This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE freezes and then I cannot open programs [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, Thanks for your help upfront. I have been having general issues with my computer. IE and FF will launch and then when trying to open something like FB it will open but then freeze when trying to navigate to anything inside FB. Then when I clicked on any program it would not open. I ran Malwarebytes, and it picked up 10 things and killed them. Now I can open a few programs okay, but IE still freezes up and then I cannot open anything again. When I click cntrl+alt+del I get a black screen. Please help. :pullhair: Thanks. I attached the latest Mbam log. Edit by Doug I'm moving your topic to our Malware Removal Forum. While this "funmoods" item can be "uninstalled" using the regular add/remove, it also makes changes to Hosts File, May change your browser home page, inserts itself as a search engine, and places "default" settings, in addition to leaving remnants which you probably don't want, and could be hazardous. therefore I think you might need some help getting rid of this completely. Our Malware Team is excellent. Please do not make any additional posts to this thread until a Malware Specialist makes a reply to you. Best Regards
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
โ€”โ€”โ€”

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
โ€”โ€”โ€”-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If asked whether you would like to update the Avast virus database please do.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
โ€”โ€”โ€”-
Hi. Thanks for your help! I have to run my computer in safe mode in order to be able to use the internet, just thought I'd mention that. Here are the logs: . DDS (Ver_2011-08-26.01) - NTFSAMD64 NETWORK Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31 Run by [removed] at 15:35:10 on 2012-08-25 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6056.5189 [GMT -5:00] . AV: Kaspersky Anti-Virus *Enabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984} SP: Kaspersky Anti-Virus *Enabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\Explorer.EXE C:\Windows\system32\ctfmon.exe C:\Windows\helppane.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Free Download Manager\fdm.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie9 uWindow Title = Windows Internet Explorer provided by Yahoo! mDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW mStart Page = hxxp://start.funmoods.com/?f=1&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1Qzu0FzztD0FyEtCtCtD0BtB0A0E0B0B0EyEtN0D0TzutBtDtCtBtDyCtBzz&cr=1256813919 uInternet Settings,ProxyOverride = *.local uURLSearchHooks: YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll mURLSearchHooks: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files (x86)\PageRage\prxtbPag0.dll mWinlogon: Userinit=userinit.exe, BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\ievkbd.dll BHO: Javaโ„ข Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files (x86)\PageRage\prxtbPag0.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll BHO: WeCareReminder Class: {d824f0de-3d60-4f57-9eb1-66033ecd8abb} - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll BHO: Javaโ„ข Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbbho.dll BHO: Yontoo: {fd72061e-9fde-484d-a58a-0bab4151cad8} - C:\Program Files (x86)\Yontoo Layers Runtime\YontooIEClient.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll TB: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files (x86)\PageRage\prxtbPag0.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent uRun: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe uRun: [Google Update] "C:\Users\Platypus\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart uRun: [PC Speed Maximizer] "C:\Program Files (x86)\PC Speed Maximizer\SPMStarter.exe" uRun: [SPMTray] "C:\Program Files (x86)\PC Speed Maximizer\SPMTray.exe" mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intelยฎ Rapid Storage Technology\IAStorIcon.exe mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" mRun: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" mRun: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" mRun: [LTCM Client] C:\Program Files (x86)\LTCM Client\ltcmClient.exe /startup mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: Download all with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\ievkbd.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbbho.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{C27298D8-DF2C-474F-A0DA-513987A13224} : DhcpNameServer = 192.168.2.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll BHO-X64: 0x1 - No File BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll BHO-X64: Canon Easy-WebPrint EX BHO - No File BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\ievkbd.dll BHO-X64: IEVkbdBHO - No File BHO-X64: Javaโ„ข Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files (x86)\PageRage\prxtbPag0.dll BHO-X64: PageRage - No File BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: Free Download Manager: {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll BHO-X64: WeCareReminder Class: {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll BHO-X64: WeCareReminder - No File BHO-X64: Javaโ„ข Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtbbho.dll BHO-X64: link filter bho - No File BHO-X64: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo Layers Runtime\YontooIEClient.dll BHO-X64: Yontoo Layers - No File BHO-X64: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll TB-X64: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll TB-X64: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files (x86)\PageRage\prxtbPag0.dll TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll TB-X64: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File EB-X64: {21347690-EC41-4F9A-8887-1F4AEE672439} - No File mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intelยฎ Rapid Storage Technology\IAStorIcon.exe mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun-x64: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" mRun-x64: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" mRun-x64: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" mRun-x64: [LTCM Client] C:\Program Files (x86)\LTCM Client\ltcmClient.exe /startup mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe mRun-x64: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe" mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Search FF - prefs.js: browser.startup.homepage - hxxp://start.funmoods.com/?f=1&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1Qzu0FzztD0FyEtCtCtD0BtB0A0E0B0B0EyEtN0D0TzutBtDtCtBtDyCtBzz&cr=1256813919 FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll FF - plugin: C:\Users\Platypus\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: C:\Users\Platypus\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll . โ€”- FIREFOX POLICIES โ€”- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true FF - user.js: extensions.funmoods.hmpg - true FF - user.js: extensions.funmoods.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1Qzu0FzztD0FyEtCtCtD0BtB0A0E0B0B0EyEtN0D0TzutBtDtCtBtDyCtBzz&cr=1256813919 FF - user.js: extensions.funmoods.dfltSrch - true FF - user.js: extensions.funmoods.srchPrvdr - Search FF - user.js: extensions.funmoods.dnsErr - true FF - user.js: extensions.funmoods_i.newTab - true FF - user.js: extensions.funmoods.newTabUrl - hxxp://start.funmoods.com/?f=2&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1Qzu0FzztD0FyEtCtCtD0BtB0A0E0B0B0EyEtN0D0TzutBtDtCtBtDyCtBzz&cr=1256813919 FF - user.js: extensions.funmoods.tlbrSrchUrl - FF - user.js: extensions.funmoods.id - 6823bbe4000000000000f80f4110b2ae FF - user.js: extensions.funmoods.instlDay - 15519 FF - user.js: extensions.funmoods.vrsn - 1.5.23.22 FF - user.js: extensions.funmoods.vrsni - 1.5.23.22 FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2218:56:19 FF - user.js: extensions.funmoods.prtnrId - funmoods FF - user.js: extensions.funmoods.prdct - funmoods FF - user.js: extensions.funmoods.aflt - fmtoby FF - user.js: extensions.funmoods_i.smplGrp - none FF - user.js: extensions.funmoods.tlbrId - base FF - user.js: extensions.funmoods.instlRef - fmtoby FF - user.js: extensions.funmoods.dfltLng - FF - user.js: extensions.funmoods.excTlbr - false FF - user.js: extensions.funmoods.autoRvrt - false FF - user.js: extensions.funmoods.envrmnt - production FF - user.js: extensions.funmoods.isdcmntcmplt - true FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0 . FF - user.js: extentions.y2layers.installId - 454ca2c7-9d28-4ca2-ad7f-da1b947ff726 FF - user.js: extentions.y2layers.defaultEnableAppsList - pagerage,ezLooker,buzzdock,toprelatedtopics,twittube . FF - user.js: extensions.autoDisableScopes - 14 . ============= SERVICES / DRIVERS =============== . R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys โ€“> C:\Windows\system32\DRIVERS\kl2.sys [?] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys โ€“> C:\Windows\system32\DRIVERS\klim6.sys [?] R3 e1cexpress;Intelยฎ PRO/1000 PCI Express Network Connection Driver C;C:\Windows\system32\DRIVERS\e1c62x64.sys โ€“> C:\Windows\system32\DRIVERS\e1c62x64.sys [?] R3 MEIx64;Intelยฎ Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys โ€“> C:\Windows\system32\DRIVERS\HECIx64.sys [?] S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-5-14 759048] S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe -r โ€“> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe -r [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 GREGService;GREGService;C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe [2010-1-8 23584] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-6-22 116648] S2 IAStorDataMgrSvc;Intelยฎ Rapid Storage Technology;C:\Program Files (x86)\Intel\Intelยฎ Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-10 13336] S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-14 655944] S2 UNS;Intelยฎ Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe [2010-11-10 2655768] S2 Updater Service;Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2010-11-10 243232] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-7 250056] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-6-22 116648] S3 IntcDAud;Intelยฎ Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys โ€“> C:\Windows\system32\DRIVERS\IntcDAud.sys [?] S3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys โ€“> C:\Windows\system32\DRIVERS\klmouflt.sys [?] S3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys โ€“> C:\Windows\system32\drivers\mbam.sys [?] S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-6 129976] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys โ€“> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys โ€“> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe โ€“> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2012-08-25 18:30:02 69000 โ€”-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317D39D5-883E-4BDF-8725-E0E4C140431F}\offreg.dll 2012-08-24 07:39:42 9309624 โ€”-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317D39D5-883E-4BDF-8725-E0E4C140431F}\mpengine.dll 2012-08-15 04:56:03 503808 โ€”-a-w- C:\Windows\System32\srcore.dll 2012-08-15 04:56:03 43008 โ€”-a-w- C:\Windows\SysWow64\srclient.dll 2012-08-15 04:55:57 751104 โ€”-a-w- C:\Windows\System32\win32spl.dll 2012-08-15 04:55:56 67072 โ€”-a-w- C:\Windows\splwow64.exe 2012-08-15 04:55:56 559104 โ€”-a-w- C:\Windows\System32\spoolsv.exe 2012-08-15 04:55:56 492032 โ€”-a-w- C:\Windows\SysWow64\win32spl.dll 2012-08-15 04:55:53 59392 โ€”-a-w- C:\Windows\System32\browcli.dll 2012-08-15 04:55:53 41984 โ€”-a-w- C:\Windows\SysWow64\browcli.dll 2012-08-15 04:55:53 136704 โ€”-a-w- C:\Windows\System32\browser.dll 2012-08-15 04:55:50 3148800 โ€”-a-w- C:\Windows\System32\win32k.sys 2012-08-15 04:55:47 956928 โ€”-a-w- C:\Windows\System32\localspl.dll 2012-08-03 03:11:32 โ€”โ€”โ€“ dโ€”โ€“w- C:\Downloads . ==================== Find3M ==================== . 2012-08-15 12:49:06 70344 โ€”-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-15 12:49:06 426184 โ€”-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-07-03 18:46:44 24904 โ€”-a-w- C:\Windows\System32\drivers\mbam.sys 2012-06-29 03:56:34 2312704 โ€”-a-w- C:\Windows\System32\jscript9.dll 2012-06-29 03:49:11 1392128 โ€”-a-w- C:\Windows\System32\wininet.dll 2012-06-29 03:48:07 1494528 โ€”-a-w- C:\Windows\System32\inetcpl.cpl 2012-06-29 03:43:49 173056 โ€”-a-w- C:\Windows\System32\ieUnatt.exe 2012-06-29 03:39:48 2382848 โ€”-a-w- C:\Windows\System32\mshtml.tlb 2012-06-29 00:16:58 1800704 โ€”-a-w- C:\Windows\SysWow64\jscript9.dll 2012-06-29 00:09:01 1129472 โ€”-a-w- C:\Windows\SysWow64\wininet.dll 2012-06-29 00:08:59 1427968 โ€”-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-06-29 00:04:43 142848 โ€”-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-06-29 00:00:45 2382848 โ€”-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-06-06 13:49:52 1070152 โ€”-a-w- C:\Windows\SysWow64\MSCOMCTL.OCX 2012-06-06 06:06:16 2004480 โ€”-a-w- C:\Windows\System32\msxml6.dll 2012-06-06 06:06:16 1881600 โ€”-a-w- C:\Windows\System32\msxml3.dll 2012-06-06 06:02:54 1133568 โ€”-a-w- C:\Windows\System32\cdosys.dll 2012-06-06 05:05:52 1390080 โ€”-a-w- C:\Windows\SysWow64\msxml6.dll 2012-06-06 05:05:52 1236992 โ€”-a-w- C:\Windows\SysWow64\msxml3.dll 2012-06-06 05:03:06 805376 โ€”-a-w- C:\Windows\SysWow64\cdosys.dll 2012-06-02 22:15:31 2622464 โ€”-a-w- C:\Windows\System32\wucltux.dll 2012-06-02 22:15:08 99840 โ€”-a-w- C:\Windows\System32\wudriver.dll 2012-06-02 20:19:42 186752 โ€”-a-w- C:\Windows\System32\wuwebv.dll 2012-06-02 20:15:12 36864 โ€”-a-w- C:\Windows\System32\wuapp.exe 2012-06-02 05:50:10 458704 โ€”-a-w- C:\Windows\System32\drivers\cng.sys 2012-06-02 05:48:16 95600 โ€”-a-w- C:\Windows\System32\drivers\ksecdd.sys 2012-06-02 05:48:16 151920 โ€”-a-w- C:\Windows\System32\drivers\ksecpkg.sys 2012-06-02 05:45:31 340992 โ€”-a-w- C:\Windows\System32\schannel.dll 2012-06-02 05:44:21 307200 โ€”-a-w- C:\Windows\System32\ncrypt.dll 2012-06-02 04:40:42 22016 โ€”-a-w- C:\Windows\SysWow64\secur32.dll 2012-06-02 04:40:39 225280 โ€”-a-w- C:\Windows\SysWow64\schannel.dll 2012-06-02 04:39:10 219136 โ€”-a-w- C:\Windows\SysWow64\ncrypt.dll 2012-06-02 04:34:09 96768 โ€”-a-w- C:\Windows\SysWow64\sspicli.dll 2012-05-31 17:25:12 279656 โ€”โ€”w- C:\Windows\System32\MpSigStub.exe . ============= FINISH: 15:36:20.11 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 5/9/2011 10:13:12 AM System Uptime: 8/25/2012 2:56:24 PM (1 hours ago) . Motherboard: Gateway | | DX4850 Processor: Intelยฎ Coreโ„ข i5-2300 CPU @ 2.80GHz | CPU 1 | 2793/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 1384 GiB total, 1259.847 GiB free. D: is CDROM (UDF) E: is Removable F: is Removable G: is Removable H: is Removable I: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: Security Processor Loader Driver Device ID: ROOT\LEGACY_SPLDR\0000 Manufacturer: Name: Security Processor Loader Driver PNP Device ID: ROOT\LEGACY_SPLDR\0000 Service: spldr . ==== System Restore Points =================== . RP162: 7/20/2012 11:55:07 AM - Windows Update RP163: 7/24/2012 1:53:59 PM - Windows Update RP164: 7/31/2012 10:52:09 AM - Windows Update RP165: 8/3/2012 6:10:35 PM - Windows Update RP166: 8/7/2012 4:04:54 AM - Windows Update RP167: 8/10/2012 1:27:57 PM - Windows Update RP168: 8/14/2012 11:53:10 PM - Windows Update RP169: 8/15/2012 3:00:13 AM - Windows Update RP170: 8/21/2012 4:53:17 PM - Windows Update . ==== Installed Programs ====================== . . ABBYY FineReader 9.0 Sprint Acrobat.com Adobe AIR Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.5.1 MUI Advertising Center Apple Application Support Apple Software Update Battlecraft 1942 Battlecraft Vietnam Battlefield 1942 Battlefield 1942: Secret Weapons of WWII Battlefield 1942: The Road To Rome Battlefield Mod Development Toolkit 2.0 Beta Battlefield Vietnamโ„ข Battlefield Vietnam: WW2 Mod Best Buy pc app Canon Easy-PhotoPrint EX Canon Easy-WebPrint EX Canon MP Navigator EX 4.1 Canon MX880 series User Registration Canon My Printer Canon Solution Menu EX Canon Speed Dial Utility Continuum 0.40 CyberLink PowerDVD 10 D3DX10 Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Epson CreativeZone Epson Easy Photo Print 2 Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) Epson Easy Photo Print Plug-in for Windows Live Photo Gallery Epson Easy Photo Print Plug-in for Windows Live Photo Gallery Setup Epson Event Manager Epson FAX Utility Epson PC-FAX Driver EPSON Scan Express Zip File Compression Software Family Tree Maker 2012 File Extractor Free Download Manager 3.8 Gateway InfoCentre Gateway Recovery Management Gateway Registration Gateway ScreenSaver Gateway Updater Google Chrome Google Drive Google Update Helper Homeworld2 Identity Card ImagXpress Intelยฎ Control Center Intelยฎ Management Engine Components Intelยฎ Processor Graphics Intelยฎ Rapid Storage Technology Invade Earth Java Auto Updater Javaโ„ข 6 Update 31 Junk Mail filter update Kaspersky Anti-Virus 2012 LEGOยฎ Star Warsโ„ข: The Complete Saga LTCM Client Malwarebytes Anti-Malware version 1.62.0.1300 Mesh Runtime Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Home and Student 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Single Image 2010 Microsoft Office Word MUI (English) 2010 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Mozilla Firefox 12.0 (x86 en-US) Mozilla Maintenance Service MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero 9 Essentials Nero ControlCenter Nero DiscSpeed Nero DiscSpeed Help Nero DriveSpeed Nero DriveSpeed Help Nero Express Help Nero InfoTool Nero InfoTool Help Nero Installer Nero Online Upgrade Nero StartSmart Nero StartSmart Help Nero StartSmart OEM NeroExpress neroxml PageRage Toolbar PC Speed Maximizer v3.0 QuickTime Realtek High Definition Audio Driver Safari SaveTheChildren Reminder by We-Care.com v4.0.18.4 Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2553322) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553260) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589322) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition Security Update for Microsoft SharePoint Workspace 2010 (KB2566445) Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition Sid Meier's Civilization 4 Complete Sid Meier's Civilization IV Colonization Sid Meier's Civilization V Sins of a Solar Empire Steam Stykz for Windows 1.0.2 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2600217) Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553272) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598289) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Welcome Center Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Windows Media Encoder 9 Series Yahoo! BrowserPlus 2.9.8 Yahoo! Messenger Yahoo! Software Update Yahoo! Toolbar . ==== Event Viewer Messages From Past Week ======== . 8/25/2012 9:17:48 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LanmanServer service. 8/25/2012 8:35:25 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Multimedia Class Scheduler service, but this action failed with the following error: An instance of the service is already running. 8/25/2012 8:35:25 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ProfSvc service. 8/25/2012 8:35:25 AM, Error: Service Control Manager [7000] - The User Profile Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/25/2012 8:34:55 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SENS service. 8/25/2012 8:34:55 AM, Error: Service Control Manager [7000] - The System Event Notification Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/25/2012 8:34:25 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the iphlpsvc service. 8/25/2012 8:34:25 AM, Error: Service Control Manager [7000] - The IP Helper service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/25/2012 8:33:55 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the gpsvc service. 8/25/2012 8:33:55 AM, Error: Service Control Manager [7000] - The Group Policy Client service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/25/2012 8:33:25 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the IKEEXT service. 8/25/2012 8:33:25 AM, Error: Service Control Manager [7000] - The IKE and AuthIP IPsec Keying Modules service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/25/2012 4:16:59 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the wuauserv service. 8/25/2012 3:35:46 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 8/25/2012 2:57:31 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start. 8/25/2012 2:57:29 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 8/25/2012 2:57:29 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 8/25/2012 2:57:13 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 8/25/2012 2:57:00 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 8/25/2012 2:56:54 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache KLIF spldr Wanarpv6 8/25/2012 2:26:44 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Winmgmt service. 8/25/2012 2:02:17 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service. 8/25/2012 1:31:47 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running. 8/25/2012 1:31:47 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Computer Browser service, but this action failed with the following error: An instance of the service is already running. 8/25/2012 1:30:47 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Computer Browser service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 8/25/2012 1:29:47 PM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. . ==== End Of File =========================== aswMBR version 0.9.9.1665 Copyrightยฉ 2011 AVAST Software Run date: 2012-08-25 16:02:20 โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“ 16:02:20.032 OS Version: Windows x64 6.1.7601 Service Pack 1 16:02:20.032 Number of processors: 4 586 0x2A07 16:02:20.032 ComputerName: FLYINGFISH UserName: Platypus 16:02:21.857 Initialize success 16:03:36.162 AVAST engine defs: 12082501 16:03:48.903 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 16:03:48.903 Disk 0 Vendor: WDC_WD15 01.0 Size: 1430799MB BusType: 3 16:03:48.923 Disk 0 MBR read successfully 16:03:48.923 Disk 0 MBR scan 16:03:48.923 Disk 0 Windows 7 default MBR code 16:03:48.933 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13312 MB offset 2048 16:03:48.943 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 27265024 16:03:48.953 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 1417385 MB offset 27469824 16:03:48.983 Disk 0 scanning C:\Windows\system32\drivers 16:03:57.122 Service scanning 16:04:11.625 Modules scanning 16:04:11.625 Disk 0 trace - called modules: 16:04:11.641 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 16:04:11.641 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006dd0790] 16:04:11.656 3 CLASSPNP.SYS[fffff880021c943f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80054ed050] 16:04:14.121 AVAST engine scan C:\Windows 16:04:17.533 AVAST engine scan C:\Windows\system32 16:06:17.685 AVAST engine scan C:\Windows\system32\drivers 16:06:25.798 AVAST engine scan C:\Users\Platypus 16:15:59.821 AVAST engine scan C:\ProgramData 16:19:00.410 Scan finished successfully 23:06:56.654 Disk 0 MBR has been saved successfully to "C:\Users\Platypus\Documents\MBR.dat" 23:06:56.654 The log file has been saved successfully to "C:\Users\Platypus\Documents\aswMBR.txt"
Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
โ€”โ€”โ€”-
Hi Jeffce, I ran combofix from safe mode and it ran okay. Then it rebooted the computer and it loaded in regular mode from there, combo fix said it was preparing the log file for over three hours. I thought it froze so I closed it down. What should I do now? I tried to rerun it in regular mode. and like before I couldn't run a program. If I should rerun it again, when it reboots, how can I make it go into safe mode again? Thanks, FF
Hi Jeffce, I found this log in the combofix folder, this might be the logfile. Even though it says Kaspersky was enabled, after the second warning I think I disabled it completely. Thanks. ComboFix 12-08-25.04 - Platypus 08/26/2012 6:02:12.1.4 - x64 NETWORK Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6056.4828 [GMT -5:00] Running from: C:\Users\[removed]\Desktop\ComboFix.exe AV: Kaspersky Anti-Virus *Enabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984} SP: Kaspersky Anti-Virus *Enabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Users\Platypus\AppData\Local\Microsoft\Windows\Temporary Internet Files\{1672255E-9019-4132-A41F-2B4E8DBE4DE3}.xps C:\Users\Platypus\AppData\Local\Microsoft\Windows\Temporary Internet Files\{E1193DCD-2042-4FAA-9579-2793CD2ED289}.xps C:\Users\Platypus\AppData\Local\Microsoft\Windows\Temporary Internet Files\{E26DD294-8B1C-4F90-948D-BEE20B03B984}.xps C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed] C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\chrome.manifest C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\funmoods.css C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\funmoods.xul C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\images\pref.jpg C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\arwDwn.gif C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ae.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\bg.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ch.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\cn.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\cz.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\de.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\eg.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\en.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\es.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\fr.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\gr.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\he.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\il.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\it.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ja.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\jp.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\nl.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\no.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\pl.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\pt.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ro.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ru.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\sa.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\se.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\sv.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\tr.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ua.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\us.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\help_16.gif C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\home.gif C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\logo.png C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\privecy_16_hot.gif C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\tellafriend.gif C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\loader.xul C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\mtstart.js C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\preferences.xul C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\tmplt.js C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\install.rdf C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.rsa C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.sf C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\META-INF\manifest.mf C:\Users\Platypus\Documents\~WRL0004.tmp C:\Windows\iun6002.exe ((((((((((((((((((((((((( Files Created from 2012-07-26 to 2012-08-26 ))))))))))))))))))))))))))))))) 2012-08-26 11:08:57 . 2012-08-26 11:08:57 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Houdini\AppData\Local\temp 2012-08-26 11:08:57 . 2012-08-26 11:08:57 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Default\AppData\Local\temp 2012-08-26 11:08:57 . 2012-08-26 11:08:57 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Dan's iPhone\AppData\Local\temp 2012-08-26 11:08:57 . 2012-08-26 11:08:57 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Angelina's ipod.phn\AppData\Local\temp 2012-08-26 11:08:57 . 2012-08-26 11:08:57 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Angelina's iPhone\AppData\Local\temp 2012-08-24 07:39:42 . 2012-08-01 22:58:21 9309624 โ€”-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{317D39D5-883E-4BDF-8725-E0E4C140431F}\mpengine.dll 2012-08-15 04:56:03 . 2012-05-05 08:36:55 503808 โ€”-a-w- C:\Windows\system32\srcore.dll 2012-08-15 04:56:03 . 2012-05-05 07:46:52 43008 โ€”-a-w- C:\Windows\SysWow64\srclient.dll 2012-08-15 04:55:57 . 2012-02-11 06:43:47 751104 โ€”-a-w- C:\Windows\system32\win32spl.dll 2012-08-15 04:55:56 . 2012-02-11 06:36:02 559104 โ€”-a-w- C:\Windows\system32\spoolsv.exe 2012-08-15 04:55:56 . 2012-02-11 06:36:01 67072 โ€”-a-w- C:\Windows\splwow64.exe 2012-08-15 04:55:56 . 2012-02-11 05:43:49 492032 โ€”-a-w- C:\Windows\SysWow64\win32spl.dll 2012-08-15 04:55:53 . 2012-07-04 22:16:43 73216 โ€”-a-w- C:\Windows\system32\netapi32.dll 2012-08-15 04:55:53 . 2012-07-04 22:13:27 59392 โ€”-a-w- C:\Windows\system32\browcli.dll 2012-08-15 04:55:53 . 2012-07-04 22:13:27 136704 โ€”-a-w- C:\Windows\system32\browser.dll 2012-08-15 04:55:53 . 2012-07-04 21:14:34 41984 โ€”-a-w- C:\Windows\SysWow64\browcli.dll 2012-08-15 04:55:50 . 2012-07-18 18:15:06 3148800 โ€”-a-w- C:\Windows\system32\win32k.sys 2012-08-15 04:55:47 . 2012-05-14 05:26:34 956928 โ€”-a-w- C:\Windows\system32\localspl.dll 2012-08-03 03:11:32 . 2012-08-08 14:25:31 โ€”โ€”โ€“ dโ€”โ€“w- C:\Downloads . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2012-08-15 12:49:06 . 2012-04-07 13:48:09 426184 โ€”-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-08-15 12:49:06 . 2011-05-15 09:00:17 70344 โ€”-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-15 08:00:29 . 2011-05-31 23:48:40 62134624 โ€”-a-w- C:\Windows\system32\MRT.exe 2012-07-03 18:46:44 . 2012-07-09 03:29:21 24904 โ€”-a-w- C:\Windows\system32\drivers\mbam.sys 2012-06-09 05:43:10 . 2012-07-11 12:24:43 14172672 โ€”-a-w- C:\Windows\system32\shell32.dll 2012-06-06 13:49:52 . 2012-06-06 13:49:52 1070152 โ€”-a-w- C:\Windows\SysWow64\MSCOMCTL.OCX 2012-06-06 06:06:16 . 2012-07-11 12:24:46 2004480 โ€”-a-w- C:\Windows\system32\msxml6.dll 2012-06-06 06:06:16 . 2012-07-11 12:24:45 1881600 โ€”-a-w- C:\Windows\system32\msxml3.dll 2012-06-06 06:02:54 . 2012-07-11 12:24:39 1133568 โ€”-a-w- C:\Windows\system32\cdosys.dll 2012-06-06 05:05:52 . 2012-07-11 12:24:45 1390080 โ€”-a-w- C:\Windows\SysWow64\msxml6.dll 2012-06-06 05:05:52 . 2012-07-11 12:24:45 1236992 โ€”-a-w- C:\Windows\SysWow64\msxml3.dll 2012-06-06 05:03:06 . 2012-07-11 12:24:39 805376 โ€”-a-w- C:\Windows\SysWow64\cdosys.dll 2012-06-02 22:19:46 . 2012-06-21 16:31:25 38424 โ€”-a-w- C:\Windows\system32\wups.dll 2012-06-02 22:19:43 . 2012-06-21 16:32:24 2428952 โ€”-a-w- C:\Windows\system32\wuaueng.dll 2012-06-02 22:19:42 . 2012-06-21 16:32:24 57880 โ€”-a-w- C:\Windows\system32\wuauclt.exe 2012-06-02 22:19:42 . 2012-06-21 16:32:24 44056 โ€”-a-w- C:\Windows\system32\wups2.dll 2012-06-02 22:19:23 . 2012-06-21 16:31:24 701976 โ€”-a-w- C:\Windows\system32\wuapi.dll 2012-06-02 22:15:31 . 2012-06-21 16:32:24 2622464 โ€”-a-w- C:\Windows\system32\wucltux.dll 2012-06-02 22:15:08 . 2012-06-21 16:31:24 99840 โ€”-a-w- C:\Windows\system32\wudriver.dll 2012-06-02 20:19:42 . 2012-06-21 16:31:10 186752 โ€”-a-w- C:\Windows\system32\wuwebv.dll 2012-06-02 20:15:12 . 2012-06-21 16:31:10 36864 โ€”-a-w- C:\Windows\system32\wuapp.exe 2012-06-02 05:50:10 . 2012-07-11 12:24:40 458704 โ€”-a-w- C:\Windows\system32\drivers\cng.sys 2012-06-02 05:48:16 . 2012-07-11 12:24:40 95600 โ€”-a-w- C:\Windows\system32\drivers\ksecdd.sys 2012-06-02 05:48:16 . 2012-07-11 12:24:40 151920 โ€”-a-w- C:\Windows\system32\drivers\ksecpkg.sys 2012-06-02 05:45:31 . 2012-07-11 12:24:40 340992 โ€”-a-w- C:\Windows\system32\schannel.dll 2012-06-02 05:44:21 . 2012-07-11 12:24:40 307200 โ€”-a-w- C:\Windows\system32\ncrypt.dll 2012-06-02 04:40:42 . 2012-07-11 12:24:40 22016 โ€”-a-w- C:\Windows\SysWow64\secur32.dll 2012-06-02 04:40:39 . 2012-07-11 12:24:40 225280 โ€”-a-w- C:\Windows\SysWow64\schannel.dll 2012-06-02 04:39:10 . 2012-07-11 12:24:40 219136 โ€”-a-w- C:\Windows\SysWow64\ncrypt.dll 2012-06-02 04:34:09 . 2012-07-11 12:24:40 96768 โ€”-a-w- C:\Windows\SysWow64\sspicli.dll 2012-05-31 17:25:12 . 2011-05-10 02:33:45 279656 โ€”โ€”w- C:\Windows\system32\MpSigStub.exe ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll" [2012-06-11 19:08:00 1524056] [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin] [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{9565115d-c7d6-46d3-bd63-b67b481a4368}] 2011-05-09 09:49:38 176936 โ€”-a-w- C:\Program Files (x86)\PageRage\prxtbPag0.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{9565115d-c7d6-46d3-bd63-b67b481a4368}"= "C:\Program Files (x86)\PageRage\prxtbPag0.dll" [2011-05-09 09:49:38 176936] [HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="C:\Program Files (x86)\Steam\Steam.exe" [2012-08-15 13:07:07 1353080] "Messenger (Yahoo!)"="C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" [2011-11-24 05:05:44 6497592] "MobileDocuments"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 17:30:40 59240] "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe" [2012-07-20 20:17:14 12218904] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="C:\Program Files (x86)\Intel\Intelยฎ Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 02:32:30 283160] "Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 12:41:07 37296] "RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 08:08:56 87336] "EEventManager"="C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 16:12:12 976320] "FUFAXSTM"="C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-12-03 06:00:00 847872] "LTCM Client"="C:\Program Files (x86)\LTCM Client\ltcmClient.exe" [2009-08-05 17:36:18 1596096] "AppleSyncNotifier"="C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 19:01:12 59240] "CanonSolutionMenuEx"="C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-09-14 23:09:52 1213848] "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 01:06:18 59280] "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 07:37:53 843712] "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 19:02:04 254696] "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe" [2012-04-19 01:56:22 421888] "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" [2012-06-08 00:33:22 421776] "Malwarebytes' Anti-Malware"="C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 18:46:44 462920]
Hi, That would be what I was looking for but it looks like the log is missing a few parts. Could you check and be sure you copied all of it to your reply please? If not please go ahead and run ComboFix again and post that log that is created.
HI Jeff, Here's the new combofix log. When the computer reboots, how can I force it to start in safe mode? Thanks, FF ComboFix 12-08-25.04 - Platypus 08/26/2012 13:10:45.2.4 - x64 NETWORK Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6056.5260 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Kaspersky Anti-Virus *Enabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984} SP: Kaspersky Anti-Virus *Enabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . โ€”- Previous Run โ€”โ€”- . c:\users\Platypus\AppData\Local\Microsoft\Windows\Temporary Internet Files\{1672255E-9019-4132-A41F-2B4E8DBE4DE3}.xps c:\users\Platypus\AppData\Local\Microsoft\Windows\Temporary Internet Files\{E1193DCD-2042-4FAA-9579-2793CD2ED289}.xps c:\users\Platypus\AppData\Local\Microsoft\Windows\Temporary Internet Files\{E26DD294-8B1C-4F90-948D-BEE20B03B984}.xps c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\chrome.manifest c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\funmoods.css c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\funmoods.xul c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\images\pref.jpg c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\arwDwn.gif c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ae.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\bg.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ch.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\cn.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\cz.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\de.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\eg.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\en.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\es.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\fr.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\gr.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\he.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\il.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\it.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ja.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\jp.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\nl.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\no.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\pl.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\pt.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ro.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ru.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\sa.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\se.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\sv.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\tr.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\ua.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\flgs\us.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\help_16.gif c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\home.gif c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\logo.png c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\privecy_16_hot.gif c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\imgs\tellafriend.gif c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\loader.xul c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\mtstart.js c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\preferences.xul c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\tmplt.js c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\install.rdf c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.rsa c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.sf c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\META-INF\manifest.mf c:\users\Platypus\Documents\~WRL0004.tmp c:\windows\iun6002.exe . . ((((((((((((((((((((((((( Files Created from 2012-07-26 to 2012-08-26 ))))))))))))))))))))))))))))))) . . 2012-08-26 18:18 . 2012-08-26 18:18 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Houdini\AppData\Local\temp 2012-08-26 18:18 . 2012-08-26 18:18 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp 2012-08-26 18:18 . 2012-08-26 18:18 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Dan's iPhone\AppData\Local\temp 2012-08-26 18:18 . 2012-08-26 18:18 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Angelina's ipod.phn\AppData\Local\temp 2012-08-26 18:18 . 2012-08-26 18:18 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Angelina's iPhone\AppData\Local\temp 2012-08-24 07:39 . 2012-08-01 22:58 9309624 โ€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{317D39D5-883E-4BDF-8725-E0E4C140431F}\mpengine.dll 2012-08-15 04:56 . 2012-05-05 08:36 503808 โ€”-a-w- c:\windows\system32\srcore.dll 2012-08-15 04:56 . 2012-05-05 07:46 43008 โ€”-a-w- c:\windows\SysWow64\srclient.dll 2012-08-15 04:55 . 2012-02-11 06:43 751104 โ€”-a-w- c:\windows\system32\win32spl.dll 2012-08-15 04:55 . 2012-02-11 06:36 559104 โ€”-a-w- c:\windows\system32\spoolsv.exe 2012-08-15 04:55 . 2012-02-11 06:36 67072 โ€”-a-w- c:\windows\splwow64.exe 2012-08-15 04:55 . 2012-02-11 05:43 492032 โ€”-a-w- c:\windows\SysWow64\win32spl.dll 2012-08-15 04:55 . 2012-07-04 22:16 73216 โ€”-a-w- c:\windows\system32\netapi32.dll 2012-08-15 04:55 . 2012-07-04 22:13 59392 โ€”-a-w- c:\windows\system32\browcli.dll 2012-08-15 04:55 . 2012-07-04 22:13 136704 โ€”-a-w- c:\windows\system32\browser.dll 2012-08-15 04:55 . 2012-07-04 21:14 41984 โ€”-a-w- c:\windows\SysWow64\browcli.dll 2012-08-15 04:55 . 2012-07-18 18:15 3148800 โ€”-a-w- c:\windows\system32\win32k.sys 2012-08-15 04:55 . 2012-05-14 05:26 956928 โ€”-a-w- c:\windows\system32\localspl.dll 2012-08-03 03:11 . 2012-08-08 14:25 โ€”โ€”โ€“ dโ€”โ€“w- C:\Downloads . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-15 12:49 . 2012-04-07 13:48 426184 โ€”-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-08-15 12:49 . 2011-05-15 09:00 70344 โ€”-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-15 08:00 . 2011-05-31 23:48 62134624 โ€”-a-w- c:\windows\system32\MRT.exe 2012-07-03 18:46 . 2012-07-09 03:29 24904 โ€”-a-w- c:\windows\system32\drivers\mbam.sys 2012-06-09 05:43 . 2012-07-11 12:24 14172672 โ€”-a-w- c:\windows\system32\shell32.dll 2012-06-06 13:49 . 2012-06-06 13:49 1070152 โ€”-a-w- c:\windows\SysWow64\MSCOMCTL.OCX 2012-06-06 06:06 . 2012-07-11 12:24 2004480 โ€”-a-w- c:\windows\system32\msxml6.dll 2012-06-06 06:06 . 2012-07-11 12:24 1881600 โ€”-a-w- c:\windows\system32\msxml3.dll 2012-06-06 06:02 . 2012-07-11 12:24 1133568 โ€”-a-w- c:\windows\system32\cdosys.dll 2012-06-06 05:05 . 2012-07-11 12:24 1390080 โ€”-a-w- c:\windows\SysWow64\msxml6.dll 2012-06-06 05:05 . 2012-07-11 12:24 1236992 โ€”-a-w- c:\windows\SysWow64\msxml3.dll 2012-06-06 05:03 . 2012-07-11 12:24 805376 โ€”-a-w- c:\windows\SysWow64\cdosys.dll 2012-06-02 22:19 . 2012-06-21 16:31 38424 โ€”-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-21 16:32 2428952 โ€”-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-21 16:32 57880 โ€”-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-21 16:32 44056 โ€”-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-21 16:31 701976 โ€”-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-21 16:32 2622464 โ€”-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-21 16:31 99840 โ€”-a-w- c:\windows\system32\wudriver.dll 2012-06-02 20:19 . 2012-06-21 16:31 186752 โ€”-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 20:15 . 2012-06-21 16:31 36864 โ€”-a-w- c:\windows\system32\wuapp.exe 2012-06-02 05:50 . 2012-07-11 12:24 458704 โ€”-a-w- c:\windows\system32\drivers\cng.sys 2012-06-02 05:48 . 2012-07-11 12:24 95600 โ€”-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-06-02 05:48 . 2012-07-11 12:24 151920 โ€”-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-06-02 05:45 . 2012-07-11 12:24 340992 โ€”-a-w- c:\windows\system32\schannel.dll 2012-06-02 05:44 . 2012-07-11 12:24 307200 โ€”-a-w- c:\windows\system32\ncrypt.dll 2012-06-02 04:40 . 2012-07-11 12:24 22016 โ€”-a-w- c:\windows\SysWow64\secur32.dll 2012-06-02 04:40 . 2012-07-11 12:24 225280 โ€”-a-w- c:\windows\SysWow64\schannel.dll 2012-06-02 04:39 . 2012-07-11 12:24 219136 โ€”-a-w- c:\windows\SysWow64\ncrypt.dll 2012-06-02 04:34 . 2012-07-11 12:24 96768 โ€”-a-w- c:\windows\SysWow64\sspicli.dll 2012-05-31 17:25 . 2011-05-10 02:33 279656 โ€”โ€”w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((( SnapShot@2012-08-26_11.13.26 ))))))))))))))))))))))))))))))))))))))))) . + 2010-11-11 03:59 . 2012-08-26 18:21 42296 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-08-26 18:21 29476 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-05-09 15:14 . 2012-08-26 18:21 8488 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3322483911-3413046056-1756558932-1000_UserData.bin - 2012-08-26 11:12 . 2012-08-26 11:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-08-26 18:19 . 2012-08-26 18:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-08-26 18:19 . 2012-08-26 18:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-08-26 11:12 . 2012-08-26 11:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll" [2012-06-11 1524056] . [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{9565115d-c7d6-46d3-bd63-b67b481a4368}] 2011-05-09 09:49 176936 โ€”-a-w- c:\program files (x86)\PageRage\prxtbPag0.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{9565115d-c7d6-46d3-bd63-b67b481a4368}"= "c:\program files (x86)\PageRage\prxtbPag0.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-08-15 1353080] "Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2011-11-24 6497592] "MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240] "GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2012-07-20 12218904] "PC Speed Maximizer"="c:\program files (x86)\PC Speed Maximizer\SPMStarter.exe" [BU] "SPMTray"="c:\program files (x86)\PC Speed Maximizer\SPMTray.exe" [BU] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intelยฎ Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336] "EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320] "FUFAXSTM"="c:\program files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-12-03 847872] "LTCM Client"="c:\program files (x86)\LTCM Client\ltcmClient.exe" [2009-08-05 1596096] "AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240] "CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-09-14 1213848] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-08 421776] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] "avp"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe" [2011-04-25 202296] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2011-8-29 16032] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 116648] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 250056] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 116648] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-06 129976] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-05-11 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11864] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2011-03-11 29488] S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048] S2 GREGService;GREGService;c:\program files (x86)\Gateway\Registration\GREGsvc.exe [2010-01-08 23584] S2 IAStorDataMgrSvc;Intelยฎ Rapid Storage Technology;c:\program files (x86)\Intel\Intelยฎ Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944] S2 UNS;Intelยฎ Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe [2010-10-05 2655768] S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2010-01-29 243232] S3 e1cexpress;Intelยฎ PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [2010-09-21 313520] S3 IntcDAud;Intelยฎ Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-08-30 317440] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-03 22544] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904] S3 MEIx64;Intelยฎ Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-09-21 56344] . . Contents of the 'Scheduled Tasks' folder . 2012-08-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 12:49] . 2012-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . 2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . 2012-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3322483911-3413046056-1756558932-1000Core.job - c:\users\Platypus\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . 2012-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3322483911-3413046056-1756558932-1000UA.job - c:\users\Platypus\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . . โ€”โ€”โ€” X64 Entries โ€”โ€”โ€”โ€“ . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-09-03 11464296] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-10-06 166936] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-10-06 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-10-06 416792] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-07-26 2782096] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . โ€”โ€”- Supplementary Scan โ€”โ€”- .uStart Page = hxxp://www.google.com/ uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://start.funmoods.com/?f=1&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1Qzu0FzztD0FyEtCtCtD0BtB0A0E0B0B0EyEtN0D0TzutBtDtCtBtDyCtBzz&cr=1256813919 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - about:home FF - user.js: yahoo.ytff.general.dontshowhpoffer - true FF - user.js: extensions.funmoods.hmpg - true FF - user.js: extensions.funmoods.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1Qzu0FzztD0FyEtCtCtD0BtB0A0E0B0B0EyEtN0D0TzutBtDtCtBtDyCtBzz&cr=1256813919 FF - user.js: extensions.funmoods.dfltSrch - true FF - user.js: extensions.funmoods.srchPrvdr - Search FF - user.js: extensions.funmoods.dnsErr - true FF - user.js: extensions.funmoods_i.newTab - true FF - user.js: extensions.funmoods.newTabUrl - hxxp://start.funmoods.com/?f=2&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1Qzu0FzztD0FyEtCtCtD0BtB0A0E0B0B0EyEtN0D0TzutBtDtCtBtDyCtBzz&cr=1256813919 FF - user.js: extensions.funmoods.tlbrSrchUrl - FF - user.js: extensions.funmoods.id - 6823bbe4000000000000f80f4110b2ae FF - user.js: extensions.funmoods.instlDay - 15519 FF - user.js: extensions.funmoods.vrsn - 1.5.23.22 FF - user.js: extensions.funmoods.vrsni - 1.5.23.22 FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2218:56 FF - user.js: extensions.funmoods.prtnrId - funmoods FF - user.js: extensions.funmoods.prdct - funmoods FF - user.js: extensions.funmoods.aflt - fmtoby FF - user.js: extensions.funmoods_i.smplGrp - none FF - user.js: extensions.funmoods.tlbrId - base FF - user.js: extensions.funmoods.instlRef - fmtoby FF - user.js: extensions.funmoods.dfltLng - FF - user.js: extensions.funmoods.excTlbr - false FF - user.js: extensions.funmoods.autoRvrt - false FF - user.js: extensions.funmoods.envrmnt - production FF - user.js: extensions.funmoods.isdcmntcmplt - true FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0 FF - user.js: extentions.y2layers.installId - 454ca2c7-9d28-4ca2-ad7f-da1b947ff726 FF - user.js: extentions.y2layers.defaultEnableAppsList - pagerage,ezLooker,buzzdock,toprelatedtopics,twittube FF - user.js: extensions.autoDisableScopes - 14 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) WebBrowser-{9565115D-C7D6-46D3-BD63-B67B481A4368} - (no file) WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file) AddRemove-Battlecraft 19422.1 - c:\windows\iun6002.exe AddRemove-Battlecraft Vietnam1.2 - c:\windows\iun6002.exe AddRemove-ExpressZip - c:\program files (x86)\NCH Software\ExpressZip\uninst.exe AddRemove-File Extractor - c:\program files (x86)\File Extractor\uninstaller.exe AddRemove-MDT - c:\windows\iun6002.exe AddRemove-Invade Earth - c:\windows\system32\javaws.exe . . . โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€” . [HKEY_USERS\S-1-5-21-3322483911-3413046056-1756558932-1000\Software\AppDataLow\Software\Conduit\Community Alerts\Settings\Locales\e*n**ยยจgร‡-] "LP_LastUpdateTime"="0" "LP_LastCheckTime"=dword:4eb92a9a . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” Other Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe c:\program files (x86)\Yahoo!\Messenger\ymsgr_tray.exe c:\program files (x86)\Intel\Intelยฎ Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2012-08-26 13:26:30 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-26 18:26 . Pre-Run: 1,356,179,480,576 bytes free Post-Run: 1,356,077,740,032 bytes free . - - End Of File - - 090EDEE088AB7FF0CF7FD011F3351FD5
Hi,

Why would you want to boot to Safe Mode?
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the box below:


    ClearJavaCache::

    DDS::
    mStart Page = hxxp://start.funmoods.com/?f=1&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1Qzu0FzztD0FyEtCtCtD0BtB0A0E0B0B0EyEtN0D0TzutBtDtCtBtDyCtBzz&cr=1256813919
    mURLSearchHooks: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files (x86)\PageRage\prxtbPag0.dll
    BHO: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files (x86)\PageRage\prxtbPag0.dll
    TB: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files (x86)\PageRage\prxtbPag0.dll
    TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
    BHO-X64: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files (x86)\PageRage\prxtbPag0.dll
    TB-X64: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - C:\Program Files (x86)\PageRage\prxtbPag0.dll
    TB-X64: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File

    Firefox::
    FF - ProfilePath - c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms}
    FF - user.js: extensions.funmoods.hmpg - true
    FF - user.js: extensions.funmoods.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1Qzu0FzztD0FyEtCtCtD0BtB0A0E0B0B0EyEtN0D0TzutBtDtCtBtDyCtBzz&cr=1256813919
    FF - user.js: extensions.funmoods.dfltSrch - true
    FF - user.js: extensions.funmoods.srchPrvdr - Search
    FF - user.js: extensions.funmoods.dnsErr - true
    FF - user.js: extensions.funmoods_i.newTab - true
    FF - user.js: extensions.funmoods.newTabUrl - hxxp://start.funmoods.com/?f=2&a=fmtoby&chnl=fmtoby&cd=2XzutAtN2Y1L1Qzu0FzztD0FyEtCtCtD0BtB0A0E0B0B0EyEtN0D0TzutBtDtCtBtDyCtBzz&cr=1256813919
    FF - user.js: extensions.funmoods.tlbrSrchUrl -
    FF - user.js: extensions.funmoods.id - 6823bbe4000000000000f80f4110b2ae
    FF - user.js: extensions.funmoods.instlDay - 15519
    FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
    FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
    FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2218:56
    FF - user.js: extensions.funmoods.prtnrId - funmoods
    FF - user.js: extensions.funmoods.prdct - funmoods
    FF - user.js: extensions.funmoods.aflt - fmtoby
    FF - user.js: extensions.funmoods_i.smplGrp - none
    FF - user.js: extensions.funmoods.tlbrId - base
    FF - user.js: extensions.funmoods.instlRef - fmtoby
    FF - user.js: extensions.funmoods.dfltLng -
    FF - user.js: extensions.funmoods.excTlbr - false
    FF - user.js: extensions.funmoods.autoRvrt - false
    FF - user.js: extensions.funmoods.envrmnt - production
    FF - user.js: extensions.funmoods.isdcmntcmplt - true
    FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0

    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{9565115d-c7d6-46d3-bd63-b67b481a4368}"=-
    [-HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
โ€”โ€”โ€”-
Hi Jeff, I wanted to reboot into safe mode since it was only in safe mode that i could use the internet and launch programs successfully. After this last reboot, IE still will not work but FF works but very slowly. Here's the latest log. ComboFix 12-08-25.04 - Platypus 08/26/2012 18:58:02.3.4 - x64 NETWORK Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6056.5206 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Platypus\Desktop\CFScript.txt AV: Kaspersky Anti-Virus *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984} SP: Kaspersky Anti-Virus *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2012-07-27 to 2012-08-27 ))))))))))))))))))))))))))))))) . . 2012-08-27 00:06 . 2012-08-27 00:06 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2012-08-27 00:06 . 2012-08-27 00:06 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Houdini\AppData\Local\temp 2012-08-27 00:06 . 2012-08-27 00:06 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp 2012-08-27 00:06 . 2012-08-27 00:06 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Dan's iPhone\AppData\Local\temp 2012-08-27 00:06 . 2012-08-27 00:06 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Angelina's ipod.phn\AppData\Local\temp 2012-08-27 00:06 . 2012-08-27 00:06 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Angelina's iPhone\AppData\Local\temp 2012-08-24 07:39 . 2012-08-01 22:58 9309624 โ€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{317D39D5-883E-4BDF-8725-E0E4C140431F}\mpengine.dll 2012-08-15 04:56 . 2012-05-05 08:36 503808 โ€”-a-w- c:\windows\system32\srcore.dll 2012-08-15 04:56 . 2012-05-05 07:46 43008 โ€”-a-w- c:\windows\SysWow64\srclient.dll 2012-08-15 04:55 . 2012-02-11 06:43 751104 โ€”-a-w- c:\windows\system32\win32spl.dll 2012-08-15 04:55 . 2012-02-11 06:36 559104 โ€”-a-w- c:\windows\system32\spoolsv.exe 2012-08-15 04:55 . 2012-02-11 06:36 67072 โ€”-a-w- c:\windows\splwow64.exe 2012-08-15 04:55 . 2012-02-11 05:43 492032 โ€”-a-w- c:\windows\SysWow64\win32spl.dll 2012-08-15 04:55 . 2012-07-04 22:16 73216 โ€”-a-w- c:\windows\system32\netapi32.dll 2012-08-15 04:55 . 2012-07-04 22:13 59392 โ€”-a-w- c:\windows\system32\browcli.dll 2012-08-15 04:55 . 2012-07-04 22:13 136704 โ€”-a-w- c:\windows\system32\browser.dll 2012-08-15 04:55 . 2012-07-04 21:14 41984 โ€”-a-w- c:\windows\SysWow64\browcli.dll 2012-08-15 04:55 . 2012-07-18 18:15 3148800 โ€”-a-w- c:\windows\system32\win32k.sys 2012-08-15 04:55 . 2012-05-14 05:26 956928 โ€”-a-w- c:\windows\system32\localspl.dll 2012-08-03 03:11 . 2012-08-08 14:25 โ€”โ€”โ€“ dโ€”โ€“w- C:\Downloads . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-15 12:49 . 2012-04-07 13:48 426184 โ€”-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-08-15 12:49 . 2011-05-15 09:00 70344 โ€”-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-15 08:00 . 2011-05-31 23:48 62134624 โ€”-a-w- c:\windows\system32\MRT.exe 2012-07-03 18:46 . 2012-07-09 03:29 24904 โ€”-a-w- c:\windows\system32\drivers\mbam.sys 2012-06-09 05:43 . 2012-07-11 12:24 14172672 โ€”-a-w- c:\windows\system32\shell32.dll 2012-06-06 13:49 . 2012-06-06 13:49 1070152 โ€”-a-w- c:\windows\SysWow64\MSCOMCTL.OCX 2012-06-06 06:06 . 2012-07-11 12:24 2004480 โ€”-a-w- c:\windows\system32\msxml6.dll 2012-06-06 06:06 . 2012-07-11 12:24 1881600 โ€”-a-w- c:\windows\system32\msxml3.dll 2012-06-06 06:02 . 2012-07-11 12:24 1133568 โ€”-a-w- c:\windows\system32\cdosys.dll 2012-06-06 05:05 . 2012-07-11 12:24 1390080 โ€”-a-w- c:\windows\SysWow64\msxml6.dll 2012-06-06 05:05 . 2012-07-11 12:24 1236992 โ€”-a-w- c:\windows\SysWow64\msxml3.dll 2012-06-06 05:03 . 2012-07-11 12:24 805376 โ€”-a-w- c:\windows\SysWow64\cdosys.dll 2012-06-02 22:19 . 2012-06-21 16:31 38424 โ€”-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-21 16:32 2428952 โ€”-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-21 16:32 57880 โ€”-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-21 16:32 44056 โ€”-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-21 16:31 701976 โ€”-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-21 16:32 2622464 โ€”-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-21 16:31 99840 โ€”-a-w- c:\windows\system32\wudriver.dll 2012-06-02 20:19 . 2012-06-21 16:31 186752 โ€”-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 20:15 . 2012-06-21 16:31 36864 โ€”-a-w- c:\windows\system32\wuapp.exe 2012-06-02 05:50 . 2012-07-11 12:24 458704 โ€”-a-w- c:\windows\system32\drivers\cng.sys 2012-06-02 05:48 . 2012-07-11 12:24 95600 โ€”-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-06-02 05:48 . 2012-07-11 12:24 151920 โ€”-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-06-02 05:45 . 2012-07-11 12:24 340992 โ€”-a-w- c:\windows\system32\schannel.dll 2012-06-02 05:44 . 2012-07-11 12:24 307200 โ€”-a-w- c:\windows\system32\ncrypt.dll 2012-06-02 04:40 . 2012-07-11 12:24 22016 โ€”-a-w- c:\windows\SysWow64\secur32.dll 2012-06-02 04:40 . 2012-07-11 12:24 225280 โ€”-a-w- c:\windows\SysWow64\schannel.dll 2012-06-02 04:39 . 2012-07-11 12:24 219136 โ€”-a-w- c:\windows\SysWow64\ncrypt.dll 2012-06-02 04:34 . 2012-07-11 12:24 96768 โ€”-a-w- c:\windows\SysWow64\sspicli.dll 2012-05-31 17:25 . 2011-05-10 02:33 279656 โ€”โ€”w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((( SnapShot@2012-08-26_11.13.26 ))))))))))))))))))))))))))))))))))))))))) . + 2010-11-11 03:59 . 2012-08-26 18:21 42296 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-08-26 18:21 29476 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-05-09 15:14 . 2012-08-26 18:21 8488 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3322483911-3413046056-1756558932-1000_UserData.bin - 2012-08-26 11:12 . 2012-08-26 11:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-08-27 00:06 . 2012-08-27 00:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-08-27 00:06 . 2012-08-27 00:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-08-26 11:12 . 2012-08-26 11:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll" [2012-06-11 1524056] . [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-08-15 1353080] "Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2011-11-24 6497592] "MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240] "GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2012-07-20 12218904] "PC Speed Maximizer"="c:\program files (x86)\PC Speed Maximizer\SPMStarter.exe" [BU] "SPMTray"="c:\program files (x86)\PC Speed Maximizer\SPMTray.exe" [BU] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intelยฎ Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336] "EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320] "FUFAXSTM"="c:\program files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-12-03 847872] "LTCM Client"="c:\program files (x86)\LTCM Client\ltcmClient.exe" [2009-08-05 1596096] "AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240] "CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-09-14 1213848] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-08 421776] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] "avp"="c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe" [2011-04-25 202296] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2011-8-29 16032] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 116648] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 250056] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 116648] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-06 129976] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-05-11 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11864] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2011-03-11 29488] S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048] S2 GREGService;GREGService;c:\program files (x86)\Gateway\Registration\GREGsvc.exe [2010-01-08 23584] S2 IAStorDataMgrSvc;Intelยฎ Rapid Storage Technology;c:\program files (x86)\Intel\Intelยฎ Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944] S2 UNS;Intelยฎ Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe [2010-10-05 2655768] S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2010-01-29 243232] S3 e1cexpress;Intelยฎ PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [2010-09-21 313520] S3 IntcDAud;Intelยฎ Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-08-30 317440] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-03 22544] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904] S3 MEIx64;Intelยฎ Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-09-21 56344] . . Contents of the 'Scheduled Tasks' folder . 2012-08-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 12:49] . 2012-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . 2012-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . 2012-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3322483911-3413046056-1756558932-1000Core.job - c:\users\Platypus\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . 2012-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3322483911-3413046056-1756558932-1000UA.job - c:\users\Platypus\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . . โ€”โ€”โ€” X64 Entries โ€”โ€”โ€”โ€“ . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-09-03 11464296] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-10-06 166936] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-10-06 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-10-06 416792] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-07-26 2782096] . โ€”โ€”- Supplementary Scan โ€”โ€”- . uStart Page = hxxp://www.google.com/ uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\ FF - prefs.js: browser.startup.homepage - about:home FF - user.js: yahoo.ytff.general.dontshowhpoffer - true FF - user.js: extentions.y2layers.installId - 454ca2c7-9d28-4ca2-ad7f-da1b947ff726 FF - user.js: extentions.y2layers.defaultEnableAppsList - pagerage,ezLooker,buzzdock,toprelatedtopics,twittube FF - user.js: extensions.autoDisableScopes - 14 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) . . . โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€” . [HKEY_USERS\S-1-5-21-3322483911-3413046056-1756558932-1000\Software\AppDataLow\Software\Conduit\Community Alerts\Settings\Locales\e*n**ยยจgร‡-] "LP_LastUpdateTime"="0" "LP_LastCheckTime"=dword:4eb92a9a . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” Other Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe c:\program files (x86)\Yahoo!\Messenger\ymsgr_tray.exe c:\program files (x86)\Intel\Intelยฎ Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2012-08-26 19:14:01 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-27 00:14 ComboFix2.txt 2012-08-26 18:26 . Pre-Run: 1,356,166,520,832 bytes free Post-Run: 1,355,822,460,928 bytes free . - - End Of File - - 24607CD0BE2AE87A6B7F3E6294CDF6F9
Hi,

Ok good job. :)

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
โ€”โ€”โ€”-

Clear Java Cache

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
โ€”โ€”โ€”-

I see that your Java software is out of date. Please go to Start >> Control Panel >> Programs and Features >> delete all versions of Java.

Now download and install the newest version from here >> http://java.com/en/download/index.jsp
โ€”โ€”โ€”โ€”-

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text fileโ€ฆ"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
โ€”โ€”โ€”-

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
โ€”โ€”โ€”-

In your next reply please post the logs made by Malwarebytes, ESET and Farbar Service Scanner.
Hi, here's the latest set of logs. ESET C:\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe a variant of Win32/SpeedingUpMyPC application C:\Program Files (x86)\Yontoo Layers Runtime\YontooIEClient.dll a variant of Win32/Adware.Yontoo.A application C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\ProgramData\{D2044A97-3875-40E7-8161-DA975C6BA7CF}\setup.res a variant of Win32/HiddenStart.A application C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Users\All Users\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Users\All Users\{D2044A97-3875-40E7-8161-DA975C6BA7CF}\setup.res a variant of Win32/HiddenStart.A application C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\overlay.js Win32/Adware.Yontoo application C:\Users\Platypus\Downloads\registrybooster.exe a variant of Win32/RegistryBooster application Farbar Service Scanner Version: 06-08-2012 Ran by [removed] (administrator) on 26-08-2012 at 22:07:07 Running from "C:\Users\Platypus\Downloads" Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.26.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Platypus :: FLYINGFISH [administrator] 8/26/2012 8:01:42 PM mbam-log-2012-08-26 (20-01-42).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 279899 Time elapsed: 2 minute(s), 49 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the box below:


    ClearJavaCache::

    File::
    C:\Program Files (x86)\Yontoo Layers Runtime\YontooIEClient.dll
    C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
    C:\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll
    C:\ProgramData\{D2044A97-3875-40E7-8161-DA975C6BA7CF}\setup.res
    C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
    C:\Users\All Users\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll
    C:\Users\All Users\{D2044A97-3875-40E7-8161-DA975C6BA7CF}\setup.res
    C:\Users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\overlay.js

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
โ€”โ€”โ€”-

How is your system running now? :)
Hi Jeff, When i drag the CFScript into combofix it runs through its normal start up but then the blue box won't appear. I had to reboot and strt in safe mode to get combofix to run correctly. Here's the log it produced. ComboFix 12-08-25.04 - Platypus 08/27/2012 18:56:10.4.4 - x64 NETWORK Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6056.4966 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Platypus\Desktop\CFScript.txt AV: Kaspersky Anti-Virus *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984} SP: Kaspersky Anti-Virus *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . FILE :: "c:\program files (x86)\Yontoo Layers Runtime\YontooIEClient.dll" "c:\programdata\{D2044A97-3875-40E7-8161-DA975C6BA7CF}\setup.res" "c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll" "c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll" "c:\users\All Users\{D2044A97-3875-40E7-8161-DA975C6BA7CF}\setup.res" "c:\users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll" "c:\users\All Users\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll" "c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\overlay.js" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Yontoo Layers Runtime\YontooIEClient.dll c:\programdata\{D2044A97-3875-40E7-8161-DA975C6BA7CF}\setup.res c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll c:\programdata\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll c:\users\All Users\{D2044A97-3875-40E7-8161-DA975C6BA7CF}\setup.res c:\users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll c:\users\All Users\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\extensions\[removed]\content\overlay.js . . ((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-28 ))))))))))))))))))))))))))))))) . . 2012-08-28 00:03 . 2012-08-28 00:03 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2012-08-28 00:03 . 2012-08-28 00:03 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Houdini\AppData\Local\temp 2012-08-28 00:03 . 2012-08-28 00:03 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp 2012-08-28 00:03 . 2012-08-28 00:03 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Dan's iPhone\AppData\Local\temp 2012-08-28 00:03 . 2012-08-28 00:03 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Angelina's ipod.phn\AppData\Local\temp 2012-08-28 00:03 . 2012-08-28 00:03 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Angelina's iPhone\AppData\Local\temp 2012-08-27 01:10 . 2012-08-27 01:10 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\ESET 2012-08-27 01:08 . 2012-08-27 01:08 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\Java 2012-08-27 01:08 . 2012-08-27 01:07 821736 โ€”-a-w- c:\windows\SysWow64\npDeployJava1.dll 2012-08-27 01:07 . 2012-08-27 01:07 95208 โ€”-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2012-08-27 01:07 . 2012-08-27 01:07 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\McAfee 2012-08-27 00:56 . 2012-07-03 18:46 24904 โ€”-a-w- c:\windows\system32\drivers\mbam.sys 2012-08-27 00:43 . 2012-08-27 00:43 770384 โ€”-a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll 2012-08-27 00:43 . 2012-08-27 00:43 421200 โ€”-a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll 2012-08-24 07:39 . 2012-08-01 22:58 9309624 โ€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{317D39D5-883E-4BDF-8725-E0E4C140431F}\mpengine.dll 2012-08-15 04:56 . 2012-05-05 08:36 503808 โ€”-a-w- c:\windows\system32\srcore.dll 2012-08-15 04:56 . 2012-05-05 07:46 43008 โ€”-a-w- c:\windows\SysWow64\srclient.dll 2012-08-15 04:55 . 2012-02-11 06:43 751104 โ€”-a-w- c:\windows\system32\win32spl.dll 2012-08-15 04:55 . 2012-02-11 06:36 559104 โ€”-a-w- c:\windows\system32\spoolsv.exe 2012-08-15 04:55 . 2012-02-11 06:36 67072 โ€”-a-w- c:\windows\splwow64.exe 2012-08-15 04:55 . 2012-02-11 05:43 492032 โ€”-a-w- c:\windows\SysWow64\win32spl.dll 2012-08-15 04:55 . 2012-07-04 22:16 73216 โ€”-a-w- c:\windows\system32\netapi32.dll 2012-08-15 04:55 . 2012-07-04 22:13 59392 โ€”-a-w- c:\windows\system32\browcli.dll 2012-08-15 04:55 . 2012-07-04 22:13 136704 โ€”-a-w- c:\windows\system32\browser.dll 2012-08-15 04:55 . 2012-07-04 21:14 41984 โ€”-a-w- c:\windows\SysWow64\browcli.dll 2012-08-15 04:55 . 2012-07-18 18:15 3148800 โ€”-a-w- c:\windows\system32\win32k.sys 2012-08-15 04:55 . 2012-05-14 05:26 956928 โ€”-a-w- c:\windows\system32\localspl.dll 2012-08-03 03:11 . 2012-08-08 14:25 โ€”โ€”โ€“ dโ€”โ€“w- C:\Downloads . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-27 01:07 . 2012-03-12 18:14 746984 โ€”-a-w- c:\windows\SysWow64\deployJava1.dll 2012-08-15 12:49 . 2012-04-07 13:48 426184 โ€”-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-08-15 12:49 . 2011-05-15 09:00 70344 โ€”-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-15 08:00 . 2011-05-31 23:48 62134624 โ€”-a-w- c:\windows\system32\MRT.exe 2012-06-09 05:43 . 2012-07-11 12:24 14172672 โ€”-a-w- c:\windows\system32\shell32.dll 2012-06-06 13:49 . 2012-06-06 13:49 1070152 โ€”-a-w- c:\windows\SysWow64\MSCOMCTL.OCX 2012-06-06 06:06 . 2012-07-11 12:24 2004480 โ€”-a-w- c:\windows\system32\msxml6.dll 2012-06-06 06:06 . 2012-07-11 12:24 1881600 โ€”-a-w- c:\windows\system32\msxml3.dll 2012-06-06 06:02 . 2012-07-11 12:24 1133568 โ€”-a-w- c:\windows\system32\cdosys.dll 2012-06-06 05:05 . 2012-07-11 12:24 1390080 โ€”-a-w- c:\windows\SysWow64\msxml6.dll 2012-06-06 05:05 . 2012-07-11 12:24 1236992 โ€”-a-w- c:\windows\SysWow64\msxml3.dll 2012-06-06 05:03 . 2012-07-11 12:24 805376 โ€”-a-w- c:\windows\SysWow64\cdosys.dll 2012-06-02 22:19 . 2012-06-21 16:31 38424 โ€”-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-21 16:32 2428952 โ€”-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-21 16:32 57880 โ€”-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-21 16:32 44056 โ€”-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-21 16:31 701976 โ€”-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-21 16:32 2622464 โ€”-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-21 16:31 99840 โ€”-a-w- c:\windows\system32\wudriver.dll 2012-06-02 20:19 . 2012-06-21 16:31 186752 โ€”-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 20:15 . 2012-06-21 16:31 36864 โ€”-a-w- c:\windows\system32\wuapp.exe 2012-06-02 05:50 . 2012-07-11 12:24 458704 โ€”-a-w- c:\windows\system32\drivers\cng.sys 2012-06-02 05:48 . 2012-07-11 12:24 95600 โ€”-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-06-02 05:48 . 2012-07-11 12:24 151920 โ€”-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-06-02 05:45 . 2012-07-11 12:24 340992 โ€”-a-w- c:\windows\system32\schannel.dll 2012-06-02 05:44 . 2012-07-11 12:24 307200 โ€”-a-w- c:\windows\system32\ncrypt.dll 2012-06-02 04:40 . 2012-07-11 12:24 22016 โ€”-a-w- c:\windows\SysWow64\secur32.dll 2012-06-02 04:40 . 2012-07-11 12:24 225280 โ€”-a-w- c:\windows\SysWow64\schannel.dll 2012-06-02 04:39 . 2012-07-11 12:24 219136 โ€”-a-w- c:\windows\SysWow64\ncrypt.dll 2012-06-02 04:34 . 2012-07-11 12:24 96768 โ€”-a-w- c:\windows\SysWow64\sspicli.dll 2012-05-31 17:25 . 2011-05-10 02:33 279656 โ€”โ€”w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((( SnapShot@2012-08-26_11.13.26 ))))))))))))))))))))))))))))))))))))))))) . + 2010-11-11 03:59 . 2012-08-28 00:10 43760 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-08-28 00:10 29540 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-05-09 15:14 . 2012-08-28 00:10 8868 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3322483911-3413046056-1756558932-1000_UserData.bin - 2012-08-26 11:12 . 2012-08-26 11:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-08-28 00:04 . 2012-08-28 00:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-08-28 00:04 . 2012-08-28 00:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-08-26 11:12 . 2012-08-26 11:12 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-08-27 01:08 . 2012-08-27 01:07 246760 c:\windows\SysWOW64\javaws.exe + 2012-08-27 01:07 . 2012-08-27 01:07 174056 c:\windows\SysWOW64\javaw.exe + 2012-08-27 01:07 . 2012-08-27 01:07 174056 c:\windows\SysWOW64\java.exe + 2009-07-14 05:01 . 2012-08-27 00:40 385772 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2012-08-27 01:08 . 2012-08-27 01:08 179200 c:\windows\Installer\12db26.msi + 2011-07-05 21:43 . 2012-08-27 00:40 14261748 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3322483911-3413046056-1756558932-1000-12288.dat + 2012-08-27 01:07 . 2012-08-27 01:07 27545600 c:\windows\Installer\12db21.msi . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll" [2012-06-11 1524056] . [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-08-15 1353080] "Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2011-11-24 6497592] "MobileDocuments"="c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe" [2012-02-23 59240] "GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2012-07-20 12218904] "PC Speed Maximizer"="c:\program files (x86)\PC Speed Maximizer\SPMStarter.exe" [BU] "SPMTray"="c:\program files (x86)\PC Speed Maximizer\SPMTray.exe" [BU] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intelยฎ Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336] "EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320] "FUFAXSTM"="c:\program files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-12-03 847872] "LTCM Client"="c:\program files (x86)\LTCM Client\ltcmClient.exe" [2009-08-05 1596096] "AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-09-27 59240] "CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-09-14 1213848] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-08 421776] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2011-8-29 16032] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 116648] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 250056] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 116648] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-08-27 113120] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-05-11 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11864] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2011-03-11 29488] S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048] S2 GREGService;GREGService;c:\program files (x86)\Gateway\Registration\GREGsvc.exe [2010-01-08 23584] S2 IAStorDataMgrSvc;Intelยฎ Rapid Storage Technology;c:\program files (x86)\Intel\Intelยฎ Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944] S2 UNS;Intelยฎ Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe [2010-10-05 2655768] S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2010-01-29 243232] S3 e1cexpress;Intelยฎ PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys [2010-09-21 313520] S3 IntcDAud;Intelยฎ Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-08-30 317440] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-03 22544] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904] S3 MEIx64;Intelยฎ Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-09-21 56344] . . Contents of the 'Scheduled Tasks' folder . 2012-08-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 12:49] . 2012-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . 2012-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . 2012-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3322483911-3413046056-1756558932-1000Core.job - c:\users\Platypus\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . 2012-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3322483911-3413046056-1756558932-1000UA.job - c:\users\Platypus\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-22 16:52] . . โ€”โ€”โ€” X64 Entries โ€”โ€”โ€”โ€“ . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2012-07-20 20:17 755544 โ€”-a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-09-03 11464296] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-10-06 166936] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-10-06 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-10-06 416792] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-07-26 2782096] . โ€”โ€”- Supplementary Scan โ€”โ€”- . uStart Page = hxxp://www.google.com/ uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Download all with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Platypus\AppData\Roaming\Mozilla\Firefox\Profiles\1a1oitt5.default\ FF - prefs.js: browser.startup.homepage - about:home FF - user.js: yahoo.ytff.general.dontshowhpoffer - true FF - user.js: extentions.y2layers.installId - 454ca2c7-9d28-4ca2-ad7f-da1b947ff726 FF - user.js: extentions.y2layers.defaultEnableAppsList - pagerage,ezLooker,buzzdock,toprelatedtopics,twittube FF - user.js: extensions.autoDisableScopes - 14 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) . . . โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€” . [HKEY_USERS\S-1-5-21-3322483911-3413046056-1756558932-1000\Software\AppDataLow\Software\Conduit\Community Alerts\Settings\Locales\e*n**ยยจgร‡-] "LP_LastUpdateTime"="0" "LP_LastCheckTime"=dword:4eb92a9a . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” Other Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files (x86)\Intel\Intelยฎ Management Engine Components\LMS\LMS.exe c:\program files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe c:\program files (x86)\Yahoo!\Messenger\ymsgr_tray.exe . ************************************************************************** . Completion time: 2012-08-27 19:14:52 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-28 00:14 ComboFix2.txt 2012-08-27 00:14 ComboFix3.txt 2012-08-26 18:26 . Pre-Run: 1,356,921,479,168 bytes free Post-Run: 1,356,632,076,288 bytes free . - - End Of File - - 363F7849BE7207F9448E1EBD2EA1C122
Hi,

Please download the file I have attached to your Desktop, save it as CFScript.txt >> file type is All Files >> drag onto ComboFix icon. Save the log that is made for your next reply.
โ€”โ€”

FRST

Download Farbar Recovery Scan Tool64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

โ€”โ€”โ€”-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI