This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with something... [Closed]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, if anyone could help me out here that would be great. My computer has been all sorts of messed up I have tried many things to fix it but to no avail. No matter what antivirus I use its scanners will be disabled before i can use them. When I boot into safe mode (with networking) I have no networking. There are two new wireless networks that you can see on any wi-fi applicable device "worm virus" & "trojan horse" networks.

Here is my Hijackthis Log:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:59:19 PM, on 8/30/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Safe mode

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
R3 - URLSearchHook: (no name) - {37483b40-c254-4a72-bda4-22ee90182c1e} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: CrossriderApp0003491 - {11111111-1111-1111-1111-110011341191} - C:\Program Files\Vid-Saver\Vid-Saver.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O3 - Toolbar: (no name) - {687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Bdagent] C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe
O4 - HKLM\..\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
O4 - HKCU\..\Run: [Game Fire] C:\Program Files\Smart PC Utilities\Game Fire\GFTray.exe /START
O4 - HKCU\..\Run: [Google Update] "C:\Users\Nemesis\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\drivermax.exe" -agent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O10 - Unknown file in Winsock LSP: c:\program files\bitdefender\bitdefender 2013\bdprovider.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: SafeBox - Bitdefender - C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
O23 - Service: Bitdefender Desktop Update Service (UPDATESRV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe
O23 - Service: Bitdefender Virus Shield (VSSERV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe

–
End of file - 9840 bytes
Hi UniversallyDope,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I'd like to see a better scan.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.

Hi UniversallyDope,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I'd like to see a better scan.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.

Hey, thank you for being so helpful!
I did as you said…

.
DDS (Ver_2011-08-26.01) - NTFSx86 MINIMAL
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.4.1
Run by [removed] at 14:09:57 on 2012-09-03
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3327.2540 [GMT -7:00]
.
AV: Bitdefender Antivirus *Disabled/Outdated* {98CD50CE-5097-4098-9669-6C401FB3969C}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Bitdefender Antispyware *Disabled/Outdated* {23ACB12A-76AD-4F16-ACD9-57326434DC21}
FW: Bitdefender Firewall *Enabled* {A0F6D1EB-1AF8-41C0-BD36-C575E160D1E7}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\helppane.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: Vid-Saver: {11111111-1111-1111-1111-110011341191} - c:\program files\vid-saver\Vid-Saver.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
TB: {687578b9-7132-4a7a-80e4-30ee31099e03} - No File
uRun: [Game Fire] c:\program files\smart pc utilities\game fire\GFTray.exe /START
uRun: [Google Update] "c:\users\nemesis\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [DriverMax] "c:\program files\innovative solutions\drivermax\drivermax.exe" -agent
uRun: [DriverMax_RESTART]
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [Bdagent] c:\program files\bitdefender\bitdefender 2013\bdagent.exe
mRun: [Logitech Download Assistant] c:\windows\system32\rundll32.exe c:\windows\system32\LogiLDA.dll,LogiFetch
StartupFolder: c:\users\nemesis\appdata\roaming\micros~1\windows\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdock\ObjectDock.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\program files\bitdefender\bitdefender 2013\BdProvider.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{7BFF42FF-C1DF-4016-BBBD-A4428145530B} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{7CED2FF4-D652-42E6-96E1-8A138F030240} : DhcpNameServer = 192.168.2.1
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~1\common~1\stardock\MCPCore.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\nemesis\appdata\roaming\mozilla\firefox\profiles\h5bpgv0x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource;=3&q;={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=112558&tt;=2912_1&babsrc;=HP_ss&mntrId;=a031ff6d00000000000000225fef33ba
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource;=2&q;=
FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\citrix\ica client\npicaN.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\users\nemesis\appdata\local\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\users\nemesis\appdata\roaming\mozilla\firefox\profiles\h5bpgv0x.default\extensions\{37483b40-c254-4a72-bda4-22ee90182c1e}\plugins\np-mswmp.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_271.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
—- FIREFOX POLICIES —-
FF - user.js: extensions.incredibar_i.newTab - false
FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6R8ypQLh0X&loc;=IB_TB&i;=26&search;=
FF - user.js: extensions.incredibar_i.id - a031ff6d00000000000000225fef33ba
FF - user.js: extensions.incredibar_i.instlDay - 15530
FF - user.js: extensions.incredibar_i.vrsn - [removed]
FF - user.js: extensions.incredibar_i.vrsni - [removed]
FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1417:40:28
FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
FF - user.js: extensions.incredibar_i.prdct - incredibar
FF - user.js: extensions.incredibar_i.aflt - orgnl
FF - user.js: extensions.incredibar_i.smplGrp - none
FF - user.js: extensions.incredibar_i.tlbrId - base
FF - user.js: extensions.incredibar_i.instlRef -
FF - user.js: extensions.incredibar_i.dfltLng -
FF - user.js: extensions.incredibar_i.excTlbr - false
FF - user.js: extensions.incredibar_i.ms_url_id -
FF - user.js: extensions.incredibar_i.upn2 - 6R8ypQLh0X
FF - user.js: extensions.incredibar_i.upn2n - 92824672681397415
FF - user.js: extensions.incredibar_i.productid - 26
FF - user.js: extensions.incredibar_i.installerproductid - 26
FF - user.js: extensions.incredibar_i.did - 10671
FF - user.js: extensions.incredibar_i.ppd -
.
============= SERVICES / DRIVERS ===============
.
R3 avchv;avchv Function Driver;c:\windows\system32\drivers\avchv.sys [2012-8-13 240184]
S0 avc3;avc3;c:\windows\system32\drivers\avc3.sys [2012-8-13 611520]
S0 gzflt;gzflt;c:\windows\system32\drivers\gzflt.sys [2012-8-23 154464]
S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [2012-8-26 74832]
S1 bdfwfpf;bdfwfpf;c:\program files\common files\bitdefender\bitdefender firewall\bdfwfpf.sys [2012-8-23 90704]
S1 BDVEDISK;BDVEDISK;c:\windows\system32\drivers\bdvedisk.sys [2012-8-13 72704]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2012-2-14 67960]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-4-3 63928]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-6-17 116648]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-5-30 1262400]
S2 SafeBox;SafeBox;c:\program files\bitdefender\bitdefender safebox\safeboxservice.exe [2012-8-13 82824]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-5-15 382272]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2012\TuneUpUtilitiesService32.exe [2012-5-29 1528672]
S2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2012-1-18 450848]
S2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\bitdefender\bitdefender 2013\updatesrv.exe [2012-8-23 55544]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-30 250056]
S3 avckf;avckf;c:\windows\system32\drivers\avckf.sys [2012-8-13 447208]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-6-17 116648]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-3 129976]
S3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\drivers\netr28.sys [2009-5-18 599040]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2012-5-30 148800]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-4-18 15872]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-6-10 394856]
S3 SWDUMon;SWDUMon;c:\windows\system32\drivers\SWDUMon.sys [2012-7-8 11232]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2012-4-20 52224]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2012\TuneUpUtilitiesDriver32.sys [2012-5-8 10064]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-4-20 1343400]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\zune\WMZuneComm.exe [2011-8-5 268512]
S4 BdDesktopParental;Bitdefender Desktop Parental Control;c:\program files\bitdefender\bitdefender 2013\bdparentalservice.exe [2012-8-26 57056]
.
=============== Created Last 30 ================
.
2012-08-30 22:52:10 31584 —-a-w- c:\windows\system32\TURegOpt.exe
2012-08-30 22:52:10 21344 —-a-w- c:\windows\system32\authuitu.dll
2012-08-30 22:51:39 ——– d—–w- c:\users\nemesis\appdata\roaming\TuneUp Software
2012-08-30 22:51:13 ——– d—–w- c:\program files\TuneUp Utilities 2012
2012-08-30 22:50:32 ——– d—–w- c:\programdata\TuneUp Software
2012-08-30 22:50:23 ——– d-sh–w- c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2012-08-30 22:50:23 ——– d–h–w- c:\programdata\Common Files
2012-08-30 22:50:10 388096 —-a-r- c:\users\nemesis\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-08-30 22:50:10 ——– d—–w- c:\program files\Trend Micro
2012-08-28 23:18:42 ——– d—–w- c:\program files\NirSoft
2012-08-28 04:50:43 ——– d—–w- c:\users\nemesis\appdata\local\Macromedia
2012-08-27 06:09:42 ——– d—–w- c:\program files\PC Tools
2012-08-27 06:07:13 ——– d—–w- c:\users\nemesis\appdata\roaming\TestApp
2012-08-27 06:07:13 ——– d—–w- c:\programdata\PC Tools
2012-08-23 23:30:28 ——– d-sh–w- C:\found.004
2012-08-23 22:53:08 ——– d—–w- c:\users\nemesis\appdata\roaming\Bitdefender
2012-08-23 22:51:08 340624 —-a-w- c:\windows\system32\drivers\trufos.sys
2012-08-23 22:51:08 1090 —-a-w- c:\programdata\1345762248.2624.bin
2012-08-23 22:51:08 1090 —-a-w- c:\programdata\1345762248.2620.bin
2012-08-23 22:51:08 ——– d—–w- c:\programdata\Bitdefender
2012-08-23 22:51:07 154464 —-a-w- c:\windows\system32\drivers\gzflt.sys
2012-08-23 22:50:53 253183 —-a-w- c:\programdata\1345762248.2188.bin
2012-08-23 22:50:50 43048 —-a-w- c:\programdata\1345762248.2168.bin
2012-08-23 22:50:50 26981 —-a-w- c:\programdata\1345762248.2164.bin
2012-08-23 22:50:48 81517 —-a-w- c:\programdata\1345762248.2124.bin
2012-08-23 22:19:40 ——– d—–w- c:\program files\Innovative Solutions
2012-08-17 14:01:28 ——– d—–w- C:\be43ac39fc4f2c0e1c0807f789a15f
2012-08-15 18:44:22 400896 —-a-w- c:\windows\system32\srcore.dll
2012-08-15 18:44:19 2345984 —-a-w- c:\windows\system32\win32k.sys
2012-08-15 18:44:16 492032 —-a-w- c:\windows\system32\win32spl.dll
2012-08-15 18:44:16 317440 —-a-w- c:\windows\system32\spoolsv.exe
2012-08-15 18:44:06 41984 —-a-w- c:\windows\system32\browcli.dll
2012-08-15 18:44:06 102912 —-a-w- c:\windows\system32\browser.dll
2012-08-15 18:44:03 769024 —-a-w- c:\windows\system32\localspl.dll
2012-08-14 18:57:00 ——– d—–w- c:\programdata\bdch
2012-08-14 02:36:46 425901 —-a-w- c:\programdata\1344911555.bdinstall.bin
2012-08-14 02:35:30 ——– d—–w- c:\programdata\BDLogging
2012-08-14 02:35:18 72704 —-a-w- c:\windows\system32\drivers\bdvedisk.sys
2012-08-14 02:35:15 74832 —-a-w- c:\windows\system32\drivers\BdfNdisf6.sys
2012-08-14 02:35:15 63056 —-a-w- c:\windows\system32\drivers\bdsandbox.sys
2012-08-14 02:35:15 511328 —-a-w- c:\windows\capicom.dll
2012-08-14 02:35:13 1461992 —-a-w- c:\windows\system32\WdfCoInstaller01009.dll
2012-08-14 02:35:10 611520 —-a-w- c:\windows\system32\drivers\avc3.sys
2012-08-14 02:35:10 447208 —-a-w- c:\windows\system32\drivers\avckf.sys
2012-08-14 02:35:10 240184 —-a-w- c:\windows\system32\drivers\avchv.sys
2012-08-14 02:33:25 ——– d—–w- c:\users\nemesis\appdata\roaming\QuickScan
2012-08-14 02:32:53 ——– d—–w- c:\program files\Bitdefender
2012-08-14 01:39:13 ——– d—–w- c:\program files\common files\Bitdefender
2012-08-14 01:36:52 ——– d—–w- c:\programdata\RegInOut
2012-08-14 01:36:47 ——– d—–w- c:\windows\RegInOut System Utilities
2012-08-14 01:36:37 ——– d—–w- c:\program files\RegInOut
2012-08-12 17:38:19 ——– d-sh–w- C:\found.003
.
==================== Find3M ====================
.
2012-08-31 01:13:37 11232 —-a-w- c:\windows\system32\drivers\SWDUMon.sys
2012-08-15 15:34:05 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 15:33:36 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-22 03:51:49 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2012-07-22 03:51:49 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2012-07-20 21:52:13 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2012-07-10 23:50:38 298016 —-a-w- c:\windows\system32\PnkBstrB.xtr
2012-07-10 03:46:11 298016 —-a-w- c:\windows\system32\PnkBstrB.ex0
2012-07-08 21:59:25 138056 —-a-w- c:\users\nemesis\appdata\roaming\PnkBstrK.sys
2012-06-29 00:16:58 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09:01 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08:59 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04:43 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00:45 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-06-06 15:49:52 1070152 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-06 05:05:52 1390080 —-a-w- c:\windows\system32\msxml6.dll
2012-06-06 05:05:52 1236992 —-a-w- c:\windows\system32\msxml3.dll
2012-06-06 05:03:06 805376 —-a-w- c:\windows\system32\cdosys.dll
.
============= FINISH: 14:11:00.62 ===============
OK… let's try this now:

Download ComboFix:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
If you just copy/paste the log instead of attaching it… it will be obvious that it is posted.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Firefox::
    FF - ProfilePath - c:\users\Nemesis\AppData\Roaming\Mozilla\Firefox\Profiles\h5bpgv0x.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
    FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=112558&tt=2912_1&babsrc=HP_ss&mntrId=a031ff6d00000000000000225fef33ba
    FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource=2&q=
    FF - user.js: extensions.incredibar_i.newTab - false
    FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6R8ypQLh0X&loc=IB_TB&i=26&search=
    FF - user.js: extensions.incredibar_i.id - a031ff6d00000000000000225fef33ba
    FF - user.js: extensions.incredibar_i.instlDay - 15530
    FF - user.js: extensions.incredibar_i.vrsn - [removed]
    FF - user.js: extensions.incredibar_i.vrsni - [removed]
    FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1417:40
    FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
    FF - user.js: extensions.incredibar_i.prdct - incredibar
    FF - user.js: extensions.incredibar_i.aflt - orgnl
    FF - user.js: extensions.incredibar_i.smplGrp - none
    FF - user.js: extensions.incredibar_i.tlbrId - base
    FF - user.js: extensions.incredibar_i.instlRef - 
    FF - user.js: extensions.incredibar_i.dfltLng - 
    FF - user.js: extensions.incredibar_i.excTlbr - false
    FF - user.js: extensions.incredibar_i.ms_url_id - 
    FF - user.js: extensions.incredibar_i.upn2 - 6R8ypQLh0X
    FF - user.js: extensions.incredibar_i.upn2n - 92824672681397415
    FF - user.js: extensions.incredibar_i.productid - 26
    FF - user.js: extensions.incredibar_i.installerproductid - 26
    FF - user.js: extensions.incredibar_i.did - 10671
    FF - user.js: extensions.incredibar_i.ppd -
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 12-09-03.07 - Nemesis 09/06/2012 16:32:26.2.4 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3327.2167 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Nemesis\Desktop\cfscript.txt AV: Bitdefender Antivirus *Disabled/Outdated* {98CD50CE-5097-4098-9669-6C401FB3969C} FW: Bitdefender Firewall *Disabled* {A0F6D1EB-1AF8-41C0-BD36-C575E160D1E7} SP: Bitdefender Antispyware *Disabled/Outdated* {23ACB12A-76AD-4F16-ACD9-57326434DC21} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2012-08-06 to 2012-09-06 ))))))))))))))))))))))))))))))) . . 2012-09-06 23:42 . 2012-09-06 23:42 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-09-06 23:42 . 2012-09-06 23:42 ——– d—–w- c:\users\Mom\AppData\Local\temp 2012-09-06 23:42 . 2012-09-06 23:42 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-09-06 18:37 . 2012-09-06 18:37 ——– d—–w- C:\found.005 2012-09-04 05:25 . 2012-09-06 23:42 ——– d—–w- c:\users\Nemesis\AppData\Local\temp 2012-08-30 22:52 . 2012-05-30 03:46 31584 —-a-w- c:\windows\system32\TURegOpt.exe 2012-08-30 22:52 . 2012-05-30 03:46 21344 —-a-w- c:\windows\system32\authuitu.dll 2012-08-30 22:51 . 2012-08-30 22:51 ——– d—–w- c:\users\Nemesis\AppData\Roaming\TuneUp Software 2012-08-30 22:51 . 2012-08-30 22:52 ——– d—–w- c:\program files\TuneUp Utilities 2012 2012-08-30 22:50 . 2012-08-30 22:52 ——– d—–w- c:\programdata\TuneUp Software 2012-08-30 22:50 . 2012-08-30 22:50 ——– d-sh–w- c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2012-08-30 22:50 . 2012-08-30 22:50 ——– d–h–w- c:\programdata\Common Files 2012-08-30 22:50 . 2012-08-30 22:50 388096 —-a-r- c:\users\Nemesis\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-08-30 22:50 . 2012-08-30 22:50 ——– d—–w- c:\program files\Trend Micro 2012-08-28 23:18 . 2012-08-28 23:18 ——– d—–w- c:\program files\NirSoft 2012-08-28 04:50 . 2012-08-28 04:50 ——– d—–w- c:\users\Nemesis\AppData\Local\Macromedia 2012-08-27 06:09 . 2012-08-28 05:17 ——– d—–w- c:\program files\PC Tools 2012-08-27 06:07 . 2012-08-28 04:54 ——– d—–w- c:\programdata\PC Tools 2012-08-27 06:07 . 2012-08-27 06:07 ——– d—–w- c:\users\Nemesis\AppData\Roaming\TestApp 2012-08-23 23:30 . 2012-08-23 23:30 ——– d—–w- C:\found.004 2012-08-23 22:53 . 2012-08-27 05:04 ——– d—–w- c:\users\Nemesis\AppData\Roaming\Bitdefender 2012-08-23 22:51 . 2012-08-27 05:10 ——– d—–w- c:\programdata\Bitdefender 2012-08-23 22:51 . 2012-04-24 22:28 340624 —-a-w- c:\windows\system32\drivers\trufos.sys 2012-08-23 22:51 . 2012-04-12 00:03 154464 —-a-w- c:\windows\system32\drivers\gzflt.sys 2012-08-23 22:19 . 2012-08-23 22:19 ——– d—–w- c:\program files\Innovative Solutions 2012-08-17 14:01 . 2012-08-17 14:11 ——– d—–w- C:\be43ac39fc4f2c0e1c0807f789a15f 2012-08-15 18:44 . 2012-05-05 07:46 400896 —-a-w- c:\windows\system32\srcore.dll 2012-08-15 18:44 . 2012-07-18 17:47 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-08-15 18:44 . 2012-02-11 05:43 492032 —-a-w- c:\windows\system32\win32spl.dll 2012-08-15 18:44 . 2012-02-11 05:37 317440 —-a-w- c:\windows\system32\spoolsv.exe 2012-08-15 18:44 . 2012-07-04 21:14 41984 —-a-w- c:\windows\system32\browcli.dll 2012-08-15 18:44 . 2012-07-04 21:14 102912 —-a-w- c:\windows\system32\browser.dll 2012-08-15 18:44 . 2012-05-14 04:33 769024 —-a-w- c:\windows\system32\localspl.dll 2012-08-14 18:57 . 2012-08-14 18:57 ——– d—–w- c:\programdata\bdch 2012-08-14 14:11 . 2012-08-15 13:57 ——– d—–w- c:\users\Mom\AppData\Roaming\Bitdefender 2012-08-14 02:35 . 2012-08-14 02:38 ——– d—–w- c:\programdata\BDLogging 2012-08-14 02:35 . 2012-04-17 21:40 72704 —-a-w- c:\windows\system32\drivers\bdvedisk.sys 2012-08-14 02:35 . 2011-11-18 00:38 63056 —-a-w- c:\windows\system32\drivers\bdsandbox.sys 2012-08-14 02:35 . 2011-11-15 03:16 74832 —-a-w- c:\windows\system32\drivers\BdfNdisf6.sys 2012-08-14 02:35 . 2007-04-11 18:11 511328 —-a-w- c:\windows\capicom.dll 2012-08-14 02:35 . 2009-07-14 21:27 1461992 —-a-w- c:\windows\system32\WdfCoInstaller01009.dll 2012-08-14 02:35 . 2012-03-21 03:22 611520 —-a-w- c:\windows\system32\drivers\avc3.sys 2012-08-14 02:35 . 2012-02-17 23:45 447208 —-a-w- c:\windows\system32\drivers\avckf.sys 2012-08-14 02:35 . 2011-11-25 21:59 240184 —-a-w- c:\windows\system32\drivers\avchv.sys 2012-08-14 02:33 . 2012-08-27 05:46 ——– d—–w- c:\users\Nemesis\AppData\Roaming\QuickScan 2012-08-14 02:32 . 2012-08-14 02:35 ——– d—–w- c:\program files\Bitdefender 2012-08-14 01:39 . 2012-08-23 22:51 ——– d—–w- c:\program files\Common Files\Bitdefender 2012-08-14 01:36 . 2012-08-14 01:36 ——– d—–w- c:\programdata\RegInOut 2012-08-14 01:36 . 2012-08-14 01:36 ——– d—–w- c:\windows\RegInOut System Utilities 2012-08-14 01:36 . 2012-08-14 01:36 ——– d—–w- c:\program files\RegInOut 2012-08-12 17:38 . 2012-08-12 17:38 ——– d—–w- C:\found.003 . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-06 23:24 . 2012-07-08 23:17 11232 —-a-w- c:\windows\system32\drivers\SWDUMon.sys 2012-08-15 15:34 . 2012-05-01 03:10 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-08-15 15:33 . 2012-05-01 03:10 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-07-22 03:51 . 2012-04-20 01:32 444952 —-a-w- c:\windows\system32\wrap_oal.dll 2012-07-22 03:51 . 2012-04-20 01:32 109080 —-a-w- c:\windows\system32\OpenAL32.dll 2012-07-20 21:52 . 2012-07-20 21:52 107888 —-a-w- c:\windows\system32\CmdLineExt.dll 2012-07-10 23:50 . 2012-07-09 01:00 298016 —-a-w- c:\windows\system32\PnkBstrB.xtr 2012-07-10 03:46 . 2012-07-08 21:59 298016 —-a-w- c:\windows\system32\PnkBstrB.ex0 2012-07-08 21:59 . 2012-07-08 21:59 138056 —-a-w- c:\users\Nemesis\AppData\Roaming\PnkBstrK.sys 2012-05-03 20:02 . 2012-04-20 04:05 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox1] @="{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}" [HKEY_CLASSES_ROOT\CLSID\{152C96EB-288E-4EDC-B7C6-D21F8250ADF3}] 2012-06-29 18:18 240920 ——w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox2] @="{342DAA0B-D796-460D-8566-901E08A1CCAD}" [HKEY_CLASSES_ROOT\CLSID\{342DAA0B-D796-460D-8566-901E08A1CCAD}] 2012-06-29 18:18 240920 ——w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox3] @="{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}" [HKEY_CLASSES_ROOT\CLSID\{57595DAE-1AE1-4D97-A49E-67CBB53B52DF}] 2012-06-29 18:18 240920 ——w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\__SafeBox4] @="{33816773-98AE-4723-ADE0-EBE54C8B5A67}" [HKEY_CLASSES_ROOT\CLSID\{33816773-98AE-4723-ADE0-EBE54C8B5A67}] 2012-06-29 18:18 240920 ——w- c:\program files\Bitdefender\Bitdefender Safebox\safeboxshell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Game Fire"="c:\program files\Smart PC Utilities\Game Fire\GFTray.exe" [2011-12-02 44032] "Steam"="c:\program files\Steam\steam.exe" [2012-08-05 1353080] "DriverMax"="c:\program files\Innovative Solutions\DriverMax\drivermax.exe" [2012-07-31 11324352] "Driver Detective"="c:\program files\PC Drivers HeadQuarters\Driver Detective\DriversHQ.DriverDetective.Client.exe" [2012-06-18 3521504] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712] "ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2012-04-05 371864] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] "XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-10-01 718688] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 159456] "Bdagent"="c:\program files\Bitdefender\Bitdefender 2013\bdagent.exe" [2012-07-31 1578872] "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2010-11-04 1246544] . c:\users\Nemesis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2012-4-19 2860792] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [x] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 SWDUMon;SWDUMon;c:\windows\system32\DRIVERS\SWDUMon.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [x] R4 BdDesktopParental;Bitdefender Desktop Parental Control;c:\program files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [x] S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [x] S0 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys [x] S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [x] S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [x] S1 BDVEDISK;BDVEDISK;c:\windows\system32\DRIVERS\bdvedisk.sys [x] S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x] S2 SafeBox;SafeBox;c:\program files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [x] S2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x] S2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender 2013\updatesrv.exe [x] S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys [x] S3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-09-06 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-01 15:37] . 2012-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-06-17 12:30] . 2012-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-06-17 12:30] . 2012-08-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3968568090-679587375-369975741-1000Core.job - c:\users\Mom\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-29 19:50] . 2012-09-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3968568090-679587375-369975741-1000UA.job - c:\users\Mom\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-29 19:50] . 2012-08-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3968568090-679587375-369975741-1001Core.job - c:\users\Nemesis\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-18 00:56] . 2012-09-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3968568090-679587375-369975741-1001UA.job - c:\users\Nemesis\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-18 00:56] . 2012-08-19 c:\windows\Tasks\RegInOut Scheduled Scan - Nemesis.job - c:\program files\RegInOut\RegInOut.exe [2011-12-30 08:33] . 2012-09-06 c:\windows\Tasks\SlimDrivers Startup.job - c:\program files\SlimDrivers\SlimDrivers.exe [2012-06-28 20:00] . . ——- Supplementary Scan ——- . uStart Page = about:blank mStart Page = about:blank IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 LSP: c:\program files\Bitdefender\Bitdefender 2013\BdProvider.dll TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Nemesis\AppData\Roaming\Mozilla\Firefox\Profiles\h5bpgv0x.default\ . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3968568090-679587375-369975741-1001\Software\SecuROM\License information*] "datasecu"=hex:1a,62,38,bc,25,c8,4c,7e,3f,44,aa,7a,59,34,6c,cc,bf,2d,73,f8,bb, 86,56,5d,4f,1b,72,e3,ef,94,5a,bd,71,4d,80,9b,46,bf,2f,25,41,3b,a7,fe,de,16,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(2916) c:\program files\Stardock\ObjectDock\DockShellHook.dll . Completion time: 2012-09-06 16:44:26 ComboFix-quarantined-files.txt 2012-09-06 23:44 ComboFix2.txt 2012-09-04 05:25 . Pre-Run: 90,449,506,304 bytes free Post-Run: 90,376,855,552 bytes free . - - End Of File - - 02D8FC5B691625039B84C8CCB7B6A7A4
Let's get an online scan (this takes a long time. Probably hours)

Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Also, please let me know how things seem to be running.
I did everything in the instructions and the scan started and took quite a while and it started to find alot of things but it got stuck on one file for an absurd amount of time(hours for just one) and I attempted to click it because it wasn't going anywhere so I clicked stop to get the log of what it had already found and it just froze up, before my computer became almost inoperable again (couldnt save logfile) I took a screenshot and I did manage to catch some of what it had listed. The file it got stuck on was a movie called blueberry, not sure if it was random or if the movie has something in it? Not sure. Anyways I will attach the picture. Oh also, my computer did seem to speed up but after that scan it was behaving badly as before.
Those look like infected downloads..

Let's run a different tool first and see if it will clean up some of those without freezing up.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI