\k.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\l.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\m.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Administrator\Application Data\PriceGong\Data\n.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\o.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\p.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\q.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\r.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\s.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\t.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\u.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\v.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\w.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\wlu.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\x.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\y.txt
c:\documents and settings\Administrator\Application Data\PriceGong\Data\z.txt
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\AppNotification.js
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\close.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\close.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Next.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Next_hover.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\powered-by.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Prev.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Prev_hover.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\settings.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\close.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Next.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Next_hover.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\powered-by.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Prev.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Prev_hover.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\settings.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Thumbs.db
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\like.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Next.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Next_hover.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\powered-by.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Prev.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Prev_hover.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\settings.png
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Thumbs.db
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\initialNotification.html
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\main.html
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\NotificationDialogStyle.css
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\AppNotificationDialog\sampleNotification.html
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\DialogsAPI.js
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\PIE.htc
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\settings.js
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Dialogs\version.txt
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_793983_789805_US.xml
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Community Alerts\LanguagePacks\en.xml
c:\documents and settings\Administrator\Local Settings\Application Data\Conduit\Toolbar\Facebook\http___facebook_conduit-services_com_Settings_ashx_locale=en&browserType=IE&toolbarVersion=6_9_0_16.xml
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\chrome.manifest
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\chrome\content\background.html
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\chrome\content\browser.xul
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\chrome\content\crossrider.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\chrome\content\crossriderapi.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\chrome\content\dialog.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\chrome\content\options.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\chrome\content\options.xul
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\chrome\content\search_dialog.xul
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\chrome\content\update.html
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\defaults\preferences\prefs.js
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\install.rdf
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\locale\en-US\translations.dtd
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\button1.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\button2.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\button3.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\button4.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\button5.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\crossrider_statusbar.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\icon128.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\icon16.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\icon24.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\icon48.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\panelarrow-up.png
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\popup.css
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\popup.html
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\popup_binding.xml
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\skin.css
c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\extensions\[removed]\skin\update.css
c:\documents and settings\Office\Application Data\PriceGong
c:\documents and settings\Office\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\j.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Office\Application Data\PriceGong\Data\z.xml
c:\program files\Free_TV_Bar_c3\prxtbFre2.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_43405483
——-\Service_nmvowknv
.
.
((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-28 )))))))))))))))))))))))))))))))
.
.
2012-08-28 18:38 . 2012-08-28 18:38 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{93E0B72F-BBC7-45B2-AA03-AC6CF0103168}\offreg.dll
2012-08-28 17:21 . 2008-04-14 04:48 52480 -c–a-w- c:\windows\system32\dllcache\i8042prt.sys
2012-08-28 17:21 . 2008-04-14 04:48 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2012-08-27 19:45 . 2012-08-01 22:51 7023536 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{93E0B72F-BBC7-45B2-AA03-AC6CF0103168}\mpengine.dll
2012-08-24 19:45 . 2012-08-01 22:51 7023536 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-23 19:48 . 2012-08-23 19:48 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2012-08-23 19:48 . 2012-08-23 19:48 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\visi_coupon
2012-08-23 19:48 . 2012-08-23 19:48 ——– d—–w- c:\documents and settings\Administrator\Application Data\Windows Search
2012-08-23 19:48 . 2012-08-28 17:44 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Free_TV_Bar_c3
2012-08-23 19:48 . 2012-08-23 19:48 ——– d—–w- c:\documents and settings\Administrator\Application Data\Superfish
2012-08-23 19:48 . 2012-08-23 19:48 ——– d—–w- c:\documents and settings\Administrator\Application Data\Yahoo!
2012-08-23 19:47 . 2012-08-23 19:47 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\HP
2012-08-23 19:47 . 2012-08-23 19:48 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2012-08-23 19:47 . 2012-08-23 19:47 ——– d—–w- c:\documents and settings\Administrator\Application Data\Apple Computer
2012-08-23 19:47 . 2012-08-23 19:47 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\S2PC
2012-08-23 19:47 . 2012-08-23 19:47 ——– d—–w- c:\documents and settings\Administrator\Application Data\Samsung
2012-08-23 19:47 . 2012-08-23 19:47 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2012-08-23 19:05 . 2012-08-23 19:05 ——– d—–w- C:\TDSSKiller_Quarantine
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-28 17:07 . 2012-05-09 18:29 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-28 17:07 . 2011-05-16 14:10 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2008-04-25 16:16 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2008-04-25 21:26 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 17:46 . 2011-12-30 17:48 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-03 13:40 . 2008-04-25 16:16 1875072 —-a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2008-04-25 16:16 916992 —-a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2008-04-25 16:16 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2008-04-25 16:16 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2008-04-25 16:16 385024 —-a-w- c:\windows\system32\html.iec
2012-06-06 12:49 . 2012-06-06 12:49 1070152 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 15:50 . 2008-04-25 16:16 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2008-04-25 16:16 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-25 16:16 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2008-10-16 18:09 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2008-10-16 18:07 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2008-04-25 21:27 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2008-04-25 21:27 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2008-04-25 21:27 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2008-10-16 18:09 45080 -c–a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2008-10-16 18:07 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2008-04-25 21:27 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2008-04-25 21:27 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2008-04-25 16:16 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2008-10-16 18:07 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2008-04-25 21:27 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2008-04-25 21:27 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2010-03-19 17:09 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18 . 2010-03-19 17:09 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 19:18 . 2010-03-19 17:09 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2008-04-25 16:16 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-07-23 19:13 . 2011-06-18 17:09 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-08-24_19.40.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-28 18:38 . 2012-08-28 18:38 16384 c:\windows\Temp\Perflib_Perfdata_284.dat
+ 2012-08-28 16:40 . 2012-08-28 16:40 690888 c:\windows\system32\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
+ 2012-08-28 17:07 . 2012-08-28 17:07 686792 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_271_Plugin.exe
+ 2012-05-09 18:29 . 2012-08-28 17:07 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
- 2012-05-09 18:29 . 2012-08-02 18:07 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-08-28 17:07 . 2012-08-28 17:07 9465032 c:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
+ 2012-08-28 14:43 . 2012-08-28 14:43 1067008 c:\windows\Installer\13845a0e.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn1\yt.dll" [2012-06-11 1524056]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-09 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-18 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-18 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-18 150040]
"8169Diag"="c:\program files\Realtek\Diagnostics Utility\8169Diag.exe" [2008-02-26 909312]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-12-04 186904]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-07-09 122368]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"STO Backup Service"="c:\program files\SmarThru Office\BackUpSvr.exe" [2009-07-01 184320]
"STO Launcher Service"="c:\program files\SmarThru Office\LegacyLauncher.exe" [2009-07-01 331776]
"Dell PanelMgr"="c:\windows\Dell\PanelMgr\SSMMgr.exe" [2009-05-18 541936]
"1235cn Scan2PC"="c:\windows\twain_32\DELL\DELL1235\Scan2Pc.exe" [2008-09-26 495616]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-06-07 421776]
.
c:\documents and settings\Office\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-08-18 22:19 57344 —-a-w- c:\windows\ALCMTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-08-18 22:20 16806912 —-a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\twain_32\\DELL\\DELL1235\\Scan2Pc.exe"=
"c:\\WINDOWS\\twain_32\\DELL\\DELL1235\\Sscan2io.exe"=
"c:\\WINDOWS\\twain_32\\DELL\\ScanMgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [5/11/2011 2:22 PM 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [5/11/2011 2:22 PM 338880]
R2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [10/21/2011 3:23 PM 196176]
R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [10/13/2011 5:21 PM 249648]
R2 LANPkt;Realtek LANPkt Protocol Driver;c:\windows\system32\drivers\LANPkt.sys [6/29/2009 3:39 PM 8960]
R3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [6/29/2009 3:39 PM 11264]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [6/29/2009 7:26 PM 110080]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/1/2010 10:35 AM 135664]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [5/9/2012 2:29 PM 250056]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/1/2010 10:35 AM 135664]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1/3/2012 12:35 AM 40776]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/9/2012 2:25 PM 113120]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [6/29/2009 3:39 PM 16640]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [5/11/2011 2:22 PM 366840]
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 17:07]
.
2012-07-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-01 14:35]
.
2012-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-01 14:35]
.
2012-08-28 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
2012-08-28 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 19:07]
.
2012-08-27 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-10-27 16:39]
.
2012-08-28 c:\windows\Tasks\ProgramUpdateCheck.job
- c:\program files\File Type Assistant\tsassist.exe [2012-05-22 02:19]
.
2012-08-28 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-10-27 16:40]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: Capture Selection - c:\program files\SmarThru Office\WebCapture.dll2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office14\EXCEL.EXE/3000
IE: Save as HTML - c:\program files\SmarThru Office\WebCapture.dll1.htm
IE: Save Selected Text - c:\program files\SmarThru Office\WebCapture.dll.htm
IE: Se&nd to OneNote - c:\progra~1\MI1933~1\Office14\ONBttnIE.dll/105
IE: Web Capture - c:\program files\SmarThru Office\WebCapture.dll
IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files\Superfish\Special Savings\SpecialSavings.dll
TCP: DhcpNameServer = 192.168.1.1
DPF: {3C648A72-C49A-48EF-9F90-68EF13293F97} - hxxp://www.priv.njmls.xmlsweb.com/XMLSearch/XMLCache.CAB
FF - ProfilePath - c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=109935&babsrc=KW_ss&mntrId=5ec20cca0000000000000024e80fcfe9&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109935
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 5ec20cca0000000000000024e80fcfe9
FF - user.js: extensions.BabylonToolbar_i.hardId - 5ec20cca0000000000000024e80fcfe9
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15482
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1711:30
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-NjvPDQr7hmWWRQ - c:\documents and settings\All Users\Application Data\NjvPDQr7hmWWRQ.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-28 14:39
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1988)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\program files\Common Files\Roxio Shared\9.0\DLLShared\DLAAPI_W.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\SearchIndexer.exe
.
**************************************************************************
.
Completion time: 2012-08-28 14:42:08 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-28 18:42
ComboFix2.txt 2012-08-28 17:43
ComboFix3.txt 2012-08-24 19:41
ComboFix4.txt 2012-08-23 19:47
.
Pre-Run: 213,291,167,744 bytes free
Post-Run: 213,318,684,672 bytes free
.
- - End Of File - - A8C29459409BE3448B8080FE10BE7ACF
See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.


Please go to Start > Control Panel > Add/Remove Programs > remove all the Java Programs you see, now download the latest Java from the following link and install it:

http://java.com/en/download/index.jsp
———-


Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-


Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
Malware Bytes Log: Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.28.06 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Office :: NEWFRONT [administrator] 8/28/2012 3:09:29 PM mbam-log-2012-08-28 (15-15-14)b Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 219679 Time elapsed: 3 minute(s), 25 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 8 HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> No action taken. HKCR\Interface\{55555555-5555-5555-5555-550055225558} (Adware.GamePlayLab) -> No action taken. HKCR\TypeLib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLab) -> No action taken. HKCR\CrossriderApp0002258.BHO (Adware.GamePlayLab) -> No action taken. HKCR\CrossriderApp0002258.BHO (PUP.CrossFire.Gen) -> No action taken. HKCU\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\215 APPS (PUP.CrossFire.SA) -> No action taken. HKLM\SOFTWARE\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk (PUP.GamesPlayLab) -> No action taken. Registry Values Detected: 1 HKCU\Software\InstalledBrowserExtensions\215 Apps|2258 (PUP.CrossFire.SA) -> Data: I Want This -> No action taken. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Documents and Settings\Office\My Documents\Downloads\Codec-V(1).exe (Affiliate.Downloader) -> No action taken. C:\Documents and Settings\Office\My Documents\Downloads\Codec-V.exe (Affiliate.Downloader) -> No action taken. (end)
ESET will probably take a while so please be patient. The entries found by Malwarebytes should be removed. Rerun Malwarebytes and remove the entries found and then post the new log along with the ESET log when that is complete. Also let me know how your system is running.
Yep ESET still scanning….. Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.28.06 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Office :: NEWFRONT [administrator] 8/28/2012 3:21:48 PM mbam-log-2012-08-28 (15-21-48).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 219848 Time elapsed: 10 minute(s), 25 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 2 HKCR\Interface\{66666666-6666-6666-6666-660066226658} (Adware.GamePlayLab) -> Quarantined and deleted successfully. HKCR\TypeLib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLab) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
C:\Documents and Settings\Office\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\aabpbagjiokhfiamedgpgidalimbegcl\background.html Win32/BHO.OEI trojan C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\lwGuXDuVJdJAFej.exe.vir a variant of Win32/Kryptik.AKEO trojan C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\NjvPDQr7hmWWRQ.exe.vir a variant of Win32/Kryptik.AKEO trojan C:\Qoobox\Quarantine\C\Program Files\I Want This\I Want This.dll.vir Win32/Toolbar.CrossRider application C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ReactivateIE.exe.vir Win32/Toolbar.Zugo application C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\Toolbar32.dll.vir Win32/Toolbar.Zugo application C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ToolbarBroker.exe.vir Win32/Toolbar.Zugo application C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe.vir Win32/Toolbar.Zugo application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1005\A0141447.exe Win32/Toolbar.Zugo application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1005\A0141448.dll Win32/Toolbar.Zugo.A application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1022\A0142570.dll Win32/Toolbar.CrossRider application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1022\A0142577.exe Win32/Toolbar.Zugo application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1022\A0142579.dll Win32/Toolbar.Zugo application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1022\A0142580.exe Win32/Toolbar.Zugo application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1022\A0142581.exe Win32/Toolbar.Zugo application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1029\A0153348.dll Win32/Toolbar.Babylon application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1029\A0153349.dll Win32/Toolbar.Babylon application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1029\A0153350.dll a variant of Win32/Toolbar.Babylon application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1029\A0153351.dll Win32/Toolbar.Babylon application C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP1029\A0153353.exe probably a variant of Win32/Toolbar.Babylon application C:\TDSSKiller_Quarantine\23.08.2012_15.05.14\mbr0000\tdlfs0000\tsk0005.dta a variant of Win32/Olmasco.O trojan C:\TDSSKiller_Quarantine\23.08.2012_15.05.14\mbr0000\tdlfs0000\tsk0006.dta Win64/Olmasco.Y trojan C:\TDSSKiller_Quarantine\23.08.2012_15.05.14\mbr0000\tdlfs0000\tsk0007.dta Win32/Olmasco.O trojan C:\TDSSKiller_Quarantine\23.08.2012_15.05.14\mbr0000\tdlfs0000\tsk0008.dta Win64/Olmasco.X trojan C:\TDSSKiller_Quarantine\23.08.2012_15.05.14\mbr0000\tdlfs0000\tsk0009.dta a variant of Win32/Olmasco.O trojan C:\TDSSKiller_Quarantine\23.08.2012_15.05.14\mbr0000\tdlfs0000\tsk0010.dta Win64/Olmasco.AA trojan C:\TDSSKiller_Quarantine\23.08.2012_15.05.14\mbr0000\tdlfs0000\tsk0011.dta Win32/Olmasco.Q trojan C:\TDSSKiller_Quarantine\23.08.2012_15.05.14\mbr0000\tdlfs0000\tsk0012.dta Win64/Olmasco.X trojan C:\TDSSKiller_Quarantine\23.08.2012_15.05.14\mbr0000\tdlfs0000\tsk0015.dta Win32/Olmasco.AA trojan C:\TDSSKiller_Quarantine\23.08.2012_15.05.14\mbr0000\tdlfs0000\tsk0016.dta Win64/Olmasco.Z trojan
Looks good. Please do the following…


Open a command prompt > Click Start >> Run type CMD and press Enter.
This will open a command prompt.

Copy the contents of the code box > right click in the command window and select paste

del "C:\Documents and Settings\Office\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\aabpbagjiokhfiamedgpgidalimbegcl\background.html"

Press Enter
Close the Command Prompt window.
———-

How is your system running now?

Looks good. Please do the following…


Open a command prompt > Click Start >> Run type CMD and press Enter.
This will open a command prompt.

Copy the contents of the code box > right click in the command window and select paste

del "C:\Documents and Settings\Office\Local Settings\Application Data\Google\Chrome\User Data\Default\Default\aabpbagjiokhfiamedgpgidalimbegcl\background.html"

Press Enter
Close the Command Prompt window.
———-

How is your system running now?


Thanks Jeff. I'll be back on that computer tomorrow. It has been running better with each step.
Ok thats fine.

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the box below:


    ClearJavaCache::

    Firefox::
    FF - ProfilePath - c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\
    FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
    FF - prefs.js: browser.startup.homepage - about:home
    FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=109935&babsrc=KW_ss&mntrId=5ec20cca0000000000000024e80fcfe9&q=
    FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109935
    FF - user.js: extensions.BabylonToolbar_i.babExt -
    FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
    FF - user.js: extensions.BabylonToolbar_i.id - 5ec20cca0000000000000024e80fcfe9
    FF - user.js: extensions.BabylonToolbar_i.hardId - 5ec20cca0000000000000024e80fcfe9
    FF - user.js: extensions.BabylonToolbar_i.instlDay - 15482
    FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
    FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
    FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1711:30
    FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
    FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
    FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
    FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
    FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
    FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

In your next reply post the new ComboFix log and let me know what remaining malware problems you are having? :)
ComboFix 12-08-30.05 - Office 08/31/2012 10:29:31.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3037.2370 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Office\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-31 )))))))))))))))))))))))))))))))
.
.
2012-08-31 14:16 . 2012-08-23 07:15 7022536 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{18A05D78-242B-44D9-B420-3B8FBC2CF084}\mpengine.dll
2012-08-29 20:56 . 2012-08-23 07:15 7022536 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-28 20:24 . 2012-08-28 20:24 ——– d—–w- c:\documents and settings\Office\Local Settings\Application Data\Sun
2012-08-28 19:17 . 2012-08-28 19:17 ——– d—–w- c:\program files\ESET
2012-08-28 19:07 . 2012-08-28 19:07 ——– d—–w- c:\program files\Common Files\Java
2012-08-28 19:07 . 2012-08-28 19:07 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-08-28 19:07 . 2012-08-28 19:07 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-08-28 19:07 . 2012-08-28 19:07 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-28 17:21 . 2008-04-14 04:48 52480 -c–a-w- c:\windows\system32\dllcache\i8042prt.sys
2012-08-28 17:21 . 2008-04-14 04:48 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2012-08-23 19:48 . 2012-08-23 19:48 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2012-08-23 19:48 . 2012-08-23 19:48 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\visi_coupon
2012-08-23 19:48 . 2012-08-23 19:48 ——– d—–w- c:\documents and settings\Administrator\Application Data\Windows Search
2012-08-23 19:48 . 2012-08-28 17:44 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Free_TV_Bar_c3
2012-08-23 19:48 . 2012-08-23 19:48 ——– d—–w- c:\documents and settings\Administrator\Application Data\Superfish
2012-08-23 19:48 . 2012-08-23 19:48 ——– d—–w- c:\documents and settings\Administrator\Application Data\Yahoo!
2012-08-23 19:47 . 2012-08-23 19:47 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\HP
2012-08-23 19:47 . 2012-08-23 19:48 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2012-08-23 19:47 . 2012-08-23 19:47 ——– d—–w- c:\documents and settings\Administrator\Application Data\Apple Computer
2012-08-23 19:47 . 2012-08-23 19:47 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\S2PC
2012-08-23 19:47 . 2012-08-23 19:47 ——– d—–w- c:\documents and settings\Administrator\Application Data\Samsung
2012-08-23 19:47 . 2012-08-23 19:47 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2012-08-23 19:05 . 2012-08-23 19:05 ——– d—–w- C:\TDSSKiller_Quarantine
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-28 17:07 . 2012-05-09 18:29 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-28 17:07 . 2011-05-16 14:10 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2008-04-25 16:16 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2008-04-25 21:26 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 17:46 . 2011-12-30 17:48 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-03 13:40 . 2008-04-25 16:16 1875072 —-a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2008-04-25 16:16 916992 —-a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2008-04-25 16:16 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2008-04-25 16:16 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2008-04-25 16:16 385024 —-a-w- c:\windows\system32\html.iec
2012-06-06 12:49 . 2012-06-06 12:49 1070152 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 15:50 . 2008-04-25 16:16 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2008-04-25 16:16 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-25 16:16 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2008-10-16 18:09 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2008-10-16 18:07 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2008-04-25 21:27 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2008-04-25 21:27 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2008-04-25 21:27 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2008-10-16 18:09 45080 -c–a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2008-10-16 18:07 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2008-04-25 21:27 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2008-04-25 21:27 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2008-04-25 16:16 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2008-10-16 18:07 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2008-04-25 21:27 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2008-04-25 21:27 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2010-03-19 17:09 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18 . 2010-03-19 17:09 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 19:18 . 2010-03-19 17:09 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-07-23 19:13 . 2011-06-18 17:09 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-08-24_19.40.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-28 20:52 . 2012-08-28 20:52 16384 c:\windows\Temp\Perflib_Perfdata_b44.dat
+ 2009-07-06 22:00 . 2012-08-30 19:35 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-06 22:00 . 2012-08-23 14:35 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-06 22:00 . 2012-08-30 19:35 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-07-06 22:00 . 2012-08-23 14:35 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2012-08-30 19:35 . 2012-08-30 19:35 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2012-08-31 14:05 . 2012-08-31 14:16 2830 c:\windows\SoftwareDistribution\EventCache\{9430C634-DE34-45FC-A2FC-74E98E5C3CD5}.bin
+ 2012-08-28 16:40 . 2012-08-28 16:40 690888 c:\windows\system32\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
+ 2012-08-28 17:07 . 2012-08-28 17:07 686792 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_271_Plugin.exe
+ 2012-05-09 18:29 . 2012-08-28 17:07 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
- 2012-05-09 18:29 . 2012-08-02 18:07 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-08-28 19:07 . 2012-08-28 19:07 246760 c:\windows\system32\javaws.exe
+ 2012-08-28 19:07 . 2012-08-28 19:07 174056 c:\windows\system32\javaw.exe
+ 2012-08-28 19:07 . 2012-08-28 19:07 174056 c:\windows\system32\java.exe
+ 2012-08-28 19:07 . 2012-08-28 19:07 176128 c:\windows\Installer\16262c.msi
+ 2012-08-28 19:07 . 2012-08-28 19:07 873984 c:\windows\Installer\16261e.msi
+ 2012-08-28 17:07 . 2012-08-28 17:07 9465032 c:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-09 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-18 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-18 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-18 150040]
"8169Diag"="c:\program files\Realtek\Diagnostics Utility\8169Diag.exe" [2008-02-26 909312]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-12-04 186904]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-07-09 122368]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"STO Backup Service"="c:\program files\SmarThru Office\BackUpSvr.exe" [2009-07-01 184320]
"STO Launcher Service"="c:\program files\SmarThru Office\LegacyLauncher.exe" [2009-07-01 331776]
"Dell PanelMgr"="c:\windows\Dell\PanelMgr\SSMMgr.exe" [2009-05-18 541936]
"1235cn Scan2PC"="c:\windows\twain_32\DELL\DELL1235\Scan2Pc.exe" [2008-09-26 495616]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-06-07 421776]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\documents and settings\Office\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-08-18 22:19 57344 —-a-w- c:\windows\ALCMTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-08-18 22:20 16806912 —-a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\twain_32\\DELL\\DELL1235\\Scan2Pc.exe"=
"c:\\WINDOWS\\twain_32\\DELL\\DELL1235\\Sscan2io.exe"=
"c:\\WINDOWS\\twain_32\\DELL\\ScanMgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [5/11/2011 2:22 PM 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [5/11/2011 2:22 PM 338880]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [6/29/2009 7:26 PM 110080]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/1/2010 10:35 AM 135664]
S2 LANPkt;Realtek LANPkt Protocol Driver;c:\windows\system32\drivers\LANPkt.sys [6/29/2009 3:39 PM 8960]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [5/9/2012 2:29 PM 250056]
S3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [6/29/2009 3:39 PM 11264]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/1/2010 10:35 AM 135664]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/9/2012 2:25 PM 113120]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [6/29/2009 3:39 PM 16640]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [5/11/2011 2:22 PM 366840]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - GUSVC
*NewlyCreated* - MPKSL9B082E05
*Deregistered* - MpKsl9b082e05
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 17:07]
.
2012-07-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-08-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-01 14:35]
.
2012-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-01 14:35]
.
2012-08-28 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
2012-08-28 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 19:07]
.
2012-08-27 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-10-27 16:39]
.
2012-08-30 c:\windows\Tasks\ProgramUpdateCheck.job
- c:\program files\File Type Assistant\tsassist.exe [2012-05-22 02:19]
.
2012-08-30 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-10-27 16:40]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: Capture Selection - c:\program files\SmarThru Office\WebCapture.dll2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office14\EXCEL.EXE/3000
IE: Save as HTML - c:\program files\SmarThru Office\WebCapture.dll1.htm
IE: Save Selected Text - c:\program files\SmarThru Office\WebCapture.dll.htm
IE: Se&nd to OneNote - c:\progra~1\MI1933~1\Office14\ONBttnIE.dll/105
IE: Web Capture - c:\program files\SmarThru Office\WebCapture.dll
IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files\Superfish\Special Savings\SpecialSavings.dll
TCP: DhcpNameServer = 192.168.1.1
DPF: {3C648A72-C49A-48EF-9F90-68EF13293F97} - hxxp://www.priv.njmls.xmlsweb.com/XMLSearch/XMLCache.CAB
FF - ProfilePath - c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\9r7ejmvu.default\
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-31 10:34
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\igfxdev.dll
.
- - - - - - - > 'explorer.exe'(3032)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-08-31 10:36:32
ComboFix-quarantined-files.txt 2012-08-31 14:36
ComboFix2.txt 2012-08-28 18:42
ComboFix3.txt 2012-08-28 17:43
ComboFix4.txt 2012-08-24 19:41
ComboFix5.txt 2012-08-31 14:28
.
Pre-Run: 212,248,903,680 bytes free
Post-Run: 212,563,738,624 bytes free
.
- - End Of File - - D9B425C3AC2A34982AEACE8CBB9D390C

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI