This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible Malware? [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, I was (unwittingly) surfing the net yesterday using Internet Explorer when all of a sudden I get a frozen full screen webpage saying: “This program cannot display the webpage”. The Window’s Taskbar and Start Menu have disappeared and you can’t close, change or move this webpage. I also can’t seem to get rid of it using the Task Manager. On this page, the button for more information is active but suggests that I have an internet connection problem, which I know I don’t. When I restart my computer and as soon as I login to Windows, this webpage comes up again and I can’t do anything. I rebooted the computer in Safe Mode and it seems to get me back onto the system okay. Disabling the offending program/application in msconfig and rebooting in normal mode seems to get my system back up and running again. Below are the Startup Item’s details: • Name: blcauwzebgfqzva • Manufacturer: Unknown • Command: C:\ProgramData\blcauwze.exe • Location: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run However, I don’t think I can get rid of the malware for good using my current system tools. There may be other related files, which are hidden and I haven’t managed to find. I’d be very grateful for any advice/suggestions. Many thanks, JB
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Hi Jeff,

Thanks very much for your reply. I really appreciate your help. :) As requested, I've included the contents of DDS, Attach, and aswMBR.

DDS.txt

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by [removed] at 21:19:57 on 2012-10-06
Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.2046.1117 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [RESTART_STICKY_NOTES] c:\windows\system32\StikyNot.exe
uRun: [iCloudServices] c:\program files\common files\apple\internet services\iCloudServices.exe
uRun: [ApplePhotoStreams] c:\program files\common files\apple\internet services\ApplePhotoStreams.exe
uRun: [MobileDocuments] c:\program files\common files\apple\internet services\ubd.exe
uRun: [{02833732-6739-48DF-7DD6-A4EEF473DA8E}] c:\users\will\appdata\roaming\microsoft\speech\files\ntkrnlpa.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.0.207\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{0D9D0A52-B495-4AF8-9AFD-62CB2E3280CE} : NameServer = 193.61.29.37 193.61.29.134 193.61.29.136
TCP: Interfaces\{0D9D0A52-B495-4AF8-9AFD-62CB2E3280CE} : DhcpNameServer = [removed] [removed] [removed]
TCP: Interfaces\{74C63197-8739-4BEA-90CE-AB1939809555} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{74C63197-8739-4BEA-90CE-AB1939809555}\6596277696E6 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{74C63197-8739-4BEA-90CE-AB1939809555}\6596277696E623 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{EA91BEA1-EAB1-40FC-AFAF-1C1C9F4F42B0} : DhcpNameServer = [removed] [removed]
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\will\appdata\roaming\mozilla\firefox\profiles\r7yg296f.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bbk.ac.uk/mybirkbeck/
FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\users\will\appdata\roaming\mozilla\firefox\profiles\r7yg296f.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\plugins\np-mswmp.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll
.
—- FIREFOX POLICIES —-
FF - user.js: -
FF - user.js: security.enable_tls - false
FF - user.js: network.http.accept-encoding -
FF - user.js: secnetwork.http.accept-encodingurity.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 193552]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-9-13 399432]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-9-13 676936]
R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 99272]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-4-19 22856]
R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-9-12 287824]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-13 311296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-28 135664]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2011-4-12 62464]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-1-28 135664]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.0.207\McCHSvc.exe [2011-6-17 237008]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-25 113120]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-11-2 1343400]
.
=============== Created Last 30 ================
.
2012-10-06 20:19:21 56200 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{e0789667-fb84-4ac6-9a45-23df53902e43}\offreg.dll
2012-10-06 14:13:58 740784 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{0a1bc471-bba4-4614-bdff-4d58a6994c06}\gapaengine.dll
2012-10-06 14:13:38 6980552 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{e0789667-fb84-4ac6-9a45-23df53902e43}\mpengine.dll
2012-10-05 17:48:17 ——– d—–w- c:\windows\pss
2012-10-05 17:18:58 ——– d—–w- c:\programdata\kymigbvkbxkpktr
2012-10-04 21:55:58 6980552 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-09-26 19:12:00 245760 —-a-w- c:\windows\system32\OxpsConverter.exe
2012-09-25 12:47:50 ——– d—–w- c:\users\will\appdata\local\F1BD89D5-3939-495D-959D-D4C704904497.aplzod
2012-09-24 19:30:45 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-09-24 19:29:28 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-09-14 14:53:47 712048 —-a-w- c:\windows\system32\drivers\ndis.sys
2012-09-14 14:53:47 33280 —-a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-14 14:53:45 240496 —-a-w- c:\windows\system32\drivers\netio.sys
2012-09-14 14:53:45 1292144 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-14 14:53:44 187760 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-14 14:53:43 490496 —-a-w- c:\windows\system32\d3d10level9.dll
2012-09-09 14:50:31 ——– d—–w- c:\programdata\McAfee Security Scan
2012-09-09 14:50:22 ——– d—–w- c:\program files\McAfee Security Scan
.
==================== Find3M ====================
.
2012-09-09 14:50:17 696520 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-09 14:50:16 73416 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-07 16:04:46 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-30 21:03:50 99272 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-08-30 21:03:50 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-24 06:59:17 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-08-24 06:51:27 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-08-24 06:51:02 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 06:47:26 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 06:47:12 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-08-24 06:43:58 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-08-21 12:01:22 106928 —-a-w- c:\windows\system32\GEARAspi.dll
2012-07-18 17:47:53 2345984 —-a-w- c:\windows\system32\win32k.sys
2012-07-09 12:42:56 4547984 —-a-w- c:\windows\system32\usbaaplrc.dll
2012-07-09 12:42:56 44032 —-a-w- c:\windows\system32\drivers\usbaapl.sys
.
============= FINISH: 21:21:28.42 ===============

Attach.txt

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 25/10/2011 05:57:37
System Uptime: 06/10/2012 20:04:16 (1 hours ago)
.
Motherboard: SAMSUNG ELECTRONICS CO., LTD. | | SR700
Processor: Intel® Core™2 Duo CPU T5450 @ 1.66GHz | U2E1 | 1667/mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 112 GiB total, 14.952 GiB free.
D: is FIXED (NTFS) - 111 GiB total, 0.02 GiB free.
E: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP150: 06/08/2012 12:31:43 - Windows Update
RP151: 10/08/2012 11:28:56 - Windows Update
RP152: 12/08/2012 19:00:25 - Windows Backup
RP153: 13/08/2012 14:44:33 - Windows Update
RP154: 15/08/2012 14:22:55 - Windows Update
RP155: 18/08/2012 15:04:05 - Windows Update
RP156: 19/08/2012 19:00:15 - Windows Backup
RP157: 22/08/2012 16:47:58 - Windows Update
RP158: 25/08/2012 19:01:41 - Windows Update
RP159: 26/08/2012 21:35:40 - Windows Backup
RP160: 29/08/2012 13:50:56 - Windows Update
RP161: 01/09/2012 16:34:03 - Windows Update
RP162: 02/09/2012 19:00:25 - Windows Backup
RP163: 05/09/2012 22:03:56 - Windows Update
RP164: 09/09/2012 15:58:36 - Windows Update
RP165: 09/09/2012 21:17:27 - Windows Backup
RP166: 13/09/2012 20:26:30 - Windows Update
RP167: 14/09/2012 19:19:21 - Windows Update
RP168: 16/09/2012 19:00:22 - Windows Backup
RP169: 17/09/2012 21:01:08 - Windows Update
RP170: 20/09/2012 21:14:57 - Windows Update
RP171: 23/09/2012 19:00:24 - Windows Backup
RP172: 23/09/2012 19:37:50 - Windows Update
RP173: 26/09/2012 20:17:23 - Windows Update
RP174: 26/09/2012 23:11:43 - Windows Update
RP175: 30/09/2012 19:13:19 - Windows Backup
RP176: 01/10/2012 19:08:54 - Windows Update
RP177: 04/10/2012 22:55:23 - Windows Update
.
==== Installed Programs ======================
.
7-Zip 9.20
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3)
Apple Application Support
Apple Mobile Device Support
Apple Software Update
BlueJ
BlueJ 3.0.5
Bonjour
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
ESET Online Scanner v3
Google Toolbar for Internet Explorer
Google Update Helper
iCloud
iTunes
Java Auto Updater
Java™ 7 Update 1
Java™ SE Development Kit 7 Update 1
Jeliot 3.7.2
Malwarebytes Anti-Malware version 1.65.0.1400
McAfee Security Scan Plus
Microsoft .NET Framework 4 Client Profile
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Mozilla Firefox 13.0.1 (x86 en-GB)
Mozilla Maintenance Service
QuickTime
Scrivener
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2553322) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2553431) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553260) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589322) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553272) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598289) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
.
==== Event Viewer Messages From Past Week ========
.
30/09/2012 23:37:45, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.137.733.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8800.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
30/09/2012 19:12:48, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.137.733.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8800.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
29/09/2012 17:40:59, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
05/10/2012 20:55:25, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
05/10/2012 20:55:24, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
05/10/2012 20:55:24, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
05/10/2012 20:55:24, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
05/10/2012 20:55:24, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
05/10/2012 20:55:23, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
05/10/2012 20:55:18, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
05/10/2012 20:54:35, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD CSC DfsC discache MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf
05/10/2012 20:54:35, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
05/10/2012 20:54:35, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
05/10/2012 20:54:35, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
05/10/2012 20:54:35, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
05/10/2012 20:54:35, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
05/10/2012 20:54:35, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
05/10/2012 20:54:35, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
05/10/2012 20:54:35, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
05/10/2012 20:54:35, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
05/10/2012 20:54:35, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
01/10/2012 19:59:55, Error: Schannel [36887] - The following fatal alert was received: 10.
01/10/2012 10:45:18, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.137.733.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8800.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
01/10/2012 08:59:22, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.137.733.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8800.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
.
==== End Of File ===========================

aswMBR.txt

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-10-06 21:27:55
—————————–
21:27:55.571 OS Version: Windows 6.1.7601 Service Pack 1
21:27:55.571 Number of processors: 2 586 0xF0D
21:27:55.571 ComputerName: WILL-PC UserName: Will
21:27:57.880 Initialize success
21:29:38.247 AVAST engine defs: 12100601
21:29:55.984 The log file has been saved successfully to "C:\Users\Will\Desktop\aswMBR.txt"

Best regards,

JB
Hi,

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Jeff, Here's the contents of C:\ComboFix.txt: ComboFix 12-10-04.02 - Will 06/10/2012 21:57:48.1.2 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.2046.1368 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2012-09-06 to 2012-10-06 ))))))))))))))))))))))))))))))) . . 2012-10-06 21:05 . 2012-10-06 21:05 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-10-06 20:21 . 2012-10-06 20:21 29904 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E0789667-FB84-4AC6-9A45-23DF53902E43}\MpKsl43aa34a5.sys 2012-10-06 20:19 . 2012-10-06 20:19 56200 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E0789667-FB84-4AC6-9A45-23DF53902E43}\offreg.dll 2012-10-06 14:13 . 2012-09-28 09:52 740784 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0A1BC471-BBA4-4614-BDFF-4D58A6994C06}\gapaengine.dll 2012-10-06 14:13 . 2012-08-30 08:17 6980552 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E0789667-FB84-4AC6-9A45-23DF53902E43}\mpengine.dll 2012-10-05 17:18 . 2012-10-05 17:19 ——– d—–w- c:\programdata\kymigbvkbxkpktr 2012-10-04 21:55 . 2012-08-30 08:17 6980552 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-09-26 19:12 . 2012-08-21 20:12 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-09-25 12:47 . 2012-09-28 09:55 ——– d—–w- c:\users\Will\AppData\Local\F1BD89D5-3939-495D-959D-D4C704904497.aplzod 2012-09-24 19:30 . 2012-08-21 12:01 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-09-24 19:29 . 2012-09-24 19:30 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-09-14 14:53 . 2012-08-22 17:16 712048 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-14 14:53 . 2012-07-04 19:45 33280 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-14 14:53 . 2012-08-22 17:16 1292144 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-14 14:53 . 2012-08-22 17:16 240496 —-a-w- c:\windows\system32\drivers\netio.sys 2012-09-14 14:53 . 2012-08-22 17:16 187760 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-09-14 14:53 . 2012-08-02 16:57 490496 —-a-w- c:\windows\system32\d3d10level9.dll 2012-09-09 14:50 . 2012-09-09 14:50 ——– d—–w- c:\programdata\McAfee Security Scan 2012-09-09 14:50 . 2012-09-09 14:50 ——– d—–w- c:\programdata\McAfee 2012-09-09 14:50 . 2012-09-20 20:06 ——– d—–w- c:\program files\McAfee Security Scan . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-28 09:52 . 2012-02-10 17:40 740784 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2012-09-09 14:50 . 2012-06-05 11:56 696520 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-09-09 14:50 . 2011-11-01 20:06 73416 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-09-07 16:04 . 2012-04-19 14:03 22856 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-08-30 21:03 . 2012-08-30 21:03 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys 2012-08-30 21:03 . 2010-10-24 21:25 99272 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2012-08-21 12:01 . 2011-12-09 12:23 106928 —-a-w- c:\windows\system32\GEARAspi.dll 2012-07-18 17:47 . 2012-08-15 11:23 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-07-09 12:42 . 2012-07-09 12:42 4547984 —-a-w- c:\windows\system32\usbaaplrc.dll 2012-07-09 12:42 . 2012-07-09 12:42 44032 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2012-07-03 13:32 . 2011-11-04 16:29 85472 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-26 39408] "RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304] "iCloudServices"="c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-08-29 59280] "ApplePhotoStreams"="c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-09-10 59280] "{02833732-6739-48DF-7DD6-A4EEF473DA8E}"="c:\users\Will\AppData\Roaming\Microsoft\Speech\Files\ntkrnlpa.exe" [2012-03-31 286720] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-09 421776] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.207\McCHSvc.exe [x] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S1 MpKsl43aa34a5;MpKsl43aa34a5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E0789667-FB84-4AC6-9A45-23DF53902E43}\MpKsl43aa34a5.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [x] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - MPKSL43AA34A5 *Deregistered* - aswMBR . Contents of the 'Scheduled Tasks' folder . 2012-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:37] . 2012-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:37] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.co.uk/ uInternet Settings,ProxyOverride = *.local IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd; to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{0D9D0A52-B495-4AF8-9AFD-62CB2E3280CE}: NameServer = 193.61.29.37 193.61.29.134 193.61.29.136 FF - ProfilePath - c:\users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\r7yg296f.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.bbk.ac.uk/mybirkbeck/ FF - user.js: - FF - user.js: security.enable_tls - false FF - user.js: network.http.accept-encoding - FF - user.js: secnetwork.http.accept-encodingurity.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file) WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file) HKCU-Run-MobileDocuments - c:\program files\Common Files\Apple\Internet Services\ubd.exe MSConfigStartUp-blcauwzebgfqzva - c:\programdata\blcauwze.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-10-06 22:07:42 ComboFix-quarantined-files.txt 2012-10-06 21:07 . Pre-Run: 16,634,392,576 bytes free Post-Run: 17,176,952,832 bytes free . - - End Of File - - 27E52E64DD438407555BA3888DC21F6A Many thanks, JB :)
Hi,

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2


**If you are using a 64bit system please use either of the following links for your download instead:
Link 1
Link 2

  • Right-click and Run as Administrator SystemLook.exe to run it.
  • Copy the content within the following codebox into the main textfield:
    :dir
    c:\programdata\kymigbvkbxkpktr /s
    c:\users\Will\AppData\Local\F1BD89D5-3939-495D-959D-D4C704904497.aplzod /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hi Jeff,

As requested, below are the contents of SystemLook.txt:

SystemLook 30.07.11 by jpshortstuff
Log created at 16:28 on 07/10/2012 by Will
Administrator - Elevation successful

========== dir ==========

c:\programdata\kymigbvkbxkpktr - Parameters: "/s"

—Files—
btn-green.png –a—- 1284 bytes [17:18 05/10/2012] [17:18 05/10/2012]
corners-btn.png –a—- 1183 bytes [17:18 05/10/2012] [17:18 05/10/2012]
corners1.png –a—- 1063 bytes [17:18 05/10/2012] [17:18 05/10/2012]
corners2.png –a—- 1070 bytes [17:18 05/10/2012] [17:18 05/10/2012]
corners3.png –a—- 1050 bytes [17:18 05/10/2012] [17:18 05/10/2012]
corners4.png –a—- 1053 bytes [17:18 05/10/2012] [17:18 05/10/2012]
ie6-7.css –a—- 63 bytes [17:18 05/10/2012] [17:18 05/10/2012]
jquery.main.js –a—- 1077 bytes [17:18 05/10/2012] [17:18 05/10/2012]
McAfee.png –a—- 3344 bytes [17:18 05/10/2012] [17:18 05/10/2012]
pay20.png –a—- 2348 bytes [17:18 05/10/2012] [17:18 05/10/2012]
pay21.png –a—- 2470 bytes [17:18 05/10/2012] [17:18 05/10/2012]
pay23.png –a—- 2520 bytes [17:18 05/10/2012] [17:18 05/10/2012]
steps-en.png –a—- 6446 bytes [17:18 05/10/2012] [17:18 05/10/2012]
style.css –a—- 11343 bytes [17:18 05/10/2012] [17:18 05/10/2012]
tabs.png –a—- 1166 bytes [17:18 05/10/2012] [17:18 05/10/2012]
uk-flag.png –a—- 2670 bytes [17:18 05/10/2012] [17:18 05/10/2012]
uk-image.png –a—- 5106 bytes [17:18 05/10/2012] [17:18 05/10/2012]
wait.html –a—- 292 bytes [17:18 05/10/2012] [17:18 05/10/2012]

No folders found.

c:\users\Will\AppData\Local\F1BD89D5-3939-495D-959D-D4C704904497.aplzod - Parameters: "/s"

—Files—
alarms.db –a—- 6144 bytes [09:53 28/09/2012] [09:55 28/09/2012]
main.db –a—- 211968 bytes [12:47 25/09/2012] [09:55 28/09/2012]
main.db-shm –a—- 32768 bytes [09:53 28/09/2012] [09:55 28/09/2012]
main.db-wal –a—- 7368 bytes [09:53 28/09/2012] [09:55 28/09/2012]

No folders found.

-= EOF =-

Best,

JB :)
Hi, I noticed that you have on your system McAfee and Microsoft Security Essentials. Are you still using McAfee? If not we need to uninstall that through Control Panel >> Programs and Features. Once uninstalled reboot your system and let me know how it's running.
Hello again, I just uninstalled McAfee. After rebooting my computer, everything seems normal (for the moment at least). Kind regards, JB :)
Hi,

Great!

I see that your Java software is out of date. Please go to Start >> Control Panel >> Programs and Features >> uninstall all versions of Java.

Now download and install the newest version from here >> http://java.com/en/download/index.jsp
————-

Clear Java Cache

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
———-

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
Hi Jeff,

Sorry for the delay in getting back to you. The ESET Online Scanner was taking forever to scan. :( Anyway, with Malwarebytes, I hope you don't mind but I was required to click remove for a couple of nasty files it found before having to reboot my computer. In terms of the behaviour, everything seems okay I think. I've posted the results of the logs you wanted below:

Malwarebytes

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.10.08.03

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Will :: WILL-PC [administrator]

08/10/2012 13:01:20
mbam-log-2012-10-08 (13-09-02).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 195426
Time elapsed: 4 minute(s), 27 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|{02833732-6739-48DF-7DD6-A4EEF473DA8E} (Malware.Gen.EVI) -> Data: C:\Users\Will\AppData\Roaming\Microsoft\Speech\Files\ntkrnlpa.exe -> No action taken.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\Will\AppData\Roaming\Microsoft\Speech\Files\ntkrnlpa.exe (Malware.Gen.EVI) -> No action taken.

(end)

ESET Online Scanner

C:\Users\Will\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CEHGB2TT\79cba1185463850dedba31f172f1dc5b[1].htm HTML/Iframe.B.Gen virus
C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\r7yg296f.default\user.js JS/SecurityDisabler.A.Gen application
C:\Users\Will\Downloads\FreeStudio.exe Win32/OpenCandy application
D:\WILL-PC\Backup Set 2012-04-22 190001\Backup Files 2012-04-29 190001\Backup files 2.zip Java/Exploit.CVE-2012-0507.W trojan
D:\WILL-PC\Backup Set 2012-04-22 190001\Backup Files 2012-05-06 190001\Backup files 3.zip multiple threats

Best,

JB :)
Hi,

Go ahead and run Malwarebytes again and then remove all entries that are found. Post the new log.
——–

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the box below:


    ClearJavaCache::

    File::
    C:\Users\Will\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CEHGB2TT\79cba1185463850dedba31f172f1dc5b[1].htm
    C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\r7yg296f.default\user.js
    C:\Users\Will\Downloads\FreeStudio.exe
    D:\WILL-PC\Backup Set 2012-04-22 190001\Backup Files 2012-04-29 190001\Backup files 2.zip
    D:\WILL-PC\Backup Set 2012-04-22 190001\Backup Files 2012-05-06 190001\Backup files 3.zip

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Post the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

Post the new Malwarebytes and ComboFix logs and let me know what remaining malware problems you are having. :)
Hi Jeff,

After updating and running Malwarebyte again, it found no malicious items this time. Below are the new logs for Malwarebytes and ComboFix:

Malwarebytes

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.10.09.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Will :: WILL-PC [administrator]

09/10/2012 15:35:07
mbam-log-2012-10-09 (15-35-07).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 198208
Time elapsed: 6 minute(s), 36 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

ComboFix

ComboFix 12-10-09.01 - Will 09/10/2012 15:50:15.2.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.2046.1125 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Will\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Will\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CEHGB2TT\79cba1185463850dedba31f172f1dc5b[1].htm"
"c:\users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\r7yg296f.default\user.js"
"c:\users\Will\Downloads\FreeStudio.exe"
"d:\will-pc\Backup Set 2012-04-22 190001\Backup Files 2012-04-29 190001\Backup files 2.zip"
"d:\will-pc\Backup Set 2012-04-22 190001\Backup Files 2012-05-06 190001\Backup files 3.zip"
.
.
((((((((((((((((((((((((( Files Created from 2012-09-09 to 2012-10-09 )))))))))))))))))))))))))))))))
.
.
2012-10-09 14:59 . 2012-10-09 14:59 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-10-09 14:43 . 2012-08-30 08:17 6980552 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AE4BC064-9F65-4EEB-A6F0-36C6D572ABED}\mpengine.dll
2012-10-08 11:59 . 2012-10-08 11:59 ——– d—–w- c:\users\Will\AppData\Local\Apple
2012-10-08 11:58 . 2012-10-08 11:58 ——– d—–w- c:\program files\Common Files\Java
2012-10-08 11:58 . 2012-10-08 11:57 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-10-07 20:39 . 2012-10-08 11:57 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-10-07 17:12 . 2012-10-07 17:12 ——– d—–w- c:\users\Will\AppData\Local\Adobe
2012-10-07 15:34 . 2012-08-30 08:17 6980552 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-10-06 14:13 . 2012-09-28 09:52 740784 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0A1BC471-BBA4-4614-BDFF-4D58A6994C06}\gapaengine.dll
2012-10-05 17:18 . 2012-10-05 17:19 ——– d—–w- c:\programdata\kymigbvkbxkpktr
2012-09-26 19:12 . 2012-08-21 20:12 245760 —-a-w- c:\windows\system32\OxpsConverter.exe
2012-09-25 12:47 . 2012-09-28 09:55 ——– d—–w- c:\users\Will\AppData\Local\F1BD89D5-3939-495D-959D-D4C704904497.aplzod
2012-09-24 19:30 . 2012-08-21 12:01 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-09-24 19:29 . 2012-09-24 19:30 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-09-14 14:53 . 2012-08-22 17:16 712048 —-a-w- c:\windows\system32\drivers\ndis.sys
2012-09-14 14:53 . 2012-07-04 19:45 33280 —-a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-14 14:53 . 2012-08-22 17:16 1292144 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-14 14:53 . 2012-08-22 17:16 240496 —-a-w- c:\windows\system32\drivers\netio.sys
2012-09-14 14:53 . 2012-08-22 17:16 187760 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-14 14:53 . 2012-08-02 16:57 490496 —-a-w- c:\windows\system32\d3d10level9.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-07 20:37 . 2011-11-01 19:18 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-09-28 09:52 . 2012-02-10 17:40 740784 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-09-09 14:50 . 2012-06-05 11:56 696520 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-09 14:50 . 2011-11-01 20:06 73416 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-07 16:04 . 2012-04-19 14:03 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-30 21:03 . 2012-08-30 21:03 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-30 21:03 . 2010-10-24 21:25 99272 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-08-21 12:01 . 2011-12-09 12:23 106928 —-a-w- c:\windows\system32\GEARAspi.dll
2012-07-18 17:47 . 2012-08-15 11:23 2345984 —-a-w- c:\windows\system32\win32k.sys
2012-07-03 13:32 . 2011-11-04 16:29 85472 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-26 39408]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
"iCloudServices"="c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe" [2012-08-29 59280]
"ApplePhotoStreams"="c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-09-10 59280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-09 421776]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-18 421888]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:37]
.
2012-10-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{0D9D0A52-B495-4AF8-9AFD-62CB2E3280CE}: NameServer = 193.61.29.37 193.61.29.134 193.61.29.136
FF - ProfilePath - c:\users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\r7yg296f.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bbk.ac.uk/mybirkbeck/
FF - user.js: -
FF - user.js: security.enable_tls - false
FF - user.js: network.http.accept-encoding -
FF - user.js: secnetwork.http.accept-encodingurity.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-10-09 16:01:17
ComboFix-quarantined-files.txt 2012-10-09 15:01
ComboFix2.txt 2012-10-06 21:07
.
Pre-Run: 16,303,718,400 bytes free
Post-Run: 16,463,937,536 bytes free
.
- - End Of File - - 868FE8A4ABC373CBBF3A832BFDA1F579

Best,

JB :)
Providing there are no other malware related problems…

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

The following will implement some cleanup procedures as well as reset System Restore points:

Press the Windows key + R and this will open the Run text box. Copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop. If you did not have Malwarebytes Antimalware before, I would keep it and run it weekly.
———-

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. FireFox If you use Firefox, I recommend installing the following add-ons to help make your Firefox browser more secure:
NoScript
AdBlock Plus

3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. **There are firewalls that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

7. Finally, I strongly recommend that you read Miekiemoes' great advice How to prevent malware.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Hi Jeff, I think you’ve done it as everything seems fine now. :clap: If there's nothing more to do, all I'd like to say is thanks very much for all your help. I really appreciate it. :D Best regards, JB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI