This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

FBI MoneyPak & more Trojans [Solved]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My daughter's computer screen started up with the a screen supposedly from the FBI/Department of Justice which locked up access to her computer. Fortunately I was able to access the computer with a second account login and changing it to administrative type account.
I ran Malwarebytes and it found several Trojans.
I have shut off her Internet access after reading that some of these infections can mine passwords and other personal data. I told her to get to a clean computer and change her login name and passwords for all her online activities.
I am using my computer to communicate with you for now.
Thanks for your help.

Here is the Malwarebytes log.

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.12.04.08

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Boys :: LISA-PC [administrator]

12/7/2012 9:45:52 AM
mbam-log-2012-12-07 (10-47-15).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 463710
Time elapsed: 1 hour(s), 27 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 1
C:\Users\Boys\AppData\Roaming\shadmx.dll (Trojan.RedirRdll2.Gen) -> No action taken.

Registry Keys Detected: 2
HKCU\SOFTWARE\CLASSES\CLSID\{42AEDC87-2188-41FD-B9A3-0C966FEABEC1}\INPROCSERVER32 (Trojan.Zaccess) -> No action taken.
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Live Security Platinum (Rogue.LiveSecurityPlatinum) -> No action taken.

Registry Values Detected: 4
HKCU\SOFTWARE\CLASSES\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32| (Trojan.Zaccess) -> Data: C:\Users\Boys\AppData\Local\{dbe772ed-b210-943c-747f-185608048705}\n. -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|XSECVA (Trojan.Agent) -> Data: "C:\Users\Boys\AppData\Roaming\xsecva\xsecva.exe" -s -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|shadmx (Trojan.RedirRdll2.Gen) -> Data: rundll32.exe "C:\Users\Boys\AppData\Roaming\shadmx.dll",PszDupW -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|bridsass (Trojan.RedirRdll4.Gen) -> Data: rundll32 "C:\Users\Boys\AppData\Local\Temp\drivinit.dll",CreateProcessNotify -> No action taken.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 5
C:\ProgramData\cl6MFSXX.exe (Trojan.Downloader) -> No action taken.
C:\Users\Lisa\wgsdgsdgdsgsd.exe (Trojan.Downloader) -> No action taken.
C:\Users\Lisa\AppData\Local\Temp\00154cb8.exe (Trojan.Agent.GNI) -> No action taken.
C:\Users\Lisa\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\4919cb1c-137e5841 (Trojan.Downloader) -> No action taken.
C:\Users\Boys\AppData\Roaming\shadmx.dll (Trojan.RedirRdll2.Gen) -> No action taken.

(end)


Ran HJT and here are the results.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:50:28 AM, on 12/7/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_FATIFJA.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Boys\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Verizon Broadband Toolbar - {A057A204-BACC-4D26-8398-26FADCF27386} - C:\PROGRA~1\VERIZO~1\VERIZO~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Verizon Broadband Toolbar - {A057A204-BACC-4D26-8398-26FADCF27386} - C:\PROGRA~1\VERIZO~1\VERIZO~1.DLL
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [Verizon_McciTrayApp] "C:\Program Files\Verizon\McciTrayApp.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
O4 - HKLM\..\Run: [FUFAXSTM] "C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WorkForce 610(Network)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIFJA.EXE /FU "C:\Users\Boys\AppData\Local\Temp\E_S8A49.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Boys\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Boys\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [XSECVA] "C:\Users\Boys\AppData\Roaming\xsecva\xsecva.exe" -s
O4 - HKCU\..\Run: [shadmx] rundll32.exe "C:\Users\Boys\AppData\Roaming\shadmx.dll",PszDupW
O4 - HKCU\..\Run: [msxdg] "C:\Windows\System32\rundll32.exe" "C:\Users\Boys\AppData\Roaming\msxdg.dll",Long_AsDouble
O4 - HKCU\..\Run: [bridsass] rundll32 "C:\Users\Boys\AppData\Local\Temp\drivinit.dll",CreateProcessNotify
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/free-tri…ploader_v10.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: IHA_MessageCenter - Verizon - C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio.exe (file missing)

–
End of file - 9969 bytes
Please do the following:

Download the appropriate version for your system of the Farbar Recovery Scan Tool and save it to a flash drive.


Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to the disclaimer.

[*]Place a check next to List Drivers MD5 as well as the default check marks that are already there

[*]Press Scan button.

[*]type exit and reboot the computer normally

[*]FRST will make a log (FRST.txt) on the flash drive, please copy and paste the log in your reply.

Good morning, CatByte and thank you for your help. Which user account should I log on to, the "Lisa" account, which is the one that is blocked, or the "Boys" account which I can access as Administrator?
it shouldn't matter at I am asking that you access the Recovery Environment, which is prior to windows loading, it gives me a good look at what is left on the machine
Here is the FRST.txt file. Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-12-2012 Ran by [removed] at 08-12-2012 08:59:03 Running from E:\ Windows Vista ™ Home Basic Service Pack 1 (X86) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\…\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [167936 2008-05-04] (Alps Electric Co., Ltd.) HKLM\…\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" [184320 2008-11-06] (CyberLink Corp.) HKLM\…\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter [x] HKLM\…\Run: [Verizon_McciTrayApp] "C:\Program Files\Verizon\McciTrayApp.exe" [1565696 2010-03-17] (Alcatel-Lucent) HKLM\…\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2007-11-12] (IDT, Inc.) HKLM\…\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" [x] HKLM\…\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-10-11] (Apple Inc.) HKLM\…\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [38872 2012-07-31] (Adobe Systems Incorporated) HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-11] (Adobe Systems Incorporated) HKLM\…\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe [669520 2009-01-12] (SEIKO EPSON CORPORATION) HKLM\…\Run: [FUFAXSTM] "C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe" [843776 2009-02-05] (SEIKO EPSON CORPORATION) HKLM\…\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-09-09] (Apple Inc.) HKLM\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-10-25] (Apple Inc.) HKU\Boys\…\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation) HKU\Boys\…\Run: [WorkForce 610(Network)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIFJA.EXE /FU "C:\Users\Boys\AppData\Local\Temp\E_S8A49.tmp" /EF "HKCU" [199680 2009-01-25] (SEIKO EPSON CORPORATION) HKU\Boys\…\Run: [Google Update] "C:\Users\Boys\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-12-04] (Google Inc.) HKU\Boys\…\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation) HKU\Boys\…\Run: [Facebook Update] "C:\Users\Boys\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [138096 2012-07-13] (Facebook Inc.) HKU\Boys\…\Run: [XSECVA] "C:\Users\Boys\AppData\Roaming\xsecva\xsecva.exe" -s [x] HKU\Boys\…\Run: [shadmx] rundll32.exe "C:\Users\Boys\AppData\Roaming\shadmx.dll",PszDupW [150528 2012-08-18] () HKU\Boys\…\Run: [msxdg] "C:\Windows\System32\rundll32.exe" "C:\Users\Boys\AppData\Roaming\msxdg.dll",Long_AsDouble [432128 2012-08-18] (Electronic Arts Inc.) HKU\Boys\…\Run: [bridsass] rundll32 "C:\Users\Boys\AppData\Local\Temp\drivinit.dll",CreateProcessNotify [x] HKU\Lisa\…\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation) HKU\Lisa\…\Run: [HLBackupScheduler] C:\Program Files\Backup Assistant Plus\V CAST Backup Scheduler.exe [5300360 2012-01-16] () HKU\Lisa\…\Run: [EPSONDA0B64] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIFJA.EXE /FU "C:\Windows\TEMP\E_SA3.tmp" /EF "HKCU" [199680 2009-01-25] (SEIKO EPSON CORPORATION) HKU\Lisa\…\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\Lisa\…\Run: [WorkForce 610(Network)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIFJA.EXE /FU "C:\Windows\TEMP\E_S45BC.tmp" /EF "HKCU" [199680 2009-01-25] (SEIKO EPSON CORPORATION) HKU\Lisa\…\Run: [Spotify] "C:\Users\Lisa\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [7880664 2012-10-29] (Spotify Ltd) HKU\Lisa\…\Run: [Spotify Web Helper] "C:\Users\Lisa\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1199576 2012-10-29] (Spotify Ltd) HKU\Lisa\…\Run: [svñhîst] %USERPROFILE%\appdata\local\temp\00154cb8.exe [x] HKU\Lisa\…\CurrentVersion\Windows: [Load] C:\Users\Lisa\LOCALS~1\Temp\msvuimuwc.exe Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [X] Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Startup: C:\Users\Boys\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\RA Media Server\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\TEMP.Lisa-PC.000\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) ==================== Services (Whitelisted) =================== 2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE.EXE" [116608 2011-11-01] (SUPERAntiSpyware.com) 2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-09-23] (Stardock Corporation) 2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) 2 IHA_MessageCenter; "C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe" [352248 2012-08-03] (Verizon) 2 mfevtp; "C:\Windows\system32\mfevtps.exe" [151912 2012-05-25] (McAfee, Inc.) 2 MotoHelper; C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe [227184 2011-08-10] () 2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) 2 a016mdm; C:\Windows\System32\winpowerrmi.dll [x] 2 a8djusb; C:\Windows\System32\AmdLLD.dll [x] 2 ABVPN2K; C:\Windows\System32\s3psddr.dll [x] 2 aexnsclient; C:\Windows\System32\ati2mtaa.dll [x] 2 alertmanager; C:\Windows\System32\caisafe.dll [x] 2 atchksrv; C:\Windows\System32\se2Dunic.dll [x] 2 atkdisplf; C:\Windows\System32\RR2IOMod.dll [x] 2 ATKGFNEXSrv; C:\Windows\System32\telnet.dll [x] 2 Cam5607; C:\Windows\System32\transactional.dll [x] 2 ccevtmgr; C:\Windows\System32\backupexecjobengine.dll [x] 2 CDRPDACC; C:\Windows\System32\se27nd5.dll [x] 2 cfosspeed; C:\Windows\System32\MaxtorFrontPanel1.dll [x] 2 citrixwmiservice; C:\Windows\System32\nmwcd.dll [x] 2 CoachUsb; C:\Windows\System32\s217bus.dll [x] 2 cobbmservice; C:\Windows\System32\belmonitorservice.dll [x] 2 com0com; C:\Windows\System32\{a7447300-8075-4b0d-83f1-3d75c8ebc623}.dll [x] 2 cqmgstor; C:\Windows\System32\s3twistr.dll [x] 2 ctsfm2k; C:\Windows\System32\zebrmdmc.dll [x] 2 DC21x4; C:\Windows\System32\ldap.dll [x] 2 diskeeper; C:\Windows\System32\CTERFXFX.DLL.dll [x] 2 dlaboiom; C:\Windows\System32\db2licd.dll [x] 2 dwusbdnt; C:\Windows\System32\superproserver.dll [x] 2 ehrecvr; C:\Windows\System32\vmauthdservice.dll [x] 2 EQDRV5; C:\Windows\System32\freepops.dll [x] 2 Freedom; C:\Windows\System32\vmnetdhcp.dll [x] 2 gearsecurity; C:\Windows\System32\rchost.dll [x] 2 GMSIPCI; C:\Windows\System32\Cam5603D.dll [x] 2 GT891x; C:\Windows\System32\Memctl.dll [x] 2 ha10kx2k; C:\Windows\System32\nim32.dll [x] 2 HIDSwvd; C:\Windows\System32\zntport.dll [x] 2 hotspotshieldservice; C:\Windows\System32\3combootp.dll [x] 2 houdinilicenseserver; C:\Windows\System32\Video3D.dll [x] 2 HPFXBULK; C:\Windows\System32\tdpipe.dll [x] 2 hwpsgt; C:\Windows\System32\FsVga.dll [x] 2 ini910u; C:\Windows\System32\tvald.dll [x] 2 IntelC53; C:\Windows\System32\anydvd.dll [x] 2 IPSECSHM; C:\Windows\System32\bridge.dll [x] 2 iviaspi; C:\Windows\System32\hpqddsvc.dll [x] 2 JGOGO; C:\Windows\System32\generichidservice.dll [x] 2 k750mdfl; C:\Windows\System32\acedrv05.dll [x] 2 kl1; C:\Windows\System32\LVRS.dll [x] 2 kraidsvc; C:\Windows\System32\NxNetMon.dll [x] 2 LMouFilt; C:\Windows\System32\3comtftp.dll [x] 2 LPCFilter; C:\Windows\System32\sisagp.dll [x] 2 ltxred; C:\Windows\System32\cachemanxp.dll [x] 2 lvcomser; C:\Windows\System32\UsbDiag.dll [x] 2 LVRS; C:\Windows\System32\w810mdfl.dll [x] 2 marvinbus; C:\Windows\System32\vzcdbsvc.dll [x] 2 modemcsa; C:\Windows\System32\se59mdm.dll [x] 2 mpe; C:\Windows\System32\PSDFilter.dll [x] 2 mrpostman; C:\Windows\System32\es1371.dll [x] 2 MSFWDrv; C:\Windows\System32\nod32krn.dll [x] 2 MTC0001_ESB; C:\Windows\System32\NMSSvc.dll [x] 2 NtMtlFax; C:\Windows\System32\atfsd.dll [x] 2 nvpvrmon; C:\Windows\System32\pciSd.dll [x] 2 oracle_load_balancer_60_client-forms6i; C:\Windows\System32\xcomm.dll [x] 2 osaio; C:\Windows\System32\mdvrmng.dll [x] 2 ovmsmaccessmanager; C:\Windows\System32\snare.dll [x] 2 pcscnsrv; C:\Windows\System32\DLH5X.dll [x] 2 pdlncbas; C:\Windows\System32\usbhub.dll [x] 2 pvservice; C:\Windows\System32\z525mgmt.dll [x] 2 RalinkRegistryWriter; C:\Windows\System32\pdlnctdl.dll [x] 2 rapapp; C:\Windows\System32\hidir.dll [x] 2 raspti; C:\Windows\System32\protexislicensing.dll [x] 2 rca; C:\Windows\System32\winachsf.dll [x] 2 REVOSENS; C:\Windows\System32\snapman.dll [x] 2 rsvp; C:\Windows\System32\pcx1unic.dll [x] 2 RTHDMIAzAudService; C:\Windows\System32\mouclass.dll [x] 2 rupsmon; C:\Windows\System32\iolodmv.dll [x] 2 RVIEG01; C:\Windows\System32\lxdm_device.dll [x] 2 s117bus; C:\Windows\System32\ssm_mdfl.dll [x] 2 s125mdm; C:\Windows\System32\p17.dll [x] 2 s7oppitx; C:\Windows\System32\BCMTPM.dll [x] 2 sdcplh; C:\Windows\System32\HFACSVC.dll [x] 2 slapd-config52; C:\Windows\System32\symc8xx.dll [x] 2 spbbcsvc; C:\Windows\System32\tvtpktfilter.dll [x] 2 SRTSPL; C:\Windows\System32\SE2Cmgmt.dll [x] 2 SrvcSSIOMngr; C:\Windows\System32\icdsptsv.dll [x] 2 st330service; C:\Windows\System32\radclock.dll [x] 2 streamloadservice; C:\Windows\System32\buslogic.dll [x] 2 SunkFilt39; C:\Windows\System32\networkx.dll [x] 2 symevent; C:\Windows\System32\idechndr.dll [x] 2 symlcbrd; C:\Windows\System32\wanatw.dll [x] 2 symredrv; C:\Windows\System32\CAM1210.dll [x] 2 tangoservice; C:\Windows\System32\tdtcp.dll [x] 2 tavsvc; C:\Windows\System32\btkrnl.dll [x] 2 tga; C:\Windows\System32\trioservice.dll [x] 2 thkeys; C:\Windows\System32\blueletaudio.dll [x] 2 tmlisten; C:\Windows\System32\se58mdm.dll [x] 2 tosrfusb; C:\Windows\System32\netddedsdm.dll [x] 2 tpsrv; C:\Windows\System32\BlueSoleilCS.dll [x] 2 transactional; C:\Windows\System32\mcontrol.dll [x] 2 trayman; C:\Windows\System32\appmgmt.dll [x] 2 USBDeviceService; C:\Windows\System32\gdrv.dll [x] 2 usnsvc; C:\Windows\System32\mqdmmdfl.dll [x] 2 vcsw; C:\Windows\System32\SED133x.dll [x] 2 VRADFIL; C:\Windows\System32\wg6n.dll [x] 2 vrfwsvc; C:\Windows\System32\se45mgmt.dll [x] 2 vulfntrs; C:\Windows\System32\sysmgmthp.dll [x] 2 WaveEnrollmentService; C:\Windows\System32\bthenum.dll [x] 2 wcontrol; C:\Windows\System32\sisnic.dll [x] 2 websenselogserver; C:\Windows\System32\ssscsisv.dll [x] 2 wuolservice; C:\Windows\System32\aiclient.dll [x] 2 z525mgmt; C:\Windows\System32\KR10I.dll [x] ==================== Drivers (Whitelisted) ==================== 0 669f37cbc1000922; C:\Windows\System32\Drivers\669f37cbc1000922.sys [71424 2012-08-19] () ATTENTION =====> Rootkit? 3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2008-10-27] (Broadcom Corporation) 3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [121544 2012-02-22] (McAfee, Inc.) 0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [464304 2012-02-22] (McAfee, Inc.) 1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-11-01] (SUPERAdBlocker.com and SUPERAntiSpyware.com) 3 SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [12872 2010-07-06] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) 1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [67664 2011-11-01] (SUPERAdBlocker.com and SUPERAntiSpyware.com) 1 Smb; C:\Windows\System32\DRIVERS\smb.sys [0 2012-05-08] () 3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [186592 2009-12-27] (Jungo) 3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x] 3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [x] 3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [x] 3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [x] 3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [x] 3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x] 3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== NETSVC: ctsfm2k -> C:\Windows\system32\zebrmdmc.dll ==> No File. NETSVC: LVRS -> C:\Windows\system32\w810mdfl.dll ==> No File. NETSVC: pvservice -> C:\Windows\system32\z525mgmt.dll ==> No File. NETSVC: ovmsmaccessmanager -> C:\Windows\system32\snare.dll ==> No File. NETSVC: HPFXBULK -> C:\Windows\system32\tdpipe.dll ==> No File. NETSVC: ha10kx2k -> C:\Windows\system32\nim32.dll ==> No File. NETSVC: pcscnsrv -> C:\Windows\system32\DLH5X.dll ==> No File. NETSVC: hwpsgt -> C:\Windows\system32\FsVga.dll ==> No File. NETSVC: thkeys -> C:\Windows\system32\blueletaudio.dll ==> No File. NETSVC: JGOGO -> C:\Windows\system32\generichidservice.dll ==> No File. NETSVC: tosrfusb -> C:\Windows\system32\netddedsdm.dll ==> No File. NETSVC: ccevtmgr -> C:\Windows\system32\backupexecjobengine.dll ==> No File. NETSVC: kl1 -> C:\Windows\system32\LVRS.dll ==> No File. NETSVC: REVOMSFWDrv -> No Registry Path. NETSVC: k750mdfl -> C:\Windows\system32\acedrv05.dll ==> No File. NETSVC: modemcsa -> C:\Windows\system32\se59mdm.dll ==> No File. NETSVC: mrpostman -> C:\Windows\system32\es1371.dll ==> No File. NETSVC: alertmanager -> C:\Windows\system32\caisafe.dll ==> No File. NETSVC: CDRPDACC -> C:\Windows\system32\se27nd5.dll ==> No File. NETSVC: EQDRV5 -> C:\Windows\system32\freepops.dll ==> No File. NETSVC: GMSIPCI -> C:\Windows\system32\Cam5603D.dll ==> No File. NETSVC: raspti -> C:\Windows\system32\protexislicensing.dll ==> No File. NETSVC: aexnsclient -> C:\Windows\system32\ati2mtaa.dll ==> No File. NETSVC: diskeeper -> C:\Windows\system32\CTERFXFX.DLL.dll ==> No File. NETSVC: cobbmservice -> C:\Windows\system32\belmonitorservice.dll ==> No File. NETSVC: transactional -> C:\Windows\system32\mcontrol.dll ==> No File. NETSVC: tangoservice -> C:\Windows\system32\tdtcp.dll ==> No File. NETSVC: streamloadservice -> C:\Windows\system32\buslogic.dll ==> No File. NETSVC: cqmgstor -> C:\Windows\system32\s3twistr.dll ==> No File. NETSVC: SrvcSSIOMngr -> C:\Windows\system32\icdsptsv.dll ==> No File. NETSVC: st330service -> C:\Windows\system32\radclock.dll ==> No File. NETSVC: iviaspi -> C:\Windows\system32\hpqddsvc.dll ==> No File. NETSVC: rsvp -> C:\Windows\system32\pcx1unic.dll ==> No File. NETSVC: tpsrv -> C:\Windows\system32\BlueSoleilCS.dll ==> No File. NETSVC: WaveEnrollmentService -> C:\Windows\system32\bthenum.dll ==> No File. NETSVC: websenselogserver -> C:\Windows\system32\ssscsisv.dll ==> No File. NETSVC: s7oppitx -> C:\Windows\system32\BCMTPM.dll ==> No File. NETSVC: tavsvc -> C:\Windows\system32\btkrnl.dll ==> No File. NETSVC: IntelC53 -> C:\Windows\system32\anydvd.dll ==> No File. NETSVC: wcontrol -> C:\Windows\system32\sisnic.dll ==> No File. NETSVC: vcsw -> C:\Windows\system32\SED133x.dll ==> No File. NETSVC: nvpvrmon -> C:\Windows\system32\pciSd.dll ==> No File. NETSVC: mpe -> C:\Windows\system32\PSDFilter.dll ==> No File. NETSVC: LMouFilt -> C:\Windows\system32\3comtftp.dll ==> No File. NETSVC: mcstrm -> No Registry Path. NETSVC: lilsgt -> No Registry Path. NETSVC: ehrecvr -> C:\Windows\system32\vmauthdservice.dll ==> No File. NETSVC: ini910u -> C:\Windows\system32\tvald.dll ==> No File. NETSVC: gearsecurity -> C:\Windows\system32\rchost.dll ==> No File. NETSVC: GT891x -> C:\Windows\system32\Memctl.dll ==> No File. NETSVC: citrixwmiservice -> C:\Windows\system32\nmwcd.dll ==> No File. NETSVC: symlcbrd -> C:\Windows\system32\wanatw.dll ==> No File. NETSVC: RTHDMIAzAudService -> C:\Windows\system32\mouclass.dll ==> No File. NETSVC: RalinkRegistryWriter -> C:\Windows\system32\pdlnctdl.dll ==> No File. NETSVC: CTAudSvcService -> No Registry Path. NETSVC: omci -> No Registry Path. NETSVC: nimcdfxk -> No Registry Path. NETSVC: mafwboot -> No Registry Path. NETSVC: NtMtlFax -> C:\Windows\system32\atfsd.dll ==> No File. NETSVC: vulfntrs -> C:\Windows\system32\sysmgmthp.dll ==> No File. NETSVC: dwusbdnt -> C:\Windows\system32\superproserver.dll ==> No File. NETSVC: ABVPN2K -> C:\Windows\system32\s3psddr.dll ==> No File. NETSVC: s125mdm -> C:\Windows\system32\p17.dll ==> No File. NETSVC: CoachUsb -> C:\Windows\system32\s217bus.dll ==> No File. NETSVC: DC21x4 -> C:\Windows\system32\ldap.dll ==> No File. NETSVC: Freedom -> C:\Windows\system32\vmnetdhcp.dll ==> No File. NETSVC: ltxred -> C:\Windows\system32\cachemanxp.dll ==> No File. NETSVC: retrolauncher -> No Registry Path. NETSVC: BTSLBCSP -> No Registry Path. NETSVC: atchksrv -> C:\Windows\system32\se2Dunic.dll ==> No File. NETSVC: vrfwsvc -> C:\Windows\system32\se45mgmt.dll ==> No File. NETSVC: oracle_load_balancer_60_client-forms6i -> C:\Windows\system32\xcomm.dll ==> No File. NETSVC: usnsvc -> C:\Windows\system32\mqdmmdfl.dll ==> No File. NETSVC: plsremotesvc -> No Registry Path. NETSVC: osaio -> C:\Windows\system32\mdvrmng.dll ==> No File. NETSVC: SRTSPL -> C:\Windows\system32\SE2Cmgmt.dll ==> No File. NETSVC: symevent -> C:\Windows\system32\idechndr.dll ==> No File. NETSVC: a8djusb -> C:\Windows\system32\AmdLLD.dll ==> No File. NETSVC: IPSECSHM -> C:\Windows\system32\bridge.dll ==> No File. NETSVC: VRADFIL -> C:\Windows\system32\wg6n.dll ==> No File. NETSVC: trayman -> C:\Windows\system32\appmgmt.dll ==> No File. NETSVC: slapd-config52 -> C:\Windows\system32\symc8xx.dll ==> No File. NETSVC: hotspotshieldservice -> C:\Windows\system32\3combootp.dll ==> No File. NETSVC: kraidsvc -> C:\Windows\system32\NxNetMon.dll ==> No File. NETSVC: symredrv -> C:\Windows\system32\CAM1210.dll ==> No File. NETSVC: LPCFilter -> C:\Windows\system32\sisagp.dll ==> No File. NETSVC: sdcplh -> C:\Windows\system32\HFACSVC.dll ==> No File. NETSVC: HIDSwvd -> C:\Windows\system32\zntport.dll ==> No File. NETSVC: a016mdm -> C:\Windows\system32\winpowerrmi.dll ==> No File. NETSVC: marvinbus -> C:\Windows\system32\vzcdbsvc.dll ==> No File. NETSVC: atkdisplf -> C:\Windows\system32\RR2IOMod.dll ==> No File. NETSVC: spbbcsvc -> C:\Windows\system32\tvtpktfilter.dll ==> No File. NETSVC: ATKGFNEXSrv -> C:\Windows\system32\telnet.dll ==> No File. NETSVC: MTC0001_ESB -> C:\Windows\system32\NMSSvc.dll ==> No File. NETSVC: rapapp -> C:\Windows\system32\hidir.dll ==> No File. NETSVC: s117bus -> C:\Windows\system32\ssm_mdfl.dll ==> No File. NETSVC: wuolservice -> C:\Windows\system32\aiclient.dll ==> No File. NETSVC: tmlisten -> C:\Windows\system32\se58mdm.dll ==> No File. NETSVC: tga -> C:\Windows\system32\trioservice.dll ==> No File. NETSVC: pdlncbas -> C:\Windows\system32\usbhub.dll ==> No File. NETSVC: com0com -> C:\Windows\system32\{a7447300-8075-4b0d-83f1-3d75c8ebc623}.dll ==> No File. NETSVC: cfosspeed -> C:\Windows\system32\MaxtorFrontPanel1.dll ==> No File. NETSVC: Cam5607 -> C:\Windows\system32\transactional.dll ==> No File. NETSVC: USBDeviceService -> C:\Windows\system32\gdrv.dll ==> No File. NETSVC: z525mgmt -> C:\Windows\system32\KR10I.dll ==> No File. NETSVC: lvcomser -> C:\Windows\system32\UsbDiag.dll ==> No File. NETSVC: SunkFilt39 -> C:\Windows\system32\networkx.dll ==> No File. NETSVC: rca -> C:\Windows\system32\winachsf.dll ==> No File. NETSVC: rupsmon -> C:\Windows\system32\iolodmv.dll ==> No File. NETSVC: RVIEG01 -> C:\Windows\system32\lxdm_device.dll ==> No File. NETSVC: dlaboiom -> C:\Windows\system32\db2licd.dll ==> No File. NETSVC: houdinilicenseserver -> C:\Windows\system32\Video3D.dll ==> No File. NETSVC: uiusys -> No Registry Path. ==================== One Month Created Files and Folders ======== 2012-12-08 08:58 - 2012-12-08 08:58 - 00000000 ____D C:\FRST 2012-12-07 07:50 - 2012-12-07 07:50 - 00009970 ____A C:\Users\Boys\Desktop\hijackthis1207-2.log 2012-12-07 06:30 - 2012-12-07 06:38 - 00009963 ____A C:\Users\Boys\Desktop\hijackthis.log 2012-12-07 06:29 - 2012-12-07 06:27 - 00388608 ____A (Trend Micro Inc.) C:\Users\Boys\Desktop\HiJackThis.exe 2012-12-04 09:41 - 2012-12-04 09:41 - 00002142 ____A C:\Users\Boys\Desktop\RegBk04 dec12.reg 2012-12-04 09:24 - 2012-12-04 09:24 - 00000000 ____D C:\Users\Lisa\AppData\Local\{71E8B520-AE74-4F45-AC45-354B1710CD6A} 2012-12-04 09:12 - 2012-12-04 09:12 - 00000000 ____D C:\Users\Boys\AppData\Local\{0EAA5A3E-C3E0-403A-8C1E-D9E76D11D631} 2012-12-02 12:46 - 2012-12-02 12:46 - 00000000 ____D C:\Users\Boys\AppData\Local\{30725F9E-4965-4E9E-B51E-9CC05DB0446B} 2012-12-02 08:11 - 2012-12-02 08:11 - 00000000 ____D C:\Users\Lisa\AppData\Local\{2896603C-D37A-4252-B0D2-86C137321B2C} 2012-12-01 15:02 - 2012-12-01 15:02 - 00000000 ____D C:\Users\Lisa\AppData\Local\{134E178C-3B35-4F21-A71C-9EE0ED9DF36D} 2012-11-30 16:11 - 2012-11-30 16:11 - 00000000 ____D C:\Users\Lisa\AppData\Local\{E5306341-FD7B-4DEC-8AE6-65E63EB68165} 2012-11-29 17:15 - 2012-11-29 17:15 - 00000000 ____D C:\Users\Lisa\AppData\Local\{1665FE41-0B3A-4A9A-8BA4-0F6514FD06C1} 2012-11-29 05:15 - 2012-11-29 05:15 - 00000000 ____D C:\Users\Lisa\AppData\Local\{006B9E28-F81E-4F6D-8F9E-2A9204E78437} 2012-11-28 19:48 - 2012-11-28 19:48 - 00182272 ____A C:\Users\Lisa\wgsdgsdgdsgsd.exe 2012-11-28 19:48 - 2012-11-28 19:48 - 00182272 ____A C:\Users\All Users\cl6MFSXX.exe 2012-11-28 19:48 - 2012-11-28 19:48 - 00000001 ____A C:\Users\All Users\cl6MFSXX.exe_.b 2012-11-28 19:48 - 2012-11-28 19:48 - 00000001 ____A C:\Users\All Users\cl6MFSXX.exe.b 2012-11-28 19:48 - 2012-11-28 19:48 - 00000000 ____A C:\Users\All Users\73b5h28.dat 2012-11-28 15:28 - 2012-11-28 15:28 - 00000000 ____D C:\Users\Lisa\AppData\Local\{36B748C4-E16C-4EA1-BF07-B4CEA6AB93CF} 2012-11-27 18:17 - 2012-11-27 18:17 - 00000000 ____D C:\Users\Lisa\AppData\Local\{9F26760B-D64F-46D6-A7EE-A10E0C850ACE} 2012-11-27 06:16 - 2012-11-27 06:16 - 00000000 ____D C:\Users\Lisa\AppData\Local\{A816FBF5-EBD4-42ED-9712-AAFA2AD333C0} 2012-11-26 18:16 - 2012-11-26 18:16 - 00000000 ____D C:\Users\Lisa\AppData\Local\{0CF8119A-D1E6-408B-9D39-69F66ECD7E18} 2012-11-26 06:16 - 2012-11-26 06:16 - 00000000 ____D C:\Users\Lisa\AppData\Local\{C9464C11-F0FD-41E8-BADD-6B66CE1AE8F6} 2012-11-25 06:15 - 2012-11-25 18:16 - 00000000 ____D C:\Users\Lisa\AppData\Local\{99508E3A-154F-4A87-B652-CC0880BA9932} 2012-11-24 15:41 - 2012-09-11 06:22 - 00196608 ____A C:\Users\Lisa\AppData\Local\common_functions.dll 2012-11-24 15:41 - 2012-06-26 02:59 - 00940544 ____A (Apache Software Foundation) C:\Users\Lisa\AppData\Local\log4cxx.dll 2012-11-24 14:00 - 2012-11-24 14:00 - 00000000 ____D C:\Users\All Users\PC Optimizer Pro 2012-11-24 13:52 - 2012-11-24 13:52 - 01639104 ____A (W3i, LLC) C:\Users\Lisa\Downloads\playalotgames_d146490.exe 2012-11-24 13:49 - 2012-11-24 15:44 - 00000000 ____D C:\Users\All Users\Yahoo! 2012-11-24 13:49 - 2012-11-24 15:44 - 00000000 ____D C:\Program Files\Yahoo! 2012-11-24 09:46 - 2012-11-24 09:46 - 00000000 ____D C:\Users\Boys\AppData\Local\{5A8C4206-278B-4C00-8BB1-54FE09DC4DC5} 2012-11-24 06:40 - 2012-11-24 06:41 - 00000000 ____D C:\Users\Lisa\AppData\Local\{B9F70A76-CBD5-418F-9D50-BE2D0290F01F} 2012-11-23 16:51 - 2012-11-23 16:51 - 00000000 ____D C:\Users\Lisa\AppData\Local\{CE087A8B-7E73-455C-95DC-657AF114C65B} 2012-11-23 16:44 - 2012-11-23 16:44 - 00000000 ____D C:\Users\Boys\AppData\Local\{21A3628D-6586-4FFC-89D2-673AFFA63102} 2012-11-22 16:12 - 2012-11-22 16:12 - 00000000 ____D C:\Users\Boys\AppData\Local\{5A74277E-4443-4394-A98B-4A6278EF92F4} 2012-11-22 07:55 - 2012-11-22 07:55 - 00000000 ____D C:\Users\Lisa\AppData\Local\{0D2C200C-D424-4B3F-847D-BB473300DC12} 2012-11-21 17:05 - 2012-11-21 17:05 - 00000000 ____D C:\Users\Lisa\AppData\Local\{6942E797-E825-4AED-8D45-F4E8ED14A9BC} 2012-11-20 07:47 - 2012-11-20 07:47 - 00000000 ____D C:\Users\Lisa\AppData\Local\{227A720C-DEB8-4E45-AD45-FB09DCEE7938} 2012-11-19 17:06 - 2012-11-19 17:06 - 00000000 ____D C:\Users\Lisa\AppData\Local\{32DE1F0F-1200-451E-B732-0673DD7F5A99} 2012-11-18 13:32 - 2012-11-18 13:32 - 00000000 ____D C:\Program Files\QuickTime 2012-11-18 09:35 - 2012-11-18 09:35 - 00000000 ____D C:\Users\Lisa\AppData\Local\{E75F393B-CD9A-4486-BE23-F7A4727C3594} 2012-11-16 15:47 - 2012-11-16 15:47 - 00000000 ____D C:\Users\Lisa\AppData\Local\{3D80F8BF-E134-4C7E-8315-AB9B4B5EB693} 2012-11-16 15:42 - 2012-11-16 15:42 - 00000000 ____D C:\Users\Lisa\AppData\Local\{F4163A2D-EC38-4DE6-AFF4-A27E9E16E2BB} 2012-11-15 16:57 - 2012-11-15 16:57 - 00000000 ____D C:\Users\Lisa\AppData\Local\{3C311E3D-3D28-4FDA-B3B0-281FE5366D29} 2012-11-15 13:08 - 2012-11-15 13:08 - 00000000 ____D C:\Users\Boys\AppData\Local\{A1B5353F-C0B5-47FB-993D-96CB5DEE427B} 2012-11-15 04:57 - 2012-11-15 04:57 - 00000000 ____D C:\Users\Lisa\AppData\Local\{ACAE0C9F-C9A6-4892-9E01-94F9DC262B7A} 2012-11-14 15:45 - 2012-11-14 15:45 - 00000000 ____D C:\Users\Boys\AppData\Local\{D9A879B1-6A1D-4134-9B61-9C473497B0CF} 2012-11-13 18:15 - 2012-11-14 15:44 - 00000000 ____D C:\Users\Lisa\AppData\Local\{90601D48-D374-4D99-BB06-BDFADA208068} 2012-11-12 18:15 - 2012-11-13 06:15 - 00000000 ____D C:\Users\Lisa\AppData\Local\{B350F2A5-E9A9-4C5A-A5DD-418385A66F9E} 2012-11-11 08:55 - 2012-11-11 08:56 - 00000000 ____D C:\Users\Lisa\AppData\Local\{C7BD14E6-D5C9-40EA-B9C4-09886E46ECC2} 2012-11-10 10:19 - 2012-11-10 10:19 - 00000000 ____D C:\Users\Lisa\AppData\Local\{81613D55-42FC-4A2E-ADB6-FC9D4F9BBF66} 2012-11-09 22:21 - 2012-11-09 22:21 - 00000000 ____D C:\Users\Boys\AppData\Local\{C66726F8-2694-4DC7-AB4A-0A8BCA39D860} 2012-11-09 22:19 - 2012-11-09 22:19 - 00000000 ____D C:\Users\Lisa\AppData\Local\{F1E10773-B9AB-42F3-9339-A9B861EB4C89} 2012-11-08 17:17 - 2012-11-09 10:08 - 00000000 ____D C:\Users\Lisa\AppData\Local\{2DC5E804-5120-4BEE-BBCC-BB80015198A1} 2012-11-08 16:46 - 2012-11-09 10:08 - 00000000 ____D C:\Users\Boys\AppData\Local\{A27051E5-1715-41FA-A4A0-532561622F7B} 2012-11-08 05:17 - 2012-11-08 05:17 - 00000000 ____D C:\Users\Lisa\AppData\Local\{0E85B759-23B3-4AB3-816D-DA0F76A3132A} ==================== One Month Modified Files and Folders ======== 2012-12-08 08:58 - 2012-12-08 08:58 - 00000000 ____D C:\FRST 2012-12-08 05:54 - 2006-11-02 04:58 - 00032568 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-12-08 05:54 - 2006-11-02 04:58 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-12-08 05:53 - 2006-11-02 04:45 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2012-12-08 05:53 - 2006-11-02 04:45 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2012-12-07 13:37 - 2012-04-17 16:24 - 00000506 ____A C:\Windows\Tasks\SystemToolsDailyTest.job 2012-12-07 13:36 - 2012-07-13 09:31 - 00000924 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4235663733-173939233-1014589813-1001UA.job 2012-12-07 13:32 - 2011-12-04 13:27 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4235663733-173939233-1014589813-1001UA.job 2012-12-07 12:56 - 2012-04-06 06:33 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-12-07 10:36 - 2012-07-13 09:31 - 00000902 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4235663733-173939233-1014589813-1001Core.job 2012-12-07 07:50 - 2012-12-07 07:50 - 00009970 ____A C:\Users\Boys\Desktop\hijackthis1207-2.log 2012-12-07 06:38 - 2012-12-07 06:30 - 00009963 ____A C:\Users\Boys\Desktop\hijackthis.log 2012-12-07 06:27 - 2012-12-07 06:29 - 00388608 ____A (Trend Micro Inc.) C:\Users\Boys\Desktop\HiJackThis.exe 2012-12-07 06:01 - 2011-12-04 13:27 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4235663733-173939233-1014589813-1001Core.job 2012-12-06 12:39 - 2010-05-08 14:45 - 00004608 ____A C:\Users\Boys\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-12-06 12:39 - 2009-02-28 07:23 - 00000000 ____D C:\users\Boys 2012-12-05 11:20 - 2012-10-10 17:19 - 00000000 ____D C:\Users\Lisa\AppData\Roaming\Spotify 2012-12-04 11:07 - 2006-11-02 02:33 - 00703388 ____A C:\Windows\System32\PerfStringBackup.INI 2012-12-04 11:02 - 2006-11-02 04:49 - 00262221 ____A C:\Windows\setupact.log 2012-12-04 09:41 - 2012-12-04 09:41 - 00002142 ____A C:\Users\Boys\Desktop\RegBk04 dec12.reg 2012-12-04 09:34 - 2009-02-17 16:28 - 01610031 ____A C:\Windows\WindowsUpdate.log 2012-12-04 09:25 - 2012-10-10 17:20 - 00000000 ____D C:\Users\Lisa\AppData\Local\Spotify 2012-12-04 09:25 - 2009-06-06 05:25 - 00005972 ____A C:\Users\Boys\AppData\Local\d3d9caps.dat 2012-12-04 09:25 - 2009-05-04 06:32 - 00000000 ____D C:\Users\Boys\Tracing 2012-12-04 09:24 - 2012-12-04 09:24 - 00000000 ____D C:\Users\Lisa\AppData\Local\{71E8B520-AE74-4F45-AC45-354B1710CD6A} 2012-12-04 09:23 - 2009-02-25 17:27 - 00000000 ____D C:\Users\Lisa\Tracing 2012-12-04 09:18 - 2012-03-20 11:06 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy 2012-12-04 09:18 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\System32\spool 2012-12-04 09:18 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\registration 2012-12-04 09:12 - 2012-12-04 09:12 - 00000000 ____D C:\Users\Boys\AppData\Local\{0EAA5A3E-C3E0-403A-8C1E-D9E76D11D631} 2012-12-02 12:48 - 2011-12-04 13:29 - 00002039 ____A C:\Users\Boys\Desktop\Google Chrome.lnk 2012-12-02 12:46 - 2012-12-02 12:46 - 00000000 ____D C:\Users\Boys\AppData\Local\{30725F9E-4965-4E9E-B51E-9CC05DB0446B} 2012-12-02 08:11 - 2012-12-02 08:11 - 00000000 ____D C:\Users\Lisa\AppData\Local\{2896603C-D37A-4252-B0D2-86C137321B2C} 2012-12-01 15:02 - 2012-12-01 15:02 - 00000000 ____D C:\Users\Lisa\AppData\Local\{134E178C-3B35-4F21-A71C-9EE0ED9DF36D} 2012-11-30 16:11 - 2012-11-30 16:11 - 00000000 ____D C:\Users\Lisa\AppData\Local\{E5306341-FD7B-4DEC-8AE6-65E63EB68165} 2012-11-29 17:15 - 2012-11-29 17:15 - 00000000 ____D C:\Users\Lisa\AppData\Local\{1665FE41-0B3A-4A9A-8BA4-0F6514FD06C1} 2012-11-29 05:15 - 2012-11-29 05:15 - 00000000 ____D C:\Users\Lisa\AppData\Local\{006B9E28-F81E-4F6D-8F9E-2A9204E78437} 2012-11-28 19:48 - 2012-11-28 19:48 - 00182272 ____A C:\Users\Lisa\wgsdgsdgdsgsd.exe 2012-11-28 19:48 - 2012-11-28 19:48 - 00182272 ____A C:\Users\All Users\cl6MFSXX.exe 2012-11-28 19:48 - 2012-11-28 19:48 - 00000001 ____A C:\Users\All Users\cl6MFSXX.exe_.b 2012-11-28 19:48 - 2012-11-28 19:48 - 00000001 ____A C:\Users\All Users\cl6MFSXX.exe.b 2012-11-28 19:48 - 2012-11-28 19:48 - 00000000 ____A C:\Users\All Users\73b5h28.dat 2012-11-28 19:48 - 2009-02-24 21:21 - 00000000 ____D C:\users\Lisa 2012-11-28 15:28 - 2012-11-28 15:28 - 00000000 ____D C:\Users\Lisa\AppData\Local\{36B748C4-E16C-4EA1-BF07-B4CEA6AB93CF} 2012-11-28 15:27 - 2009-03-25 05:04 - 00006648 ____A C:\Users\Lisa\AppData\Local\d3d9caps.dat 2012-11-27 18:17 - 2012-11-27 18:17 - 00000000 ____D C:\Users\Lisa\AppData\Local\{9F26760B-D64F-46D6-A7EE-A10E0C850ACE} 2012-11-27 06:16 - 2012-11-27 06:16 - 00000000 ____D C:\Users\Lisa\AppData\Local\{A816FBF5-EBD4-42ED-9712-AAFA2AD333C0} 2012-11-26 18:16 - 2012-11-26 18:16 - 00000000 ____D C:\Users\Lisa\AppData\Local\{0CF8119A-D1E6-408B-9D39-69F66ECD7E18} 2012-11-26 06:16 - 2012-11-26 06:16 - 00000000 ____D C:\Users\Lisa\AppData\Local\{C9464C11-F0FD-41E8-BADD-6B66CE1AE8F6} 2012-11-26 05:13 - 2009-02-17 22:51 - 00000000 ____D C:\Users\All Users\Adobe 2012-11-25 18:16 - 2012-11-25 06:15 - 00000000 ____D C:\Users\Lisa\AppData\Local\{99508E3A-154F-4A87-B652-CC0880BA9932} 2012-11-24 15:52 - 2008-01-20 19:02 - 00169246 ____A C:\Windows\PFRO.log 2012-11-24 15:44 - 2012-11-24 13:49 - 00000000 ____D C:\Users\All Users\Yahoo! 2012-11-24 15:44 - 2012-11-24 13:49 - 00000000 ____D C:\Program Files\Yahoo! 2012-11-24 14:00 - 2012-11-24 14:00 - 00000000 ____D C:\Users\All Users\PC Optimizer Pro 2012-11-24 13:52 - 2012-11-24 13:52 - 01639104 ____A (W3i, LLC) C:\Users\Lisa\Downloads\playalotgames_d146490.exe 2012-11-24 09:46 - 2012-11-24 09:46 - 00000000 ____D C:\Users\Boys\AppData\Local\{5A8C4206-278B-4C00-8BB1-54FE09DC4DC5} 2012-11-24 06:41 - 2012-11-24 06:40 - 00000000 ____D C:\Users\Lisa\AppData\Local\{B9F70A76-CBD5-418F-9D50-BE2D0290F01F} 2012-11-23 16:51 - 2012-11-23 16:51 - 00000000 ____D C:\Users\Lisa\AppData\Local\{CE087A8B-7E73-455C-95DC-657AF114C65B} 2012-11-23 16:44 - 2012-11-23 16:44 - 00000000 ____D C:\Users\Boys\AppData\Local\{21A3628D-6586-4FFC-89D2-673AFFA63102} 2012-11-22 16:12 - 2012-11-22 16:12 - 00000000 ____D C:\Users\Boys\AppData\Local\{5A74277E-4443-4394-A98B-4A6278EF92F4} 2012-11-22 07:55 - 2012-11-22 07:55 - 00000000 ____D C:\Users\Lisa\AppData\Local\{0D2C200C-D424-4B3F-847D-BB473300DC12} 2012-11-21 17:05 - 2012-11-21 17:05 - 00000000 ____D C:\Users\Lisa\AppData\Local\{6942E797-E825-4AED-8D45-F4E8ED14A9BC} 2012-11-20 07:47 - 2012-11-20 07:47 - 00000000 ____D C:\Users\Lisa\AppData\Local\{227A720C-DEB8-4E45-AD45-FB09DCEE7938} 2012-11-19 17:06 - 2012-11-19 17:06 - 00000000 ____D C:\Users\Lisa\AppData\Local\{32DE1F0F-1200-451E-B732-0673DD7F5A99} 2012-11-18 13:32 - 2012-11-18 13:32 - 00000000 ____D C:\Program Files\QuickTime 2012-11-18 09:35 - 2012-11-18 09:35 - 00000000 ____D C:\Users\Lisa\AppData\Local\{E75F393B-CD9A-4486-BE23-F7A4727C3594} 2012-11-16 15:47 - 2012-11-16 15:47 - 00000000 ____D C:\Users\Lisa\AppData\Local\{3D80F8BF-E134-4C7E-8315-AB9B4B5EB693} 2012-11-16 15:42 - 2012-11-16 15:42 - 00000000 ____D C:\Users\Lisa\AppData\Local\{F4163A2D-EC38-4DE6-AFF4-A27E9E16E2BB} 2012-11-15 16:57 - 2012-11-15 16:57 - 00000000 ____D C:\Users\Lisa\AppData\Local\{3C311E3D-3D28-4FDA-B3B0-281FE5366D29} 2012-11-15 13:08 - 2012-11-15 13:08 - 00000000 ____D C:\Users\Boys\AppData\Local\{A1B5353F-C0B5-47FB-993D-96CB5DEE427B} 2012-11-15 04:57 - 2012-11-15 04:57 - 00000000 ____D C:\Users\Lisa\AppData\Local\{ACAE0C9F-C9A6-4892-9E01-94F9DC262B7A} 2012-11-14 15:45 - 2012-11-14 15:45 - 00000000 ____D C:\Users\Boys\AppData\Local\{D9A879B1-6A1D-4134-9B61-9C473497B0CF} 2012-11-14 15:44 - 2012-11-13 18:15 - 00000000 ____D C:\Users\Lisa\AppData\Local\{90601D48-D374-4D99-BB06-BDFADA208068} 2012-11-13 06:15 - 2012-11-12 18:15 - 00000000 ____D C:\Users\Lisa\AppData\Local\{B350F2A5-E9A9-4C5A-A5DD-418385A66F9E} 2012-11-11 08:56 - 2012-11-11 08:55 - 00000000 ____D C:\Users\Lisa\AppData\Local\{C7BD14E6-D5C9-40EA-B9C4-09886E46ECC2} 2012-11-11 08:54 - 2012-04-17 16:24 - 00000564 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job 2012-11-10 10:19 - 2012-11-10 10:19 - 00000000 ____D C:\Users\Lisa\AppData\Local\{81613D55-42FC-4A2E-ADB6-FC9D4F9BBF66} 2012-11-09 22:21 - 2012-11-09 22:21 - 00000000 ____D C:\Users\Boys\AppData\Local\{C66726F8-2694-4DC7-AB4A-0A8BCA39D860} 2012-11-09 22:19 - 2012-11-09 22:19 - 00000000 ____D C:\Users\Lisa\AppData\Local\{F1E10773-B9AB-42F3-9339-A9B861EB4C89} 2012-11-09 10:12 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\tapi 2012-11-09 10:08 - 2012-11-08 17:17 - 00000000 ____D C:\Users\Lisa\AppData\Local\{2DC5E804-5120-4BEE-BBCC-BB80015198A1} 2012-11-09 10:08 - 2012-11-08 16:46 - 00000000 ____D C:\Users\Boys\AppData\Local\{A27051E5-1715-41FA-A4A0-532561622F7B} 2012-11-08 19:19 - 2012-04-12 04:51 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-11-08 19:19 - 2010-02-11 18:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2012-11-08 05:17 - 2012-11-08 05:17 - 00000000 ____D C:\Users\Lisa\AppData\Local\{0E85B759-23B3-4AB3-816D-DA0F76A3132A} ZeroAccess: C:\Users\Boys\AppData\Local\{dbe772ed-b210-943c-747f-185608048705} C:\Users\Boys\AppData\Local\{dbe772ed-b210-943c-747f-185608048705}\@ C:\Users\Boys\AppData\Local\{dbe772ed-b210-943c-747f-185608048705}\L C:\Users\Boys\AppData\Local\{dbe772ed-b210-943c-747f-185608048705}\U C:\Users\Boys\AppData\Local\{dbe772ed-b210-943c-747f-185608048705}\L\00000004.@ ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2012-10-14 11:16:50 Restore point made on: 2012-10-15 15:57:40 Restore point made on: 2012-10-16 08:21:25 Restore point made on: 2012-10-18 14:32:50 Restore point made on: 2012-10-19 12:14:53 Restore point made on: 2012-10-20 13:48:55 Restore point made on: 2012-10-25 10:46:08 Restore point made on: 2012-11-01 06:19:51 Restore point made on: 2012-11-01 13:41:10 Restore point made on: 2012-11-01 13:41:49 Restore point made on: 2012-11-01 13:43:10 Restore point made on: 2012-11-03 10:55:10 Restore point made on: 2012-11-04 18:49:18 Restore point made on: 2012-11-06 05:56:28 Restore point made on: 2012-11-08 11:52:03 Restore point made on: 2012-11-11 18:59:26 Restore point made on: 2012-11-13 10:22:11 Restore point made on: 2012-11-21 17:53:43 Restore point made on: 2012-11-22 20:46:13 Restore point made on: 2012-11-24 15:45:26 Restore point made on: 2012-11-24 15:45:58 Restore point made on: 2012-11-29 10:03:29 Restore point made on: 2012-12-04 09:16:22 Restore point made on: 2012-12-07 06:17:18 ==================== Memory info =========================== Percentage of memory in use: 9% Total physical RAM: 3061.31 MB Available physical RAM: 2758.94 MB Total Pagefile: 2959.96 MB Available Pagefile: 2826.15 MB Total Virtual: 2047.88 MB Available Virtual: 1966.31 MB ==================== Partitions ============================= 1 Drive c: (OS) (Fixed) (Total:280.9 GB) (Free:188.33 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 3 Drive e: () (Removable) (Total:7.45 GB) (Free:5.27 GB) FAT32 4 Drive x: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:9.18 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ———- ——- ——- — — Disk 0 Online 298 GB 0 B Disk 1 Online 7634 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 OEM 39 MB 32 KB Partition 2 Primary 15 GB 40 MB Partition 3 Primary 281 GB 15 GB Partition 0 Extended 2559 MB 296 GB Partition 4 Logical 2558 MB 296 GB ========================================================= Disk: 0 Partition 1 Type : DE Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 4 FAT Partition 39 MB Healthy Hidden ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 X RECOVERY NTFS Partition 15 GB Healthy Boot ========================================================= Disk: 0 Partition 3 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C OS NTFS Partition 281 GB Healthy ========================================================= Disk: 0 Partition 4 Type : DD Hidden: Yes Active: No There is no volume associated with this partition. ========================================================= Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 7633 MB 16 KB ========================================================= Disk: 1 Partition 1 Type : 0B Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 E FAT32 Removable 7633 MB Healthy ========================================================= Last Boot: 2012-12-04 09:28 ==================== End Of Log ============================
Please run the following:

  • NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system
  • Please download [attachment removed]
  • Save it to your flash drive.
  • Boot to System Recovery Options as you did before and select "Command Prompt".
  • Run FRST and press the Fix button just once and wait.
  • The tool will make a log on the flashdrive (Fixlog.txt) please post it to your next reply.



NEXT


Reboot normally and log into the account that had the infection, make sure you can log in properly now, then please run the following:


Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Could not do the Startup Repair. Got a message that "Startup Repair could not detect a problem" "If you have recently attached a device to this computer, such as a camera or portable music player, remove it and restart your computer. If you continue to see this message, contact your system administrator or computer manufacturer for assistance" If I click on finish, it goes back to the "Choose a Recovery Tool" options. I have tried restarting 3 times. Same meassage.
Fixlog.txt Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 06-12-2012 Ran by [removed] at 2012-12-08 10:31:55 Run:1 Running from E:\ ============================================== HKEY_USERS\Boys\Software\Microsoft\Windows\CurrentVersion\Run\\shadmx Value deleted successfully. C:\Users\Boys\AppData\Roaming\shadmx.dll moved successfully. HKEY_USERS\Boys\Software\Microsoft\Windows\CurrentVersion\Run\\XSECVA Value deleted successfully. C:\Users\Boys\AppData\Roaming\xsecva\xsecva.exe not found. HKEY_USERS\Boys\Software\Microsoft\Windows\CurrentVersion\Run\\msxdg Value deleted successfully. C:\Users\Boys\AppData\Roaming\msxdg.dll moved successfully. HKEY_USERS\Boys\Software\Microsoft\Windows\CurrentVersion\Run\\bridsass Value deleted successfully. C:\Users\Boys\AppData\Local\Temp\drivinit.dll not found. HKEY_USERS\Lisa\Software\Microsoft\Windows\CurrentVersion\Run\\svñhîst Value deleted successfully. HKEY_USERS\Lisa\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load Value not found. C:\Users\Lisa\LOCALS~1\Temp\msvuimuwc.exe moved successfully. a016mdm service deleted successfully. a8djusb service deleted successfully. ABVPN2K service deleted successfully. aexnsclient service deleted successfully. alertmanager service deleted successfully. atchksrv service deleted successfully. atkdisplf service deleted successfully. ATKGFNEXSrv service deleted successfully. Cam5607 service deleted successfully. ccevtmgr service deleted successfully. CDRPDACC service deleted successfully. cfosspeed service deleted successfully. citrixwmiservice service deleted successfully. CoachUsb service deleted successfully. cobbmservice service deleted successfully. com0com service deleted successfully. cqmgstor service deleted successfully. ctsfm2k service deleted successfully. DC21x4 service deleted successfully. diskeeper service deleted successfully. dlaboiom service deleted successfully. dwusbdnt service deleted successfully. ehrecvr service deleted successfully. EQDRV5 service deleted successfully. Freedom service deleted successfully. gearsecurity service deleted successfully. GMSIPCI service deleted successfully. GT891x service deleted successfully. ha10kx2k service deleted successfully. HIDSwvd service deleted successfully. hotspotshieldservice service deleted successfully. houdinilicenseserver service deleted successfully. HPFXBULK service deleted successfully. hwpsgt service deleted successfully. ini910u service deleted successfully. IntelC53 service deleted successfully. IPSECSHM service deleted successfully. iviaspi service deleted successfully. JGOGO service deleted successfully. k750mdfl service deleted successfully. kl1 service deleted successfully. kraidsvc service deleted successfully. LMouFilt service deleted successfully. LPCFilter service deleted successfully. ltxred service deleted successfully. lvcomser service deleted successfully. LVRS service deleted successfully. marvinbus service deleted successfully. modemcsa service deleted successfully. mpe service deleted successfully. mrpostman service deleted successfully. MSFWDrv service deleted successfully. MTC0001_ESB service deleted successfully. NtMtlFax service deleted successfully. nvpvrmon service deleted successfully. oracle_load_balancer_60_client-forms6i service deleted successfully. osaio service deleted successfully. ovmsmaccessmanager service deleted successfully. pcscnsrv service deleted successfully. pdlncbas service deleted successfully. pvservice service deleted successfully. RalinkRegistryWriter service deleted successfully. rapapp service deleted successfully. raspti service deleted successfully. rca service deleted successfully. REVOSENS service deleted successfully. rsvp service deleted successfully. RTHDMIAzAudService service deleted successfully. rupsmon service deleted successfully. RVIEG01 service deleted successfully. s117bus service deleted successfully. s125mdm service deleted successfully. s7oppitx service deleted successfully. sdcplh service deleted successfully. slapd-config52 service deleted successfully. spbbcsvc service deleted successfully. SRTSPL service deleted successfully. SrvcSSIOMngr service deleted successfully. st330service service deleted successfully. streamloadservice service deleted successfully. SunkFilt39 service deleted successfully. symevent service deleted successfully. symlcbrd service deleted successfully. symredrv service deleted successfully. tangoservice service deleted successfully. tavsvc service deleted successfully. tga service deleted successfully. thkeys service deleted successfully. tmlisten service deleted successfully. tosrfusb service deleted successfully. tpsrv service deleted successfully. transactional service deleted successfully. trayman service deleted successfully. USBDeviceService service deleted successfully. usnsvc service deleted successfully. vcsw service deleted successfully. VRADFIL service deleted successfully. vrfwsvc service deleted successfully. vulfntrs service deleted successfully. WaveEnrollmentService service deleted successfully. wcontrol service deleted successfully. websenselogserver service deleted successfully. wuolservice service deleted successfully. z525mgmt service deleted successfully. 669f37cbc1000922 service deleted successfully. C:\Windows\System32\Drivers\669f37cbc1000922.sys moved successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ctsfm2k Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs LVRS Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs pvservice Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ovmsmaccessmanager Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs HPFXBULK Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ha10kx2k Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs pcscnsrv Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs hwpsgt Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs thkeys Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs JGOGO Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs tosrfusb Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ccevtmgr Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs kl1 Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs REVOMSFWDrv not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs k750mdfl Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs modemcsa Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs mrpostman Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs alertmanager Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs CDRPDACC Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs EQDRV5 Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs GMSIPCI Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs raspti Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs aexnsclient Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs diskeeper Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs cobbmservice Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs transactional Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs tangoservice Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs streamloadservice Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs cqmgstor Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs SrvcSSIOMngr Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs st330service Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs iviaspi Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs rsvp Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs tpsrv Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs WaveEnrollmentService Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs websenselogserver Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs s7oppitx Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs tavsvc Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs IntelC53 Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs wcontrol Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs vcsw Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs nvpvrmon Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs mpe Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs LMouFilt Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs mcstrm Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs lilsgt Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ehrecvr Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ini910u Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs gearsecurity Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs GT891x Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs citrixwmiservice Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs symlcbrd Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs RTHDMIAzAudService Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs RalinkRegistryWriter Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs CTAudSvcService Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs omci Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs nimcdfxk Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs mafwboot Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs NtMtlFax Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs vulfntrs Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs dwusbdnt Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ABVPN2K Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs s125mdm Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs CoachUsb Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs DC21x4 Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs Freedom Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ltxred Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs retrolauncher Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs BTSLBCSP Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs atchksrv Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs vrfwsvc Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs oracle_load_balancer_60_client-forms6i Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs usnsvc Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs plsremotesvc Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs osaio Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs SRTSPL Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs symevent Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs a8djusb Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs IPSECSHM Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs VRADFIL Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs trayman Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs slapd-config52 Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs hotspotshieldservice Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs kraidsvc Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs symredrv Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs LPCFilter Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs sdcplh Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs HIDSwvd Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs a016mdm Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs marvinbus Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs atkdisplf Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs spbbcsvc Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ATKGFNEXSrv Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs MTC0001_ESB Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs rapapp Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs s117bus Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs wuolservice Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs tmlisten Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs tga Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs pdlncbas Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs com0com Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs cfosspeed Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs Cam5607 Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs USBDeviceService Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs z525mgmt Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs lvcomser Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs SunkFilt39 Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs rca Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs rupsmon Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs RVIEG01 Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs dlaboiom Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs houdinilicenseserver Deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs uiusys Deleted successfully. C:\Users\Boys\Desktop\RegBk04 dec12.reg moved successfully. C:\Users\Lisa\AppData\Local\{71E8B520-AE74-4F45-AC45-354B1710CD6A} moved successfully. C:\Users\Boys\AppData\Local\{0EAA5A3E-C3E0-403A-8C1E-D9E76D11D631} moved successfully. C:\Users\Boys\AppData\Local\{30725F9E-4965-4E9E-B51E-9CC05DB0446B} moved successfully. C:\Users\Lisa\AppData\Local\{2896603C-D37A-4252-B0D2-86C137321B2C} moved successfully. C:\Users\Lisa\AppData\Local\{134E178C-3B35-4F21-A71C-9EE0ED9DF36D} moved successfully. C:\Users\Lisa\AppData\Local\{E5306341-FD7B-4DEC-8AE6-65E63EB68165} moved successfully. C:\Users\Lisa\AppData\Local\{1665FE41-0B3A-4A9A-8BA4-0F6514FD06C1} moved successfully. C:\Users\Lisa\AppData\Local\{006B9E28-F81E-4F6D-8F9E-2A9204E78437} moved successfully. C:\Users\Lisa\wgsdgsdgdsgsd.exe moved successfully. C:\Users\All Users\cl6MFSXX.exe moved successfully. C:\Users\All Users\cl6MFSXX.exe_.b moved successfully. C:\Users\All Users\cl6MFSXX.exe.b moved successfully. C:\Users\All Users\73b5h28.dat moved successfully. C:\Users\Lisa\AppData\Local\{36B748C4-E16C-4EA1-BF07-B4CEA6AB93CF} moved successfully. C:\Users\Lisa\AppData\Local\{9F26760B-D64F-46D6-A7EE-A10E0C850ACE} moved successfully. C:\Users\Lisa\AppData\Local\{A816FBF5-EBD4-42ED-9712-AAFA2AD333C0} moved successfully. C:\Users\Lisa\AppData\Local\{0CF8119A-D1E6-408B-9D39-69F66ECD7E18} moved successfully. C:\Users\Lisa\AppData\Local\{C9464C11-F0FD-41E8-BADD-6B66CE1AE8F6} moved successfully. C:\Users\Lisa\AppData\Local\{99508E3A-154F-4A87-B652-CC0880BA9932} moved successfully. C:\Users\Lisa\AppData\Local\{B9F70A76-CBD5-418F-9D50-BE2D0290F01F} moved successfully. C:\Users\Lisa\AppData\Local\{CE087A8B-7E73-455C-95DC-657AF114C65B} moved successfully. C:\Users\Boys\AppData\Local\{21A3628D-6586-4FFC-89D2-673AFFA63102} moved successfully. C:\Users\Boys\AppData\Local\{5A74277E-4443-4394-A98B-4A6278EF92F4} moved successfully. C:\Users\Lisa\AppData\Local\{0D2C200C-D424-4B3F-847D-BB473300DC12} moved successfully. C:\Users\Lisa\AppData\Local\{6942E797-E825-4AED-8D45-F4E8ED14A9BC} moved successfully. C:\Users\Lisa\AppData\Local\{227A720C-DEB8-4E45-AD45-FB09DCEE7938} moved successfully. C:\Users\Lisa\AppData\Local\{32DE1F0F-1200-451E-B732-0673DD7F5A99} moved successfully. C:\Users\Lisa\AppData\Local\{E75F393B-CD9A-4486-BE23-F7A4727C3594} moved successfully. C:\Users\Lisa\AppData\Local\{3D80F8BF-E134-4C7E-8315-AB9B4B5EB693} moved successfully. C:\Users\Lisa\AppData\Local\{F4163A2D-EC38-4DE6-AFF4-A27E9E16E2BB} moved successfully. C:\Users\Lisa\AppData\Local\{3C311E3D-3D28-4FDA-B3B0-281FE5366D29} moved successfully. C:\Users\Boys\AppData\Local\{A1B5353F-C0B5-47FB-993D-96CB5DEE427B} moved successfully. C:\Users\Lisa\AppData\Local\{ACAE0C9F-C9A6-4892-9E01-94F9DC262B7A} moved successfully. C:\Users\Boys\AppData\Local\{D9A879B1-6A1D-4134-9B61-9C473497B0CF} moved successfully. C:\Users\Lisa\AppData\Local\{90601D48-D374-4D99-BB06-BDFADA208068} moved successfully. C:\Users\Lisa\AppData\Local\{B350F2A5-E9A9-4C5A-A5DD-418385A66F9E} moved successfully. C:\Users\Lisa\AppData\Local\{C7BD14E6-D5C9-40EA-B9C4-09886E46ECC2} moved successfully. C:\Users\Lisa\AppData\Local\{81613D55-42FC-4A2E-ADB6-FC9D4F9BBF66} moved successfully. C:\Users\Boys\AppData\Local\{C66726F8-2694-4DC7-AB4A-0A8BCA39D860} moved successfully. C:\Users\Lisa\AppData\Local\{F1E10773-B9AB-42F3-9339-A9B861EB4C89} moved successfully. C:\Users\Lisa\AppData\Local\{2DC5E804-5120-4BEE-BBCC-BB80015198A1} moved successfully. C:\Users\Boys\AppData\Local\{A27051E5-1715-41FA-A4A0-532561622F7B} moved successfully. C:\Users\Lisa\AppData\Local\{0E85B759-23B3-4AB3-816D-DA0F76A3132A} moved successfully. C:\Users\Boys\AppData\Local\{dbe772ed-b210-943c-747f-185608048705} moved successfully. ==== End of Fixlog ====
I verified that Spybot and the Super AntiSpyware were not active. She normally has been using McAfee but had trouble with it a couple months ago and could not get it working. She was trying to contact McAfee to get it running again. I search for McAfee on her computer but it did not seem to be installed. So, I ran ComboFix and it said McAfee real time scanner was running. Cannot find anything to shut it off.
I restarted ComboFix and clicked OK through the McAfee warnings. ComboFix appeared to be scanning and eventually a dialog box came up that's titled "Administrator: AutoScan". The message in the box says: "Scanning for infected files. . . This typically doesn't take more that 10 minutes However, scan times for badly infected machines may easily double" This has been running like this for about 1 hour now. I have not clicked on the box.
give it another half hour or so, if there is no progress, then close it out and run the following:


  • Download RogueKiller and save it to your desktop.
  • Quit all other programs
  • Start RogueKiller.exe
  • Wait until the Prescan has finished …
  • Click on Scan
    [external image: Posted Image]
  • Wait for the end of the scan
  • A report will be created on your desktop.
  • Click on the Delete button
    [external image: Posted Image]
  • Next click on the ShortcutsFix
    [external image: Posted Image]
  • another report will be created on your desktop.

Please post: All RKreport.txt text files located on your desktop.
OK, the dialog box I previously mentioned was still there. I forgot to mention that it appears to be a Command Prompt box While I type this, a ComboFix box popped up with message about a ZeroAccess Rootkit infection. Another box popped up on top of that one before I could finish reading it. The second box says "Rootkit detected Be patient as this may take some time" Another box popped up with: "ComboFix has detected the presence of rootkit activity and needs to reboot the machine." The computer has now rebooted and when I logged on the first dialog box (the Admisistrator: AutoScan) is on the screen but there is no desktop only a black background. Dialog box now is running with statements: "Completed Stage_1 and is now up to Stage 5

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI