Spyware / Malware / Virus Removal
adware and possible malware problems [Solved]
8 min read
budjiman
Topic Starter
I have searched through the forums and can't seem to find anything that could help my situation. I'll explain… I have a dell inspiron 1420 (i know…not exactly the best machine, but I like it). My laptop shipped with vista which I ended up not being much of a fan of so when I got a really bad infection about 2 months ago that murdered my hard drive so i ordered the correct replacement from dell and I decided to ditch vista and go to xp pro 32 bit. Everything seemed to be working great until one day I was watching youtube vids and all of the sudden the sound was crackling and the laptop started acting very slow and funny (alot of freezing up and the lagging too). I had avg at the time so I ran a scan and downloaded malwarebytes and ran it and also tried switching to avast and even avira. I then tried out spybot S&D, super antispyware and comodo products as well. Nothing is totally getting rid of the infection it seems. I keep finding adware and one of the last times I actually remembered to write what I had found down and it was… hkcu\software\crossrider1215appveri and hkcu\software\crossrider (adware.gameplaylab). I really hope you can help, I have been trying to do this on my own for almost 3 weeks now and I am at my witts end. I did download hijack this but didnt want to post anything or use it as per forum instructions.
MrCharlie
Welcome to the forum.
Download DDS from one of the links below and save it to your desktop:
http://download.bleepingcomputer.com/sUBs/dds.scr
http://download.bleepingcomputer.com/sUBs/dds.com
Temporarily disable any script blocker if your Anti-Virus/Anti-Malware has it.
Once downloaded you can disconnect from the Internet and disable your Ant-Virus temporarily if needed.
Then double click dds.scr or dds.com to run the tool, on Vista or Win 7 or Win 8 right click and select Run as administrator
Click the Run button if prompted with an Open File - Security Warning dialog box.
A black DOS console should open and run for a moment.
When done, DDS will open two (2) logs: DDS.txt and Attach.txt
Save both reports to your desktop
Please Copy & Paste the contents of the following logs in your next reply
You can ignore the note about zipping the Attach.txt file
Then………
Please remove any usb or external drives from the computer before you run this scan!
Please download and run RogueKiller to your desktop.
http://tigzy.geekstogo.com/Tools/RogueKillerX64.exe <—use this one for 64 bit systems
Quit all running programs.
For Windows XP, double-click to start.
For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
Click Scan to scan the system.
When the scan completes > Close out the program > Don't Fix anything!
Don't run any other options, they're not all bad!!!!!!!
Post back the report which should be located on your desktop.
MrC
Download DDS from one of the links below and save it to your desktop:
http://download.bleepingcomputer.com/sUBs/dds.scr
http://download.bleepingcomputer.com/sUBs/dds.com
Temporarily disable any script blocker if your Anti-Virus/Anti-Malware has it.
Once downloaded you can disconnect from the Internet and disable your Ant-Virus temporarily if needed.
Then double click dds.scr or dds.com to run the tool, on Vista or Win 7 or Win 8 right click and select Run as administrator
Click the Run button if prompted with an Open File - Security Warning dialog box.
A black DOS console should open and run for a moment.
When done, DDS will open two (2) logs: DDS.txt and Attach.txt
Save both reports to your desktop
Please Copy & Paste the contents of the following logs in your next reply
You can ignore the note about zipping the Attach.txt file
Then………
Please remove any usb or external drives from the computer before you run this scan!
Please download and run RogueKiller to your desktop.
http://tigzy.geekstogo.com/Tools/RogueKillerX64.exe <—use this one for 64 bit systems
Quit all running programs.
For Windows XP, double-click to start.
For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
Click Scan to scan the system.
When the scan completes > Close out the program > Don't Fix anything!
Don't run any other options, they're not all bad!!!!!!!
Post back the report which should be located on your desktop.
MrC
budjiman
I hope I did this all correctly. Please let me know if I went about this the wrong way. Thank you in advance for your help!
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 18:26:47 on 2013-02-26
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2550 [GMT -5:00]
.
AV: PC Cleaner Pro *Disabled/Updated* {737A8864-C2D9-4337-B49A-B5E35815B9BB}
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe
C:\WINDOWS\system32\STacSV.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uLocal Page = about:blank
uWindow Title = Microsoft Internet Explorer
mStart Page = about:blank
mLocal Page = about:blank
mWindow Title = Microsoft Internet Explorer
mDefault_Page_URL = about:blank
uSearchAssistant = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms}
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
EB: {377D8121-EFAA-4D1C-981B-8BFAD9F10DE3} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\stsystra.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Anvi Smart Defender] c:\program files\anvisoft\anvi smart defender\ASDTray.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1355970665265
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1359911853812
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2013-2-4 13560]
R1 asdrm;asdrm;c:\windows\system32\drivers\asdrm.sys [2013-2-19 16208]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-2-18 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-2-18 361032]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2012-7-11 116608]
R2 asdrs;AntiMalware Host-based Intrusion Prevention System;c:\windows\system32\drivers\asdrs.sys [2013-2-19 22864]
R2 asdsrv;Anvi Smart Defender Realtime Guard Service;c:\program files\anvisoft\anvi smart defender\ASDSrv.exe [2012-12-20 735592]
R2 asdws;AnviSmartDefender Web Guard;c:\windows\system32\drivers\asdws.sys [2013-2-19 14160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-2-18 21256]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-2-18 44808]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [2011-3-28 1034240]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 SBRE;SBRE;c:\windows\system32\drivers\sbredrv.sys –> c:\windows\system32\drivers\SBREDrv.sys [?]
.
=============== Created Last 30 ================
.
2013-02-26 13:38:03 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-26 13:38:03 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-26 13:13:20 ——– d—–w- c:\documents and settings\dell\local settings\application data\Opera
2013-02-21 00:01:46 ——– d—–w- c:\program files\Spybot - Search & Destroy
2013-02-20 04:13:01 ——– d—–w- c:\documents and settings\dell\local settings\application data\Updater21804
2013-02-20 04:11:39 ——– d—–w- c:\program files\Free Window Registry Repair
2013-02-20 03:59:16 ——– d—–w- c:\program files\RegistryNuke 2012
2013-02-20 01:47:47 ——– d—–w- c:\documents and settings\dell\application data\ElevatedDiagnostics
2013-02-20 01:07:20 ——– d—–w- c:\documents and settings\all users\application data\COMODO
2013-02-20 01:03:46 ——– d—–w- c:\documents and settings\dell\local settings\application data\COMODO
2013-02-20 01:02:12 1700352 —-a-w- c:\windows\system32\gdiplus.dll
2013-02-20 00:44:46 ——– d—–w- c:\documents and settings\dell\application data\Anvisoft
2013-02-20 00:43:10 22864 —-a-w- c:\windows\system32\drivers\asdrs.sys
2013-02-20 00:43:10 16208 —-a-w- c:\windows\system32\drivers\asdrm.sys
2013-02-20 00:43:10 14160 —-a-w- c:\windows\system32\drivers\asdws.sys
2013-02-20 00:41:33 ——– d—–w- c:\documents and settings\all users\application data\Anvisoft
2013-02-20 00:40:31 ——– d—–w- c:\program files\Anvisoft
2013-02-19 16:40:03 ——– d—–w- c:\documents and settings\dell\application data\SUPERAntiSpyware.com
2013-02-19 16:38:42 ——– d—–w- c:\program files\SUPERAntiSpyware
2013-02-19 16:38:42 ——– d—–w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2013-02-19 13:08:06 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-02-19 13:08:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-02-19 01:51:35 738504 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-19 01:49:29 41224 —-a-w- c:\windows\avastSS.scr
2013-02-18 02:02:02 172032 —-a-w- c:\windows\system32\igfxres.dll
2013-02-18 01:23:39 94208 —-a-w- c:\windows\system32\stacsv.exe
2013-02-18 01:23:39 4952064 —-a-w- c:\windows\system32\stacgui.cpl
2013-02-18 01:23:39 405504 —-a-w- c:\windows\stsystra.exe
2013-02-18 01:23:39 1601536 —-a-w- c:\windows\system32\stlang.dll
2013-02-18 01:22:33 270336 —-a-w- c:\windows\system32\stacapi.dll
2013-02-17 04:54:16 142848 ——w- c:\windows\system32\staco.dll
2013-02-17 03:08:41 37376 —-a-w- c:\windows\system32\drivers\rixdptsk.sys
2013-02-17 03:08:41 32256 —-a-w- c:\windows\system32\drivers\rimmptsk.sys
2013-02-17 03:08:41 16480 —-a-w- c:\windows\system32\rixdicon.dll
2013-02-17 03:08:40 90112 —-a-w- c:\windows\system32\snymsico.dll
2013-02-17 03:08:40 43520 —-a-w- c:\windows\system32\drivers\rimsptsk.sys
2013-02-17 02:21:31 ——– d—–w- c:\windows\system32\wbem\repository\FS
2013-02-17 02:21:31 ——– d—–w- c:\windows\system32\wbem\Repository
2013-02-17 01:39:35 ——– d—–w- c:\program files\Zoom Downloader
2013-02-17 01:39:28 ——– d—–w- c:\documents and settings\dell\local settings\application data\DownloadManager
2013-02-16 18:12:04 ——– d—–w- c:\program files\Dell Support
2013-02-15 21:03:35 ——– d—–w- c:\program files\Windows Media Connect 2
2013-02-15 20:58:15 ——– d—–w- C:\89e75420b9091ae03378
2013-02-15 20:57:51 ——– d—–w- c:\windows\system32\LogFiles
2013-02-15 20:56:09 ——– d—–w- C:\71e074b94d03ab0e3356
2013-02-15 20:47:34 5270256 —-a-w- c:\windows\uninst.exe
2013-02-15 20:45:49 ——– d—–w- c:\documents and settings\all users\application data\PC1Data
2013-02-15 20:12:34 ——– d—–w- c:\documents and settings\dell\local settings\application data\Deployment
2013-02-14 21:55:14 ——– d—–w- c:\program files\Conduit
2013-02-14 21:54:38 ——– d—–w- c:\documents and settings\dell\application data\FoxTab
2013-02-14 21:53:24 ——– d—–w- c:\documents and settings\all users\application data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-02-14 21:51:06 ——– d-sh–w- c:\windows\system32\AI_RecycleBin
2013-02-14 21:34:20 ——– d—–w- c:\program files\MixiDJ
2013-02-14 21:32:23 ——– d—–w- c:\program files\VisualBee_V.1
2013-02-14 21:31:59 ——– d—–w- c:\documents and settings\all users\VisualBee
2013-02-14 16:16:25 ——– d—–w- C:\cbe0c8a47d35439bea88484c
2013-02-14 05:12:30 ——– d—–w- c:\documents and settings\dell\application data\PriceGong
2013-02-14 03:14:42 ——– d—–w- c:\documents and settings\dell\application data\SwvUpdater
2013-02-14 03:12:51 ——– d—–w- c:\documents and settings\dell\local settings\application data\Conduit
2013-02-13 23:58:18 ——– d—–w- c:\documents and settings\dell\application data\Searchya
2013-02-13 21:23:52 ——– d—–w- c:\documents and settings\all users\application data\APN
2013-02-12 12:39:59 ——– d—–w- c:\documents and settings\dell\application data\Strongvault
2013-02-11 19:22:55 ——– d—–w- c:\documents and settings\dell\local settings\application data\adawarebp
2013-02-11 19:05:02 ——– d—–w- c:\documents and settings\dell\application data\QuickScan
2013-02-10 23:16:52 ——– d—–w- c:\documents and settings\all users\application data\SecTaskMan
2013-02-10 23:16:28 ——– d—–w- c:\documents and settings\dell\application data\LavasoftStatistics
2013-02-10 14:58:18 ——– d-sha-r- C:\cmdcons
2013-02-10 14:56:24 256000 —-a-w- c:\windows\PEV.exe
2013-02-10 14:56:24 208896 —-a-w- c:\windows\MBR.exe
2013-02-10 14:47:12 ——– d—–w- c:\documents and settings\dell\local settings\application data\VisualBeeExe
2013-02-10 14:29:41 ——– d—–w- c:\documents and settings\dell\local settings\application data\Coupon Companion Plugin
2013-02-10 03:07:44 118784 —-a-w- c:\windows\system32\MSSTDFMT.DLL
2013-02-10 03:07:44 1071088 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2013-02-09 19:26:00 ——– d-sh–w- c:\documents and settings\dell\IECompatCache
2013-02-09 17:43:58 ——– dc-h–w- c:\windows\ie8
2013-02-09 17:13:26 6144 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2013-02-09 16:26:25 ——– d—–w- c:\documents and settings\all users\application data\Drivers For Free
2013-02-09 16:25:55 ——– d—–w- c:\documents and settings\dell\local settings\application data\Drivers_For_Free
2013-02-09 16:22:18 ——– d—–w- c:\documents and settings\all users\application data\UAB
2013-02-09 16:22:09 ——– d—–w- c:\documents and settings\dell\application data\Drivers For Free
2013-02-09 15:31:00 656542 —-a-w- C:\271_ico1.dll
2013-02-09 05:55:33 656542 —-a-w- C:\271_icol.dll
2013-02-08 15:03:29 ——– d—–w- c:\documents and settings\dell\application data\GlarySoft
2013-02-08 14:00:58 ——– d—–w- c:\documents and settings\dell\Incomplete
2013-02-08 13:59:09 ——– d—–w- c:\documents and settings\dell\application data\YouTubeFreeDownloader
2013-02-08 13:58:31 ——– d—–w- c:\program files\YouTube Free Downloader
2013-02-08 13:31:31 ——– d—–w- c:\documents and settings\dell\local settings\application data\Identities
2013-02-08 05:51:32 ——– d—–w- c:\documents and settings\dell\application data\FindeXer
2013-02-08 03:22:55 153153 —-a-w- c:\windows\BricoPackUninst.cmd
2013-02-08 03:05:12 ——– d—–w- c:\program files\RK Launcher
2013-02-08 03:04:56 ——– d—–w- c:\documents and settings\dell\local settings\application data\Stardock
2013-02-08 03:04:27 ——– d—–w- c:\program files\MacSearch_v.1.4.3
2013-02-08 02:44:06 7891 —-a-w- c:\windows\BricoPackFoldersDelete.cmd
2013-02-08 02:40:05 ——– d—–w- c:\windows\BricoPacks
2013-02-06 21:15:33 ——– d—–w- C:\110e7134daea3e1a009b
2013-02-06 14:23:55 ——– d—–w- c:\documents and settings\all users\application data\AVAST Software
2013-02-06 14:23:54 ——– d—–w- c:\program files\AVAST Software
2013-02-06 08:46:14 ——– d—–w- C:\d635b693b6fbd2f741cc4ebe31a705
2013-02-06 08:40:31 ——– d—–w- c:\windows\system32\XPSViewer
2013-02-06 08:37:52 89088 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2013-02-06 08:36:34 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2013-02-06 08:36:34 117760 ——w- c:\windows\system32\prntvpt.dll
2013-02-06 08:36:33 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2013-02-06 08:36:33 597504 ——w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2013-02-06 08:36:32 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2013-02-06 08:36:32 575488 ——w- c:\windows\system32\xpsshhdr.dll
2013-02-06 08:36:26 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2013-02-06 08:36:26 1676288 ——w- c:\windows\system32\xpssvcs.dll
2013-02-06 08:36:21 ——– d—–w- C:\fe61f5577fc36b0fa828980e86cd70
2013-02-05 06:27:14 ——– d—–w- C:\04ef57bbca634a67615b70d8d7
2013-02-05 06:26:31 ——– d—–w- C:\21f06413fcabb3020739
2013-02-04 23:02:13 ——– d—–w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2013-02-04 22:55:55 ——– d—–w- c:\documents and settings\all users\application data\Ad-Aware Antivirus
2013-02-04 22:53:05 ——– d—–w- c:\program files\Ad-Aware Antivirus
2013-02-04 22:51:48 ——– d—–w- c:\documents and settings\dell\local settings\application data\Downloaded Installations
2013-02-04 22:51:25 13560 —-a-w- c:\windows\system32\drivers\gfibto.sys
2013-02-04 22:51:24 44424 —-a-w- c:\windows\system32\sbbd.exe
2013-02-04 22:48:33 ——– d—–w- c:\documents and settings\all users\application data\blekko toolbars
2013-02-04 22:48:12 ——– d—–w- c:\program files\adawaretb
2013-02-04 22:48:12 ——– d—–w- c:\documents and settings\dell\application data\adawaretb
2013-02-04 22:48:08 ——– d—–w- c:\program files\Toolbar Cleaner
2013-02-04 22:45:58 ——– d—–w- c:\documents and settings\dell\application data\Ad-Aware Antivirus
2013-02-03 17:23:27 ——– d—–w- c:\documents and settings\all users\application data\RegInOut
2013-02-03 15:40:15 ——– d-sh–w- c:\documents and settings\all users\application data\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-02-03 15:39:25 ——– d—–w- c:\windows\system32\appmgmt
2013-02-03 15:38:17 ——– d—–w- c:\documents and settings\dell\application data\IObit
2013-02-03 15:38:17 ——– d—–w- c:\documents and settings\all users\application data\IObit
2013-02-03 15:36:31 ——– d—–w- c:\program files\DellTPad
2013-02-03 15:32:43 ——– d—–w- c:\documents and settings\dell\local settings\application data\Apple
2013-02-03 14:59:54 ——– d—–w- c:\windows\system32\NtmsData
2013-02-03 13:36:31 ——– d—–w- c:\documents and settings\dell\application data\MapsGalaxy_39
2013-02-03 13:36:05 ——– d—–w- c:\program files\MapsGalaxy_39
2013-02-03 03:40:48 ——– d—–w- c:\documents and settings\dell\application data\AVG
2013-02-03 03:38:31 ——– d—–w- c:\documents and settings\all users\application data\AVG
2013-02-02 00:00:48 ——– d—–w- c:\program files\IObit
2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2013-02-01 18:10:05 155136 —-a-w- c:\windows\system32\drivers\Apfiltr.sys
2013-02-01 18:10:05 1419232 —-a-w- c:\windows\system32\WdfCoInstaller01005.dll
2013-02-01 18:10:04 100418 —-a-w- c:\windows\system32\Vxdif.dll
2013-02-01 15:07:50 ——– d—–w- c:\documents and settings\dell\local settings\application data\Apple Computer
2013-02-01 15:02:53 ——– d—–w- c:\documents and settings\all users\application data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-02-01 14:12:03 ——– d—–w- C:\5517ec06987c51c96fea803303df
2013-02-01 06:04:29 ——– d—–w- c:\windows\pss
2013-01-31 16:48:08 ——– d—–w- c:\documents and settings\dell\application data\Malwarebytes
2013-01-31 16:33:50 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes
2013-01-28 17:40:10 1431552 —-a-w- c:\windows\system32\rewire.dll
2013-01-28 17:40:10 ——– d—–w- c:\program files\VstPlugins
2013-01-28 17:39:38 1554944 —-a-w- c:\windows\system32\vorbis.acm
2013-01-28 17:29:18 ——– d—–w- c:\program files\Image-Line
2013-01-28 16:24:40 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2013-01-28 16:24:40 21504 —-a-w- c:\windows\system32\hidserv.dll
2013-01-28 16:24:26 12160 -c–a-w- c:\windows\system32\dllcache\mouhid.sys
2013-01-28 16:24:26 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2013-01-28 16:24:21 14592 -c–a-w- c:\windows\system32\dllcache\kbdhid.sys
2013-01-28 16:24:21 14592 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2013-01-28 16:24:11 10368 -c–a-w- c:\windows\system32\dllcache\hidusb.sys
2013-01-28 16:24:11 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
.
==================== Find3M ====================
.
2013-02-18 13:12:31 499712 —-a-w- c:\windows\system32\msvcp71.dll
2013-02-18 13:12:31 348160 —-a-w- c:\windows\system32\msvcr71.dll
2013-02-10 16:19:47 861088 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-02-10 16:19:47 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-02-08 03:22:42 218624 —-a-w- c:\windows\system32\uxtheme.dll
2013-01-26 03:55:44 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-01-25 03:43:02 35488 —-a-w- c:\windows\system32\cmdcsr.dll
2013-01-25 03:43:02 354752 —-a-w- c:\windows\system32\guard32.dll
2013-01-25 03:42:50 40656 —-a-w- c:\windows\system32\cmdkbd32.dll
2013-01-25 03:42:50 263888 —-a-w- c:\windows\system32\cmdvrt32.dll
2013-01-17 06:28:58 232336 ——w- c:\windows\system32\MpSigStub.exe
2013-01-17 00:51:56 586728 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2013-01-17 00:51:56 32824 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2013-01-17 00:51:54 18536 —-a-w- c:\windows\system32\drivers\cmderd.sys
2013-01-07 01:19:45 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37:01 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20:00 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49:10 148992 —-a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49:10 1292288 —-a-w- c:\windows\system32\quartz.dll
2012-12-26 20:16:29 916480 —-a-w- c:\windows\system32\wininet.dll
2012-12-26 20:16:28 43520 ——w- c:\windows\system32\licmgr10.dll
2012-12-26 20:16:28 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40:59 385024 ——w- c:\windows\system32\html.iec
2012-12-16 12:23:59 290560 —-a-w- c:\windows\system32\atmfd.dll
.
============= FINISH: 18:26:59.65 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/18/2012 11:58:15 PM
System Uptime: 2/26/2013 11:46:38 AM (7 hours ago)
.
Motherboard: Dell Inc. | | 0DT492
Processor: Intel® Pentium® Dual CPU T2390 @ 1.86GHz | Microprocessor | 1321/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 233 GiB total, 219.905 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: Modem Device on High Definition Audio Bus
Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2C06&SUBSYS_14F1000F&REV_1000\4&220DA15F&1&0102
Manufacturer:
Name: Modem Device on High Definition Audio Bus
PNP Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2C06&SUBSYS_14F1000F&REV_1000\4&220DA15F&1&0102
Service:
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Adobe Flash Player 11 Plugin
Advanced Audio FX Engine
Advanced Video FX Engine
avast! Free Antivirus
Broadcom Gigabit Integrated Controller
Broadcom Management Programs
CCleaner
Dell Touchpad
Dell Wireless WLAN Card
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2779562)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Intel® Graphics Media Accelerator Driver
Malwarebytes Anti-Malware version 1.70.0.1100
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Opera 12.14
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2744842)
Security Update for Windows Internet Explorer 8 (KB2761465)
Security Update for Windows Internet Explorer 8 (KB2792100)
Security Update for Windows Internet Explorer 8 (KB2797052)
Security Update for Windows Internet Explorer 8 (KB2799329)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2510581)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2544521)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2659262)
Security Update for Windows XP (KB2661637)
Security Update for Windows XP (KB2676562)
Security Update for Windows XP (KB2686509)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2705219-v2)
Security Update for Windows XP (KB2712808)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB2723135-v2)
Security Update for Windows XP (KB2724197)
Security Update for Windows XP (KB2727528)
Security Update for Windows XP (KB2753842-v2)
Security Update for Windows XP (KB2753842)
Security Update for Windows XP (KB2757638)
Security Update for Windows XP (KB2758857)
Security Update for Windows XP (KB2761465)
Security Update for Windows XP (KB2770660)
Security Update for Windows XP (KB2778344)
Security Update for Windows XP (KB2779030)
Security Update for Windows XP (KB2780091)
Security Update for Windows XP (KB2799329)
Security Update for Windows XP (KB2799494)
Security Update for Windows XP (KB2802968)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982665)
SigmaTel Audio
Spybot - Search & Destroy
SUPERAntiSpyware
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB2598845)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2661254-v2)
Update for Windows XP (KB2736233)
Update for Windows XP (KB2749655)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows PowerShell™ 1.0
Windows XP Service Pack 3
.
==== Event Viewer Messages From Past Week ========
.
2/25/2013 7:12:14 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'kxqcsx.sys' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
2/25/2013 6:57:10 PM, error: Service Control Manager [7034] - The Dell Wireless WLAN Tray Service service terminated unexpectedly. It has done this 1 time(s).
2/25/2013 10:47:46 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
2/21/2013 5:46:57 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD asdrm AswRdr aswSnx aswSP aswTdi cmdGuard cmdHlp Fips intelppm IPSec MRxSmb NetBIOS NetBT ohci1394 RasAcd Rdbss SASDIFSV SASKUTIL Tcpip WS2IFSL
2/21/2013 1:29:48 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 asdrm aswSnx aswSP aswTdi cmdGuard Fips intelppm SASDIFSV SASKUTIL
2/20/2013 9:40:13 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD asdrm AswRdr aswSnx aswSP aswTdi cmdGuard cmdHlp Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip WS2IFSL
2/20/2013 9:40:13 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2013 9:40:13 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2013 9:40:13 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2013 9:40:13 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
2/20/2013 9:39:48 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
2/20/2013 9:39:47 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/20/2013 9:03:54 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.
2/20/2013 9:03:54 AM, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/20/2013 8:20:13 AM, error: Service Control Manager [7034] - The Anvi Smart Defender Realtime Guard Service service terminated unexpectedly. It has done this 1 time(s).
2/20/2013 1:52:46 AM, error: Service Control Manager [7034] - The RealNetworks Downloader Resolver Service service terminated unexpectedly. It has done this 1 time(s).
2/19/2013 7:25:12 PM, error: Service Control Manager [7031] - The Windows Defender service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
2/19/2013 7:10:34 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
2/19/2013 7:09:19 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
2/19/2013 7:04:07 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSnx aswSP aswTdi Fips intelppm SASDIFSV SASKUTIL
2/19/2013 5:14:46 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
2/19/2013 11:10:52 AM, error: Service Control Manager [7031] - The Windows Defender service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
.
==== End Of File ===========================
budjiman
I think I may have done something wrong here… Please let me know where I messed up b\c this is all I got.
[00:00:0000] ***** Global Init *****
[00:00:0000] Has crashed before : Yes
[00:00:0000] Create mutex : RogueKiller
MrCharlie
Don't worry about RogueKiller.
Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.
Download Malwarebytes Anti-Rootkit from HERE
~~~~~~~~~~~~~~~~~~~~~~~
Note:
If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
Internet access
Windows Update
Windows Firewall
If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot.
Verify that your system is now functioning normally.
MrC
Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.
Download Malwarebytes Anti-Rootkit from HERE
- Unzip the contents to a folder in a convenient location.
- Open the folder where the contents were unzipped and run mbar.exe
- Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
- Click on the Cleanup button to remove any threats and reboot if prompted to do so.
- Wait while the system shuts down and the cleanup process is performed.
- Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
- When done, please post the two logs produced they will be in the MBAR folder….. mbar-log.txt and system-log.txt
~~~~~~~~~~~~~~~~~~~~~~~
Note:
If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
Internet access
Windows Update
Windows Firewall
If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot.
Verify that your system is now functioning normally.
MrC
budjiman
I apologize for the delay in getting back to you. i ran that mbar dl as you instructed. It was able to find 2 instances of malware. I may have messed something up because there were no logs saved to my desktop. but I did write them down. the 2 were … "iron source searchyahlpr" and there was another that ended in "hlpr1". I restarted the laptop and ran it again and there doesn't seem to be anything else.
Please let me know what to try next. 
MrCharlie
Next:
Please download and run ComboFix.
The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.
Please visit this webpage for download links, and instructions for running ComboFix
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Information on disabling your malware programs can be found Here.
Make sure you run ComboFix from your desktop.
Give it at least 30-45 minutes to finish if needed.
Please include the C:\ComboFix.txt in your next reply for further review.
MrC
Please download and run ComboFix.
The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.
Please visit this webpage for download links, and instructions for running ComboFix
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Information on disabling your malware programs can be found Here.
Make sure you run ComboFix from your desktop.
Give it at least 30-45 minutes to finish if needed.
Please include the C:\ComboFix.txt in your next reply for further review.
———->NOTE<———-
If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix….please reboot the computer, this should resolve the problem. You may have to do this several times if needed.MrC
budjiman
Please let me know if this is correct and whats next…thanks!!!!!!!!
ComboFix 13-02-26.01 - Dell 02/27/2013 9:45.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2428 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Dell\Application Data\PriceGong
c:\documents and settings\Dell\Application Data\PriceGong\Data\1.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\a.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\b.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\c.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\d.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\e.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\f.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\g.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\h.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\i.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\j.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\k.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\l.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\m.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\n.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\o.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\p.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\q.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\r.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\s.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\t.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\u.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\v.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\w.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\wlu.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\x.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\y.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\z.txt
c:\windows\system32\SET12B.tmp
c:\windows\system32\SET12F.tmp
c:\windows\system32\SET130.tmp
c:\windows\system32\SET137.tmp
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2013-01-27 to 2013-02-27 )))))))))))))))))))))))))))))))
.
.
2013-02-27 12:51 . 2013-02-27 12:51 ——– d—–w- c:\windows\LastGood
2013-02-27 03:10 . 2013-02-27 03:10 35144 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2013-02-26 13:38 . 2013-02-26 15:47 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-26 13:38 . 2013-02-26 15:47 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-26 13:13 . 2013-02-26 13:13 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Opera
2013-02-26 13:12 . 2013-02-26 13:12 ——– d—–w- c:\program files\Opera
2013-02-22 07:30 . 2013-02-25 16:26 ——– d—–w- c:\documents and settings\admin
2013-02-21 00:01 . 2013-02-25 16:22 ——– d—–w- c:\program files\Spybot - Search & Destroy
2013-02-20 04:13 . 2013-02-20 04:13 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Updater21804
2013-02-20 04:11 . 2013-02-25 23:08 ——– d—–w- c:\program files\Free Window Registry Repair
2013-02-20 03:59 . 2013-02-20 05:56 ——– d—–w- c:\program files\RegistryNuke 2012
2013-02-20 01:47 . 2013-02-27 12:04 ——– d—–w- c:\documents and settings\Dell\Application Data\ElevatedDiagnostics
2013-02-20 01:15 . 2013-02-26 15:47 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\COMODO
2013-02-20 01:07 . 2013-02-26 15:55 ——– d—–w- c:\documents and settings\All Users\Application Data\COMODO
2013-02-20 01:03 . 2013-02-26 15:47 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\COMODO
2013-02-20 01:02 . 2013-02-20 01:02 1700352 —-a-w- c:\windows\system32\gdiplus.dll
2013-02-20 00:44 . 2013-02-25 21:29 ——– d—–w- c:\documents and settings\Dell\Application Data\Anvisoft
2013-02-20 00:43 . 2012-11-07 07:16 22864 —-a-w- c:\windows\system32\drivers\asdrs.sys
2013-02-20 00:43 . 2012-11-07 07:16 14160 —-a-w- c:\windows\system32\drivers\asdws.sys
2013-02-20 00:43 . 2012-11-07 07:16 16208 —-a-w- c:\windows\system32\drivers\asdrm.sys
2013-02-20 00:41 . 2013-02-20 00:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Anvisoft
2013-02-20 00:40 . 2013-02-20 00:40 ——– d—–w- c:\program files\Anvisoft
2013-02-19 16:40 . 2013-02-19 16:40 ——– d—–w- c:\documents and settings\Dell\Application Data\SUPERAntiSpyware.com
2013-02-19 16:38 . 2013-02-19 16:40 ——– d—–w- c:\program files\SUPERAntiSpyware
2013-02-19 16:38 . 2013-02-19 16:38 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2013-02-19 13:08 . 2013-02-19 13:08 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-02-19 13:08 . 2012-12-14 21:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-02-19 01:51 . 2012-10-30 23:51 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-19 01:51 . 2012-10-30 23:51 361032 —-a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-19 01:51 . 2012-10-30 23:51 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2013-02-19 01:51 . 2012-10-30 23:51 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-19 01:51 . 2012-10-30 23:51 738504 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-19 01:51 . 2012-10-30 23:51 97608 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2013-02-19 01:51 . 2012-10-30 23:51 89752 —-a-w- c:\windows\system32\drivers\aswmon.sys
2013-02-19 01:51 . 2012-10-30 23:51 25256 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2013-02-19 01:49 . 2012-10-30 23:51 41224 —-a-w- c:\windows\avastSS.scr
2013-02-19 01:49 . 2012-10-30 23:50 227648 —-a-w- c:\windows\system32\aswBoot.exe
2013-02-18 13:12 . 2013-02-26 17:06 ——– d—–w- c:\program files\Real
2013-02-18 02:02 . 2008-02-16 01:45 172032 —-a-w- c:\windows\system32\igfxres.dll
2013-02-18 01:23 . 2007-05-10 15:23 94208 —-a-w- c:\windows\system32\stacsv.exe
2013-02-18 01:23 . 2007-05-10 15:23 4952064 —-a-w- c:\windows\system32\stacgui.cpl
2013-02-18 01:23 . 2007-05-10 15:22 405504 —-a-w- c:\windows\stsystra.exe
2013-02-18 01:23 . 2007-04-10 22:02 1601536 —-a-w- c:\windows\system32\stlang.dll
2013-02-18 01:22 . 2007-05-10 15:23 270336 —-a-w- c:\windows\system32\stacapi.dll
2013-02-17 04:54 . 2007-02-19 19:26 142848 ——w- c:\windows\system32\staco.dll
2013-02-17 03:09 . 2013-02-17 03:09 ——– d—–w- c:\program files\DIFX
2013-02-17 03:08 . 2006-11-15 05:16 32256 —-a-w- c:\windows\system32\drivers\rimmptsk.sys
2013-02-17 03:08 . 2006-11-14 22:35 37376 —-a-w- c:\windows\system32\drivers\rixdptsk.sys
2013-02-17 03:08 . 2005-05-07 00:06 16480 —-a-w- c:\windows\system32\rixdicon.dll
2013-02-17 03:08 . 2006-11-15 00:42 43520 —-a-w- c:\windows\system32\drivers\rimsptsk.sys
2013-02-17 03:08 . 2004-09-03 15:00 90112 —-a-w- c:\windows\system32\snymsico.dll
2013-02-17 02:21 . 2013-02-17 02:21 ——– d—–w- c:\windows\system32\wbem\Repository
2013-02-17 01:39 . 2013-02-17 02:01 ——– d—–w- c:\program files\Zoom Downloader
2013-02-17 01:39 . 2013-02-17 02:01 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\DownloadManager
2013-02-16 18:12 . 2013-02-17 02:17 ——– d—–w- c:\documents and settings\Dell\Application Data\GTek
2013-02-16 18:12 . 2013-02-17 02:17 ——– d—–w- c:\program files\Dell Support
2013-02-16 18:12 . 2013-02-17 02:16 ——– d—–w- c:\documents and settings\All Users\Application Data\GTek
2013-02-15 21:34 . 2008-04-14 10:42 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2013-02-15 21:03 . 2013-02-15 21:03 ——– d—–w- c:\program files\Windows Media Connect 2
2013-02-15 20:58 . 2013-02-15 21:01 ——– d—–w- C:\89e75420b9091ae03378
2013-02-15 20:57 . 2013-02-20 00:12 ——– d—–w- c:\windows\system32\drivers\UMDF
2013-02-15 20:57 . 2013-02-15 20:57 ——– d—–w- c:\windows\system32\LogFiles
2013-02-15 20:56 . 2013-02-15 20:58 ——– d—–w- C:\71e074b94d03ab0e3356
2013-02-15 20:47 . 2013-02-15 20:44 5270256 —-a-w- c:\windows\uninst.exe
2013-02-15 20:45 . 2013-02-15 20:56 ——– d—–w- c:\documents and settings\All Users\Application Data\PC1Data
2013-02-15 20:12 . 2013-02-18 23:13 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Deployment
2013-02-14 21:55 . 2013-02-14 21:55 ——– d—–w- c:\program files\Conduit
2013-02-14 21:54 . 2013-02-14 21:54 ——– d—–w- c:\documents and settings\Dell\Application Data\FoxTab
2013-02-14 21:53 . 2013-02-14 21:53 ——– d—–w- c:\documents and settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-02-14 21:51 . 2013-02-14 21:51 ——– d-sh–w- c:\windows\system32\AI_RecycleBin
2013-02-14 21:34 . 2013-02-14 21:34 ——– d—–w- c:\program files\MixiDJ
2013-02-14 21:32 . 2013-02-14 21:32 ——– d—–w- c:\program files\VisualBee_V.1
2013-02-14 21:31 . 2013-02-14 21:32 ——– d—–w- c:\documents and settings\All Users\VisualBee
2013-02-14 16:16 . 2013-02-14 21:56 ——– d—–w- C:\cbe0c8a47d35439bea88484c
2013-02-14 03:14 . 2013-02-15 18:13 ——– d—–w- c:\documents and settings\Dell\Application Data\SwvUpdater
2013-02-14 03:12 . 2013-02-15 18:10 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Conduit
2013-02-13 23:58 . 2013-02-13 23:58 ——– d—–w- c:\documents and settings\Dell\Application Data\Searchya
2013-02-13 21:23 . 2013-02-13 21:23 ——– d—–w- c:\documents and settings\All Users\Application Data\APN
2013-02-13 20:32 . 2013-02-13 20:32 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2013-02-12 12:39 . 2013-02-12 12:39 ——– d—–w- c:\documents and settings\Dell\Application Data\Strongvault
2013-02-11 19:22 . 2013-02-15 18:26 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\adawarebp
2013-02-11 19:05 . 2013-02-11 19:05 ——– d—–w- c:\documents and settings\Dell\Application Data\QuickScan
2013-02-10 23:16 . 2013-02-20 06:50 ——– d—–w- c:\documents and settings\All Users\Application Data\SecTaskMan
2013-02-10 23:16 . 2013-02-16 16:58 ——– d—–w- c:\documents and settings\Dell\Application Data\LavasoftStatistics
2013-02-10 14:47 . 2013-02-15 18:17 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\VisualBeeExe
2013-02-10 14:29 . 2013-02-15 18:12 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Coupon Companion Plugin
2013-02-10 04:40 . 2013-02-21 06:51 ——– d—–w- c:\documents and settings\Administrator
2013-02-10 03:07 . 2010-01-10 23:40 118784 —-a-w- c:\windows\system32\MSSTDFMT.DLL
2013-02-10 03:07 . 2010-01-10 23:40 1071088 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2013-02-09 19:26 . 2013-02-09 19:26 ——– d-sh–w- c:\documents and settings\Dell\IECompatCache
2013-02-09 17:43 . 2013-02-09 17:49 ——– dc-h–w- c:\windows\ie8
2013-02-09 17:13 . 2011-08-16 10:45 6144 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2013-02-09 16:33 . 2013-02-09 16:33 ——– d—–w- c:\program files\Intel
2013-02-09 16:26 . 2013-02-09 16:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Drivers For Free
2013-02-09 16:25 . 2013-02-09 16:25 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Drivers_For_Free
2013-02-09 16:22 . 2013-02-09 16:22 ——– d—–w- c:\documents and settings\All Users\Application Data\UAB
2013-02-09 16:22 . 2013-02-09 16:22 ——– d—–w- c:\documents and settings\Dell\Application Data\Drivers For Free
2013-02-09 16:19 . 2013-02-09 16:19 ——– d—–w- c:\program files\Microsoft.NET
2013-02-09 15:31 . 2004-06-18 12:07 656542 —-a-w- C:\271_ico1.dll
2013-02-09 05:55 . 2004-06-18 12:07 656542 —-a-w- C:\271_icol.dll
2013-02-08 15:03 . 2013-02-08 15:09 ——– d—–w- c:\documents and settings\Dell\Application Data\GlarySoft
2013-02-08 14:00 . 2013-02-08 14:18 ——– d—–w- c:\documents and settings\Dell\Incomplete
2013-02-08 13:59 . 2013-02-10 14:34 ——– d—–w- c:\documents and settings\Dell\Application Data\YouTubeFreeDownloader
2013-02-08 13:58 . 2013-02-14 21:31 ——– d—–w- c:\program files\YouTube Free Downloader
2013-02-08 13:31 . 2013-02-08 13:31 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Identities
2013-02-08 05:51 . 2013-02-08 05:51 ——– d—–w- c:\documents and settings\Dell\Application Data\FindeXer
2013-02-08 03:22 . 2013-02-08 03:22 153153 —-a-w- c:\windows\BricoPackUninst.cmd
2013-02-08 03:05 . 2013-02-08 03:05 ——– d—–w- c:\program files\RK Launcher
2013-02-08 03:04 . 2013-02-08 03:04 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Stardock
2013-02-08 03:04 . 2013-02-09 15:47 ——– d—–w- c:\program files\MacSearch_v.1.4.3
2013-02-08 02:44 . 2013-02-08 03:22 7891 —-a-w- c:\windows\BricoPackFoldersDelete.cmd
2013-02-08 02:40 . 2013-02-08 02:40 ——– d—–w- c:\windows\BricoPacks
2013-02-07 12:39 . 2013-02-07 12:39 ——– d—–w- c:\documents and settings\Dell\Application Data\Creative
2013-02-06 21:15 . 2013-02-06 21:17 ——– d—–w- C:\110e7134daea3e1a009b
2013-02-06 20:32 . 2013-02-06 20:32 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2013-02-06 14:23 . 2013-02-19 01:46 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2013-02-06 14:23 . 2013-02-19 01:46 ——– d—–w- c:\program files\AVAST Software
2013-02-06 08:46 . 2013-02-06 08:46 ——– d—–w- C:\d635b693b6fbd2f741cc4ebe31a705
2013-02-06 08:40 . 2013-02-06 22:25 ——– d—–w- c:\windows\system32\XPSViewer
2013-02-06 08:40 . 2013-02-06 08:40 ——– d—–w- c:\program files\MSBuild
2013-02-06 08:38 . 2013-02-06 08:38 ——– d—–w- c:\program files\Reference Assemblies
2013-02-06 08:37 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2013-02-06 08:36 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2013-02-06 08:36 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2013-02-06 08:36 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-18 13:12 . 2012-12-19 05:48 348160 —-a-w- c:\windows\system32\msvcr71.dll
2013-02-18 13:12 . 2012-12-19 05:48 499712 —-a-w- c:\windows\system32\msvcp71.dll
2013-02-10 16:19 . 2012-12-19 06:38 861088 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-02-10 16:19 . 2012-12-19 06:38 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-02-08 03:22 . 2006-02-28 12:00 218624 —-a-w- c:\windows\system32\uxtheme.dll
2013-01-26 03:55 . 2006-02-28 12:00 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-01-25 03:43 . 2013-01-25 03:43 35488 —-a-w- c:\windows\system32\cmdcsr.dll
2013-01-25 03:43 . 2013-01-25 03:43 354752 —-a-w- c:\windows\system32\guard32.dll
2013-01-25 03:42 . 2013-01-25 03:42 40656 —-a-w- c:\windows\system32\cmdkbd32.dll
2013-01-25 03:42 . 2013-01-25 03:42 263888 —-a-w- c:\windows\system32\cmdvrt32.dll
2013-01-17 06:28 . 2012-12-20 02:28 232336 ——w- c:\windows\system32\MpSigStub.exe
2013-01-17 00:51 . 2013-01-17 00:51 586728 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2013-01-17 00:51 . 2013-01-17 00:51 32824 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2013-01-17 00:51 . 2013-01-17 00:51 18536 —-a-w- c:\windows\system32\drivers\cmderd.sys
2013-01-07 01:19 . 2006-02-28 12:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37 . 2004-08-03 22:59 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20 . 2006-02-28 12:00 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2006-02-28 12:00 148992 —-a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2006-02-28 12:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2012-12-26 20:16 . 2006-02-28 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2012-12-26 20:16 . 2006-02-28 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2012-12-26 20:16 . 2006-02-28 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40 . 2006-02-28 12:00 385024 ——w- c:\windows\system32\html.iec
2012-12-16 12:23 . 2006-02-28 12:00 290560 —-a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 23:50 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-11-01 4763008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"Anvi Smart Defender"="c:\program files\Anvisoft\Anvi Smart Defender\ASDTray.exe" [2012-12-21 1434984]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotDeletingD3137]
del [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-02-28 22:32 166424 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotDeletingB61]
2006-02-28 12:00 50620 —-a-w- c:\windows\system32\command.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MBAMService"=2 (0x2)
"MBAMScheduler"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2/4/2013 5:51 PM 13560]
R1 asdrm;asdrm;c:\windows\system32\drivers\asdrm.sys [2/19/2013 7:43 PM 16208]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2/18/2013 8:51 PM 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/18/2013 8:51 PM 361032]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [7/11/2012 1:54 PM 116608]
R2 asdrs;AntiMalware Host-based Intrusion Prevention System;c:\windows\system32\drivers\asdrs.sys [2/19/2013 7:43 PM 22864]
R2 asdsrv;Anvi Smart Defender Realtime Guard Service;c:\program files\Anvisoft\Anvi Smart Defender\ASDSrv.exe [12/20/2012 9:43 PM 735592]
R2 asdws;AnviSmartDefender Web Guard;c:\windows\system32\drivers\asdws.sys [2/19/2013 7:43 PM 14160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/18/2013 8:51 PM 21256]
R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2/26/2013 10:10 PM 35144]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [3/28/2011 9:22 AM 1034240]
S4 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys –> c:\windows\system32\drivers\SBREDrv.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MBAMCHAMELEON
.
Contents of the 'Scheduled Tasks' folder
.
2013-02-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-26 15:47]
.
2013-02-27 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-02-19 23:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uLocal Page = about:blank
mStart Page = about:blank
mWindow Title = Microsoft Internet Explorer
mLocal Page = about:blank
uSearchAssistant = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms}
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
Trusted Zone: dell.com
TCP: DhcpNameServer = 10.0.0.1
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-RunOnce-Z1 - c:\documents and settings\Dell\Local Settings\Application Data\Opera\Opera\temporary_downloads\mbar-1.01.0.1020\mbar\mbar.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-27 09:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD2500BPVT-75JJ5T0 rev.03.01A03 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A485864
user & kernel MBR OK
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(712)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2013-02-27 09:58:31
ComboFix-quarantined-files.txt 2013-02-27 14:58
ComboFix2.txt 2013-02-12 13:09
ComboFix3.txt 2013-02-10 15:57
.
Pre-Run: 236,009,160,704 bytes free
Post-Run: 236,043,522,048 bytes free
.
- - End Of File - - E61EDA7C10C15515A9FB2B46B84E9783
ComboFix 13-02-26.01 - Dell 02/27/2013 9:45.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2428 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Dell\Application Data\PriceGong
c:\documents and settings\Dell\Application Data\PriceGong\Data\1.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\a.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\b.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\c.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\d.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\e.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\f.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\g.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\h.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\i.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\j.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\k.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\l.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\m.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\n.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\o.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\p.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\q.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\r.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\s.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\t.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\u.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\v.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\w.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\wlu.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\x.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\y.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\z.txt
c:\windows\system32\SET12B.tmp
c:\windows\system32\SET12F.tmp
c:\windows\system32\SET130.tmp
c:\windows\system32\SET137.tmp
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2013-01-27 to 2013-02-27 )))))))))))))))))))))))))))))))
.
.
2013-02-27 12:51 . 2013-02-27 12:51 ——– d—–w- c:\windows\LastGood
2013-02-27 03:10 . 2013-02-27 03:10 35144 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2013-02-26 13:38 . 2013-02-26 15:47 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-26 13:38 . 2013-02-26 15:47 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-26 13:13 . 2013-02-26 13:13 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Opera
2013-02-26 13:12 . 2013-02-26 13:12 ——– d—–w- c:\program files\Opera
2013-02-22 07:30 . 2013-02-25 16:26 ——– d—–w- c:\documents and settings\admin
2013-02-21 00:01 . 2013-02-25 16:22 ——– d—–w- c:\program files\Spybot - Search & Destroy
2013-02-20 04:13 . 2013-02-20 04:13 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Updater21804
2013-02-20 04:11 . 2013-02-25 23:08 ——– d—–w- c:\program files\Free Window Registry Repair
2013-02-20 03:59 . 2013-02-20 05:56 ——– d—–w- c:\program files\RegistryNuke 2012
2013-02-20 01:47 . 2013-02-27 12:04 ——– d—–w- c:\documents and settings\Dell\Application Data\ElevatedDiagnostics
2013-02-20 01:15 . 2013-02-26 15:47 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\COMODO
2013-02-20 01:07 . 2013-02-26 15:55 ——– d—–w- c:\documents and settings\All Users\Application Data\COMODO
2013-02-20 01:03 . 2013-02-26 15:47 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\COMODO
2013-02-20 01:02 . 2013-02-20 01:02 1700352 —-a-w- c:\windows\system32\gdiplus.dll
2013-02-20 00:44 . 2013-02-25 21:29 ——– d—–w- c:\documents and settings\Dell\Application Data\Anvisoft
2013-02-20 00:43 . 2012-11-07 07:16 22864 —-a-w- c:\windows\system32\drivers\asdrs.sys
2013-02-20 00:43 . 2012-11-07 07:16 14160 —-a-w- c:\windows\system32\drivers\asdws.sys
2013-02-20 00:43 . 2012-11-07 07:16 16208 —-a-w- c:\windows\system32\drivers\asdrm.sys
2013-02-20 00:41 . 2013-02-20 00:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Anvisoft
2013-02-20 00:40 . 2013-02-20 00:40 ——– d—–w- c:\program files\Anvisoft
2013-02-19 16:40 . 2013-02-19 16:40 ——– d—–w- c:\documents and settings\Dell\Application Data\SUPERAntiSpyware.com
2013-02-19 16:38 . 2013-02-19 16:40 ——– d—–w- c:\program files\SUPERAntiSpyware
2013-02-19 16:38 . 2013-02-19 16:38 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2013-02-19 13:08 . 2013-02-19 13:08 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-02-19 13:08 . 2012-12-14 21:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-02-19 01:51 . 2012-10-30 23:51 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-19 01:51 . 2012-10-30 23:51 361032 —-a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-19 01:51 . 2012-10-30 23:51 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2013-02-19 01:51 . 2012-10-30 23:51 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-19 01:51 . 2012-10-30 23:51 738504 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-19 01:51 . 2012-10-30 23:51 97608 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2013-02-19 01:51 . 2012-10-30 23:51 89752 —-a-w- c:\windows\system32\drivers\aswmon.sys
2013-02-19 01:51 . 2012-10-30 23:51 25256 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2013-02-19 01:49 . 2012-10-30 23:51 41224 —-a-w- c:\windows\avastSS.scr
2013-02-19 01:49 . 2012-10-30 23:50 227648 —-a-w- c:\windows\system32\aswBoot.exe
2013-02-18 13:12 . 2013-02-26 17:06 ——– d—–w- c:\program files\Real
2013-02-18 02:02 . 2008-02-16 01:45 172032 —-a-w- c:\windows\system32\igfxres.dll
2013-02-18 01:23 . 2007-05-10 15:23 94208 —-a-w- c:\windows\system32\stacsv.exe
2013-02-18 01:23 . 2007-05-10 15:23 4952064 —-a-w- c:\windows\system32\stacgui.cpl
2013-02-18 01:23 . 2007-05-10 15:22 405504 —-a-w- c:\windows\stsystra.exe
2013-02-18 01:23 . 2007-04-10 22:02 1601536 —-a-w- c:\windows\system32\stlang.dll
2013-02-18 01:22 . 2007-05-10 15:23 270336 —-a-w- c:\windows\system32\stacapi.dll
2013-02-17 04:54 . 2007-02-19 19:26 142848 ——w- c:\windows\system32\staco.dll
2013-02-17 03:09 . 2013-02-17 03:09 ——– d—–w- c:\program files\DIFX
2013-02-17 03:08 . 2006-11-15 05:16 32256 —-a-w- c:\windows\system32\drivers\rimmptsk.sys
2013-02-17 03:08 . 2006-11-14 22:35 37376 —-a-w- c:\windows\system32\drivers\rixdptsk.sys
2013-02-17 03:08 . 2005-05-07 00:06 16480 —-a-w- c:\windows\system32\rixdicon.dll
2013-02-17 03:08 . 2006-11-15 00:42 43520 —-a-w- c:\windows\system32\drivers\rimsptsk.sys
2013-02-17 03:08 . 2004-09-03 15:00 90112 —-a-w- c:\windows\system32\snymsico.dll
2013-02-17 02:21 . 2013-02-17 02:21 ——– d—–w- c:\windows\system32\wbem\Repository
2013-02-17 01:39 . 2013-02-17 02:01 ——– d—–w- c:\program files\Zoom Downloader
2013-02-17 01:39 . 2013-02-17 02:01 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\DownloadManager
2013-02-16 18:12 . 2013-02-17 02:17 ——– d—–w- c:\documents and settings\Dell\Application Data\GTek
2013-02-16 18:12 . 2013-02-17 02:17 ——– d—–w- c:\program files\Dell Support
2013-02-16 18:12 . 2013-02-17 02:16 ——– d—–w- c:\documents and settings\All Users\Application Data\GTek
2013-02-15 21:34 . 2008-04-14 10:42 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2013-02-15 21:03 . 2013-02-15 21:03 ——– d—–w- c:\program files\Windows Media Connect 2
2013-02-15 20:58 . 2013-02-15 21:01 ——– d—–w- C:\89e75420b9091ae03378
2013-02-15 20:57 . 2013-02-20 00:12 ——– d—–w- c:\windows\system32\drivers\UMDF
2013-02-15 20:57 . 2013-02-15 20:57 ——– d—–w- c:\windows\system32\LogFiles
2013-02-15 20:56 . 2013-02-15 20:58 ——– d—–w- C:\71e074b94d03ab0e3356
2013-02-15 20:47 . 2013-02-15 20:44 5270256 —-a-w- c:\windows\uninst.exe
2013-02-15 20:45 . 2013-02-15 20:56 ——– d—–w- c:\documents and settings\All Users\Application Data\PC1Data
2013-02-15 20:12 . 2013-02-18 23:13 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Deployment
2013-02-14 21:55 . 2013-02-14 21:55 ——– d—–w- c:\program files\Conduit
2013-02-14 21:54 . 2013-02-14 21:54 ——– d—–w- c:\documents and settings\Dell\Application Data\FoxTab
2013-02-14 21:53 . 2013-02-14 21:53 ——– d—–w- c:\documents and settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-02-14 21:51 . 2013-02-14 21:51 ——– d-sh–w- c:\windows\system32\AI_RecycleBin
2013-02-14 21:34 . 2013-02-14 21:34 ——– d—–w- c:\program files\MixiDJ
2013-02-14 21:32 . 2013-02-14 21:32 ——– d—–w- c:\program files\VisualBee_V.1
2013-02-14 21:31 . 2013-02-14 21:32 ——– d—–w- c:\documents and settings\All Users\VisualBee
2013-02-14 16:16 . 2013-02-14 21:56 ——– d—–w- C:\cbe0c8a47d35439bea88484c
2013-02-14 03:14 . 2013-02-15 18:13 ——– d—–w- c:\documents and settings\Dell\Application Data\SwvUpdater
2013-02-14 03:12 . 2013-02-15 18:10 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Conduit
2013-02-13 23:58 . 2013-02-13 23:58 ——– d—–w- c:\documents and settings\Dell\Application Data\Searchya
2013-02-13 21:23 . 2013-02-13 21:23 ——– d—–w- c:\documents and settings\All Users\Application Data\APN
2013-02-13 20:32 . 2013-02-13 20:32 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2013-02-12 12:39 . 2013-02-12 12:39 ——– d—–w- c:\documents and settings\Dell\Application Data\Strongvault
2013-02-11 19:22 . 2013-02-15 18:26 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\adawarebp
2013-02-11 19:05 . 2013-02-11 19:05 ——– d—–w- c:\documents and settings\Dell\Application Data\QuickScan
2013-02-10 23:16 . 2013-02-20 06:50 ——– d—–w- c:\documents and settings\All Users\Application Data\SecTaskMan
2013-02-10 23:16 . 2013-02-16 16:58 ——– d—–w- c:\documents and settings\Dell\Application Data\LavasoftStatistics
2013-02-10 14:47 . 2013-02-15 18:17 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\VisualBeeExe
2013-02-10 14:29 . 2013-02-15 18:12 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Coupon Companion Plugin
2013-02-10 04:40 . 2013-02-21 06:51 ——– d—–w- c:\documents and settings\Administrator
2013-02-10 03:07 . 2010-01-10 23:40 118784 —-a-w- c:\windows\system32\MSSTDFMT.DLL
2013-02-10 03:07 . 2010-01-10 23:40 1071088 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2013-02-09 19:26 . 2013-02-09 19:26 ——– d-sh–w- c:\documents and settings\Dell\IECompatCache
2013-02-09 17:43 . 2013-02-09 17:49 ——– dc-h–w- c:\windows\ie8
2013-02-09 17:13 . 2011-08-16 10:45 6144 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2013-02-09 16:33 . 2013-02-09 16:33 ——– d—–w- c:\program files\Intel
2013-02-09 16:26 . 2013-02-09 16:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Drivers For Free
2013-02-09 16:25 . 2013-02-09 16:25 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Drivers_For_Free
2013-02-09 16:22 . 2013-02-09 16:22 ——– d—–w- c:\documents and settings\All Users\Application Data\UAB
2013-02-09 16:22 . 2013-02-09 16:22 ——– d—–w- c:\documents and settings\Dell\Application Data\Drivers For Free
2013-02-09 16:19 . 2013-02-09 16:19 ——– d—–w- c:\program files\Microsoft.NET
2013-02-09 15:31 . 2004-06-18 12:07 656542 —-a-w- C:\271_ico1.dll
2013-02-09 05:55 . 2004-06-18 12:07 656542 —-a-w- C:\271_icol.dll
2013-02-08 15:03 . 2013-02-08 15:09 ——– d—–w- c:\documents and settings\Dell\Application Data\GlarySoft
2013-02-08 14:00 . 2013-02-08 14:18 ——– d—–w- c:\documents and settings\Dell\Incomplete
2013-02-08 13:59 . 2013-02-10 14:34 ——– d—–w- c:\documents and settings\Dell\Application Data\YouTubeFreeDownloader
2013-02-08 13:58 . 2013-02-14 21:31 ——– d—–w- c:\program files\YouTube Free Downloader
2013-02-08 13:31 . 2013-02-08 13:31 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Identities
2013-02-08 05:51 . 2013-02-08 05:51 ——– d—–w- c:\documents and settings\Dell\Application Data\FindeXer
2013-02-08 03:22 . 2013-02-08 03:22 153153 —-a-w- c:\windows\BricoPackUninst.cmd
2013-02-08 03:05 . 2013-02-08 03:05 ——– d—–w- c:\program files\RK Launcher
2013-02-08 03:04 . 2013-02-08 03:04 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Stardock
2013-02-08 03:04 . 2013-02-09 15:47 ——– d—–w- c:\program files\MacSearch_v.1.4.3
2013-02-08 02:44 . 2013-02-08 03:22 7891 —-a-w- c:\windows\BricoPackFoldersDelete.cmd
2013-02-08 02:40 . 2013-02-08 02:40 ——– d—–w- c:\windows\BricoPacks
2013-02-07 12:39 . 2013-02-07 12:39 ——– d—–w- c:\documents and settings\Dell\Application Data\Creative
2013-02-06 21:15 . 2013-02-06 21:17 ——– d—–w- C:\110e7134daea3e1a009b
2013-02-06 20:32 . 2013-02-06 20:32 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2013-02-06 14:23 . 2013-02-19 01:46 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2013-02-06 14:23 . 2013-02-19 01:46 ——– d—–w- c:\program files\AVAST Software
2013-02-06 08:46 . 2013-02-06 08:46 ——– d—–w- C:\d635b693b6fbd2f741cc4ebe31a705
2013-02-06 08:40 . 2013-02-06 22:25 ——– d—–w- c:\windows\system32\XPSViewer
2013-02-06 08:40 . 2013-02-06 08:40 ——– d—–w- c:\program files\MSBuild
2013-02-06 08:38 . 2013-02-06 08:38 ——– d—–w- c:\program files\Reference Assemblies
2013-02-06 08:37 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2013-02-06 08:36 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2013-02-06 08:36 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2013-02-06 08:36 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-18 13:12 . 2012-12-19 05:48 348160 —-a-w- c:\windows\system32\msvcr71.dll
2013-02-18 13:12 . 2012-12-19 05:48 499712 —-a-w- c:\windows\system32\msvcp71.dll
2013-02-10 16:19 . 2012-12-19 06:38 861088 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-02-10 16:19 . 2012-12-19 06:38 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-02-08 03:22 . 2006-02-28 12:00 218624 —-a-w- c:\windows\system32\uxtheme.dll
2013-01-26 03:55 . 2006-02-28 12:00 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-01-25 03:43 . 2013-01-25 03:43 35488 —-a-w- c:\windows\system32\cmdcsr.dll
2013-01-25 03:43 . 2013-01-25 03:43 354752 —-a-w- c:\windows\system32\guard32.dll
2013-01-25 03:42 . 2013-01-25 03:42 40656 —-a-w- c:\windows\system32\cmdkbd32.dll
2013-01-25 03:42 . 2013-01-25 03:42 263888 —-a-w- c:\windows\system32\cmdvrt32.dll
2013-01-17 06:28 . 2012-12-20 02:28 232336 ——w- c:\windows\system32\MpSigStub.exe
2013-01-17 00:51 . 2013-01-17 00:51 586728 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2013-01-17 00:51 . 2013-01-17 00:51 32824 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2013-01-17 00:51 . 2013-01-17 00:51 18536 —-a-w- c:\windows\system32\drivers\cmderd.sys
2013-01-07 01:19 . 2006-02-28 12:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37 . 2004-08-03 22:59 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20 . 2006-02-28 12:00 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2006-02-28 12:00 148992 —-a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2006-02-28 12:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2012-12-26 20:16 . 2006-02-28 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2012-12-26 20:16 . 2006-02-28 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2012-12-26 20:16 . 2006-02-28 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40 . 2006-02-28 12:00 385024 ——w- c:\windows\system32\html.iec
2012-12-16 12:23 . 2006-02-28 12:00 290560 —-a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 23:50 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-11-01 4763008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"Anvi Smart Defender"="c:\program files\Anvisoft\Anvi Smart Defender\ASDTray.exe" [2012-12-21 1434984]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotDeletingD3137]
del [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-02-28 22:32 166424 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotDeletingB61]
2006-02-28 12:00 50620 —-a-w- c:\windows\system32\command.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MBAMService"=2 (0x2)
"MBAMScheduler"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2/4/2013 5:51 PM 13560]
R1 asdrm;asdrm;c:\windows\system32\drivers\asdrm.sys [2/19/2013 7:43 PM 16208]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2/18/2013 8:51 PM 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/18/2013 8:51 PM 361032]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [7/11/2012 1:54 PM 116608]
R2 asdrs;AntiMalware Host-based Intrusion Prevention System;c:\windows\system32\drivers\asdrs.sys [2/19/2013 7:43 PM 22864]
R2 asdsrv;Anvi Smart Defender Realtime Guard Service;c:\program files\Anvisoft\Anvi Smart Defender\ASDSrv.exe [12/20/2012 9:43 PM 735592]
R2 asdws;AnviSmartDefender Web Guard;c:\windows\system32\drivers\asdws.sys [2/19/2013 7:43 PM 14160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/18/2013 8:51 PM 21256]
R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2/26/2013 10:10 PM 35144]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [3/28/2011 9:22 AM 1034240]
S4 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys –> c:\windows\system32\drivers\SBREDrv.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MBAMCHAMELEON
.
Contents of the 'Scheduled Tasks' folder
.
2013-02-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-26 15:47]
.
2013-02-27 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-02-19 23:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uLocal Page = about:blank
mStart Page = about:blank
mWindow Title = Microsoft Internet Explorer
mLocal Page = about:blank
uSearchAssistant = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms}
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
Trusted Zone: dell.com
TCP: DhcpNameServer = 10.0.0.1
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-RunOnce-Z1 - c:\documents and settings\Dell\Local Settings\Application Data\Opera\Opera\temporary_downloads\mbar-1.01.0.1020\mbar\mbar.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-27 09:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD2500BPVT-75JJ5T0 rev.03.01A03 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A485864
user & kernel MBR OK
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(712)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2013-02-27 09:58:31
ComboFix-quarantined-files.txt 2013-02-27 14:58
ComboFix2.txt 2013-02-12 13:09
ComboFix3.txt 2013-02-10 15:57
.
Pre-Run: 236,009,160,704 bytes free
Post-Run: 236,043,522,048 bytes free
.
- - End Of File - - E61EDA7C10C15515A9FB2B46B84E9783
MrCharlie
OK…Next:
Please download AdwCleaner from here and save it on your Desktop.
Note: The log can also be located at C:\ >> AdwCleaner[XX].txt >> XX <– Denotes the number of times the application has been ran, so in this should be something like R1.
Note:
Please look over what was found……especially any folders, we're going to permanently delete it all in the next step….if there's something you may want to keep…please let me know and I'll explain to why it shouldn't be on your system.
MrC
Please download AdwCleaner from here and save it on your Desktop.
AdwCleaner is a reliable removal tool for Adware, Foistware, toolbars and potentially unwanted programs.
AdwCleaner is a tool that deletes :
· Adwares (software ads)
· PUP/LPI (Potentially Undesirable Program)
· Toolbars
· Hijacker (Hijack of the browser's homepage)
It works with a Search and Deletion methode. It can be easily uninstalled using the "Uninstall" mode.
- Right-click on adwcleaner.exe and select Run As Administrator (for XP just double click) to launch the application.
- Now click on the Search tab.
- Please post the contents of the log-file created in your next post.
Note: The log can also be located at C:\ >> AdwCleaner[XX].txt >> XX <– Denotes the number of times the application has been ran, so in this should be something like R1.
Note:
Please look over what was found……especially any folders, we're going to permanently delete it all in the next step….if there's something you may want to keep…please let me know and I'll explain to why it shouldn't be on your system.
MrC
budjiman
# AdwCleaner v2.113 - Logfile created 02/27/2013 at 11:19:01
# Updated 23/02/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Dell - DAVID
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Dell\desktop\adwcleaner.exe
# Option [Search]
***** [Services] *****
***** [Files / Folders] *****
File Found : C:\Program Files\Mozilla Firefox\defaults\pref\all-iminent.js
Folder Found : C:\Documents and Settings\All Users\Application Data\APN
Folder Found : C:\Documents and Settings\All Users\Application Data\blekko toolbars
Folder Found : C:\Documents and Settings\All Users\Application Data\Tarma Installer
Folder Found : C:\Documents and Settings\Dell\Application Data\adawaretb
Folder Found : C:\Documents and Settings\Dell\Application Data\SearchYa
Folder Found : C:\Documents and Settings\Dell\Application Data\SwvUpdater
Folder Found : C:\Documents and Settings\Dell\Local Settings\Application Data\Conduit
Folder Found : C:\Documents and Settings\Dell\Local Settings\Application Data\Coupon Companion Plugin
Folder Found : C:\Program Files\adawaretb
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\VisualBee_V.1
Folder Found : C:\Program Files\Zoom Downloader
***** [Registry] *****
Key Found : HKCU\Software\5a2d78dbc6fb849
Key Found : HKCU\Software\AppDataLow\Software\Search Settings
Key Found : HKCU\Software\ConduitSearchScopes
Key Found : HKCU\Software\Iminent
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{05478A66-EDB6-4A22-A870-A5987F80A7DA}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Found : HKCU\Software\searchya
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\VisualBee_V.1
Key Found : HKCU\Software\wecarereminder
Key Found : HKLM\SOFTWARE\Classes\AppID\{15F6BCB7-BB0F-4A66-8762-4765B05597EB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{1973277F-87B0-4EA3-9ED2-470A91D284CF}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Found : HKLM\SOFTWARE\Classes\esrv.searchyaESrvc
Key Found : HKLM\SOFTWARE\Classes\esrv.searchyaESrvc.1
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3281023
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{15F6BCB7-BB0F-4A66-8762-4765B05597EB}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\Iminent
Key Found : HKLM\Software\InstallCore
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{819DC4CA-4FFF-4C2E-800D-F346471D99BC}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Key Found : HKLM\Software\VisualBee_V.1
Key Found : HKU\S-1-5-21-746137067-1958367476-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms}
[HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms}
-\\ Opera v12.14.1738.0
File : C:\Documents and Settings\Dell\Application Data\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [5517 octets] - [27/02/2013 11:19:01]
########## EOF - C:\AdwCleaner[R1].txt - [5577 octets] ##########
MrCharlie
Please create a new system restore point before continuing.
Lots of adware found….lets clear it out…..
Note: You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
Then……
Lets check your computers security before you go and we have a little cleanup to do also:
Download Security Check by screen317 from HERE or HERE.
Lots of adware found….lets clear it out…..
- Please re-run AdwCleaner
- Click on Delete button.
- Confirm each time with OK if asked.
- Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.
Note: You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
Then……
Lets check your computers security before you go and we have a little cleanup to do also:
Download Security Check by screen317 from HERE or HERE.
- Save it to your Desktop.
- Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
- A Notepad document should open automatically called checkup.txt.
- Please Post the contents of that document.
- Do Not Attach It!!!
budjiman
its amazing how much garbage really gets in there! wow!
# AdwCleaner v2.113 - Logfile created 02/27/2013 at 13:30:52
# Updated 23/02/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Dell - DAVID
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Dell\desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\all-iminent.js
Folder Deleted : C:\Documents and Settings\All Users\Application Data\APN
Folder Deleted : C:\Documents and Settings\All Users\Application Data\blekko toolbars
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Tarma Installer
Folder Deleted : C:\Documents and Settings\Dell\Application Data\adawaretb
Folder Deleted : C:\Documents and Settings\Dell\Application Data\SearchYa
Folder Deleted : C:\Documents and Settings\Dell\Application Data\SwvUpdater
Folder Deleted : C:\Documents and Settings\Dell\Local Settings\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\Dell\Local Settings\Application Data\Coupon Companion Plugin
Folder Deleted : C:\Program Files\adawaretb
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\VisualBee_V.1
Folder Deleted : C:\Program Files\Zoom Downloader
***** [Registry] *****
Key Deleted : HKCU\Software\5a2d78dbc6fb849
Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings
Key Deleted : HKCU\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{05478A66-EDB6-4A22-A870-A5987F80A7DA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\searchya
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\VisualBee_V.1
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{15F6BCB7-BB0F-4A66-8762-4765B05597EB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1973277F-87B0-4EA3-9ED2-470A91D284CF}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Classes\esrv.searchyaESrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.searchyaESrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3281023
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{15F6BCB7-BB0F-4A66-8762-4765B05597EB}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\InstallCore
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{819DC4CA-4FFF-4C2E-800D-F346471D99BC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Key Deleted : HKLM\Software\VisualBee_V.1
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms} –> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms} –> hxxp://www.google.com
-\\ Opera v12.14.1738.0
File : C:\Documents and Settings\Dell\Application Data\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [5646 octets] - [27/02/2013 11:19:01]
AdwCleaner[S1].txt - [5612 octets] - [27/02/2013 13:30:52]
########## EOF - C:\AdwCleaner[S1].txt - [5672 octets] ##########
MrCharlie
Can you post the log from Security Check? MrC
budjiman
Please forgive me if I posted the wrong thing. If I did just let me know how to fix it.
Results of screen317's Security Check version 0.99.60
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Please wait while WMIC compiles updated MOF files.d
i
s
p
l
a
y
N
a
m
e
ECHO is off.
a
v
a
s
t
!
ECHO is off.
A
n
t
i
v
i
r
u
s
ECHO is off.
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
SUPERAntiSpyware
Malwarebytes Anti-Malware version 1.70.0.1100
CCleaner
Adobe Flash Player 11.6.602.171
Google Chrome 22.0.1229.95
````````Process Check: objlist.exe by Laurent````````
Anvisoft Anvi Smart Defender ASDSrv.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 5%
````````````````````End of Log``````````````````````
Results of screen317's Security Check version 0.99.60
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Please wait while WMIC compiles updated MOF files.d
i
s
p
l
a
y
N
a
m
e
ECHO is off.
a
v
a
s
t
!
ECHO is off.
A
n
t
i
v
i
r
u
s
ECHO is off.
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
SUPERAntiSpyware
Malwarebytes Anti-Malware version 1.70.0.1100
CCleaner
Adobe Flash Player 11.6.602.171
Google Chrome 22.0.1229.95
````````Process Check: objlist.exe by Laurent````````
Anvisoft Anvi Smart Defender ASDSrv.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 5%
````````````````````End of Log``````````````````````
MrCharlie
That log looks OK.
How is it?? MrC
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI