This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware [Solved]

70 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It appears from those screenshots that you already have the file downloaded. The number in () like the (4) in the last screenshot tell me that you have already downloaded that file three other times, and this is the 4th time you are downloading it. Although, your file associations could be a bit messed up, perhaps the reinstallation of windows didn't quite work out as expected.

Given that you are still experiencing some issues, let's see if we can do a startup repair of your system.


We are going to utilize the Repair your computer option.
You may wish to print these instructions so you will have them available. They will not be available to you as you complete the steps below.



Reboot your computer and tap F8 on startup. Select Repair your computer from the list of startup options.
In the subsequent System Recovery Options menu, select Startup Repair

[external image: Posted Image]

Please follow any onscreen instructions. It may take awhile for this to complete. The system may tell you that it did not find any problems (and that will be fine) it eliminates one possible problem in our troubleshooting.

After this has finished, if the system does not do so automatically, please reboot the system and tell me if there is any improvement.
I did as you have told me and my laptop rebooted automatically. I still cannot download adobe flash player, it's stuck at the ".exe" phase. My computer seems to be normal, it's still taking around 6minutes to boot up. And now my antivirus is giving me this warning:

[external image: Posted Image]
Symantec tries to check for updated definitions when you boot your computer. If there is something corrupted in the installation, that could explain why it's so slow when you boot the computer. There are a couple of options you can try. You could click the options button you see and check if there are any options to repair the definitions. Or you can contact the family friend who installed the security program to see if they can assist you in reinstalling it to see if that will remedy the problem. The other option would be to remove Symantec completely and to reinstall another program to replace it.

Until you have that resolved, you won't know if that is the cause of you slow booting or not. It may be - or it may not be. There can be any number of causes for slow booting.

I would also suggest that you try using Internet Explorer for your Adobe download. See if you are able to successfully do it there. If you have been able to install other programs successfully (even ones we have used like DDS or TDSSKiller) then your file associations are OK. It could be something in Firefox blocking the install. Give that a try and see what happens. Are you downloading directly from the Adobe site? If so, you could also try going to www.Filehippo.com and use their downloads. They are virus free and I never have any trouble with their downloads for various programs.
I'll see if I can contact the family friend to help me re-install Symantec. I also did what you suggested and tried downloading Adobe through Internet Explorer and nothing pops up. It tells me my download will start automatically but nothing happens. Also - I was using TDSSkiller & DDS from before my antivirus got wiped. My family friend left it on my computer so I didn't need to re-install it.
I'm so sorry. I'm such an idiot. I fixed the adobe & the anti virus problem. (Both really stupid stupid mistakes) I ran the anti virus a few times and it fixed the warning. Adobe….firefox seemed to be blocking me from downloading it so when it little tab popped up when I went on youtube…I downloaded it from there. Everything seems to be working fine now! I don't think anything is broken/corrupt.
Merry Christmas! It's still really slow, I actually had some problems booting it up this morning. It was a black screen with a little underscroll in the top left corner, it was blinking. It sat there for a couple minutes, and I ended up restarting it.
Merry Christmas to you as well! Hopefully you've had a great day :)

Let's go ahead and right-click and uninstall the version of Combofix on your desktop and download and install a fresh version and run it to be sure there is nothing hiding on the machine. If Windows had been completely and fully reinstalled with a full reformat, none of your existing programs would have been there, so I'm thinking it was a repair of Windows that was done. To be on the safe side - let's go ahead and run Combofix.


Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.
I did, thank you very much. I hope yours was well too! ComboFix log: ComboFix 12-12-26.02 - Angel 12/26/2012 20:52:28.1.4 - x64 Running from: c:\users\[removed]\Desktop\ComboFix.exe . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\PCDr\6032\AddOnDownloaded\016060e8-e1de-4d82-bd11-b667007b1f12.dll c:\programdata\PCDr\6032\AddOnDownloaded\06004c97-c212-44da-81de-706b46554efe.dll c:\programdata\PCDr\6032\AddOnDownloaded\087abda5-3ca9-433a-8a4e-6b9fc9285607.dll c:\programdata\PCDr\6032\AddOnDownloaded\0d03215e-4c16-4ea7-b7d7-805a2556effc.dll c:\programdata\PCDr\6032\AddOnDownloaded\0d461521-7dbf-4cec-a29e-936c88cdf8c9.dll c:\programdata\PCDr\6032\AddOnDownloaded\0d85b53c-d766-4bf0-8940-17b534910268.dll c:\programdata\PCDr\6032\AddOnDownloaded\100c3865-0c76-461b-b2fd-042d6d5fa7f6.dll c:\programdata\PCDr\6032\AddOnDownloaded\111e1115-314f-4404-be4a-ad58e8e2423d.dll c:\programdata\PCDr\6032\AddOnDownloaded\16837627-a839-41c5-a88f-3a0335128383.dll c:\programdata\PCDr\6032\AddOnDownloaded\173c4dd2-e93c-4725-b006-db1d8f465192.dll c:\programdata\PCDr\6032\AddOnDownloaded\1d151f53-1500-414d-85b4-ab85d24f0785.dll c:\programdata\PCDr\6032\AddOnDownloaded\1e0aaf9a-9947-4a7b-b1ae-8a89919438ed.dll c:\programdata\PCDr\6032\AddOnDownloaded\21eb1c2f-b0d8-40e6-96dd-163437759b68.dll c:\programdata\PCDr\6032\AddOnDownloaded\263d6ac9-4f87-466c-947c-bd9af71d7035.dll c:\programdata\PCDr\6032\AddOnDownloaded\2f733848-355c-4a6f-89a5-08a4dcc89c5c.dll c:\programdata\PCDr\6032\AddOnDownloaded\3410f47b-5e8c-47c6-bf2c-234af4121d4c.dll c:\programdata\PCDr\6032\AddOnDownloaded\35445406-e7ed-4a0e-9922-45505e71594b.dll c:\programdata\PCDr\6032\AddOnDownloaded\358ba71b-117f-40d5-95aa-57de622719b7.dll c:\programdata\PCDr\6032\AddOnDownloaded\378deb7f-049e-4a5e-83b2-5381dcd9e928.dll c:\programdata\PCDr\6032\AddOnDownloaded\3972fea3-214c-4935-a7d1-96bf66115683.dll c:\programdata\PCDr\6032\AddOnDownloaded\3b1c7acd-5e3e-4459-ab98-5109117e2341.dll c:\programdata\PCDr\6032\AddOnDownloaded\3c49c05a-0eb3-4044-a0f8-d4ea2a439295.dll c:\programdata\PCDr\6032\AddOnDownloaded\3d656744-60b2-4576-8124-a39729f8b522.dll c:\programdata\PCDr\6032\AddOnDownloaded\406007ac-5ba8-43e6-97b6-0c6ed58bb6e8.dll c:\programdata\PCDr\6032\AddOnDownloaded\4546f2bc-b9d9-4667-abe7-b0bacc90279e.dll c:\programdata\PCDr\6032\AddOnDownloaded\468d25c7-baa8-4db4-a17f-ceac895a9bc8.dll c:\programdata\PCDr\6032\AddOnDownloaded\4704833a-6508-40cc-b98b-5ebd235e52ca.dll c:\programdata\PCDr\6032\AddOnDownloaded\4804ced5-915b-48a3-a465-b8a5e02714bf.dll c:\programdata\PCDr\6032\AddOnDownloaded\4818e109-9489-4cd8-9044-44defd8ec187.dll c:\programdata\PCDr\6032\AddOnDownloaded\489f121a-4538-4839-9d1d-3c48e590be59.dll c:\programdata\PCDr\6032\AddOnDownloaded\493f295d-1a46-46f6-926c-63b474cedab4.dll c:\programdata\PCDr\6032\AddOnDownloaded\4cfdf1e7-d0b2-449c-bd2d-084cd975e5d8.dll c:\programdata\PCDr\6032\AddOnDownloaded\4f1c58d6-ca02-4906-b156-709481baca61.dll c:\programdata\PCDr\6032\AddOnDownloaded\4f64943e-d62a-4f2e-a3cd-98fb91e30469.dll c:\programdata\PCDr\6032\AddOnDownloaded\59bb1a7b-2122-4c71-82b0-30bee96f063e.dll c:\programdata\PCDr\6032\AddOnDownloaded\5cd81d7c-326c-42d2-8929-1ee85c69dc1d.dll c:\programdata\PCDr\6032\AddOnDownloaded\5f169f6e-cfce-411e-b266-aa53ac35ce83.dll c:\programdata\PCDr\6032\AddOnDownloaded\62089595-46e8-4c4f-9d7b-48be969390bb.dll c:\programdata\PCDr\6032\AddOnDownloaded\62d1f0b0-bc9a-4f6c-bad7-93b19a91276a.dll c:\programdata\PCDr\6032\AddOnDownloaded\67c3d4fe-b638-467a-9fe2-c5813ade3330.dll c:\programdata\PCDr\6032\AddOnDownloaded\6820b110-e483-4f1e-9b48-438f7916f078.dll c:\programdata\PCDr\6032\AddOnDownloaded\6b5978fa-48d7-4309-a523-7e157768c0d8.dll c:\programdata\PCDr\6032\AddOnDownloaded\6f4fb483-ce30-493a-8cb4-3e530ab1be5b.dll c:\programdata\PCDr\6032\AddOnDownloaded\7119bf4b-d404-4b31-8779-44fac71761fa.dll c:\programdata\PCDr\6032\AddOnDownloaded\72f0dc20-5af7-4221-9657-442597ce030b.dll c:\programdata\PCDr\6032\AddOnDownloaded\739db3eb-d3cd-4c86-a6ea-01a49984fa3b.dll c:\programdata\PCDr\6032\AddOnDownloaded\73a14ca6-4567-413f-a60f-d04159cb72eb.dll c:\programdata\PCDr\6032\AddOnDownloaded\75c8751b-fcad-4846-80ce-3a2efec60612.dll c:\programdata\PCDr\6032\AddOnDownloaded\7779c9df-2dc0-4fd5-92bb-c64027285f8b.dll c:\programdata\PCDr\6032\AddOnDownloaded\788ad19e-7745-402f-a5a5-20d2ab8b5f1b.dll c:\programdata\PCDr\6032\AddOnDownloaded\7bd83798-7a02-4f50-83a2-b91cabcbd1f9.dll c:\programdata\PCDr\6032\AddOnDownloaded\7dbfef1a-6148-4748-a1b3-71627763a45a.dll c:\programdata\PCDr\6032\AddOnDownloaded\813755dc-2229-47a2-b85b-19d0aaa641c9.dll c:\programdata\PCDr\6032\AddOnDownloaded\872965c7-08b7-47fc-a74c-ff167590b71a.dll c:\programdata\PCDr\6032\AddOnDownloaded\8c199aef-9eca-4ab6-863d-c9136ebec654.dll c:\programdata\PCDr\6032\AddOnDownloaded\8d357f17-07ad-4392-ba06-fb67564c98cd.dll c:\programdata\PCDr\6032\AddOnDownloaded\918ee45c-eb0a-4e61-97ad-c1849c2623ee.dll c:\programdata\PCDr\6032\AddOnDownloaded\934f6059-2d35-4bd9-a130-a17cb5563507.dll c:\programdata\PCDr\6032\AddOnDownloaded\9881c561-a45a-4c53-9d45-de93a99e2898.dll c:\programdata\PCDr\6032\AddOnDownloaded\a61f44a8-21a3-4c4a-a04b-993dfb73bf96.dll c:\programdata\PCDr\6032\AddOnDownloaded\a7201707-7895-43cf-9119-8a0279b75d4c.dll c:\programdata\PCDr\6032\AddOnDownloaded\a9de0c84-9a7c-4638-9653-13aa8cf56e80.dll c:\programdata\PCDr\6032\AddOnDownloaded\ae67b364-b69e-471e-b177-2459120b84d4.dll c:\programdata\PCDr\6032\AddOnDownloaded\b0654984-096d-4244-a127-3364577b6279.dll c:\programdata\PCDr\6032\AddOnDownloaded\b2152f30-7380-4987-8fcf-e4c06952615d.dll c:\programdata\PCDr\6032\AddOnDownloaded\b2ed8d53-41ce-48e6-b4ac-8b8e5e1a4fdf.dll c:\programdata\PCDr\6032\AddOnDownloaded\b4cc2a4a-87f5-49cd-935c-18f1a80e65b7.dll c:\programdata\PCDr\6032\AddOnDownloaded\b510dd11-341c-4dfa-9f1e-dd5ddcc444f4.dll c:\programdata\PCDr\6032\AddOnDownloaded\b72409f9-df97-4592-bbfd-fff1ce0a9559.dll c:\programdata\PCDr\6032\AddOnDownloaded\ba58cab8-833c-4868-95e2-cff538a852a7.dll c:\programdata\PCDr\6032\AddOnDownloaded\bbd4d2b0-9dc6-46d0-a352-dbcd92f63c4d.dll c:\programdata\PCDr\6032\AddOnDownloaded\bbfa36b0-30b0-4e36-8d8c-69df1d87626b.dll c:\programdata\PCDr\6032\AddOnDownloaded\bc6fc708-5b6b-4a72-b336-09b3089baa7a.dll c:\programdata\PCDr\6032\AddOnDownloaded\bf647bd7-dfb5-4746-a6b4-b7c2fdbbf3b1.dll c:\programdata\PCDr\6032\AddOnDownloaded\c4211805-b43b-471d-81af-4e0589f8607b.dll c:\programdata\PCDr\6032\AddOnDownloaded\c882e61c-ecc2-4db0-9a28-7cbe8bd4876b.dll c:\programdata\PCDr\6032\AddOnDownloaded\cb7af81b-44d9-4f99-b223-18a71e8c85b6.dll c:\programdata\PCDr\6032\AddOnDownloaded\cdda52ec-6ccd-425a-8c72-b7bbdc8b3acd.dll c:\programdata\PCDr\6032\AddOnDownloaded\cf9bce06-e765-4c6f-afa9-0d82a3adc417.dll c:\programdata\PCDr\6032\AddOnDownloaded\d1f4dc82-bc4c-4916-b37c-3ab9c30ae468.dll c:\programdata\PCDr\6032\AddOnDownloaded\d220b53c-6a3c-4b5d-8797-965d39e82fff.dll c:\programdata\PCDr\6032\AddOnDownloaded\d34c0cf7-889f-43dd-9283-b2b6f442aae3.dll c:\programdata\PCDr\6032\AddOnDownloaded\d3ef65ec-842a-4640-b428-aca2f4a966e6.dll c:\programdata\PCDr\6032\AddOnDownloaded\d78fa15b-2d61-4303-adaa-edec9ebbb2b3.dll c:\programdata\PCDr\6032\AddOnDownloaded\daf30858-49d8-434b-b4b1-068b5dc9267c.dll c:\programdata\PCDr\6032\AddOnDownloaded\dbecb802-efe1-453f-828f-29af4ab73508.dll c:\programdata\PCDr\6032\AddOnDownloaded\ddb9fe5d-525c-4d5d-ac37-0bd10f2864f8.dll c:\programdata\PCDr\6032\AddOnDownloaded\e16f2788-babe-4a60-93d0-d507a5228753.dll c:\programdata\PCDr\6032\AddOnDownloaded\e1ce76af-328a-41dc-b2c4-0dd9771f6aa1.dll c:\programdata\PCDr\6032\AddOnDownloaded\e3e252fe-80ab-4f89-82a9-b607007220bd.dll c:\programdata\PCDr\6032\AddOnDownloaded\e45cd45a-4d7c-4802-881f-74582b847e5c.dll c:\programdata\PCDr\6032\AddOnDownloaded\eb115e4d-8592-4082-bffa-e65ae6b21e95.dll c:\programdata\PCDr\6032\AddOnDownloaded\ed26c1b3-d9f9-42e8-80e0-cd62e65fd901.dll c:\programdata\PCDr\6032\AddOnDownloaded\ef78c3e8-1d94-4219-8070-7617e119bba4.dll c:\programdata\PCDr\6032\AddOnDownloaded\f06c5597-1a85-4d1f-ac16-a6fdd2a6bedc.dll c:\programdata\PCDr\6032\AddOnDownloaded\f28ef68b-8cc4-4c00-891d-473fb67bd0b0.dll c:\programdata\PCDr\6032\AddOnDownloaded\f80d4ad1-1fad-43b5-b6f3-347848b5ddd5.dll c:\programdata\PCDr\6032\AddOnDownloaded\f9dc840b-c6f7-42a5-acec-50cc7a2827fd.dll c:\programdata\PCDr\6032\AddOnDownloaded\ff24953d-0c6e-4af9-a727-84ce58c99035.dll c:\programdata\Roaming . . ((((((((((((((((((((((((( Files Created from 2012-11-27 to 2012-12-27 ))))))))))))))))))))))))))))))) . . 2012-12-27 04:56 . 2012-12-27 04:56 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-12-23 06:44 . 2012-12-23 06:44 15728568 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2012-12-23 06:29 . 2012-12-23 06:44 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-22 21:04 . 2012-12-22 21:04 ——– d—–w- c:\programdata\PC-Doctor for Windows 2012-12-22 21:04 . 2012-12-22 21:04 ——– d—–w- c:\program files\Dell Support Center 2012-12-22 18:43 . 2012-12-22 18:43 ——– d—–w- c:\program files (x86)\Common Files\Java 2012-12-22 18:43 . 2012-12-22 18:43 859072 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2012-12-22 18:43 . 2012-12-22 18:43 95184 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2012-12-21 22:14 . 2012-12-21 22:14 ——– dc—-w- c:\windows\system32\DRVSTORE 2012-12-21 22:14 . 2012-08-21 19:01 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-12-21 22:13 . 2012-12-21 22:13 ——– d—–w- c:\program files\iPod 2012-12-21 22:13 . 2012-12-21 22:14 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-21 22:13 . 2012-12-21 22:14 ——– d—–w- c:\program files\iTunes 2012-12-21 22:13 . 2012-12-21 22:14 ——– d—–w- c:\program files (x86)\iTunes 2012-12-21 22:13 . 2012-12-21 22:13 ——– d—–w- c:\programdata\Apple Computer 2012-12-21 22:13 . 2012-12-21 22:13 ——– d—–w- c:\program files (x86)\Apple Software Update 2012-12-21 22:12 . 2012-12-21 22:12 ——– d—–w- c:\program files\Common Files\Apple 2012-12-21 22:12 . 2012-12-21 22:12 ——– d—–w- c:\program files\Bonjour 2012-12-21 22:12 . 2012-12-21 22:12 ——– d—–w- c:\program files (x86)\Bonjour 2012-12-21 22:12 . 2012-12-21 22:13 ——– d—–w- c:\program files (x86)\Common Files\Apple 2012-12-21 22:12 . 2012-12-21 22:13 ——– d—–w- c:\programdata\Apple 2012-12-21 21:37 . 2012-12-21 21:37 ——– d—–w- c:\programdata\SwiftKit 2012-12-21 21:37 . 2012-11-30 10:45 203976 —-a-w- c:\windows\SysWow64\RICHTX32.OCX 2012-12-21 21:37 . 2012-11-30 10:45 117507 —-a-w- c:\windows\SysWow64\msinet.ocx 2012-12-21 21:37 . 2012-11-30 10:45 109248 —-a-w- c:\windows\SysWow64\MSWINSCK.OCX 2012-12-21 21:37 . 2012-12-27 03:07 ——– d—–w- c:\program files (x86)\SwiftKit 2012-12-21 21:34 . 2012-12-21 21:34 ——– d—–w- c:\program files (x86)\Mozilla Maintenance Service 2012-12-21 21:27 . 2012-10-30 23:50 285328 —-a-w- c:\windows\system32\aswBoot.exe 2012-12-21 21:26 . 2012-12-21 21:55 ——– d—–w- c:\programdata\AVAST Software 2012-12-21 21:26 . 2012-12-21 21:26 ——– d—–w- c:\program files\AVAST Software 2012-12-21 21:03 . 2012-12-16 14:13 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-21 21:03 . 2012-12-16 17:11 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-21 21:03 . 2012-12-16 14:45 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-21 21:03 . 2012-12-16 14:13 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-21 21:00 . 2012-12-22 21:03 ——– d—–w- c:\programdata\PCDr 2012-12-21 00:06 . 2012-12-21 00:06 ——– d—–w- c:\programdata\Creative 2012-12-20 12:36 . 2012-12-20 12:36 ——– d—–w- c:\windows\SysWow64\Wat 2012-12-20 12:36 . 2012-12-20 12:36 ——– d—–w- c:\windows\system32\Wat 2012-12-20 12:36 . 2012-12-20 12:36 ——– d—–r- c:\program files (x86)\Skype 2012-12-20 12:36 . 2012-12-20 12:36 ——– d—–w- c:\program files (x86)\Common Files\Skype 2012-12-20 06:18 . 2012-07-26 04:47 2560 —-a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui 2012-12-20 06:18 . 2012-07-26 04:55 785512 —-a-w- c:\windows\system32\drivers\Wdf01000.sys 2012-12-20 06:18 . 2012-07-26 04:55 54376 —-a-w- c:\windows\system32\drivers\WdfLdr.sys 2012-12-20 06:18 . 2012-07-26 02:36 9728 —-a-w- c:\windows\system32\Wdfres.dll 2012-12-20 06:15 . 2012-11-28 21:58 67413224 —-a-w- c:\windows\system32\MRT.exe 2012-12-20 06:00 . 2012-11-14 05:52 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-12-20 05:56 . 2012-07-26 02:26 87040 —-a-w- c:\windows\system32\drivers\WUDFPf.sys 2012-12-20 05:56 . 2012-07-26 02:26 198656 —-a-w- c:\windows\system32\drivers\WUDFRd.sys 2012-12-20 05:56 . 2012-07-26 03:08 84992 —-a-w- c:\windows\system32\WUDFSvc.dll 2012-12-20 05:56 . 2012-07-26 03:08 194048 —-a-w- c:\windows\system32\WUDFPlatform.dll 2012-12-20 05:56 . 2012-07-26 03:08 229888 —-a-w- c:\windows\system32\WUDFHost.exe 2012-12-20 05:56 . 2012-07-26 03:08 744448 —-a-w- c:\windows\system32\WUDFx.dll 2012-12-20 05:56 . 2012-07-26 03:08 45056 —-a-w- c:\windows\system32\WUDFCoinstaller.dll 2012-12-20 05:53 . 2012-03-01 06:46 23408 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-12-20 05:53 . 2012-03-01 06:33 81408 —-a-w- c:\windows\system32\imagehlp.dll 2012-12-20 05:53 . 2012-03-01 05:33 159232 —-a-w- c:\windows\SysWow64\imagehlp.dll 2012-12-20 05:53 . 2012-03-01 06:28 5120 —-a-w- c:\windows\system32\wmi.dll 2012-12-20 05:53 . 2012-03-01 05:29 5120 —-a-w- c:\windows\SysWow64\wmi.dll 2012-12-20 05:43 . 2012-08-31 18:19 1659760 —-a-w- c:\windows\system32\drivers\ntfs.sys 2012-12-20 05:42 . 2012-10-04 17:46 362496 —-a-w- c:\windows\system32\wow64win.dll 2012-12-20 05:41 . 2012-01-04 10:44 509952 —-a-w- c:\windows\system32\ntshrui.dll 2012-12-20 05:40 . 2012-03-03 06:35 1544704 —-a-w- c:\windows\system32\DWrite.dll 2012-12-20 05:39 . 2012-05-01 05:40 209920 —-a-w- c:\windows\system32\profsvc.dll 2012-12-20 05:21 . 2012-11-14 00:29 233120 —-a-w- c:\windows\system32\drivers\wpshelper.sys 2012-12-20 05:20 . 2012-12-20 05:20 173616 —-a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2012-12-20 05:19 . 2012-12-20 05:20 ——– d—–w- c:\program files\Symantec 2012-12-20 05:19 . 2007-03-22 02:33 348160 —-a-w- c:\windows\SysWow64\MSVCR71.DLL 2012-12-20 05:19 . 2007-03-22 02:39 1060864 —-a-w- c:\windows\SysWow64\MFC71.DLL 2012-12-20 05:19 . 2007-03-22 02:33 503808 —-a-w- c:\windows\SysWow64\MSVCP71.DLL 2012-12-20 05:19 . 2012-12-20 05:23 ——– d—–w- c:\program files (x86)\Common Files\Symantec Shared 2012-12-20 05:19 . 2012-12-20 05:20 ——– d—–w- c:\programdata\Symantec 2012-12-20 05:19 . 2012-12-20 05:19 ——– d—–w- c:\program files\Common Files\Symantec Shared 2012-12-20 05:19 . 2012-12-20 05:19 ——– d—–w- c:\program files (x86)\Symantec 2012-12-20 05:07 . 2012-12-20 05:07 ——– d—–w- c:\windows\PCHEALTH 2012-12-20 05:04 . 2012-12-20 05:04 ——– d—–w- c:\program files\Microsoft Office 2012-12-20 05:04 . 2012-12-20 05:04 ——– d—–w- c:\program files (x86)\Microsoft Analysis Services 2012-12-20 05:04 . 2012-12-20 12:16 ——– d—–w- c:\programdata\Microsoft Help 2012-12-20 05:04 . 2012-12-20 05:04 ——– d—–r- C:\MSOCache 2012-12-20 04:30 . 2012-02-17 06:38 1031680 —-a-w- c:\windows\system32\rdpcore.dll 2012-12-20 04:30 . 2012-02-17 05:34 826880 —-a-w- c:\windows\SysWow64\rdpcore.dll 2012-12-20 04:30 . 2012-02-17 04:57 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-12-20 04:27 . 2012-06-02 22:19 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-12-20 04:27 . 2012-06-02 22:19 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-12-20 04:27 . 2012-06-02 22:19 44056 —-a-w- c:\windows\system32\wups2.dll 2012-12-20 04:27 . 2012-06-02 22:15 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-12-20 04:27 . 2012-06-02 22:19 38424 —-a-w- c:\windows\system32\wups.dll 2012-12-20 04:27 . 2012-06-02 22:19 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-12-20 04:27 . 2012-06-02 22:15 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-12-20 04:26 . 2012-06-02 21:19 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-12-20 04:26 . 2012-06-02 21:15 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-12-20 04:20 . 2012-12-23 23:30 ——– d—–w- c:\users\Angel 2012-12-20 03:57 . 2012-12-22 16:32 ——– d—–w- c:\windows\SMINST 2012-11-30 10:45 . 2012-11-30 10:45 1645320 —-a-w- c:\windows\SysWow64\gdiplus.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-23 06:44 . 2012-02-28 09:53 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-22 18:43 . 2012-02-28 09:54 779704 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-11-30 10:45 . 2000-05-22 22:58 152848 —-a-w- c:\windows\SysWow64\comdlg32.ocx 2012-10-16 08:38 . 2012-12-20 05:43 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-12-20 05:43 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-12-20 05:43 561664 —-a-w- c:\windows\apppatch\AcLayers.dll 2012-10-04 16:40 . 2012-12-20 05:42 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-09-28 16:32 . 2012-09-28 16:32 5989776 —-a-w- c:\windows\system32\usbaaplrc.dll 2012-09-28 16:32 . 2012-09-28 16:32 53760 —-a-w- c:\windows\system32\drivers\usbaapl64.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-07-13 17418928] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160] "Dell Registration"="c:\program files (x86)\System Registration\prodreg.exe" [2011-08-04 4165440] "ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2010-08-11 115560] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2011-05-19 995392] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2011-09-15 299008] R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-03-13 65128] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-06-21 34200] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-03-13 98728] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-09-16 340240] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-10-30 250984] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208] R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-12-20 1255736] R4 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600] R4 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-05-19 921664] R4 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2011-05-19 1335360] R4 BTHSSecurityMgr;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-06-03 134928] R4 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-03-13 281928] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2011-03-13 75672] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-09-15 1166848] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-03-13 208272] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-03-13 158832] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-06 2655768] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2011-09-15 299008] S3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [2011-05-19 51712] S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2011-05-19 53248] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2011-11-15 327168] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2011-01-20 176096] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-12-17 138912] S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2011-12-10 60416] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-06-21 25496] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-03-13 481376] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-10-26 406632] S3 tihub3;TI USB3 Hub Service;c:\windows\system32\DRIVERS\tihub3.sys [2011-07-20 136000] S3 tixhci;TI XHCI Service;c:\windows\system32\DRIVERS\tixhci.sys [2011-07-20 406336] . . Contents of the 'Scheduled Tasks' folder . 2012-12-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-23 06:44] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-20 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-20 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-20 416024] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-01-25 525312] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-04-12 609144] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-09-16 1935120] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-05-19 10365952] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.1.1 [removed] FF - ProfilePath - c:\users\Angel\AppData\Roaming\Mozilla\Firefox\Profiles\eirwg56j.default\ FF - ExtSQL: 2012-12-21 13:52; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Angel\AppData\Roaming\Mozilla\Firefox\Profiles\eirwg56j.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi . - - - - ORPHANS REMOVED - - - - . SafeBoot-Symantec Antvirus AddRemove-WT089446 - c:\program files (x86)\WildTangent\Dell Games\Wedding Dash - Ready . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-12-26 20:58:06 ComboFix-quarantined-files.txt 2012-12-27 04:58 . Pre-Run: 435,031,695,360 bytes free Post-Run: 435,813,486,592 bytes free . - - End Of File - - 2F3C74B74B6E1F53DBE03B58EC87731E
Hopefully, the machine has been rebooted since this was run. How was the boot time since this tool removed a few items? Any better? The log on this looks clear now, so let's go ahead and run a couple of other scans to see if there is anything else hiding in places where we might not have seen with this tool.


I believe you said you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

If it doesn't find anything there will be no log to post.
Hi PatnDoris, Sorry for the late reply. I've been having problems away from the computer as well. I hope you do not take any offense, I do appreciate your help very much. For the ESET scan there was nothing found. Malwarebytes log: Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2012.12.29.10 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Angel :: ANGEL-20121219 [administrator] 12/29/2012 12:16:54 PM mbam-log-2012-12-29 (12-16-54).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 222705 Time elapsed: 2 minute(s), 56 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Users\Angel\Documents\Downloads\Setup.exe (Adware.Hotbar) -> Quarantined and deleted successfully. (end)
Real life takes priority :) Your logs are looking good. Let's clean up our tools.

The following will implement some cleanup procedures as well as reset System Restore points:
  • Click the Windows Key + R to open the Run box.
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]

If there are any remaining tools or logs on your desktop you can right-click and delete them.


Let's go ahead a run a rather new tool to remove what we call "junkware" - things that you really don't want to have on your machine, Let's see if that helps any.

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


After doing this, please let me know how your boot time is.
I removed ComboFix. Unfortunately, my computer isn't installing JRT. It tells me it's not installed correctly so I click on "Put on correct settings and install" but then it doesn't do anything after that.
Do you see the icon on the desktop? If not, let's not worry about it. I was just going to see if we could remove some potentially unwanted items to help speed up your boot time a little. Let me know either way and I'll give you some final instructions for the future, if that icon isn't there :)
I cannot see the icon. I usually just put my laptop to sleep and restart when it needs to be restarted, so the slow start up shouldn't be too much of a problem. Thank you so much for your time & effort for helping me with my laptop!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI