Browser Redirect & Ads On The Corner [Closed]
8 min read
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
———
Please download DDS from either of these links
LINK 1
LINK 2
and save it to your desktop.
- Disable any script blocking protection
- Right-click and Run as Administrator dds to run the tool.
- When done, two DDS.txt's will open.
- Save both reports to your desktop.
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt
———-
Please download aswMBR to your desktop.
- Double click the aswMBR icon to run it.
- Click the Scan button to start scan.
- If you are asked to update the Avast Virus database please allow it to do so.
- When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.
[external image: Posted Image]
Click the image to enlarge it
———-
DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
Run by [removed] at 22:25:43 on 2012-10-06
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.3764.1685 [GMT -4:00]
.
AV: McAfee VirusScan *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee VirusScan *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Personal Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files\Acer\Acer Updater\UpdaterService.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Users\7741-6694\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\system32\igfxext.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\Share YouTube Videos\Share YouTube Videos.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskhost.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\7741-6694\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.searchqu.com/102
uDefault_Page_URL = hxxp://acer.msn.com
mDefault_Page_URL = hxxp://acer.msn.com
mStart Page = hxxp://acer.msn.com
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe,
uWindows: Load=C:\Users\7741-6~1\LOCALS~1\Temp\msxaeuaw.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: !{95B7759C-8C7F-4BF1-B163-73684A933233} - No File
TB: {687578B9-7132-4A7A-80E4-30EE31099E03} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [OfficeSyncProcess] "C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe" /quietlaunch "MSOSYNC 9014006104090000"
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Vagex] C:\Users\7741-6694\Desktop\Vagex (1)\Vagex\Vagex.exe
uRun: [Google Update] "C:\Users\7741-6694\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [l]
mRun: [Windows]
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
dRun: [Hkcu] C:\Windows\system32\config\systemprofile\AppData\Roaming\Skype\Skype.exe
dRunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid}
mExplorerRun: [61325] C:\PROGRA~3\LOCALS~1\Temp\msdessmc.scr
StartupFolder: C:\Users\7741-6~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\7741-6694\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\7741-6~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - {50C3F0BE-A832-45AB-BB6E-352D173AFD8C} - C:\Program Files (x86)\iOpus\iMacros\iMacrosSidebar.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = [removed]
TCP: Interfaces\{DAE8B212-6735-4048-BCE1-35440F9038D2} : DhcpNameServer = [removed]
TCP: Interfaces\{DAE8B212-6735-4048-BCE1-35440F9038D2}\449656E672 : DhcpNameServer = [removed] [removed]
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {RFS47S11-1O4O-54C0-L570-6AG5CK21O2QO} - C:\Program Files (x86)\install\adf.lyBOT2012.exe
BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO-X64: 0x1 - No File
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: {687578B9-7132-4A7A-80E4-30EE31099E03} - No File
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
mRun-x64: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun-x64: [l]
mRun-x64: [Windows]
mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce-x64: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
Hosts: 149.5.18.172 www.google-analytics.com.
Hosts: 149.5.18.172 ad-emea.doubleclick.net.
Hosts: 149.5.18.172 www.statcounter.com.
Hosts: 108.163.215.51 www.google-analytics.com.
Hosts: 108.163.215.51 ad-emea.doubleclick.net.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\7741-6694\AppData\Roaming\Mozilla\Firefox\Profiles\6yqijbkl.default\
FF - prefs.js: browser.search.selectedEngine - Web Search (powered by Google)
FF - prefs.js: browser.startup.homepage - hxxp://ca.search.yahoo.com/?fr=w3i&type=W3i_SP,205,0_0,StartPage,20120728,16673,0,29,0
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=2&q=
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\7741-6694\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
—- FIREFOX POLICIES —-
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);
============= SERVICES / DRIVERS ===============
.
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672]
R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-7-26 867712]
R2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-1-8 23584]
R2 Live Updater Service;Live Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2011-4-8 244624]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-4 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-4 676936]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568]
R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-6-28 255744]
R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-7-26 2320920]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys –> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys –> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys –> C:\Windows\system32\drivers\mbam.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-6-14 116648]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-5-15 250288]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-6-14 116648]
S3 ManyCam;ManyCam Virtual Webcam;C:\Windows\system32\DRIVERS\mcvidrv_x64.sys –> C:\Windows\system32\DRIVERS\mcvidrv_x64.sys [?]
S3 mcaudrv_simple;ManyCam Virtual Microphone;C:\Windows\system32\drivers\mcaudrv_x64.sys –> C:\Windows\system32\drivers\mcaudrv_x64.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-15 113120]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys –> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-10-05 23:50:38 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5E2D4577-C6B8-4F22-93C7-8FEFDE0BAE61}\offreg.dll
2012-10-05 23:46:37 ——– d—–w- C:\Program Files (x86)\TorrentHandler
2012-10-05 23:46:19 ——– d—–w- C:\Program Files (x86)\1ClickDownload
2012-10-05 23:33:33 9308616 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5E2D4577-C6B8-4F22-93C7-8FEFDE0BAE61}\mpengine.dll
2012-10-04 17:22:56 ——– d—–w- C:\Users\7741-6694\AppData\Local\{704AB26A-9A48-4BFC-87F4-1976E737B466}
2012-10-04 05:00:45 ——– d—–w- C:\Users\7741-6694\AppData\Roaming\SUPERAntiSpyware.com
2012-10-04 05:00:33 ——– d—–w- C:\ProgramData\SUPERAntiSpyware.com
2012-10-04 05:00:33 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2012-10-04 04:41:36 ——– d—–w- C:\Users\7741-6694\AppData\Local\{0E394F62-BA98-464D-B687-D7CACB9557FD}
2012-10-04 04:31:58 ——– d—–w- C:\Users\7741-6694\AppData\Roaming\Malwarebytes
2012-10-04 04:31:51 ——– d—–w- C:\ProgramData\Malwarebytes
2012-10-04 04:31:50 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys
2012-10-04 04:31:50 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-10-03 12:03:33 ——– d—–w- C:\Users\7741-6694\AppData\Local\{9F61C8D5-9B64-4915-A2E3-A2AE8F7025C9}
2012-10-03 04:43:10 ——– d—–w- C:\Users\7741-6694\AppData\Local\MadCompany
2012-10-03 04:36:10 ——– d—–w- C:\Windows\OEMTemp
2012-10-02 19:44:22 ——– d—–w- C:\Users\7741-6694\AppData\Local\{AA4A80B6-3C0A-4AFA-A625-9A8F199E3A1D}
2012-09-29 19:42:41 ——– d—–w- C:\Users\7741-6694\AppData\Local\{C333246E-50F3-4535-A66E-EC06BC3BE094}
2012-09-28 16:58:18 ——– d—–w- C:\Users\7741-6694\AppData\Local\{BC5474CC-B97C-40A4-9ED7-62E6A1C29B88}
2012-09-28 04:08:43 ——– d—–w- C:\Program Files (x86)\Video Spin Blaster
2012-09-28 03:38:07 ——– d—–w- C:\Users\7741-6694\AppData\Local\Geckofx
2012-09-28 03:38:06 ——– d—–w- C:\ProgramData\u2bviews
2012-09-28 03:37:30 ——– d—–w- C:\Program Files (x86)\U2bviews
2012-09-27 12:08:58 ——– d—–w- C:\Users\7741-6694\AppData\Local\{8CB6F971-AE27-44B1-A8D6-C2D3A0DFF30E}
2012-09-27 05:52:48 ——– d—–w- C:\Program Files (x86)\SwfModify
2012-09-26 21:33:30 ——– d—–w- C:\Users\7741-6694\AppData\Local\CrashDumps
2012-09-26 19:32:34 ——– d—–w- C:\Users\7741-6694\AppData\Local\{D3D3C548-FF89-4932-B492-C27E747ED2BF}
2012-09-26 16:48:57 245760 —-a-w- C:\Windows\System32\OxpsConverter.exe
2012-09-26 08:59:12 ——– d—–w- C:\Users\7741-6694\AppData\Local\{41C4E89E-2676-4C06-B7CC-37A168EF6C3B}
2012-09-25 20:58:45 ——– d—–w- C:\Users\7741-6694\AppData\Local\{56C9788D-90E7-48BF-AFF6-E17991E17507}
2012-09-25 04:12:23 ——– d—–w- C:\Users\7741-6694\AppData\Roaming\TechSmith
2012-09-25 04:12:14 ——– d—–w- C:\Users\7741-6694\AppData\Local\TechSmith
2012-09-25 02:58:27 ——– d—–w- C:\Program Files (x86)\Common Files\TechSmith Shared
2012-09-24 05:14:55 ——– d—–w- C:\Program Files (x86)\Share YouTube Videos
2012-09-23 14:01:00 ——– d—–w- C:\Users\7741-6694\AppData\Roaming\tiger-k
2012-09-23 14:00:59 ——– d—–w- C:\Users\7741-6694\AppData\Roaming\Moyea
2012-09-23 14:00:59 ——– d—–w- C:\ProgramData\Moyea
2012-09-23 14:00:23 175616 —-a-w- C:\Windows\SysWow64\unrar.dll
2012-09-23 14:00:20 ——– d—–w- C:\Program Files (x86)\K-Lite Codec Pack
2012-09-23 14:00:07 606208 —-a-w- C:\Windows\SysWow64\xvidcore.dll
2012-09-23 14:00:07 139264 —-a-w- C:\Windows\SysWow64\xvid.ax
2012-09-23 13:51:28 ——– d—–w- C:\Users\7741-6694\AppData\Local\{43649722-1BE7-41D8-9A1B-7ACDF22B2C17}
2012-09-22 22:46:47 ——– d—–w- C:\Users\7741-6694\AppData\Local\{3D86F035-50FE-41D9-B42A-0E14D9241EFD}
2012-09-22 22:41:09 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-09-22 22:40:37 ——– d—–w- C:\Program Files\iPod
2012-09-22 22:40:36 ——– d—–w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-09-22 22:40:36 ——– d—–w- C:\Program Files\iTunes
2012-09-22 22:38:02 ——– d—–w- C:\Program Files\Bonjour
2012-09-22 22:38:02 ——– d—–w- C:\Program Files (x86)\Bonjour
2012-09-21 02:47:44 ——– d—–w- C:\Program Files (x86)\No Hands SEO
2012-09-20 20:41:48 ——– d—–w- C:\ProgramData\Sincell
2012-09-20 20:41:10 ——– d—–w- C:\Program Files (x86)\Sincell
2012-09-20 19:43:45 ——– d—–w- C:\Users\7741-6694\AppData\Local\{633DB8B4-5405-4D1F-95E2-BEA5D8F1DC94}
2012-09-19 19:29:30 ——– d-sh–w- C:\found.001
2012-09-19 17:20:02 ——– d—–w- C:\Windows\CheckSur
2012-09-19 15:52:28 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys
2012-09-19 15:52:28 41472 —-a-w- C:\Windows\System32\drivers\RNDISMP.sys
2012-09-19 15:52:26 574464 —-a-w- C:\Windows\System32\d3d10level9.dll
2012-09-19 15:52:26 490496 —-a-w- C:\Windows\SysWow64\d3d10level9.dll
2012-09-19 15:47:10 ——– d—–w- C:\Users\7741-6694\AppData\Local\{75F5D823-8C12-4F35-BAC0-21AA1316E357}
2012-09-18 01:18:18 ——– d—–w- C:\Program Files\WinHTTrack
2012-09-12 00:23:44 ——– d—–w- C:\Users\7741-6694\AppData\Local\{C0C39773-BB45-4E63-B098-1EE54E3B40A1}
2012-09-11 19:01:37 ——– d—–w- C:\Users\7741-6694\AppData\Local\{9305826C-F564-4BE7-AF85-9C5170464B1E}
2012-09-08 19:53:56 ——– d—–w- C:\Users\7741-6694\AppData\Local\{0B56D1D4-C476-48C1-ADD3-338966260C72}
2012-09-07 19:56:05 ——– d—–w- C:\Users\7741-6694\AppData\Local\{5830FC18-8606-4BEE-9EE4-326B1F29E500}
.
==================== Find3M ====================
.
2012-09-21 02:47:21 696240 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-09-21 02:47:20 73136 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-24 10:31:32 2312704 —-a-w- C:\Windows\System32\jscript9.dll
2012-08-24 10:21:18 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-08-24 10:20:11 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-08-24 10:14:45 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-08-24 10:13:29 599040 —-a-w- C:\Windows\System32\vbscript.dll
2012-08-24 10:09:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-08-24 06:59:17 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-08-24 06:51:27 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-08-24 06:51:02 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-08-24 06:47:26 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-08-24 06:47:12 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll
2012-08-24 06:43:58 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-08-21 17:01:20 125872 —-a-w- C:\Windows\System32\GEARAspi64.dll
2012-08-21 17:01:20 106928 —-a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-08-15 18:37:19 32032 —-a-w- C:\Users\7741-6694\AppData\Roaming\SQLite3.dll
2012-07-18 18:15:06 3148800 —-a-w- C:\Windows\System32\win32k.sys
2012-07-09 17:42:56 4547984 —-a-w- C:\Windows\System32\usbaaplrc.dll
2012-07-09 17:42:54 52736 —-a-w- C:\Windows\System32\drivers\usbaapl64.sys
.
============= FINISH: 22:28:04.87 ===============
Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 27/07/2011 12:28:48 PM
System Uptime: 06/10/2012 12:51:26 PM (10 hours ago)
.
Motherboard: Acer | | JE70_CP
Processor: Intel® Core™ i3 CPU M 380 @ 2.53GHz | CPU 1 | 2381/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 581 GiB total, 494.698 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Officejet 4500 G510n-z
Device ID: ROOT\MULTIFUNCTION\0002
Manufacturer: HP
Name: Officejet 4500 G510n-z
PNP Device ID: ROOT\MULTIFUNCTION\0002
Service:
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: Officejet 4500 G510n-z
Device ID: ROOT\IMAGE\0001
Manufacturer: HP
Name: Officejet 4500 G510n-z
PNP Device ID: ROOT\IMAGE\0001
Service: StillCam
.
Class GUID:
Description: Ethernet Controller
Device ID: PCI\VEN_14E4&DEV_1692&SUBSYS_033D1025&REV_01\4&2624DE0E&0&00E0
Manufacturer:
Name: Ethernet Controller
PNP Device ID: PCI\VEN_14E4&DEV_1692&SUBSYS_033D1025&REV_01\4&2624DE0E&0&00E0
Service:
.
Class GUID:
Description: Officejet 4500 G510n-z
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer:
Name: Officejet 4500 G510n-z
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
.
Class GUID:
Description: Officejet 4500 G510n-z
Device ID: ROOT\MULTIFUNCTION\0001
Manufacturer:
Name: Officejet 4500 G510n-z
PNP Device ID: ROOT\MULTIFUNCTION\0001
Service:
.
==== System Restore Points ===================
.
RP105: 26/09/2012 12:54:29 PM - Windows Update
RP106: 27/09/2012 2:46:32 AM - Windows Update
RP107: 27/09/2012 11:36:38 PM - Installed U2bviews Software
RP108: 27/09/2012 11:43:25 PM - Installed Toggle Flash
RP109: 28/09/2012 12:08:30 AM - Installed Video Spin Blaster
RP110: 02/10/2012 3:12:12 AM - Windows Update
RP111: 02/10/2012 9:53:57 PM - Removed Contrôle ActiveX Windows Live Mesh pour connexions à distance
RP112: 02/10/2012 9:55:37 PM - Removed Windows Live Mesh ActiveX Control for Remote Connections
RP113: 03/10/2012 12:18:03 AM - Removed RuneScape Launcher 1.2
RP114: 03/10/2012 12:19:03 AM - Removed Facebook Video Calling 1.2.0.159
RP115: 03/10/2012 12:20:03 AM - Removed Google Drive
RP116: 03/10/2012 12:25:30 AM - Removed Toggle Flash
RP117: 03/10/2012 12:29:52 AM - Removed Tube Toolbox
RP118: 03/10/2012 12:35:58 AM - Removed Acer eRecovery Management
RP119: 05/10/2012 7:31:24 PM - Windows Update
.
==== Hosts File Hijack ======================
.
Hosts: 149.5.18.172 www.google-analytics.com.
Hosts: 149.5.18.172 ad-emea.doubleclick.net.
Hosts: 149.5.18.172 www.statcounter.com.
Hosts: 108.163.215.51 www.google-analytics.com.
Hosts: 108.163.215.51 ad-emea.doubleclick.net.
Hosts: 108.163.215.51 www.statcounter.com.
.
==== Installed Programs ======================
.
1ClickDownloader
4500_G510nz_Help
4500G510nz
4500G510nz_Software_Min
7-Zip 9.20
Acer Backup Manager
Acer Crystal Eye Webcam
Acer ePower Management
Acer Games
Acer Registration
Acer ScreenSaver
Acer Updater
Acrobat.com
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.1 MUI
Agatha Christie - 4:50 from Paddington
Alcor Micro USB Card Reader
Apple Application Support
Apple Software Update
µTorrent
Backup Manager Basic
Bejeweled 2 Deluxe
BufferChm
Build-a-lot 2
Camtasia Studio 8
Chuzzle Deluxe
Cross Fire En
D3DX10
DarkComet RAT Remover version 1.0
Destinations
DeviceDiscovery
Diner Dash 2 Restaurant Rescue
DocMgr
DocProc
Dora's World Adventure
Dropbox
eBay Worldwide
EpicBot
FATE - The Traitor Soul
Fax
Final Drive: Nitro
Galerie de photos Windows Live
Google Chrome
Google Update Helper
Hide Window Hotkey
Hotfix for Microsoft Visual C++ 2010 Express - ENU (KB2542054)
HP Update
HPSSupply
iMacros Version 8.0.2.1970
iMobsters Auto
Intel® Graphics Media Accelerator Driver
Intel® Management Engine Components
Intel® Rapid Storage Technology
Java Auto Updater
Java™ 6 Update 31
Java™ 7 Update 5
JavaFX 2.1.1
Jewel Quest Heritage
Junk Mail filter update
K-Lite Codec Pack 8.7.0 (Basic)
Malwarebytes Anti-Malware version 1.65.0.1400
MarketResearch
Mesh Runtime
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft Application Error Reporting
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server 2008 R2 Management Objects
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft SQL Server System CLR Types
Microsoft Visual Basic 2010 Express - ENU
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 Express - ENU
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
Mozilla Firefox 13.0.1 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mystery P.I. - Stolen in San Francisco
Namco All-Stars: PAC-MAN
No-IP DUC
Norton Online Backup
OpenOffice.org 3.3
Palringo
Penguins!
Plants vs. Zombies - Game of the Year
Poker Superstars III
Polar Bowler
Polar Golfer
QuickTime
Resource Hacker Version 3.6.0
Scan
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft Visual Basic 2010 Express - ENU (KB2251489)
Security Update for Microsoft Visual C++ 2010 Express - ENU (KB2251489)
Share YouTube Videos version 1
Skype™ 5.10
SmartWebPrinting
Status
Toolbox
Torchlight
TrayApp
U2bviews Software
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update Installer for WildTangent Games App
Video Spin Blaster
Virtual Villagers 4 - The Tree of Life
Visual Studio 2008 x64 Redistributables
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
VLC media player 2.0.0
WebReg
WildTangent Games App (Acer Games)
Windows Live
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Zuma's Revenge
.
==== Event Viewer Messages From Past Week ========
.
06/10/2012 1:10:48 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
04/10/2012 7:42:51 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.
04/10/2012 12:45:30 AM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
03/10/2012 8:02:33 AM, Error: Service Control Manager [7000] - The svflooje service failed to start due to the following error: The system cannot find the file specified.
03/10/2012 8:02:33 AM, Error: Service Control Manager [7000] - The Host Generic Process for Win32 Services service failed to start due to the following error: The system cannot find the file specified.
.
==== End Of File ===========================
I will be posting the logfile for aswMBR as soon as it finishes.
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-10-06 22:26:39
—————————–
22:26:39.537 OS Version: Windows x64 6.1.7601 Service Pack 1
22:26:39.537 Number of processors: 4 586 0x2505
22:26:39.540 ComputerName: 7741-6694-PC UserName: 7741-6694
22:26:43.607 Initialize success
22:27:55.294 AVAST engine defs: 12100601
22:27:59.041 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:27:59.041 Disk 0 Vendor: WDC_WD64 01.0 Size: 610480MB BusType: 3
22:27:59.119 Disk 0 MBR read successfully
22:27:59.135 Disk 0 MBR scan
22:27:59.135 Disk 0 Windows VISTA default MBR code
22:27:59.229 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 15000 MB offset 2048
22:27:59.291 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 30722048
22:27:59.322 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 595378 MB offset 30926848
22:27:59.548 Disk 0 scanning C:\Windows\system32\drivers
22:28:23.169 Service scanning
22:29:09.642 Modules scanning
22:29:09.642 Disk 0 trace - called modules:
22:29:09.658 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
22:29:09.658 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004bd0060]
22:29:09.658 3 CLASSPNP.SYS[fffff88001b9743f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004915050]
22:29:11.661 AVAST engine scan C:\Windows
22:29:16.847 AVAST engine scan C:\Windows\system32
22:32:40.058 AVAST engine scan C:\Windows\system32\drivers
22:32:55.218 AVAST engine scan C:\Users\7741-6694
22:51:32.233 File: C:\Users\7741-6694\AppData\Local\Temp\00111e97.tmp **INFECTED** Win32:Crypt-LYZ [Trj]
22:51:32.281 File: C:\Users\7741-6694\AppData\Local\Temp\0038fa94.tmp **INFECTED** MSIL:Crypt-HR [Trj]
22:51:33.345 File: C:\Users\7741-6694\AppData\Local\Temp\030eec70.tmp **INFECTED** MSIL:Crypt-IA [Trj]
22:51:33.499 File: C:\Users\7741-6694\AppData\Local\Temp\0313a6d9.tmp **INFECTED** MSIL:Crypt-IA [Trj]
22:51:33.656 File: C:\Users\7741-6694\AppData\Local\Temp\033de521.tmp **INFECTED** Win32:Malware-gen
22:51:34.089 File: C:\Users\7741-6694\AppData\Local\Temp\03cd2c8f.tmp **INFECTED** Win32:Malware-gen
22:51:34.671 File: C:\Users\7741-6694\AppData\Local\Temp\11181.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:35.259 File: C:\Users\7741-6694\AppData\Local\Temp\14831.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:37.213 File: C:\Users\7741-6694\AppData\Local\Temp\34279.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:37.334 File: C:\Users\7741-6694\AppData\Local\Temp\39762.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:38.586 File: C:\Users\7741-6694\AppData\Local\Temp\63451.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:51.501 File: C:\Users\7741-6694\AppData\Local\Temp\82685.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:51.569 File: C:\Users\7741-6694\AppData\Local\Temp\84843.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:51.640 File: C:\Users\7741-6694\AppData\Local\Temp\84862.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:51.733 File: C:\Users\7741-6694\AppData\Local\Temp\88947.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:51.994 File: C:\Users\7741-6694\AppData\Local\Temp\92978.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:52.220 File: C:\Users\7741-6694\AppData\Local\Temp\99796.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:51:52.745 File: C:\Users\7741-6694\AppData\Local\Temp\andro.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:53:11.493 File: C:\Users\7741-6694\AppData\Local\Temp\jar_cache8408653609040883843.tmp **INFECTED** Win32:Malware-gen
22:55:18.112 File: C:\Users\7741-6694\AppData\Roaming\0671d74c1.exe **INFECTED** MSIL:Agent-FF [Trj]
22:56:15.789 File: C:\Users\7741-6694\AppData\Roaming\jkbiem.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:57:40.208 File: C:\Users\7741-6694\AppData\Roaming\rmcxkn.exe **INFECTED** Win32:VBCrypt-AFC [Trj]
22:58:42.985 File: C:\Users\7741-6694\Downloads\Speedy Viewer V1.1 (1).exe **INFECTED** Win32:Malware-gen
22:58:43.040 File: C:\Users\7741-6694\Downloads\Speedy Viewer V1.1.exe **INFECTED** Win32:Malware-gen
22:59:02.139 File: C:\Users\7741-6694\Dropbox\Private\CyberGate v1.00.1\CyberGate v1.00.1.exe **INFECTED** Win32:Rebhip-B [Trj]
22:59:08.110 File: C:\Users\7741-6694\Dropbox\Private\FUTools\Cliente UdTooS.NET.exe **INFECTED** Win32:Malware-gen
22:59:08.909 File: C:\Users\7741-6694\Dropbox\Private\iStealer 3.0\iStealer 3.0.exe **INFECTED** Win32:Malware-gen
22:59:10.570 File: C:\Users\7741-6694\Dropbox\Public\CamMe.exe **INFECTED** Win32:Malware-gen
22:59:10.874 File: C:\Users\7741-6694\Dropbox\Public\RunescapeHackBundle.exe **INFECTED** Win32:Malware-gen
22:59:47.396 AVAST engine scan C:\ProgramData
23:00:56.160 Scan finished successfully
23:03:58.007 Disk 0 MBR has been saved successfully to "C:\Users\7741-6694\Desktop\MBR.dat"
23:03:58.012 The log file has been saved successfully to "C:\Users\7741-6694\Desktop\aswMBR.txt"
Download Combofix from the link below, and save it to your desktop.
Link
**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.
——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–
Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the C:\ComboFix.txt for further review.
- Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the box below:
ClearJavaCache::
DDS::
uStart Page = hxxp://www.searchqu.com/102
Firefox::
FF - ProfilePath - c:\users\7741-6694\AppData\Roaming\Mozilla\Firefox\Profiles\6yqijbkl.default\
FF - prefs.js: browser.search.selectedEngine - Web Search (powered by Google)
FF - prefs.js: browser.startup.homepage - hxxp://ca.search.yahoo.com/?fr=w3i&type=W3i_SP,205,0_0,StartPage,20120728,16673,0,29,0
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=2&q=
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);
File::
c:\progra~3\LOCALS~1\Temp\msdessmc.scr
c:\windows\SysWOW64\Drivers\X6va009
c:\windows\SysWOW64\Drivers\X6va010
c:\windows\SysWOW64\Drivers\X6va011
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"61325"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va009]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va010]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va011]
Driver::
X6va009
X6va010
X6va011
- Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.
[external image: Posted Image]
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix may request an update; please allow it.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you. Post the contents of the log in your next reply.
———-
Post the new ComboFix log to your next reply and also let me know how your system is running.
and also let me know how your system is running.
Good but stick with me…we are almost done.Have't seen any ads since. Wow thanks!
——–
P2P - I see you have P2P software uTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Programs and Features.
———-
I see that your Java software is out of date. Please go to Start >> Control Panel >> Programs and Features >> uninstall all versions of Java.
Now download and install the newest version from here >> http://java.com/en/download/index.jsp
————-
Clear Java Cache
See this page for instructions on how to clear java's cache.
Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
- Under Temporary Internet Files, click the Delete Files button.
- There are three options in the window to clear the cache - Leave ALL 3 Checked
- Downloaded Applets
Downloaded Applications
Other Files
- Downloaded Applets
- Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE. - Click OK to leave the Java Control Panel.
Malwarebytes
I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-
ESET Online Scanner
Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
- Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
- Turn off the real time scanner of any existing antivirus program while performing the online scan
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the activex control to install
- Click Start
- Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
- Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
- Click Scan
- Wait for the scan to finish
- When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
- Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
- Close the ESET online scan, and let me know how things are now.
If you need help please start a new thread.
New members follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI