This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

adware and possible malware problems [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have searched through the forums and can't seem to find anything that could help my situation. I'll explain… I have a dell inspiron 1420 (i know…not exactly the best machine, but I like it). My laptop shipped with vista which I ended up not being much of a fan of so when I got a really bad infection about 2 months ago that murdered my hard drive so i ordered the correct replacement from dell and I decided to ditch vista and go to xp pro 32 bit. Everything seemed to be working great until one day I was watching youtube vids and all of the sudden the sound was crackling and the laptop started acting very slow and funny (alot of freezing up and the lagging too). I had avg at the time so I ran a scan and downloaded malwarebytes and ran it and also tried switching to avast and even avira. I then tried out spybot S&D, super antispyware and comodo products as well. Nothing is totally getting rid of the infection it seems. I keep finding adware and one of the last times I actually remembered to write what I had found down and it was… hkcu\software\crossrider1215appveri and hkcu\software\crossrider (adware.gameplaylab). I really hope you can help, I have been trying to do this on my own for almost 3 weeks now and I am at my witts end. I did download hijack this but didnt want to post anything or use it as per forum instructions.
Welcome to the forum.

Download DDS from one of the links below and save it to your desktop:
http://download.bleepingcomputer.com/sUBs/dds.scr
http://download.bleepingcomputer.com/sUBs/dds.com

Temporarily disable any script blocker if your Anti-Virus/Anti-Malware has it.
Once downloaded you can disconnect from the Internet and disable your Ant-Virus temporarily if needed.
Then double click dds.scr or dds.com to run the tool, on Vista or Win 7 or Win 8 right click and select Run as administrator
Click the Run button if prompted with an Open File - Security Warning dialog box.
A black DOS console should open and run for a moment.
When done, DDS will open two (2) logs: DDS.txt and Attach.txt
Save both reports to your desktop
Please Copy & Paste the contents of the following logs in your next reply
You can ignore the note about zipping the Attach.txt file

Then………

Please remove any usb or external drives from the computer before you run this scan!

Please download and run RogueKiller to your desktop.

http://tigzy.geekstogo.com/Tools/RogueKillerX64.exe <—use this one for 64 bit systems

Quit all running programs.

For Windows XP, double-click to start.
For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.


Click Scan to scan the system.
When the scan completes > Close out the program > Don't Fix anything!

Don't run any other options, they're not all bad!!!!!!!

Post back the report which should be located on your desktop.

MrC
I hope I did this all correctly. Please let me know if I went about this the wrong way. Thank you in advance for your help! DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 18:26:47 on 2013-02-26 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2550 [GMT -5:00] . AV: PC Cleaner Pro *Disabled/Updated* {737A8864-C2D9-4337-B49A-B5E35815B9BB} AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ============== Running Processes ================ . C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe C:\WINDOWS\system32\STacSV.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\Program Files\DellTPad\Apoint.exe C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\AVAST Software\Avast\avastUI.exe C:\Program Files\DellTPad\Apntex.exe C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Opera\Opera.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uStart Page = about:blank uLocal Page = about:blank uWindow Title = Microsoft Internet Explorer mStart Page = about:blank mLocal Page = about:blank mWindow Title = Microsoft Internet Explorer mDefault_Page_URL = about:blank uSearchAssistant = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms} uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com EB: {377D8121-EFAA-4D1C-981B-8BFAD9F10DE3} - uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\stsystra.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [Anvi Smart Defender] c:\program files\anvisoft\anvi smart defender\ASDTray.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:323 uPolicies-Explorer: NoDriveAutoRun = dword:67108863 uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 mPolicies-Explorer: NoDriveTypeAutoRun = dword:323 mPolicies-Explorer: NoDrives = dword:0 mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:323 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1355970665265 DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1359911853812 Notify: igfxcui - igfxdev.dll SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL . ============= SERVICES / DRIVERS =============== . R0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2013-2-4 13560] R1 asdrm;asdrm;c:\windows\system32\drivers\asdrm.sys [2013-2-19 16208] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-2-18 738504] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-2-18 361032] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2012-7-11 116608] R2 asdrs;AntiMalware Host-based Intrusion Prevention System;c:\windows\system32\drivers\asdrs.sys [2013-2-19 22864] R2 asdsrv;Anvi Smart Defender Realtime Guard Service;c:\program files\anvisoft\anvi smart defender\ASDSrv.exe [2012-12-20 735592] R2 asdws;AnviSmartDefender Web Guard;c:\windows\system32\drivers\asdws.sys [2013-2-19 14160] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-2-18 21256] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-2-18 44808] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [2011-3-28 1034240] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 SBRE;SBRE;c:\windows\system32\drivers\sbredrv.sys –> c:\windows\system32\drivers\SBREDrv.sys [?] . =============== Created Last 30 ================ . 2013-02-26 13:38:03 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-02-26 13:38:03 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-02-26 13:13:20 ——– d—–w- c:\documents and settings\dell\local settings\application data\Opera 2013-02-21 00:01:46 ——– d—–w- c:\program files\Spybot - Search & Destroy 2013-02-20 04:13:01 ——– d—–w- c:\documents and settings\dell\local settings\application data\Updater21804 2013-02-20 04:11:39 ——– d—–w- c:\program files\Free Window Registry Repair 2013-02-20 03:59:16 ——– d—–w- c:\program files\RegistryNuke 2012 2013-02-20 01:47:47 ——– d—–w- c:\documents and settings\dell\application data\ElevatedDiagnostics 2013-02-20 01:07:20 ——– d—–w- c:\documents and settings\all users\application data\COMODO 2013-02-20 01:03:46 ——– d—–w- c:\documents and settings\dell\local settings\application data\COMODO 2013-02-20 01:02:12 1700352 —-a-w- c:\windows\system32\gdiplus.dll 2013-02-20 00:44:46 ——– d—–w- c:\documents and settings\dell\application data\Anvisoft 2013-02-20 00:43:10 22864 —-a-w- c:\windows\system32\drivers\asdrs.sys 2013-02-20 00:43:10 16208 —-a-w- c:\windows\system32\drivers\asdrm.sys 2013-02-20 00:43:10 14160 —-a-w- c:\windows\system32\drivers\asdws.sys 2013-02-20 00:41:33 ——– d—–w- c:\documents and settings\all users\application data\Anvisoft 2013-02-20 00:40:31 ——– d—–w- c:\program files\Anvisoft 2013-02-19 16:40:03 ——– d—–w- c:\documents and settings\dell\application data\SUPERAntiSpyware.com 2013-02-19 16:38:42 ——– d—–w- c:\program files\SUPERAntiSpyware 2013-02-19 16:38:42 ——– d—–w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com 2013-02-19 13:08:06 21104 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-02-19 13:08:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2013-02-19 01:51:35 738504 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-02-19 01:49:29 41224 —-a-w- c:\windows\avastSS.scr 2013-02-18 02:02:02 172032 —-a-w- c:\windows\system32\igfxres.dll 2013-02-18 01:23:39 94208 —-a-w- c:\windows\system32\stacsv.exe 2013-02-18 01:23:39 4952064 —-a-w- c:\windows\system32\stacgui.cpl 2013-02-18 01:23:39 405504 —-a-w- c:\windows\stsystra.exe 2013-02-18 01:23:39 1601536 —-a-w- c:\windows\system32\stlang.dll 2013-02-18 01:22:33 270336 —-a-w- c:\windows\system32\stacapi.dll 2013-02-17 04:54:16 142848 ——w- c:\windows\system32\staco.dll 2013-02-17 03:08:41 37376 —-a-w- c:\windows\system32\drivers\rixdptsk.sys 2013-02-17 03:08:41 32256 —-a-w- c:\windows\system32\drivers\rimmptsk.sys 2013-02-17 03:08:41 16480 —-a-w- c:\windows\system32\rixdicon.dll 2013-02-17 03:08:40 90112 —-a-w- c:\windows\system32\snymsico.dll 2013-02-17 03:08:40 43520 —-a-w- c:\windows\system32\drivers\rimsptsk.sys 2013-02-17 02:21:31 ——– d—–w- c:\windows\system32\wbem\repository\FS 2013-02-17 02:21:31 ——– d—–w- c:\windows\system32\wbem\Repository 2013-02-17 01:39:35 ——– d—–w- c:\program files\Zoom Downloader 2013-02-17 01:39:28 ——– d—–w- c:\documents and settings\dell\local settings\application data\DownloadManager 2013-02-16 18:12:04 ——– d—–w- c:\program files\Dell Support 2013-02-15 21:03:35 ——– d—–w- c:\program files\Windows Media Connect 2 2013-02-15 20:58:15 ——– d—–w- C:\89e75420b9091ae03378 2013-02-15 20:57:51 ——– d—–w- c:\windows\system32\LogFiles 2013-02-15 20:56:09 ——– d—–w- C:\71e074b94d03ab0e3356 2013-02-15 20:47:34 5270256 —-a-w- c:\windows\uninst.exe 2013-02-15 20:45:49 ——– d—–w- c:\documents and settings\all users\application data\PC1Data 2013-02-15 20:12:34 ——– d—–w- c:\documents and settings\dell\local settings\application data\Deployment 2013-02-14 21:55:14 ——– d—–w- c:\program files\Conduit 2013-02-14 21:54:38 ——– d—–w- c:\documents and settings\dell\application data\FoxTab 2013-02-14 21:53:24 ——– d—–w- c:\documents and settings\all users\application data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A} 2013-02-14 21:51:06 ——– d-sh–w- c:\windows\system32\AI_RecycleBin 2013-02-14 21:34:20 ——– d—–w- c:\program files\MixiDJ 2013-02-14 21:32:23 ——– d—–w- c:\program files\VisualBee_V.1 2013-02-14 21:31:59 ——– d—–w- c:\documents and settings\all users\VisualBee 2013-02-14 16:16:25 ——– d—–w- C:\cbe0c8a47d35439bea88484c 2013-02-14 05:12:30 ——– d—–w- c:\documents and settings\dell\application data\PriceGong 2013-02-14 03:14:42 ——– d—–w- c:\documents and settings\dell\application data\SwvUpdater 2013-02-14 03:12:51 ——– d—–w- c:\documents and settings\dell\local settings\application data\Conduit 2013-02-13 23:58:18 ——– d—–w- c:\documents and settings\dell\application data\Searchya 2013-02-13 21:23:52 ——– d—–w- c:\documents and settings\all users\application data\APN 2013-02-12 12:39:59 ——– d—–w- c:\documents and settings\dell\application data\Strongvault 2013-02-11 19:22:55 ——– d—–w- c:\documents and settings\dell\local settings\application data\adawarebp 2013-02-11 19:05:02 ——– d—–w- c:\documents and settings\dell\application data\QuickScan 2013-02-10 23:16:52 ——– d—–w- c:\documents and settings\all users\application data\SecTaskMan 2013-02-10 23:16:28 ——– d—–w- c:\documents and settings\dell\application data\LavasoftStatistics 2013-02-10 14:58:18 ——– d-sha-r- C:\cmdcons 2013-02-10 14:56:24 256000 —-a-w- c:\windows\PEV.exe 2013-02-10 14:56:24 208896 —-a-w- c:\windows\MBR.exe 2013-02-10 14:47:12 ——– d—–w- c:\documents and settings\dell\local settings\application data\VisualBeeExe 2013-02-10 14:29:41 ——– d—–w- c:\documents and settings\dell\local settings\application data\Coupon Companion Plugin 2013-02-10 03:07:44 118784 —-a-w- c:\windows\system32\MSSTDFMT.DLL 2013-02-10 03:07:44 1071088 —-a-w- c:\windows\system32\MSCOMCTL.OCX 2013-02-09 19:26:00 ——– d-sh–w- c:\documents and settings\dell\IECompatCache 2013-02-09 17:43:58 ——– dc-h–w- c:\windows\ie8 2013-02-09 17:13:26 6144 -c—-w- c:\windows\system32\dllcache\iecompat.dll 2013-02-09 16:26:25 ——– d—–w- c:\documents and settings\all users\application data\Drivers For Free 2013-02-09 16:25:55 ——– d—–w- c:\documents and settings\dell\local settings\application data\Drivers_For_Free 2013-02-09 16:22:18 ——– d—–w- c:\documents and settings\all users\application data\UAB 2013-02-09 16:22:09 ——– d—–w- c:\documents and settings\dell\application data\Drivers For Free 2013-02-09 15:31:00 656542 —-a-w- C:\271_ico1.dll 2013-02-09 05:55:33 656542 —-a-w- C:\271_icol.dll 2013-02-08 15:03:29 ——– d—–w- c:\documents and settings\dell\application data\GlarySoft 2013-02-08 14:00:58 ——– d—–w- c:\documents and settings\dell\Incomplete 2013-02-08 13:59:09 ——– d—–w- c:\documents and settings\dell\application data\YouTubeFreeDownloader 2013-02-08 13:58:31 ——– d—–w- c:\program files\YouTube Free Downloader 2013-02-08 13:31:31 ——– d—–w- c:\documents and settings\dell\local settings\application data\Identities 2013-02-08 05:51:32 ——– d—–w- c:\documents and settings\dell\application data\FindeXer 2013-02-08 03:22:55 153153 —-a-w- c:\windows\BricoPackUninst.cmd 2013-02-08 03:05:12 ——– d—–w- c:\program files\RK Launcher 2013-02-08 03:04:56 ——– d—–w- c:\documents and settings\dell\local settings\application data\Stardock 2013-02-08 03:04:27 ——– d—–w- c:\program files\MacSearch_v.1.4.3 2013-02-08 02:44:06 7891 —-a-w- c:\windows\BricoPackFoldersDelete.cmd 2013-02-08 02:40:05 ——– d—–w- c:\windows\BricoPacks 2013-02-06 21:15:33 ——– d—–w- C:\110e7134daea3e1a009b 2013-02-06 14:23:55 ——– d—–w- c:\documents and settings\all users\application data\AVAST Software 2013-02-06 14:23:54 ——– d—–w- c:\program files\AVAST Software 2013-02-06 08:46:14 ——– d—–w- C:\d635b693b6fbd2f741cc4ebe31a705 2013-02-06 08:40:31 ——– d—–w- c:\windows\system32\XPSViewer 2013-02-06 08:37:52 89088 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll 2013-02-06 08:36:34 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2013-02-06 08:36:34 117760 ——w- c:\windows\system32\prntvpt.dll 2013-02-06 08:36:33 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2013-02-06 08:36:33 597504 ——w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2013-02-06 08:36:32 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll 2013-02-06 08:36:32 575488 ——w- c:\windows\system32\xpsshhdr.dll 2013-02-06 08:36:26 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll 2013-02-06 08:36:26 1676288 ——w- c:\windows\system32\xpssvcs.dll 2013-02-06 08:36:21 ——– d—–w- C:\fe61f5577fc36b0fa828980e86cd70 2013-02-05 06:27:14 ——– d—–w- C:\04ef57bbca634a67615b70d8d7 2013-02-05 06:26:31 ——– d—–w- C:\21f06413fcabb3020739 2013-02-04 23:02:13 ——– d—–w- c:\documents and settings\all users\application data\Spybot - Search & Destroy 2013-02-04 22:55:55 ——– d—–w- c:\documents and settings\all users\application data\Ad-Aware Antivirus 2013-02-04 22:53:05 ——– d—–w- c:\program files\Ad-Aware Antivirus 2013-02-04 22:51:48 ——– d—–w- c:\documents and settings\dell\local settings\application data\Downloaded Installations 2013-02-04 22:51:25 13560 —-a-w- c:\windows\system32\drivers\gfibto.sys 2013-02-04 22:51:24 44424 —-a-w- c:\windows\system32\sbbd.exe 2013-02-04 22:48:33 ——– d—–w- c:\documents and settings\all users\application data\blekko toolbars 2013-02-04 22:48:12 ——– d—–w- c:\program files\adawaretb 2013-02-04 22:48:12 ——– d—–w- c:\documents and settings\dell\application data\adawaretb 2013-02-04 22:48:08 ——– d—–w- c:\program files\Toolbar Cleaner 2013-02-04 22:45:58 ——– d—–w- c:\documents and settings\dell\application data\Ad-Aware Antivirus 2013-02-03 17:23:27 ——– d—–w- c:\documents and settings\all users\application data\RegInOut 2013-02-03 15:40:15 ——– d-sh–w- c:\documents and settings\all users\application data\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F} 2013-02-03 15:39:25 ——– d—–w- c:\windows\system32\appmgmt 2013-02-03 15:38:17 ——– d—–w- c:\documents and settings\dell\application data\IObit 2013-02-03 15:38:17 ——– d—–w- c:\documents and settings\all users\application data\IObit 2013-02-03 15:36:31 ——– d—–w- c:\program files\DellTPad 2013-02-03 15:32:43 ——– d—–w- c:\documents and settings\dell\local settings\application data\Apple 2013-02-03 14:59:54 ——– d—–w- c:\windows\system32\NtmsData 2013-02-03 13:36:31 ——– d—–w- c:\documents and settings\dell\application data\MapsGalaxy_39 2013-02-03 13:36:05 ——– d—–w- c:\program files\MapsGalaxy_39 2013-02-03 03:40:48 ——– d—–w- c:\documents and settings\dell\application data\AVG 2013-02-03 03:38:31 ——– d—–w- c:\documents and settings\all users\application data\AVG 2013-02-02 00:00:48 ——– d—–w- c:\program files\IObit 2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll 2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll 2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll 2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll 2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll 2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll 2013-02-01 18:41:44 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll 2013-02-01 18:10:05 155136 —-a-w- c:\windows\system32\drivers\Apfiltr.sys 2013-02-01 18:10:05 1419232 —-a-w- c:\windows\system32\WdfCoInstaller01005.dll 2013-02-01 18:10:04 100418 —-a-w- c:\windows\system32\Vxdif.dll 2013-02-01 15:07:50 ——– d—–w- c:\documents and settings\dell\local settings\application data\Apple Computer 2013-02-01 15:02:53 ——– d—–w- c:\documents and settings\all users\application data\188F1432-103A-4ffb-80F1-36B633C5C9E1 2013-02-01 14:12:03 ——– d—–w- C:\5517ec06987c51c96fea803303df 2013-02-01 06:04:29 ——– d—–w- c:\windows\pss 2013-01-31 16:48:08 ——– d—–w- c:\documents and settings\dell\application data\Malwarebytes 2013-01-31 16:33:50 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2013-01-28 17:40:10 1431552 —-a-w- c:\windows\system32\rewire.dll 2013-01-28 17:40:10 ——– d—–w- c:\program files\VstPlugins 2013-01-28 17:39:38 1554944 —-a-w- c:\windows\system32\vorbis.acm 2013-01-28 17:29:18 ——– d—–w- c:\program files\Image-Line 2013-01-28 16:24:40 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll 2013-01-28 16:24:40 21504 —-a-w- c:\windows\system32\hidserv.dll 2013-01-28 16:24:26 12160 -c–a-w- c:\windows\system32\dllcache\mouhid.sys 2013-01-28 16:24:26 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys 2013-01-28 16:24:21 14592 -c–a-w- c:\windows\system32\dllcache\kbdhid.sys 2013-01-28 16:24:21 14592 —-a-w- c:\windows\system32\drivers\kbdhid.sys 2013-01-28 16:24:11 10368 -c–a-w- c:\windows\system32\dllcache\hidusb.sys 2013-01-28 16:24:11 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys . ==================== Find3M ==================== . 2013-02-18 13:12:31 499712 —-a-w- c:\windows\system32\msvcp71.dll 2013-02-18 13:12:31 348160 —-a-w- c:\windows\system32\msvcr71.dll 2013-02-10 16:19:47 861088 —-a-w- c:\windows\system32\npDeployJava1.dll 2013-02-10 16:19:47 782240 —-a-w- c:\windows\system32\deployJava1.dll 2013-02-08 03:22:42 218624 —-a-w- c:\windows\system32\uxtheme.dll 2013-01-26 03:55:44 552448 —-a-w- c:\windows\system32\oleaut32.dll 2013-01-25 03:43:02 35488 —-a-w- c:\windows\system32\cmdcsr.dll 2013-01-25 03:43:02 354752 —-a-w- c:\windows\system32\guard32.dll 2013-01-25 03:42:50 40656 —-a-w- c:\windows\system32\cmdkbd32.dll 2013-01-25 03:42:50 263888 —-a-w- c:\windows\system32\cmdvrt32.dll 2013-01-17 06:28:58 232336 ——w- c:\windows\system32\MpSigStub.exe 2013-01-17 00:51:56 586728 —-a-w- c:\windows\system32\drivers\cmdGuard.sys 2013-01-17 00:51:56 32824 —-a-w- c:\windows\system32\drivers\cmdhlp.sys 2013-01-17 00:51:54 18536 —-a-w- c:\windows\system32\drivers\cmderd.sys 2013-01-07 01:19:45 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-01-07 00:37:01 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe 2013-01-04 01:20:00 1867264 —-a-w- c:\windows\system32\win32k.sys 2013-01-02 06:49:10 148992 —-a-w- c:\windows\system32\mpg2splt.ax 2013-01-02 06:49:10 1292288 —-a-w- c:\windows\system32\quartz.dll 2012-12-26 20:16:29 916480 —-a-w- c:\windows\system32\wininet.dll 2012-12-26 20:16:28 43520 ——w- c:\windows\system32\licmgr10.dll 2012-12-26 20:16:28 1469440 ——w- c:\windows\system32\inetcpl.cpl 2012-12-24 06:40:59 385024 ——w- c:\windows\system32\html.iec 2012-12-16 12:23:59 290560 —-a-w- c:\windows\system32\atmfd.dll . ============= FINISH: 18:26:59.65 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 12/18/2012 11:58:15 PM System Uptime: 2/26/2013 11:46:38 AM (7 hours ago) . Motherboard: Dell Inc. | | 0DT492 Processor: Intel® Pentium® Dual CPU T2390 @ 1.86GHz | Microprocessor | 1321/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 233 GiB total, 219.905 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: Description: Modem Device on High Definition Audio Bus Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2C06&SUBSYS_14F1000F&REV_1000\4&220DA15F&1&0102 Manufacturer: Name: Modem Device on High Definition Audio Bus PNP Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2C06&SUBSYS_14F1000F&REV_1000\4&220DA15F&1&0102 Service: . ==== System Restore Points =================== . No restore point in system. . ==== Installed Programs ====================== . Adobe Flash Player 11 Plugin Advanced Audio FX Engine Advanced Video FX Engine avast! Free Antivirus Broadcom Gigabit Integrated Controller Broadcom Management Programs CCleaner Dell Touchpad Dell Wireless WLAN Card High Definition Audio Driver Package - KB835221 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2779562) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Intel® Graphics Media Accelerator Driver Malwarebytes Anti-Malware version 1.70.0.1100 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Opera 12.14 Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2744842) Security Update for Windows Internet Explorer 8 (KB2761465) Security Update for Windows Internet Explorer 8 (KB2792100) Security Update for Windows Internet Explorer 8 (KB2797052) Security Update for Windows Internet Explorer 8 (KB2799329) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544521) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2655992) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2691442) Security Update for Windows XP (KB2698365) Security Update for Windows XP (KB2705219-v2) Security Update for Windows XP (KB2712808) Security Update for Windows XP (KB2719985) Security Update for Windows XP (KB2723135-v2) Security Update for Windows XP (KB2724197) Security Update for Windows XP (KB2727528) Security Update for Windows XP (KB2753842-v2) Security Update for Windows XP (KB2753842) Security Update for Windows XP (KB2757638) Security Update for Windows XP (KB2758857) Security Update for Windows XP (KB2761465) Security Update for Windows XP (KB2770660) Security Update for Windows XP (KB2778344) Security Update for Windows XP (KB2779030) Security Update for Windows XP (KB2780091) Security Update for Windows XP (KB2799329) Security Update for Windows XP (KB2799494) Security Update for Windows XP (KB2802968) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982665) SigmaTel Audio Spybot - Search & Destroy SUPERAntiSpyware Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB2598845) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2661254-v2) Update for Windows XP (KB2736233) Update for Windows XP (KB2749655) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB973815) WebFldrs XP Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows PowerShell™ 1.0 Windows XP Service Pack 3 . ==== Event Viewer Messages From Past Week ======== . 2/25/2013 7:12:14 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'kxqcsx.sys' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 2/25/2013 6:57:10 PM, error: Service Control Manager [7034] - The Dell Wireless WLAN Tray Service service terminated unexpectedly. It has done this 1 time(s). 2/25/2013 10:47:46 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service. 2/21/2013 5:46:57 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD asdrm AswRdr aswSnx aswSP aswTdi cmdGuard cmdHlp Fips intelppm IPSec MRxSmb NetBIOS NetBT ohci1394 RasAcd Rdbss SASDIFSV SASKUTIL Tcpip WS2IFSL 2/21/2013 1:29:48 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 asdrm aswSnx aswSP aswTdi cmdGuard Fips intelppm SASDIFSV SASKUTIL 2/20/2013 9:40:13 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD asdrm AswRdr aswSnx aswSP aswTdi cmdGuard cmdHlp Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip WS2IFSL 2/20/2013 9:40:13 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 2/20/2013 9:40:13 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 2/20/2013 9:40:13 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 2/20/2013 9:40:13 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 2/20/2013 9:39:48 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 2/20/2013 9:39:47 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 2/20/2013 9:03:54 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect. 2/20/2013 9:03:54 AM, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 2/20/2013 8:20:13 AM, error: Service Control Manager [7034] - The Anvi Smart Defender Realtime Guard Service service terminated unexpectedly. It has done this 1 time(s). 2/20/2013 1:52:46 AM, error: Service Control Manager [7034] - The RealNetworks Downloader Resolver Service service terminated unexpectedly. It has done this 1 time(s). 2/19/2013 7:25:12 PM, error: Service Control Manager [7031] - The Windows Defender service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service. 2/19/2013 7:10:34 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 2/19/2013 7:09:19 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 2/19/2013 7:04:07 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSnx aswSP aswTdi Fips intelppm SASDIFSV SASKUTIL 2/19/2013 5:14:46 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 2/19/2013 11:10:52 AM, error: Service Control Manager [7031] - The Windows Defender service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service. . ==== End Of File ===========================
I think I may have done something wrong here… Please let me know where I messed up b\c this is all I got. [00:00:0000] ***** Global Init ***** [00:00:0000] Has crashed before : Yes [00:00:0000] Create mutex : RogueKiller
Don't worry about RogueKiller.

Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.

Download Malwarebytes Anti-Rootkit from HERE
  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder….. mbar-log.txt and system-log.txt

~~~~~~~~~~~~~~~~~~~~~~~

Note:
If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
Internet access
Windows Update
Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot.
Verify that your system is now functioning normally.


MrC
I apologize for the delay in getting back to you. i ran that mbar dl as you instructed. It was able to find 2 instances of malware. I may have messed something up because there were no logs saved to my desktop. but I did write them down. the 2 were … "iron source searchyahlpr" and there was another that ended in "hlpr1". I restarted the laptop and ran it again and there doesn't seem to be anything else. Please let me know what to try next. :)
Next:

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.

———->NOTE<———-

If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix….please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

MrC
Please let me know if this is correct and whats next…thanks!!!!!!!!


ComboFix 13-02-26.01 - Dell 02/27/2013 9:45.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2428 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Dell\Application Data\PriceGong
c:\documents and settings\Dell\Application Data\PriceGong\Data\1.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\a.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\b.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\c.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\d.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\e.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\f.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\g.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\h.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\i.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\j.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\k.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\l.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\m.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\n.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\o.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\p.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\q.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\r.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\s.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\t.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\u.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\v.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\w.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\wlu.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\x.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\y.txt
c:\documents and settings\Dell\Application Data\PriceGong\Data\z.txt
c:\windows\system32\SET12B.tmp
c:\windows\system32\SET12F.tmp
c:\windows\system32\SET130.tmp
c:\windows\system32\SET137.tmp
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2013-01-27 to 2013-02-27 )))))))))))))))))))))))))))))))
.
.
2013-02-27 12:51 . 2013-02-27 12:51 ——– d—–w- c:\windows\LastGood
2013-02-27 03:10 . 2013-02-27 03:10 35144 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2013-02-26 13:38 . 2013-02-26 15:47 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-26 13:38 . 2013-02-26 15:47 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-26 13:13 . 2013-02-26 13:13 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Opera
2013-02-26 13:12 . 2013-02-26 13:12 ——– d—–w- c:\program files\Opera
2013-02-22 07:30 . 2013-02-25 16:26 ——– d—–w- c:\documents and settings\admin
2013-02-21 00:01 . 2013-02-25 16:22 ——– d—–w- c:\program files\Spybot - Search & Destroy
2013-02-20 04:13 . 2013-02-20 04:13 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Updater21804
2013-02-20 04:11 . 2013-02-25 23:08 ——– d—–w- c:\program files\Free Window Registry Repair
2013-02-20 03:59 . 2013-02-20 05:56 ——– d—–w- c:\program files\RegistryNuke 2012
2013-02-20 01:47 . 2013-02-27 12:04 ——– d—–w- c:\documents and settings\Dell\Application Data\ElevatedDiagnostics
2013-02-20 01:15 . 2013-02-26 15:47 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\COMODO
2013-02-20 01:07 . 2013-02-26 15:55 ——– d—–w- c:\documents and settings\All Users\Application Data\COMODO
2013-02-20 01:03 . 2013-02-26 15:47 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\COMODO
2013-02-20 01:02 . 2013-02-20 01:02 1700352 —-a-w- c:\windows\system32\gdiplus.dll
2013-02-20 00:44 . 2013-02-25 21:29 ——– d—–w- c:\documents and settings\Dell\Application Data\Anvisoft
2013-02-20 00:43 . 2012-11-07 07:16 22864 —-a-w- c:\windows\system32\drivers\asdrs.sys
2013-02-20 00:43 . 2012-11-07 07:16 14160 —-a-w- c:\windows\system32\drivers\asdws.sys
2013-02-20 00:43 . 2012-11-07 07:16 16208 —-a-w- c:\windows\system32\drivers\asdrm.sys
2013-02-20 00:41 . 2013-02-20 00:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Anvisoft
2013-02-20 00:40 . 2013-02-20 00:40 ——– d—–w- c:\program files\Anvisoft
2013-02-19 16:40 . 2013-02-19 16:40 ——– d—–w- c:\documents and settings\Dell\Application Data\SUPERAntiSpyware.com
2013-02-19 16:38 . 2013-02-19 16:40 ——– d—–w- c:\program files\SUPERAntiSpyware
2013-02-19 16:38 . 2013-02-19 16:38 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2013-02-19 13:08 . 2013-02-19 13:08 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-02-19 13:08 . 2012-12-14 21:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-02-19 01:51 . 2012-10-30 23:51 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-19 01:51 . 2012-10-30 23:51 361032 —-a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-19 01:51 . 2012-10-30 23:51 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2013-02-19 01:51 . 2012-10-30 23:51 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-19 01:51 . 2012-10-30 23:51 738504 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-19 01:51 . 2012-10-30 23:51 97608 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2013-02-19 01:51 . 2012-10-30 23:51 89752 —-a-w- c:\windows\system32\drivers\aswmon.sys
2013-02-19 01:51 . 2012-10-30 23:51 25256 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2013-02-19 01:49 . 2012-10-30 23:51 41224 —-a-w- c:\windows\avastSS.scr
2013-02-19 01:49 . 2012-10-30 23:50 227648 —-a-w- c:\windows\system32\aswBoot.exe
2013-02-18 13:12 . 2013-02-26 17:06 ——– d—–w- c:\program files\Real
2013-02-18 02:02 . 2008-02-16 01:45 172032 —-a-w- c:\windows\system32\igfxres.dll
2013-02-18 01:23 . 2007-05-10 15:23 94208 —-a-w- c:\windows\system32\stacsv.exe
2013-02-18 01:23 . 2007-05-10 15:23 4952064 —-a-w- c:\windows\system32\stacgui.cpl
2013-02-18 01:23 . 2007-05-10 15:22 405504 —-a-w- c:\windows\stsystra.exe
2013-02-18 01:23 . 2007-04-10 22:02 1601536 —-a-w- c:\windows\system32\stlang.dll
2013-02-18 01:22 . 2007-05-10 15:23 270336 —-a-w- c:\windows\system32\stacapi.dll
2013-02-17 04:54 . 2007-02-19 19:26 142848 ——w- c:\windows\system32\staco.dll
2013-02-17 03:09 . 2013-02-17 03:09 ——– d—–w- c:\program files\DIFX
2013-02-17 03:08 . 2006-11-15 05:16 32256 —-a-w- c:\windows\system32\drivers\rimmptsk.sys
2013-02-17 03:08 . 2006-11-14 22:35 37376 —-a-w- c:\windows\system32\drivers\rixdptsk.sys
2013-02-17 03:08 . 2005-05-07 00:06 16480 —-a-w- c:\windows\system32\rixdicon.dll
2013-02-17 03:08 . 2006-11-15 00:42 43520 —-a-w- c:\windows\system32\drivers\rimsptsk.sys
2013-02-17 03:08 . 2004-09-03 15:00 90112 —-a-w- c:\windows\system32\snymsico.dll
2013-02-17 02:21 . 2013-02-17 02:21 ——– d—–w- c:\windows\system32\wbem\Repository
2013-02-17 01:39 . 2013-02-17 02:01 ——– d—–w- c:\program files\Zoom Downloader
2013-02-17 01:39 . 2013-02-17 02:01 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\DownloadManager
2013-02-16 18:12 . 2013-02-17 02:17 ——– d—–w- c:\documents and settings\Dell\Application Data\GTek
2013-02-16 18:12 . 2013-02-17 02:17 ——– d—–w- c:\program files\Dell Support
2013-02-16 18:12 . 2013-02-17 02:16 ——– d—–w- c:\documents and settings\All Users\Application Data\GTek
2013-02-15 21:34 . 2008-04-14 10:42 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2013-02-15 21:03 . 2013-02-15 21:03 ——– d—–w- c:\program files\Windows Media Connect 2
2013-02-15 20:58 . 2013-02-15 21:01 ——– d—–w- C:\89e75420b9091ae03378
2013-02-15 20:57 . 2013-02-20 00:12 ——– d—–w- c:\windows\system32\drivers\UMDF
2013-02-15 20:57 . 2013-02-15 20:57 ——– d—–w- c:\windows\system32\LogFiles
2013-02-15 20:56 . 2013-02-15 20:58 ——– d—–w- C:\71e074b94d03ab0e3356
2013-02-15 20:47 . 2013-02-15 20:44 5270256 —-a-w- c:\windows\uninst.exe
2013-02-15 20:45 . 2013-02-15 20:56 ——– d—–w- c:\documents and settings\All Users\Application Data\PC1Data
2013-02-15 20:12 . 2013-02-18 23:13 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Deployment
2013-02-14 21:55 . 2013-02-14 21:55 ——– d—–w- c:\program files\Conduit
2013-02-14 21:54 . 2013-02-14 21:54 ——– d—–w- c:\documents and settings\Dell\Application Data\FoxTab
2013-02-14 21:53 . 2013-02-14 21:53 ——– d—–w- c:\documents and settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-02-14 21:51 . 2013-02-14 21:51 ——– d-sh–w- c:\windows\system32\AI_RecycleBin
2013-02-14 21:34 . 2013-02-14 21:34 ——– d—–w- c:\program files\MixiDJ
2013-02-14 21:32 . 2013-02-14 21:32 ——– d—–w- c:\program files\VisualBee_V.1
2013-02-14 21:31 . 2013-02-14 21:32 ——– d—–w- c:\documents and settings\All Users\VisualBee
2013-02-14 16:16 . 2013-02-14 21:56 ——– d—–w- C:\cbe0c8a47d35439bea88484c
2013-02-14 03:14 . 2013-02-15 18:13 ——– d—–w- c:\documents and settings\Dell\Application Data\SwvUpdater
2013-02-14 03:12 . 2013-02-15 18:10 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Conduit
2013-02-13 23:58 . 2013-02-13 23:58 ——– d—–w- c:\documents and settings\Dell\Application Data\Searchya
2013-02-13 21:23 . 2013-02-13 21:23 ——– d—–w- c:\documents and settings\All Users\Application Data\APN
2013-02-13 20:32 . 2013-02-13 20:32 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2013-02-12 12:39 . 2013-02-12 12:39 ——– d—–w- c:\documents and settings\Dell\Application Data\Strongvault
2013-02-11 19:22 . 2013-02-15 18:26 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\adawarebp
2013-02-11 19:05 . 2013-02-11 19:05 ——– d—–w- c:\documents and settings\Dell\Application Data\QuickScan
2013-02-10 23:16 . 2013-02-20 06:50 ——– d—–w- c:\documents and settings\All Users\Application Data\SecTaskMan
2013-02-10 23:16 . 2013-02-16 16:58 ——– d—–w- c:\documents and settings\Dell\Application Data\LavasoftStatistics
2013-02-10 14:47 . 2013-02-15 18:17 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\VisualBeeExe
2013-02-10 14:29 . 2013-02-15 18:12 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Coupon Companion Plugin
2013-02-10 04:40 . 2013-02-21 06:51 ——– d—–w- c:\documents and settings\Administrator
2013-02-10 03:07 . 2010-01-10 23:40 118784 —-a-w- c:\windows\system32\MSSTDFMT.DLL
2013-02-10 03:07 . 2010-01-10 23:40 1071088 —-a-w- c:\windows\system32\MSCOMCTL.OCX
2013-02-09 19:26 . 2013-02-09 19:26 ——– d-sh–w- c:\documents and settings\Dell\IECompatCache
2013-02-09 17:43 . 2013-02-09 17:49 ——– dc-h–w- c:\windows\ie8
2013-02-09 17:13 . 2011-08-16 10:45 6144 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2013-02-09 16:33 . 2013-02-09 16:33 ——– d—–w- c:\program files\Intel
2013-02-09 16:26 . 2013-02-09 16:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Drivers For Free
2013-02-09 16:25 . 2013-02-09 16:25 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Drivers_For_Free
2013-02-09 16:22 . 2013-02-09 16:22 ——– d—–w- c:\documents and settings\All Users\Application Data\UAB
2013-02-09 16:22 . 2013-02-09 16:22 ——– d—–w- c:\documents and settings\Dell\Application Data\Drivers For Free
2013-02-09 16:19 . 2013-02-09 16:19 ——– d—–w- c:\program files\Microsoft.NET
2013-02-09 15:31 . 2004-06-18 12:07 656542 —-a-w- C:\271_ico1.dll
2013-02-09 05:55 . 2004-06-18 12:07 656542 —-a-w- C:\271_icol.dll
2013-02-08 15:03 . 2013-02-08 15:09 ——– d—–w- c:\documents and settings\Dell\Application Data\GlarySoft
2013-02-08 14:00 . 2013-02-08 14:18 ——– d—–w- c:\documents and settings\Dell\Incomplete
2013-02-08 13:59 . 2013-02-10 14:34 ——– d—–w- c:\documents and settings\Dell\Application Data\YouTubeFreeDownloader
2013-02-08 13:58 . 2013-02-14 21:31 ——– d—–w- c:\program files\YouTube Free Downloader
2013-02-08 13:31 . 2013-02-08 13:31 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Identities
2013-02-08 05:51 . 2013-02-08 05:51 ——– d—–w- c:\documents and settings\Dell\Application Data\FindeXer
2013-02-08 03:22 . 2013-02-08 03:22 153153 —-a-w- c:\windows\BricoPackUninst.cmd
2013-02-08 03:05 . 2013-02-08 03:05 ——– d—–w- c:\program files\RK Launcher
2013-02-08 03:04 . 2013-02-08 03:04 ——– d—–w- c:\documents and settings\Dell\Local Settings\Application Data\Stardock
2013-02-08 03:04 . 2013-02-09 15:47 ——– d—–w- c:\program files\MacSearch_v.1.4.3
2013-02-08 02:44 . 2013-02-08 03:22 7891 —-a-w- c:\windows\BricoPackFoldersDelete.cmd
2013-02-08 02:40 . 2013-02-08 02:40 ——– d—–w- c:\windows\BricoPacks
2013-02-07 12:39 . 2013-02-07 12:39 ——– d—–w- c:\documents and settings\Dell\Application Data\Creative
2013-02-06 21:15 . 2013-02-06 21:17 ——– d—–w- C:\110e7134daea3e1a009b
2013-02-06 20:32 . 2013-02-06 20:32 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2013-02-06 14:23 . 2013-02-19 01:46 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2013-02-06 14:23 . 2013-02-19 01:46 ——– d—–w- c:\program files\AVAST Software
2013-02-06 08:46 . 2013-02-06 08:46 ——– d—–w- C:\d635b693b6fbd2f741cc4ebe31a705
2013-02-06 08:40 . 2013-02-06 22:25 ——– d—–w- c:\windows\system32\XPSViewer
2013-02-06 08:40 . 2013-02-06 08:40 ——– d—–w- c:\program files\MSBuild
2013-02-06 08:38 . 2013-02-06 08:38 ——– d—–w- c:\program files\Reference Assemblies
2013-02-06 08:37 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2013-02-06 08:36 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2013-02-06 08:36 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2013-02-06 08:36 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-18 13:12 . 2012-12-19 05:48 348160 —-a-w- c:\windows\system32\msvcr71.dll
2013-02-18 13:12 . 2012-12-19 05:48 499712 —-a-w- c:\windows\system32\msvcp71.dll
2013-02-10 16:19 . 2012-12-19 06:38 861088 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-02-10 16:19 . 2012-12-19 06:38 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-02-08 03:22 . 2006-02-28 12:00 218624 —-a-w- c:\windows\system32\uxtheme.dll
2013-01-26 03:55 . 2006-02-28 12:00 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-01-25 03:43 . 2013-01-25 03:43 35488 —-a-w- c:\windows\system32\cmdcsr.dll
2013-01-25 03:43 . 2013-01-25 03:43 354752 —-a-w- c:\windows\system32\guard32.dll
2013-01-25 03:42 . 2013-01-25 03:42 40656 —-a-w- c:\windows\system32\cmdkbd32.dll
2013-01-25 03:42 . 2013-01-25 03:42 263888 —-a-w- c:\windows\system32\cmdvrt32.dll
2013-01-17 06:28 . 2012-12-20 02:28 232336 ——w- c:\windows\system32\MpSigStub.exe
2013-01-17 00:51 . 2013-01-17 00:51 586728 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2013-01-17 00:51 . 2013-01-17 00:51 32824 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2013-01-17 00:51 . 2013-01-17 00:51 18536 —-a-w- c:\windows\system32\drivers\cmderd.sys
2013-01-07 01:19 . 2006-02-28 12:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37 . 2004-08-03 22:59 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20 . 2006-02-28 12:00 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2006-02-28 12:00 148992 —-a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2006-02-28 12:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2012-12-26 20:16 . 2006-02-28 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2012-12-26 20:16 . 2006-02-28 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2012-12-26 20:16 . 2006-02-28 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40 . 2006-02-28 12:00 385024 ——w- c:\windows\system32\html.iec
2012-12-16 12:23 . 2006-02-28 12:00 290560 —-a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 23:50 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-11-01 4763008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"Anvi Smart Defender"="c:\program files\Anvisoft\Anvi Smart Defender\ASDTray.exe" [2012-12-21 1434984]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotDeletingD3137]
del [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-02-28 22:32 166424 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotDeletingB61]
2006-02-28 12:00 50620 —-a-w- c:\windows\system32\command.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MBAMService"=2 (0x2)
"MBAMScheduler"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2/4/2013 5:51 PM 13560]
R1 asdrm;asdrm;c:\windows\system32\drivers\asdrm.sys [2/19/2013 7:43 PM 16208]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2/18/2013 8:51 PM 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/18/2013 8:51 PM 361032]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [7/11/2012 1:54 PM 116608]
R2 asdrs;AntiMalware Host-based Intrusion Prevention System;c:\windows\system32\drivers\asdrs.sys [2/19/2013 7:43 PM 22864]
R2 asdsrv;Anvi Smart Defender Realtime Guard Service;c:\program files\Anvisoft\Anvi Smart Defender\ASDSrv.exe [12/20/2012 9:43 PM 735592]
R2 asdws;AnviSmartDefender Web Guard;c:\windows\system32\drivers\asdws.sys [2/19/2013 7:43 PM 14160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/18/2013 8:51 PM 21256]
R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2/26/2013 10:10 PM 35144]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [3/28/2011 9:22 AM 1034240]
S4 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys –> c:\windows\system32\drivers\SBREDrv.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MBAMCHAMELEON
.
Contents of the 'Scheduled Tasks' folder
.
2013-02-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-26 15:47]
.
2013-02-27 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-02-19 23:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uLocal Page = about:blank
mStart Page = about:blank
mWindow Title = Microsoft Internet Explorer
mLocal Page = about:blank
uSearchAssistant = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms}
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
Trusted Zone: dell.com
TCP: DhcpNameServer = 10.0.0.1
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-RunOnce-Z1 - c:\documents and settings\Dell\Local Settings\Application Data\Opera\Opera\temporary_downloads\mbar-1.01.0.1020\mbar\mbar.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-27 09:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD2500BPVT-75JJ5T0 rev.03.01A03 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A485864
user & kernel MBR OK
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(712)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2013-02-27 09:58:31
ComboFix-quarantined-files.txt 2013-02-27 14:58
ComboFix2.txt 2013-02-12 13:09
ComboFix3.txt 2013-02-10 15:57
.
Pre-Run: 236,009,160,704 bytes free
Post-Run: 236,043,522,048 bytes free
.
- - End Of File - - E61EDA7C10C15515A9FB2B46B84E9783
OK…Next:

Please download AdwCleaner from here and save it on your Desktop.

AdwCleaner is a reliable removal tool for Adware, Foistware, toolbars and potentially unwanted programs.

AdwCleaner is a tool that deletes :
· Adwares (software ads)
· PUP/LPI (Potentially Undesirable Program)
· Toolbars
· Hijacker (Hijack of the browser's homepage)

It works with a Search and Deletion methode. It can be easily uninstalled using the "Uninstall" mode.


  • Right-click on adwcleaner.exe and select Run As Administrator (for XP just double click) to launch the application.
  • Now click on the Search tab.
  • Please post the contents of the log-file created in your next post.

Note: The log can also be located at C:\ >> AdwCleaner[XX].txt >> XX <– Denotes the number of times the application has been ran, so in this should be something like R1.

Note:
Please look over what was found……especially any folders, we're going to permanently delete it all in the next step….if there's something you may want to keep…please let me know and I'll explain to why it shouldn't be on your system.

MrC
# AdwCleaner v2.113 - Logfile created 02/27/2013 at 11:19:01 # Updated 23/02/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Dell - DAVID # Boot Mode : Normal # Running from : C:\Documents and Settings\Dell\desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** File Found : C:\Program Files\Mozilla Firefox\defaults\pref\all-iminent.js Folder Found : C:\Documents and Settings\All Users\Application Data\APN Folder Found : C:\Documents and Settings\All Users\Application Data\blekko toolbars Folder Found : C:\Documents and Settings\All Users\Application Data\Tarma Installer Folder Found : C:\Documents and Settings\Dell\Application Data\adawaretb Folder Found : C:\Documents and Settings\Dell\Application Data\SearchYa Folder Found : C:\Documents and Settings\Dell\Application Data\SwvUpdater Folder Found : C:\Documents and Settings\Dell\Local Settings\Application Data\Conduit Folder Found : C:\Documents and Settings\Dell\Local Settings\Application Data\Coupon Companion Plugin Folder Found : C:\Program Files\adawaretb Folder Found : C:\Program Files\Conduit Folder Found : C:\Program Files\VisualBee_V.1 Folder Found : C:\Program Files\Zoom Downloader ***** [Registry] ***** Key Found : HKCU\Software\5a2d78dbc6fb849 Key Found : HKCU\Software\AppDataLow\Software\Search Settings Key Found : HKCU\Software\ConduitSearchScopes Key Found : HKCU\Software\Iminent Key Found : HKCU\Software\InstallCore Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{05478A66-EDB6-4A22-A870-A5987F80A7DA} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Found : HKCU\Software\searchya Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\VisualBee_V.1 Key Found : HKCU\Software\wecarereminder Key Found : HKLM\SOFTWARE\Classes\AppID\{15F6BCB7-BB0F-4A66-8762-4765B05597EB} Key Found : HKLM\SOFTWARE\Classes\AppID\{1973277F-87B0-4EA3-9ED2-470A91D284CF} Key Found : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Found : HKLM\SOFTWARE\Classes\esrv.searchyaESrvc Key Found : HKLM\SOFTWARE\Classes\esrv.searchyaESrvc.1 Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\Prod.cap Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3281023 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{15F6BCB7-BB0F-4A66-8762-4765B05597EB} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\Software\Conduit Key Found : HKLM\Software\Iminent Key Found : HKLM\Software\InstallCore Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{819DC4CA-4FFF-4C2E-800D-F346471D99BC} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 Key Found : HKLM\Software\VisualBee_V.1 Key Found : HKU\S-1-5-21-746137067-1958367476-725345543-1003\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms} [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms} -\\ Opera v12.14.1738.0 File : C:\Documents and Settings\Dell\Application Data\Opera\Opera\operaprefs.ini [OK] File is clean. ************************* AdwCleaner[R1].txt - [5517 octets] - [27/02/2013 11:19:01] ########## EOF - C:\AdwCleaner[R1].txt - [5577 octets] ##########
Please create a new system restore point before continuing.

Lots of adware found….lets clear it out…..
  • Please re-run AdwCleaner
  • Click on Delete button.
  • Confirm each time with OK if asked.
  • Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.

Note: You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.

Then……

Lets check your computers security before you go and we have a little cleanup to do also:

Download Security Check by screen317 from HERE or HERE.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt.
  • Please Post the contents of that document.
  • Do Not Attach It!!!
MrC
its amazing how much garbage really gets in there! wow! # AdwCleaner v2.113 - Logfile created 02/27/2013 at 13:30:52 # Updated 23/02/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : Dell - DAVID # Boot Mode : Normal # Running from : C:\Documents and Settings\Dell\desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\all-iminent.js Folder Deleted : C:\Documents and Settings\All Users\Application Data\APN Folder Deleted : C:\Documents and Settings\All Users\Application Data\blekko toolbars Folder Deleted : C:\Documents and Settings\All Users\Application Data\Tarma Installer Folder Deleted : C:\Documents and Settings\Dell\Application Data\adawaretb Folder Deleted : C:\Documents and Settings\Dell\Application Data\SearchYa Folder Deleted : C:\Documents and Settings\Dell\Application Data\SwvUpdater Folder Deleted : C:\Documents and Settings\Dell\Local Settings\Application Data\Conduit Folder Deleted : C:\Documents and Settings\Dell\Local Settings\Application Data\Coupon Companion Plugin Folder Deleted : C:\Program Files\adawaretb Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Program Files\VisualBee_V.1 Folder Deleted : C:\Program Files\Zoom Downloader ***** [Registry] ***** Key Deleted : HKCU\Software\5a2d78dbc6fb849 Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings Key Deleted : HKCU\Software\ConduitSearchScopes Key Deleted : HKCU\Software\Iminent Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{05478A66-EDB6-4A22-A870-A5987F80A7DA} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKCU\Software\searchya Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\VisualBee_V.1 Key Deleted : HKCU\Software\wecarereminder Key Deleted : HKLM\SOFTWARE\Classes\AppID\{15F6BCB7-BB0F-4A66-8762-4765B05597EB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1973277F-87B0-4EA3-9ED2-470A91D284CF} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Deleted : HKLM\SOFTWARE\Classes\esrv.searchyaESrvc Key Deleted : HKLM\SOFTWARE\Classes\esrv.searchyaESrvc.1 Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3281023 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{15F6BCB7-BB0F-4A66-8762-4765B05597EB} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\Iminent Key Deleted : HKLM\Software\InstallCore Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{819DC4CA-4FFF-4C2E-800D-F346471D99BC} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 Key Deleted : HKLM\Software\VisualBee_V.1 ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms} –> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=79be7b8c-190f-4716-94cd-c72af77e0462&searchtype=ds&q={searchTerms} –> hxxp://www.google.com -\\ Opera v12.14.1738.0 File : C:\Documents and Settings\Dell\Application Data\Opera\Opera\operaprefs.ini [OK] File is clean. ************************* AdwCleaner[R1].txt - [5646 octets] - [27/02/2013 11:19:01] AdwCleaner[S1].txt - [5612 octets] - [27/02/2013 13:30:52] ########## EOF - C:\AdwCleaner[S1].txt - [5672 octets] ##########
Please forgive me if I posted the wrong thing. If I did just let me know how to fix it.



Results of screen317's Security Check version 0.99.60
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Please wait while WMIC compiles updated MOF files.d
i
s
p
l
a
y
N
a
m
e
ECHO is off.
a
v
a
s
t
!
ECHO is off.
A
n
t
i
v
i
r
u
s
ECHO is off.
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
SUPERAntiSpyware
Malwarebytes Anti-Malware version 1.70.0.1100
CCleaner
Adobe Flash Player 11.6.602.171
Google Chrome 22.0.1229.95
````````Process Check: objlist.exe by Laurent````````
Anvisoft Anvi Smart Defender ASDSrv.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 5%
````````````````````End of Log``````````````````````

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI