Win32: Malware-gen [Solved]
51 min read
Can you post the Attach.txt
Please remove any usb or external drives from the computer before you run this scan!
Please download and run RogueKiller to your desktop.
RogueKiller<—use this one for 64 bit systems
Quit all running programs.
For Windows XP, double-click to start.
For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
Click Scan to scan the system.
When the scan completes > Close out the program > Don't Fix anything!
Don't run any other options, they're not all bad!!!!!!!
Post back the report which should be located on your desktop.
(please don't put logs in code or quotes)
P2P Warning:
If you're using Peer 2 Peer software such as uTorrent or similar you must either fully uninstall it or completely disable it from running while being assisted here.
Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.
MrC
<+>Please don't run any other scans, download, install or uninstall any programs while I'm working with you.
<+>Please stick with me until I give you the "all clear".
<+>The removal of malware isn't instantaneous, please be patient.
——->Your topic will be closed if you haven't replied within 3 days!<——–
(If I don't respond within 24 hours, please send me a PM)
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 5/26/2007 4:19:35 PM
System Uptime: 3/2/2013 4:31:51 PM (1 hours ago)
.
Motherboard: Intel Corporation | | DP965LV
Processor: Intel® Core™2 CPU 6300 @ 1.86GHz | | 1864/266mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 293 GiB total, 265.667 GiB free.
D: is FIXED (FAT32) - 5 GiB total, 1.732 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (FAT32) - 233 GiB total, 232.407 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description:
Device ID: ROOT\LEGACY_SASKUTIL\0000
Manufacturer:
Name:
PNP Device ID: ROOT\LEGACY_SASKUTIL\0000
Service:
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Privacyware Filter Miniport
Device ID: ROOT\PWIPF6MP\0001
Manufacturer: Privacyware
Name: Privacyware Filter Miniport #2
PNP Device ID: ROOT\PWIPF6MP\0001
Service: pwipf6
.
==== System Restore Points ===================
.
RP690: 2/28/2013 7:04:51 AM - Installed Privatefirewall 7.0
RP691: 2/28/2013 7:04:51 AM - System Checkpoint
RP692: 2/28/2013 7:04:51 AM - Revo Uninstaller's restore point - CCleaner
RP693: 2/28/2013 7:04:51 AM - Revo Uninstaller's restore point - CCleaner
RP694: 2/28/2013 7:04:51 AM - Revo Uninstaller's restore point - Privatefirewall 7.0
RP695: 2/28/2013 7:04:51 AM - Removed Privatefirewall 7.0
RP696: 2/28/2013 7:04:51 AM - Installed Privatefirewall 7.0
RP697: 2/28/2013 7:04:51 AM - Revo Uninstaller's restore point - Sandboxie 3.76 (32-bit)
RP698: 2/28/2013 7:04:51 AM - Revo Uninstaller's restore point - Privatefirewall 7.0
RP699: 2/28/2013 7:04:51 AM - Removed Privatefirewall 7.0
RP700: 2/28/2013 7:04:50 AM - Software Distribution Service 3.0
RP701: 2/28/2013 7:04:50 AM - Online Armor installation
RP702: 2/27/2013 11:05:55 PM - Revo Uninstaller's restore point - Online Armor 6.0
RP703: 2/28/2013 11:57:58 AM - Revo Uninstaller's restore point - ZoneAlarm Free Firewall
RP704: 3/1/2013 2:03:09 PM - Installed Privatefirewall 7.0
RP705: 3/1/2013 2:28:12 PM - Revo Uninstaller's restore point - Privatefirewall 7.0
RP706: 3/1/2013 2:28:56 PM - Removed Privatefirewall 7.0
RP707: 3/1/2013 5:15:33 PM - Agnitum Outpost Security Suite Free Restore Point: install
RP708: 3/1/2013 5:19:04 PM - Revo Uninstaller's restore point - Outpost Security Suite 7.1.1
RP709: 3/1/2013 5:19:12 PM - Agnitum Outpost Security Suite Free Restore Point: uninstall
RP710: 3/1/2013 9:20:15 PM - Revo Uninstaller's restore point - Windows7FirewallControl Free XP Edition (32/64) 5.1.7.69
RP711: 3/2/2013 8:50:17 AM - Revo Uninstaller's restore point - SpywareBlaster 4.6
RP712: 3/2/2013 1:38:28 PM - Agnitum Outpost Firewall Restore Point: install
RP713: 3/2/2013 1:57:46 PM - Revo Uninstaller's restore point - WinPatrol
RP714: 3/2/2013 1:58:57 PM - Revo Uninstaller's restore point - Outpost Firewall 2009
RP715: 3/2/2013 1:59:09 PM - Agnitum Outpost Firewall Restore Point: uninstall
RP716: 3/2/2013 2:00:55 PM - Online Armor installation
.
==== Installed Programs ======================
.
Adobe Flash Player 11 ActiveX
aioprnt
aioscnnr
Apple Application Support
ArcSoft PhotoStudio 5.5
Auslogics Disk Defrag
avast! Free Antivirus
Belkin Setup and Router Monitor
Bonjour
Bonjour Print Services
C4USelfUpdater
CCleaner
center
Citrix Authentication Manager
Citrix Receiver
Citrix Receiver (HDX Flash Redirection)
Citrix Receiver Inside
Citrix Receiver(Aero)
Citrix Receiver(DV)
Citrix Receiver(USB)
Critical Update for Windows Media Player 11 (KB959772)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
eReg
ERUNT 1.1j
essentials
Foxit Reader
Google Chrome
Google Update Helper
HitmanPro 3.7
HostsMan 3.2.73
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB2756822)
Hotfix for Windows XP (KB2779562)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Kodak AIO Printer
KODAK AiO Software
ksDIP
Logitech SetPoint 6.32
Malwarebytes Anti-Malware version 1.70.0.1100
Microsoft .NET Framework 1.0 Hotfix (KB2604042)
Microsoft .NET Framework 1.0 Hotfix (KB2656378)
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.0 Security Update (KB2698035)
Microsoft .NET Framework 1.0 Security Update (KB2742607)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2698023)
Microsoft .NET Framework 1.1 Security Update (KB2742597)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Software Update for Web Folders (English) 14
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2721691)
MSXML 4.0 SP3 Parser (KB2758694)
MSXML 6.0 Parser
MyITLab ActiveX Installer 2, 9, 8, 65535
ocr
Online Armor 6.0
Online Plug-in
PreReq
PrintMaster Platinum 18
QuickTime
Revo Uninstaller 1.94
Secunia PSI (3.0.0.4001)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589337) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition
Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition
Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition
Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB2675157)
Security Update for Windows Internet Explorer 8 (KB2699988)
Security Update for Windows Internet Explorer 8 (KB2722913)
Security Update for Windows Internet Explorer 8 (KB2744842)
Security Update for Windows Internet Explorer 8 (KB2761465)
Security Update for Windows Internet Explorer 8 (KB2792100)
Security Update for Windows Internet Explorer 8 (KB2797052)
Security Update for Windows Internet Explorer 8 (KB2799329)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2659262)
Security Update for Windows XP (KB2660465)
Security Update for Windows XP (KB2661637)
Security Update for Windows XP (KB2676562)
Security Update for Windows XP (KB2685939)
Security Update for Windows XP (KB2686509)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2695962)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2705219)
Security Update for Windows XP (KB2707511)
Security Update for Windows XP (KB2709162)
Security Update for Windows XP (KB2712808)
Security Update for Windows XP (KB2718523)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB2723135)
Security Update for Windows XP (KB2724197)
Security Update for Windows XP (KB2727528)
Security Update for Windows XP (KB2731847)
Security Update for Windows XP (KB2753842-v2)
Security Update for Windows XP (KB2753842)
Security Update for Windows XP (KB2757638)
Security Update for Windows XP (KB2758857)
Security Update for Windows XP (KB2761226)
Security Update for Windows XP (KB2770660)
Security Update for Windows XP (KB2778344)
Security Update for Windows XP (KB2779030)
Security Update for Windows XP (KB2780091)
Security Update for Windows XP (KB2799494)
Security Update for Windows XP (KB2802968)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
SEGA Genesis Classics
Self-service Plug-in
SpywareBlaster 5.0
swMSM
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2641690)
Update for Windows XP (KB2661254-v2)
Update for Windows XP (KB2718704)
Update for Windows XP (KB2736233)
Update for Windows XP (KB2749655)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
VLC media player 2.0.5
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Player Firefox Plugin
Windows XP Media Center Edition 2005 KB2619340
Windows XP Media Center Edition 2005 KB2628259
Windows XP Service Pack 3
ZoneAlarm LTD Toolbar
.
==== Event Viewer Messages From Past Week ========
.
3/2/2013 2:16:43 PM, error: Service Control Manager [7034] - The Kodak AiO Status Monitor Service service terminated unexpectedly. It has done this 1 time(s).
3/2/2013 2:16:36 PM, error: Service Control Manager [7034] - The Kodak AiO Network Discovery Service service terminated unexpectedly. It has done this 1 time(s).
3/2/2013 1:49:44 PM, error: Server [2505] - The server could not bind to the transport \Device\NetbiosSmb because another computer on the network has the same name. The server could not start.
2/27/2013 7:00:05 AM, error: Service Control Manager [7022] - The Intel® Software Services Manager service hung on starting.
2/27/2013 7:00:05 AM, error: Service Control Manager [7001] - The Intel® Viiv™ Media Server service depends on the Intel® Software Services Manager service which failed to start because of the following error: After starting, the service hung in a start-pending state.
2/27/2013 10:54:19 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the ELService service.
2/27/2013 1:19:36 PM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001676DFE735. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
2/27/2013 1:12:41 PM, error: LEqdUsb [12293] - An attempt to clear an error on the USB bus failed.
2/26/2013 10:04:50 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
2/25/2013 11:48:51 AM, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/25/2013 11:48:43 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.
2/25/2013 11:48:02 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Vsdatant
2/25/2013 11:47:55 AM, error: Service Control Manager [7000] - The Intel® Viiv™ Media Server service failed to start due to the following error: The system cannot find the path specified.
2/25/2013 11:47:51 AM, error: Service Control Manager [7001] - The TrueVector Internet Monitor service depends on the Vsdatant service which failed to start because of the following error: A device attached to the system is not functioning.
2/25/2013 11:47:51 AM, error: Service Control Manager [7000] - The Logitech Beep Suppression Driver service failed to start due to the following error: A device attached to the system is not functioning.
2/24/2013 5:31:36 PM, error: Service Control Manager [7022] - The Intel® Quick Resume technology service hung on starting.
2/24/2013 11:05:01 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the NVSvc service.
.
==== End Of File ===========================
RogueKiller V8.5.2 [Feb 23 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/
Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Owner [Admin rights]
Mode : Scan – Date : 03/03/2013 08:01:33
| ARK || FAK || MBR |
¤¤¤ Bad processes : 4 ¤¤¤
[SUSP PATH] arservice.exe – C:\WINDOWS\arservice.exe [7] -> KILLED [TermProc]
[SUSP PATH] arpwrmsg.exe – C:\WINDOWS\arpwrmsg.exe [7] -> KILLED [TermProc]
[SUSP PATH] CNYHKey.exe – C:\WINDOWS\CNYHKey.exe [-] -> KILLED [TermProc]
[SUSP PATH] mHotkey.exe – C:\WINDOWS\mHotkey.exe [-] -> KILLED [TermProc]
¤¤¤ Registry Entries : 3 ¤¤¤
[DNS] HKLM\[…]\ControlSet001\Services\Tcpip\Interfaces\{BB122B61-EA9A-4AD1-994F-C5627F64764E} : NameServer (198.153.192.50,198.153.194.50) -> FOUND
[DNS] HKLM\[…]\ControlSet003\Services\Tcpip\Interfaces\{BB122B61-EA9A-4AD1-994F-C5627F64764E} : NameServer (198.153.192.50,198.153.194.50) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
::1 localhost #[IPv6]
127.0.0.1 fr.a2dfp.net
127.0.0.1 m.fr.a2dfp.net
127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 abcstats.com
127.0.0.1 a.abv.bg
127.0.0.1 adserver.abv.bg
127.0.0.1 adv.abv.bg
127.0.0.1 bimg.abv.bg
127.0.0.1 ca.abv.bg
127.0.0.1 www2.a-counter.kiev.ua
127.0.0.1 track.acclaimnetwork.com
127.0.0.1 accuserveadsystem.com
127.0.0.1 www.accuserveadsystem.com
127.0.0.1 achmedia.com
127.0.0.1 aconti.net
127.0.0.1 secure.aconti.net
127.0.0.1 www.aconti.net #[Dialer.Aconti]
[…]
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST3320833AS +++++
— User —
[MBR] 4f8c98c40d1f9ac01490450f76ccb4a3
[BSP] db63615aa66f3fdfa2e467ad7beb91fe : Legit.B MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 11197305 | Size: 299767 Mo
1 - [XXXXXX] FAT32 (0x0b) [VISIBLE] Offset (sectors): 63 | Size: 5467 Mo
User = LL1 … OK!
User = LL2 … OK!
Finished : << RKreport[1]_S_03032013_02d0801.txt >>
RKreport[1]_S_03032013_02d0801.txt
Download Malwarebytes Anti-Rootkit from HERE
- Unzip the contents to a folder in a convenient location.
- Open the folder where the contents were unzipped and run mbar.exe
- Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
- Click on the Cleanup button to remove any threats and reboot if prompted to do so.
- Wait while the system shuts down and the cleanup process is performed.
- Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
- When done, please post the two logs produced they will be in the MBAR folder….. mbar-log.txt and system-log.txt
~~~~~~~~~~~~~~~~~~~~~~~
Note:
If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
Internet access
Windows Update
Windows Firewall
If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot.
Verify that your system is now functioning normally.
MrC
Please download and run ComboFix.
The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.
Please visit this webpage for download links, and instructions for running ComboFix
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Information on disabling your malware programs can be found Here.
Make sure you run ComboFix from your desktop.
Give it at least 30-45 minutes to finish if needed.
Please include the C:\ComboFix.txt in your next reply for further review.
———->NOTE<———-
If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix….please reboot the computer, this should resolve the problem. You may have to do this several times if needed.MrC
1st run: everything went fine, combofix restarted to only then freeze up when saying please wait, no log.
2nd run: everything went fine, computer rebooted; but, this time Online armor came on and blocked combofix from running. I had Online armor disabled prior before restart. Once again, no log.
3rd time everything went fine and a log was produced.
ComboFix 13-03-03.01 - Owner 03/03/2013 15:40:43.15.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2030.1465 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Online Armor Firewall *Disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\docume~1\OWNER~1.AMA\LOCALS~1\Temp\1.tmp\F_IN_BOX.dll
c:\documents and settings\Owner.amarlowe\Local Settings\Temp\1.tmp\F_IN_BOX.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-02-03 to 2013-03-03 )))))))))))))))))))))))))))))))
.
.
2013-03-02 19:01 . 2013-03-02 19:07 ——– d—–w- c:\documents and settings\All Users\Application Data\OnlineArmor
2013-03-02 19:01 . 2013-03-02 19:01 ——– d—–w- c:\documents and settings\Owner.amarlowe\Application Data\OnlineArmor
2013-03-02 19:00 . 2012-10-02 20:03 44992 —-a-w- c:\windows\system32\drivers\oahlp32.sys
2013-03-02 19:00 . 2012-10-02 20:02 31920 —-a-w- c:\windows\system32\drivers\OAnet.sys
2013-03-02 19:00 . 2012-10-02 20:02 27648 —-a-w- c:\windows\system32\drivers\OAmon.sys
2013-03-02 19:00 . 2012-10-02 20:02 208320 —-a-w- c:\windows\system32\drivers\OADriver.sys
2013-03-02 19:00 . 2013-03-03 20:36 ——– d—–w- c:\program files\Online Armor
2013-03-02 16:43 . 2013-03-02 16:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Licenses
2013-03-02 16:43 . 2013-03-02 16:45 ——– d—–w- c:\program files\SpywareBlaster
2013-02-26 14:07 . 2013-02-26 14:07 ——– d—–w- c:\program files\CCleaner
2013-02-20 10:55 . 2013-02-20 10:56 ——– d—–w- c:\documents and settings\Owner.amarlowe\Local Settings\Application Data\Google
2013-02-20 10:55 . 2013-02-20 10:56 ——– d—–w- c:\program files\Google
2013-02-20 04:10 . 2013-02-20 04:10 ——– d—–w- c:\windows\system32\wbem\Repository
2013-02-15 12:31 . 2013-02-15 12:31 ——– d—–w- c:\documents and settings\Owner.amarlowe\Application Data\Foxit Software
2013-02-15 12:31 . 2013-02-15 12:31 ——– d—–w- c:\program files\Foxit Software
2013-02-14 11:59 . 2013-02-26 22:11 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-14 11:59 . 2013-02-26 22:11 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-04 21:56 . 2012-10-30 23:51 361032 —-a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-04 21:56 . 2012-10-30 23:51 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-04 21:56 . 2012-10-30 23:51 738504 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-04 21:56 . 2012-10-30 23:51 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-04 21:56 . 2012-10-30 23:51 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2013-02-04 21:56 . 2012-10-30 23:51 97608 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2013-02-04 21:56 . 2012-10-30 23:51 89752 —-a-w- c:\windows\system32\drivers\aswmon.sys
2013-02-04 21:56 . 2012-10-30 23:51 25256 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2013-02-04 21:56 . 2012-10-30 23:51 41224 —-a-w- c:\windows\avastSS.scr
2013-02-04 21:56 . 2012-10-30 23:50 227648 —-a-w- c:\windows\system32\aswBoot.exe
2013-02-04 21:55 . 2013-02-04 21:55 ——– d—–w- c:\program files\AVAST Software
2013-02-04 21:55 . 2013-02-04 21:55 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-26 03:55 . 2006-06-17 09:23 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-01-09 21:00 . 2011-12-25 20:16 16400 —-a-w- c:\windows\system32\drivers\LNonPnP.sys
2013-01-07 01:19 . 2006-06-17 09:23 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37 . 2004-08-04 05:59 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20 . 2006-06-17 09:23 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2006-06-17 09:23 1292288 —-a-w- c:\windows\system32\quartz.dll
2012-12-26 20:16 . 2006-06-17 09:23 916480 —-a-w- c:\windows\system32\wininet.dll
2012-12-26 20:16 . 2006-06-17 09:23 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-12-26 20:16 . 2006-06-17 09:23 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40 . 2006-06-17 09:23 385024 —-a-w- c:\windows\system32\html.iec
2012-12-16 12:23 . 2006-06-17 09:23 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-12-14 21:49 . 2009-03-28 21:04 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[7] 2004-08-10 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys
.
c:\windows\System32\drivers\beep.sys … is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 23:50 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-07-13 9134080]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 77312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-05 7393280]
"InstaLAN"="c:\program files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2010-07-28 1485208]
"Conime"="c:\windows\system32\conime.exe" [2008-04-14 27648]
"showwnd"="showwnd.exe" [2003-09-19 36864]
"ledpointer"="CNYHKey.exe" [2004-03-03 5576704]
"CHotkey"="mHotkey.exe" [2004-12-09 550912]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1387288]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]
"EKStatusMonitor"="c:\program files\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe" [2012-10-15 2844608]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2012-10-08 2804224]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\redirector.exe" [2012-05-23 130232]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"@OnlineArmor GUI"="c:\program files\Online Armor\oaui.exe" [2012-10-02 2415104]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-12-21 519584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"KeyScrambler"="c:\program files\KeyScrambler\getting_started.html" [X]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
"KodakHomeCenter"="c:\program files\Kodak\AiO\Center\AiOHomeCenter.exe" [2012-10-19 2235840]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2012-9-24 573536]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2012-10-02 366440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2011-09-27 19:03 66328 —-a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon]
2005-12-10 01:44 139264 —-a-w- c:\program files\Digital Media Reader\readericon45G.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Kodak\\AiO\\Center\\AiOHomeCenter.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\Kodak.Statistics.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\NetworkPrinterDiscovery.exe"=
"c:\\Program Files\\Kodak\\AiO\\Firmware\\KodakAiOUpdater.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kodak\\Installer\\Setup.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:UDP"= 5353:UDP:*:Disabled:Bonjour Port 5353
"9322:TCP"= 9322:TCP:*:Disabled:EKDiscovery
"135:TCP"= 135:TCP:DCOM(135)
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2/4/2013 4:56 PM 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/4/2013 4:56 PM 361032]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [3/19/2012 9:18 AM 67960]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [3/2/2013 2:00 PM 208320]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [3/2/2013 2:00 PM 27648]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [3/2/2013 2:00 PM 31920]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/4/2013 4:56 PM 21256]
R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\EKAiOHostService.exe [10/19/2012 1:51 PM 395200]
R2 Kodak AiO Status Monitor Service;Kodak AiO Status Monitor Service;c:\program files\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe [10/15/2012 10:58 AM 779200]
R2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [3/2/2013 2:00 PM 216072]
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\psia.exe [9/24/2012 7:46 AM 1328736]
R2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [9/24/2012 7:46 AM 656480]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\drivers\LEqdUsb.sys [3/18/2010 4:01 AM 42648]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\drivers\LHidEqd.sys [3/18/2010 4:01 AM 12184]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [12/16/2011 9:19 AM 15544]
S1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [3/2/2013 2:00 PM 44992]
S2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [12/25/2011 3:15 PM 12184]
S2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [3/2/2013 2:00 PM 4463864]
S3 cpuz130;cpuz130;\??\c:\docume~1\OWNER~1.AMA\LOCALS~1\Temp\cpuz130\cpuz_x32.sys –> c:\docume~1\OWNER~1.AMA\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 rkhdrv40;Rootkit Unhooker Driver; [x]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-02-22 02:05 1629648 —-a-w- c:\program files\Google\Chrome\Application\25.0.1364.97\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-14 22:11]
.
2013-03-03 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-02-04 23:50]
.
2013-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-20 10:55]
.
2013-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-20 10:55]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
Trusted Zone: devry.edu\lab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{BB122B61-EA9A-4AD1-994F-C5627F64764E}: NameServer = 198.153.192.50,198.153.194.50
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-03-03 15:46
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-534591739-3740957444-4262820010-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Opera.HTML\DefaultIcon]
@DACL=(02 0000)
@="\"c:\\Program Files\\Opera\\Opera.exe\",1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(604)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
- - - - - - - > 'explorer.exe'(4468)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2013-03-03 15:50:07
ComboFix-quarantined-files.txt 2013-03-03 20:50
.
Pre-Run: 285,246,054,400 bytes free
Post-Run: 285,189,152,768 bytes free
.
- - End Of File - - 55F059705EE36FB293D29C4F55C58A54
Using ComboFix……
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
4. If ComboFix wants to update…..please allow it to.
FCopy::
c:\windows\system32\dllcache\beep.sys | c:\windows\System32\drivers\beep.sys
ClearJavaCache::
Save this as CFScript.txt, in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.
After reboot, (in case it asks to reboot)……
Please provide the contents of the ComboFix log (C:\ComboFix.txt) in your next reply.
MrC
ComboFix 13-03-03.01 - Owner 03/03/2013 18:49:48.16.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2030.1337 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner.amarlowe\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Online Armor Firewall *Disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
————— FCopy —————
.
c:\windows\system32\dllcache\beep.sys –> c:\windows\System32\drivers\beep.sys
.
((((((((((((((((((((((((( Files Created from 2013-02-03 to 2013-03-03 )))))))))))))))))))))))))))))))
.
.
2013-03-03 23:49 . 2004-08-10 19:00 4224 -c–a-w- c:\windows\system32\dllcache\beep.sys
2013-03-02 19:01 . 2013-03-02 19:07 ——– d—–w- c:\documents and settings\All Users\Application Data\OnlineArmor
2013-03-02 19:01 . 2013-03-02 19:01 ——– d—–w- c:\documents and settings\Owner.amarlowe\Application Data\OnlineArmor
2013-03-02 19:00 . 2012-10-02 20:03 44992 —-a-w- c:\windows\system32\drivers\oahlp32.sys
2013-03-02 19:00 . 2012-10-02 20:02 31920 —-a-w- c:\windows\system32\drivers\OAnet.sys
2013-03-02 19:00 . 2012-10-02 20:02 27648 —-a-w- c:\windows\system32\drivers\OAmon.sys
2013-03-02 19:00 . 2012-10-02 20:02 208320 —-a-w- c:\windows\system32\drivers\OADriver.sys
2013-03-02 19:00 . 2013-03-03 20:36 ——– d—–w- c:\program files\Online Armor
2013-03-02 16:43 . 2013-03-02 16:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Licenses
2013-03-02 16:43 . 2013-03-02 16:45 ——– d—–w- c:\program files\SpywareBlaster
2013-02-26 14:07 . 2013-02-26 14:07 ——– d—–w- c:\program files\CCleaner
2013-02-20 10:55 . 2013-02-20 10:56 ——– d—–w- c:\documents and settings\Owner.amarlowe\Local Settings\Application Data\Google
2013-02-20 10:55 . 2013-02-20 10:56 ——– d—–w- c:\program files\Google
2013-02-20 04:10 . 2013-02-20 04:10 ——– d—–w- c:\windows\system32\wbem\Repository
2013-02-15 12:31 . 2013-02-15 12:31 ——– d—–w- c:\documents and settings\Owner.amarlowe\Application Data\Foxit Software
2013-02-15 12:31 . 2013-02-15 12:31 ——– d—–w- c:\program files\Foxit Software
2013-02-14 11:59 . 2013-02-26 22:11 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-14 11:59 . 2013-02-26 22:11 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-04 21:56 . 2012-10-30 23:51 361032 —-a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-04 21:56 . 2012-10-30 23:51 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-04 21:56 . 2012-10-30 23:51 738504 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-04 21:56 . 2012-10-30 23:51 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-04 21:56 . 2012-10-30 23:51 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2013-02-04 21:56 . 2012-10-30 23:51 97608 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2013-02-04 21:56 . 2012-10-30 23:51 89752 —-a-w- c:\windows\system32\drivers\aswmon.sys
2013-02-04 21:56 . 2012-10-30 23:51 25256 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2013-02-04 21:56 . 2012-10-30 23:51 41224 —-a-w- c:\windows\avastSS.scr
2013-02-04 21:56 . 2012-10-30 23:50 227648 —-a-w- c:\windows\system32\aswBoot.exe
2013-02-04 21:55 . 2013-02-04 21:55 ——– d—–w- c:\program files\AVAST Software
2013-02-04 21:55 . 2013-02-04 21:55 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-26 03:55 . 2006-06-17 09:23 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-01-09 21:00 . 2011-12-25 20:16 16400 —-a-w- c:\windows\system32\drivers\LNonPnP.sys
2013-01-07 01:19 . 2006-06-17 09:23 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37 . 2004-08-04 05:59 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20 . 2006-06-17 09:23 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2006-06-17 09:23 1292288 —-a-w- c:\windows\system32\quartz.dll
2012-12-26 20:16 . 2006-06-17 09:23 916480 —-a-w- c:\windows\system32\wininet.dll
2012-12-26 20:16 . 2006-06-17 09:23 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-12-26 20:16 . 2006-06-17 09:23 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40 . 2006-06-17 09:23 385024 —-a-w- c:\windows\system32\html.iec
2012-12-16 12:23 . 2006-06-17 09:23 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-12-14 21:49 . 2009-03-28 21:04 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 23:50 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-07-13 9134080]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 77312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-05 7393280]
"InstaLAN"="c:\program files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2010-07-28 1485208]
"Conime"="c:\windows\system32\conime.exe" [2008-04-14 27648]
"showwnd"="showwnd.exe" [2003-09-19 36864]
"ledpointer"="CNYHKey.exe" [2004-03-03 5576704]
"CHotkey"="mHotkey.exe" [2004-12-09 550912]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1387288]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]
"EKStatusMonitor"="c:\program files\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe" [2012-10-15 2844608]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2012-10-08 2804224]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\redirector.exe" [2012-05-23 130232]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"@OnlineArmor GUI"="c:\program files\Online Armor\oaui.exe" [2012-10-02 2415104]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-12-21 519584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"KeyScrambler"="c:\program files\KeyScrambler\getting_started.html" [X]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
"KodakHomeCenter"="c:\program files\Kodak\AiO\Center\AiOHomeCenter.exe" [2012-10-19 2235840]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2012-9-24 573536]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2012-10-02 366440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2011-09-27 19:03 66328 —-a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon]
2005-12-10 01:44 139264 —-a-w- c:\program files\Digital Media Reader\readericon45G.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Kodak\\AiO\\Center\\AiOHomeCenter.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\Kodak.Statistics.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\NetworkPrinterDiscovery.exe"=
"c:\\Program Files\\Kodak\\AiO\\Firmware\\KodakAiOUpdater.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kodak\\Installer\\Setup.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:UDP"= 5353:UDP:*:Disabled:Bonjour Port 5353
"9322:TCP"= 9322:TCP:*:Disabled:EKDiscovery
"135:TCP"= 135:TCP:DCOM(135)
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2/4/2013 4:56 PM 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/4/2013 4:56 PM 361032]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [3/19/2012 9:18 AM 67960]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [3/2/2013 2:00 PM 208320]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [3/2/2013 2:00 PM 27648]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [3/2/2013 2:00 PM 31920]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/4/2013 4:56 PM 21256]
R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\EKAiOHostService.exe [10/19/2012 1:51 PM 395200]
R2 Kodak AiO Status Monitor Service;Kodak AiO Status Monitor Service;c:\program files\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe [10/15/2012 10:58 AM 779200]
R2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [3/2/2013 2:00 PM 216072]
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\psia.exe [9/24/2012 7:46 AM 1328736]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\drivers\LEqdUsb.sys [3/18/2010 4:01 AM 42648]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\drivers\LHidEqd.sys [3/18/2010 4:01 AM 12184]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [12/16/2011 9:19 AM 15544]
S1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [3/2/2013 2:00 PM 44992]
S2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [12/25/2011 3:15 PM 12184]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [9/24/2012 7:46 AM 656480]
S2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [3/2/2013 2:00 PM 4463864]
S3 cpuz130;cpuz130;\??\c:\docume~1\OWNER~1.AMA\LOCALS~1\Temp\cpuz130\cpuz_x32.sys –> c:\docume~1\OWNER~1.AMA\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 rkhdrv40;Rootkit Unhooker Driver; [x]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-02-22 02:05 1629648 —-a-w- c:\program files\Google\Chrome\Application\25.0.1364.97\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-14 22:11]
.
2013-03-03 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-02-04 23:50]
.
2013-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-20 10:55]
.
2013-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-20 10:55]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
Trusted Zone: devry.edu\lab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{BB122B61-EA9A-4AD1-994F-C5627F64764E}: NameServer = 198.153.192.50,198.153.194.50
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-03-03 18:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-534591739-3740957444-4262820010-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Opera.HTML\DefaultIcon]
@DACL=(02 0000)
@="\"c:\\Program Files\\Opera\\Opera.exe\",1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(604)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
- - - - - - - > 'explorer.exe'(4760)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2013-03-03 18:58:11
ComboFix-quarantined-files.txt 2013-03-03 23:58
ComboFix2.txt 2013-03-03 20:50
.
Pre-Run: 285,300,486,144 bytes free
Post-Run: 285,274,775,552 bytes free
.
- - End Of File - - 07D322495FC9378D5B94BAEF2CA1DD75
Please download AdwCleaner from here and save it on your Desktop.
AdwCleaner is a reliable removal tool for Adware, Foistware, toolbars and potentially unwanted programs.
AdwCleaner is a tool that deletes :
· Adwares (software ads)
· PUP/LPI (Potentially Undesirable Program)
· Toolbars
· Hijacker (Hijack of the browser's homepage)
It works with a Search and Deletion methode. It can be easily uninstalled using the "Uninstall" mode.
- Right-click on adwcleaner.exe and select Run As Administrator (for XP just double click) to launch the application.
- Now click on the Search tab.
- Please post the contents of the log-file created in your next post.
Note: The log can also be located at C:\ >> AdwCleaner[XX].txt >> XX <– Denotes the number of times the application has been ran, so in this should be something like R1.
Note:
Please look over what was found……especially any folders, we're going to permanently delete it all in the next step….if there's something you may want to keep…please let me know and I'll explain to why it shouldn't be on your system.
MrC
Some adware found….lets clear it out…..
- Please re-run AdwCleaner
- Click on Delete button.
- Confirm each time with OK if asked.
- Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.
Note: You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
Then……
Lets check your computers security before you go and we have a little cleanup to do also:
Download Security Check by screen317 from HERE or HERE.
- Save it to your Desktop.
- Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
- A Notepad document should open automatically called checkup.txt.
- Please Post the contents of that document.
- Do Not Attach It!!!
# AdwCleaner v2.113 - Logfile created 03/04/2013 at 08:20:24
# Updated 23/02/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Owner - AMARLOWE
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Owner.amarlowe\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\END
***** [Registry] *****
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Billeo
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9DBB28C1-1925-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Viewpoint Manager
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\Viewpoint
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] Registry is clean.
-\\ Google Chrome v25.0.1364.97
*************************
AdwCleaner[R1].txt - [1381 octets] - [03/03/2013 23:05:43]
AdwCleaner[S1].txt - [1334 octets] - [04/03/2013 08:20:24]
########## EOF - C:\AdwCleaner[S1].txt - [1394 octets] ##########
With the SecurityCheck log it says avast was disabled. I disabled it so avast would not interfere with the program. I enabled avast after the scan was completed.
Results of screen317's Security Check version 0.99.60
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
avast! Antivirus
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
SpywareBlaster 5.0
Secunia PSI (3.0.0.4001)
HostsMan 3.2.73
Malwarebytes Anti-Malware version 1.70.0.1100
CCleaner
Google Chrome 24.0.1312.57
Google Chrome 25.0.1364.97
````````Process Check: objlist.exe by Laurent````````
Tall Emu Online Armor OAcat.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 7%
````````````````````End of Log``````````````````````
Please download and run OldChromeRemover.
@Windows Vista/Windows 7 users must use “Run As Administrator.”
@Do not use if you have multiple Chrome channels installed simultaneously!
Google Chrome 24.0.1312.57
Google Chrome 25.0.1364.97
—————————————–
A little clean up to do….
Please Uninstall ComboFix: (if you used it)
Press the Windows logo key + R to bring up the "run box"
Copy and paste next command in the field:
ComboFix /uninstall
Make sure there's a space between Combofix and /
[external image: Posted Image]
Then hit enter.
This will uninstall Combofix, delete its related folders and files, hide file extensions, hide the system/hidden files and clears System Restore cache and create new Restore point
(If that doesn't work…..you can simply rename ComboFix.exe to Uninstall.exe and double click it to complete the uninstall)
———————————
Please download OTL from one of the links below: (you may already have OTL on the system)
http://oldtimer.geekstogo.com/OTL.exe
http://oldtimer.geekstogo.com/OTL.com
http://www.itxassociates.com/OT-Tools/OTL.exe
Save it to your desktop.
Run OTL and hit the CleanUp button. (This will cleanup the tools and logs used including itself)
Any other programs or logs you can manually delete.
IE: RogueKiller.exe, RKreport.txt, RK_Quarantine folder, C:\FRST, MBAR, etc….AdwCleaner > just run the program and click uninstall.
——————————-
Any questions…please post back.
If you think I've helped you, please leave a comment > click on my avatar picture > click Profile Feed.
Take a look at My Preventive Maintenance to avoid being infected again.
Good Luck and Thanks for using the forum, MrC
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI