This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32/Small.CA [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got a message in the Action Center today that I have this virus/Trojan, whatever it is. I've never had a virus before and this scares me. Have run Spybot, Malwarebytes and SuperAntiSpyware, along with a few others, with no results. Here is the log from HijackThis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:29:12 PM, on 3/3/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal

Running processes:
C:Windowssystem32taskhost.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesMicrosoft Security Clientmsseces.exe
C:Program FilesCommon FilesJavaJava Updatejusched.exe
C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
C:Program FilesNVIDIA CorporationDisplaynvtray.exe
C:Windowssystem32wuauclt.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:UsersTACDownloadsHiJackThis.exe
C:Windowssystem32taskeng.exe
C:Windowssystem32DllHost.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://ieaddons.com/en/students
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://ieaddons.com/en/students
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…k/?LinkId=69157
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:Program FilesYouTube Downloader ToolbarIE4.6youtubedownloaderToolbarIE.dll (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: CrossriderApp0021804 - {11111111-1111-1111-1111-110211181104} - C:Program FilesCoupon Companion PluginCoupon Companion Plugin.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:ProgramDataRealRealPlayerBrowserRecordPluginIErpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:Program FilesMicrosoftSearch Enhancement PackSearch HelperSEPsearchhelperie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre7binssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:Program FilesWindows LiveCompanioncompanioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O2 - BHO: MSN Toolbar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:Program FilesMSN ToolbarPlatform4.0.0401.0npwinext.dll
O2 - BHO: WeCareReminder - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:ProgramDataWeCareReminderIEHelperv2.5.0.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre7binjp2ssv.dll
O2 - BHO: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:Program FilesYouTube Downloader ToolbarIE4.6youtubedownloaderToolbarIE.dll (file missing)
O3 - Toolbar: (no name) - {97C67AEE-274F-48BF-82B6-F1E0C39A4E3F} - (no file)
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: MSN Toolbar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:Program FilesMSN ToolbarPlatform4.0.0401.0npwinext.dll
O3 - Toolbar: YouTube Downloader Toolbar - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:Program FilesYouTube Downloader ToolbarIE4.6youtubedownloaderToolbarIE.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll
O4 - HKLM..Run: [Microsoft Default Manager] "C:Program FilesMicrosoftSearch Enhancement PackDefault ManagerDefMgr.exe" -resume
O4 - HKLM..Run: [JMB36X IDE Setup] C:WindowsRaidToolxInsIDE.exe
O4 - HKLM..Run: [MSC] "C:Program FilesMicrosoft Security Clientmsseces.exe" -hide -runkey
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesCommon FilesJavaJava Updatejusched.exe"
O4 - HKLM..Run: [Adobe ARM] "C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe"
O4 - HKLM..Run: [StereoLinksInstall] "C:Program FilesNVIDIA Corporation3D Visionnvstlink.exe" /install1
O4 - HKLM..Run: [SBAMTray] "C:Program FilesGFI SoftwareVIPRESBAMTray.exe"
O4 - HKCU..Run: [SUPERAntiSpyware] C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:PROGRA~1MICROS~4OFFICE11EXCEL.EXE/3000
O9 - Extra button: @C:Program FilesWindows LiveCompanioncompanionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:Program FilesWindows LiveCompanioncompanioncore.dll
O9 - Extra button: @C:Program FilesWindows LiveWriterWindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:Program FilesWindows LiveWriterWindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~4OFFICE11REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:program filescommon filesmicrosoft sharedwindows livewlidnsp.dll
O10 - Unknown file in Winsock LSP: c:program filescommon filesmicrosoft sharedwindows livewlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLMSystemCCSServicesTcpipParameters: Domain = Sacred
O17 - HKLMSystemCS1ServicesTcpipParameters: Domain = Sacred
O17 - HKLMSystemCS2ServicesTcpipParameters: Domain = Sacred
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:Program FilesSkypeToolbarsInternet Explorerskypeieplugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:Program FilesWindows LivePhoto GalleryAlbumDownloadProtocolHandler.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:Program FilesSUPERAntiSpywareSASCORE.EXE
O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:Program FilesAdobeElements Organizer 8.0PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:Program FilesCommon FilesAdobeARM1.0armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:Windowssystem32MacromedFlashFlashPlayerUpdateService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:Program FilesBonjourmDNSResponder.exe
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:Program FilesCommon FilesEPSONEPW!3 SSRPE_S50RP7.EXE
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1ca778e350221d0) (gupdate1ca778e350221d0) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:Program FilesGoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:Program FilesCommon FilesLogishrdLVMVFMLVPrcSrv.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:Program FilesMalwarebytes' Anti-Malwarembamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:Windowssystem32nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:Program FilesNVIDIA CorporationNVIDIA Update Coredaemonu.exe
O23 - Service: VIPRE Antivirus (SBAMSvc) - GFI Software - C:Program FilesGFI SoftwareVIPRESBAMSvc.exe
O23 - Service: SB Recovery Service (SBPIMSvc) - GFI Software - C:Program FilesGFI SoftwareVIPRESBPIMSvc.exe
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:PROGRA~1ENIGMA~1SPYHUN~1SH4SER~1.EXE

–
End of file - 10154 bytes


I also got an error message from HijackThis that it coldn't write everything to notepad, or something to that effect, so this may not be sufficient. TIA for any help with this.

P.S. I've hardly browsed the web at all lately and have only been to reputable sites, as well as downloaded updates to Java and Adobe. I have no idea where this came from.

As requested, here is the DDS file:

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 16:42:45.28 on Sun 03/03/2013
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.13.2
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3071.1579 [GMT -8:00]
.
AV: GFI Software VIPRE *Disabled/Outdated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: GFI Software VIPRE *Disabled/Outdated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ===============
.
C:Windowssystem32wininit.exe
C:Windowssystem32lsm.exe
C:Windowssystem32svchost.exe -k DcomLaunch
C:PROGRA~1ENIGMA~1SPYHUN~1SH4SER~1.EXE
C:Windowssystem32nvvsvc.exe
C:Windowssystem32svchost.exe -k RPCSS
C:Program FilesMicrosoft Security ClientMsMpEng.exe
C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted
C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted
C:Windowssystem32svchost.exe -k netsvcs
C:Windowssystem32svchost.exe -k LocalService
C:Windowssystem32svchost.exe -k NetworkService
C:WindowsSystem32spoolsv.exe
C:Windowssystem32svchost.exe -k LocalServiceNoNetwork
C:Program FilesSUPERAntiSpywareSASCORE.EXE
C:Program FilesCommon FilesAdobeARM1.0armsvc.exe
C:Program FilesCommon FilesEPSONEPW!3 SSRPE_S50RP7.EXE
C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation
C:Program FilesCommon FilesLogishrdLVMVFMLVPrcSrv.exe
C:Program FilesMalwarebytes' Anti-Malwarembamscheduler.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesMicrosoft SQL ServerMSSQL10.SQLEXPRESSMSSQLBinnsqlservr.exe
C:Program FilesGFI SoftwareVIPRESBPIMSvc.exe
C:Program FilesMicrosoftSearch Enhancement PackSeaPortSeaPort.exe
C:WindowsSystem32tcpsvcs.exe
C:WindowsSystem32snmp.exe
C:Program FilesMicrosoft SQL Server90Sharedsqlbrowser.exe
C:Program FilesMicrosoft SQL Server90Sharedsqlwriter.exe
C:Windowssystem32svchost.exe -k LocalSystemNetworkRestricted
C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE
C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exe
C:Program FilesMicrosoft Security ClientNisSrv.exe
C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted
C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe
C:Program FilesNVIDIA CorporationDisplaynvxdsync.exe
C:Windowssystem32nvvsvc.exe
C:Windowssystem32taskhost.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:Program FilesMicrosoft Security Clientmsseces.exe
C:Program FilesCommon FilesJavaJava Updatejusched.exe
C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe
C:Program FilesNVIDIA CorporationDisplaynvtray.exe
C:Windowssystem32SearchIndexer.exe
C:Program FilesWindows Media Playerwmpnetwk.exe
C:WindowsSystem32svchost.exe -k LocalServicePeerNet
C:Windowssystem32SearchProtocolHost.exe
C:Windowssystem32DllHost.exe
C:Program FilesNVIDIA CorporationNVIDIA Update Coredaemonu.exe
C:Windowssystem32wuauclt.exe
C:Program FilesESETESET Online ScannerOnlineScannerApp.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Windowssystem32SearchFilterHost.exe
C:Program FilesGoogleChromeApplicationchrome.exe
C:Windowssystem32DllHost.exe
C:Windowssystem32DllHost.exe
C:UsersTACDownloadsdds.scr
C:Windowssystem32conhost.exe
C:Windowssystem32wbemwmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://ieaddons.com/en/students
uDefault_Page_URL = hxxp://ieaddons.com/en/students
uURLSearchHooks: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:program filesyoutube downloader toolbarie

4.6youtubedownloaderToolbarIE.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Coupon Companion Plugin: {11111111-1111-1111-1111-110211181104} - c:program filescoupon companion pluginCoupon Companion Plugin.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:programdatarealrealplayer

browserrecordpluginierpbrowserrecordplugin.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:program filesmicrosoftsearch enhancement packsearch helperSEPsearchhelperie.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:program filesjavajre7binssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:program filescommon filesmicrosoft sharedwindows live

WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:program fileswindows livecompanioncompanioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:program filesgooglegoogle toolbarGoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:program filesmsn toolbarplatform4.0.0401.0npwinext.dll
BHO: WeCareReminder Class: {d824f0de-3d60-4f57-9eb1-66033ecd8abb} - c:programdatawecarereminderIEHelperv2.5.0.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:program filesjavajre7binjp2ssv.dll
BHO: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:program filesyoutube downloader toolbarie4.6youtubedownloaderToolbarIE.dll
TB: {97C67AEE-274F-48BF-82B6-F1E0C39A4E3F} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:program filesmsn toolbarplatform4.0.0401.0npwinext.dll
TB: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:program filesyoutube downloader toolbarie4.6youtubedownloaderToolbarIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:program filesgooglegoogle toolbarGoogleToolbar_32.dll
TB: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File
uRun: [SUPERAntiSpyware] c:program filessuperantispywareSUPERAntiSpyware.exe
mRun: [Microsoft Default Manager] "c:program filesmicrosoftsearch enhancement packdefault managerDefMgr.exe" -resume
mRun: [JMB36X IDE Setup] c:windowsraidtoolxInsIDE.exe
mRun: [MSC] "c:program filesmicrosoft security clientmsseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:program filescommon filesjavajava updatejusched.exe"
mRun: [Adobe ARM] "c:program filescommon filesadobearm1.0AdobeARM.exe"
mRun: [StereoLinksInstall] "c:program filesnvidia corporation3d visionnvstlink.exe" /install1
mRun: [SBAMTray] "c:program filesgfi softwarevipreSBAMTray.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:progra~1micros~4office11EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:program fileswindows livecompanioncompanioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:program fileswindows livewriterWriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~4office11REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:program filesskypetoolbarsinternet explorerskypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:program fileswindows livephoto galleryAlbumDownloadProtocolHandler.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:program filessuperantispywareSASSEH.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:program filescommon fileslightscribeLSRunOnce.exe"
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:program filesgooglechromeapplication25.0.1364.97installerchrmstp.exe" –configure-user-settings

–verbose-logging –system-level –multi-install –chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:userstacappdataroamingmozillafirefoxprofiles2jquws5c.default
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=hp
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=937811&p;=
FF - plugin: c:program filesadobereader 10.0readerairnppdf32.dll
FF - plugin: c:program filesdivxdivx plus web playernpdivx32.dll
FF - plugin: c:program filesgooglegoogle earthpluginnpgeplugin.dll
FF - plugin: c:program filesgoogleupdate1.3.21.135npGoogleUpdate3.dll
FF - plugin: c:program filesjavajre6binnew_pluginnpdeployJava1.dll
FF - plugin: c:program filesjavajre6binplugin2npjp2.dll
FF - plugin: c:program filesmicrosoft silverlight5.1.10411.0npctrlui.dll
FF - plugin: c:program filesmicrosoftoffice livenpOLW.dll
FF - plugin: c:program filesmozilla firefoxpluginsnpicaN.dll
FF - plugin: c:program filesmozilla firefoxpluginsnprpplugin.dll
FF - plugin: c:program filesnvidia corporation3d visionnpnv3dv.dll
FF - plugin: c:program filesnvidia corporation3d visionnpnv3dvstreaming.dll
FF - plugin: c:program filesrealrealplayernetscape6nprpplugin.dll
FF - plugin: c:program fileswindows livephoto galleryNPWLPG.dll
FF - plugin: c:programdatarealrealplayerbrowserrecordpluginmozillapluginsnprpchromebrow
serrecordext.dll
FF - plugin: c:programdatarealrealplayerbrowserrecordpluginmozillapluginsnprphtml5video
shim.dll
FF - plugin: c:windowssystem32npdeployJava1.dll
FF - plugin: c:windowssystem32npmproxy.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true);user_pref(extentions.y2layers.installId, 1098dc1a-cb91-4fab-af0e-8da7a9cbb5a3
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:windowssystem32driversMpFilter.sys [2013-1-20 195296]
R1 CLBStor;InstantBurn Storage Helper Driver;c:windowssystem32driversCLBStor.sys [2009-11-25 16048]
R1 MpKsl8ca09e82;MpKsl8ca09e82;c:programdatamicrosoftmicrosoft antimalwaredefinition updates{8de6ca8e-9ce6-4a19-8846-fd7dfdcc00ae}MpKsl8ca09e82.sys

[2013-3-3 29904]
R1 SASDIFSV;SASDIFSV;c:program filessuperantispywaresasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:program filessuperantispywareSASKUTIL.SYS [2011-7-12 67664]
R1 vwififlt;Virtual WiFi Filter Driver;c:windowssystem32driversvwififlt.sys [2009-7-13 48128]
R2 !SASCORE;SAS Core Service;c:program filessuperantispywareSASCore.exe [2012-7-11 116608]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:program filescommon filesadobearm1.0armsvc.exe [2012-12-18 65192]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384]
R2 cpuz135;cpuz135;c:windowssystem32driverscpuz135_x32.sys [2011-3-8 22504]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:program filescommon filesepsonepw!3 ssrpE_S50RP7.EXE [2013-2-12 142432]
R2 MBAMScheduler;MBAMScheduler;c:program filesmalwarebytes' anti-malwarembamscheduler.exe [2012-11-6 398184]
R2 NisDrv;Microsoft Network Inspection System;c:windowssystem32driversNisDrvWFP.sys [2012-3-20 100328]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:program filesnvidia corporationnvidia update coredaemonu.exe [2013-2-24 1266464]
R2 sbapifs;sbapifs;c:windowssystem32driverssbapifs.sys [2012-12-4 68904]
R2 SBPIMSvc;SB Recovery Service;c:program filesgfi softwarevipreSBPIMSvc.exe [2013-2-20 175936]
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:progra~1enigma~1spyhun~1SH4SER~1.EXE [2013-1-14 769920]
R3 esgiguard;esgiguard;c:program filesenigma software groupspyhunteresgiguard.sys [2011-5-6 13904]
R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [2011-3-8 21104]
R3 NisSrv;Microsoft Network Inspection;c:program filesmicrosoft security clientNisSrv.exe [2013-1-27 295232]
S2 gupdate1ca778e350221d0;Google Update Service (gupdate1ca778e350221d0);c:program filesgoogleupdateGoogleUpdate.exe [2009-12-7 133104]
S2 MBAMService;MBAMService;c:program filesmalwarebytes' anti-malwarembamservice.exe [2012-5-4 682344]
S2 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:program filesmicrosoft sql server100sharedsqladhlp.exe [2009-7-22 47128]
S2 SBAMSvc;VIPRE Antivirus;c:program filesgfi softwarevipreSBAMSvc.exe [2013-2-20 3680512]
S2 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:program filesmicrosoft sql servermssql10.sqlexpressmssqlbinnSQLAGENT.EXE [2011-9-22 370024]
S3 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:program filesadobeelements organizer 8.0PhotoshopElementsFileAgent.exe [2009-10-9 169312]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32macromedflashFlashPlayerUpdateService.exe [2012-6-25 251248]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:windowssystem32driversb57nd60x.sys [2009-7-13 229888]
S3 EsgScanner;EsgScanner;c:windowssystem32driversEsgScanner.sys [2012-6-22 19984]
S3 gfiark;gfiark;c:windowssystem32driversgfiark.sys [2013-3-3 35896]
S3 gupdatem;Google Update Service (gupdatem);c:program filesgoogleupdateGoogleUpdate.exe [2009-12-7 133104]
S3 netr28u;RT2870 USB Extensible Wireless LAN Card Driver;c:windowssystem32driversnetr28u.sys [2009-5-25 734208]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:windowssystem32driversrdpvideominiport.sys [2011-5-10 15872]
S3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:windowssystem32driversRTL8192su.sys [2012-10-14 602216]
S3 sbwtis;sbwtis;c:windowssystem32driverssbwtis.sys [2012-12-11 76064]
S3 SWDUMon;SWDUMon;c:windowssystem32driversSWDUMon.sys [2011-4-17 11232]
S3 TsUsbFlt;TsUsbFlt;c:windowssystem32driversTsUsbFlt.sys [2011-5-10 52224]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:windowssystem32driversvwifimp.sys [2009-7-13 14336]
S3 WatAdminSvc;Windows Activation Technologies Service;c:windowssystem32watWatAdminSvc.exe [2010-3-3 1343400]
S4 nlsX86cc;Nalpeiron Licensing Service;c:windowssystem32nlssrv32.exe [2011-11-14 66560]
S4 RsFx0105;RsFx0105 Driver;c:windowssystem32driversRsFx0105.sys [2011-9-22 238696]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:program fileswindows livemeshwlcrasvc.exe [2010-9-22 51040]
SUnknown MpKslb1e5f4f4;MpKslb1e5f4f4; [x]
.
=============== Created Last 30 ================
.
2013-03-04 00:16:23 29904 —-a-w- c:progra~2microsoftmicrosoft antimalwaredefinition updates{8de6ca8e-9ce6-4a19-8846-

fd7dfdcc00ae}MpKsl8ca09e82.sys
2013-03-03 23:33:33 ——– d—–w- c:userstacappdataroamingSUPERAntiSpyware.com
2013-03-03 23:33:24 ——– d—–w- c:program filesSUPERAntiSpyware
2013-03-03 23:33:24 ——– d—–w- c:progra~2SUPERAntiSpyware.com
2013-03-03 22:30:15 2347008 —-a-w- c:windowssystem32win32k.sys
2013-03-03 22:29:50 3967848 —-a-w- c:windowssystem32ntkrnlpa.exe
2013-03-03 22:29:50 3913064 —-a-w- c:windowssystem32ntoskrnl.exe
2013-03-03 22:29:40 187752 —-a-w- c:windowssystem32driversFWPKCLNT.SYS
2013-03-03 22:29:40 1293672 —-a-w- c:windowssystem32driverstcpip.sys
2013-03-03 22:29:24 169984 —-a-w- c:windowssystem32winsrv.dll
2013-03-03 21:00:53 ——– d—–w- c:program filesESET
2013-03-03 20:01:06 35896 —-a-w- c:windowssystem32driversgfiark.sys
2013-03-03 19:59:43 ——– d—–w- c:progra~2GFI Software
2013-03-03 19:59:24 ——– d—–w- c:windowssystem32driversVDD
2013-03-03 19:58:06 ——– d—–w- c:progra~2Downloaded Installations
2013-03-03 19:56:45 ——– d—–w- c:program filesGFI Software
2013-03-03 19:56:31 ——– d—–w- c:userstacappdataroamingGFI Software
2013-03-03 18:44:21 110080 —-a-r- c:userstacappdataroamingmicrosoftinstaller{0ac0f1b2-61c7-4b6e-acef-58fcc0b94835}IconF7A21AF7.exe
2013-03-03 18:44:21 110080 —-a-r- c:userstacappdataroamingmicrosoftinstaller{0ac0f1b2-61c7-4b6e-acef-58fcc0b94835}IconD7F16134.exe
2013-03-03 18:44:21 110080 —-a-r- c:userstacappdataroamingmicrosoftinstaller{0ac0f1b2-61c7-4b6e-acef-58fcc0b94835}IconCF33A0CE.exe
2013-03-03 18:44:16 ——– d—–w- C:sh4ldr
2013-03-03 18:44:16 ——– d—–w- c:program filesEnigma Software Group
2013-03-03 18:43:23 ——– d—–w- c:windows\0AC0F1B261C74B6EACEF58FCC0B94835.TMP
2013-03-03 18:43:19 ——– d—–w- c:program filescommon filesWise Installation Wizard
2013-03-03 17:57:32 ——– d—–w- c:userstacappdatalocalPrograms
2013-03-03 01:55:29 6954968 —-a-w- c:progra~2microsoftmicrosoft antimalwaredefinition updates{8de6ca8e-9ce6-4a19-8846-

fd7dfdcc00ae}mpengine.dll
2013-02-25 22:26:46 740840 ——w- c:progra~2microsoftmicrosoft antimalwaredefinition updates{ca371aa4-7078-4e30-a0d3-

eb57db1b2e33}gapaengine.dll
2013-02-25 22:26:34 6954968 —-a-w- c:progra~2microsoftmicrosoft antimalwaredefinition updatesbackupmpengine.dll
2013-02-24 22:07:52 768000 —-a-w- c:program filescommon filesmicrosoft sharedvgxVGX.dll
2013-02-24 21:53:43 53024 —-a-w- c:windowssystem32OpenCL.dll
2013-02-24 21:53:34 ——– d—–w- c:progra~2NVIDIA Corporation
2013-02-24 21:52:39 8944416 —-a-w- c:windowssystem32driversnvlddmkm.sys
2013-02-24 21:52:39 892704 —-a-w- c:windowssystem32nvdispgenco3220162.dll
2013-02-24 21:52:39 7964680 —-a-w- c:windowssystem32nvcuda.dll
2013-02-24 21:52:39 6267240 —-a-w- c:windowssystem32nvopencl.dll
2013-02-24 21:52:39 2726176 —-a-w- c:windowssystem32nvcuvid.dll
2013-02-24 21:52:39 20534560 —-a-w- c:windowssystem32nvoglv32.dll
2013-02-24 21:52:39 1990944 —-a-w- c:windowssystem32nvcuvenc.dll
2013-02-24 21:52:39 15038296 —-a-w- c:windowssystem32nvd3dum.dll
2013-02-24 21:52:39 12862400 —-a-w- c:windowssystem32nvwgf2um.dll
2013-02-24 21:52:39 1012512 —-a-w- c:windowssystem32nvdispco3220294.dll
2013-02-24 21:52:38 2528840 —-a-w- c:windowssystem32nvapi.dll
2013-02-24 21:52:38 17560352 —-a-w- c:windowssystem32nvcompiler.dll
2013-02-24 17:56:18 ——– d—–w- c:userstacappdatalocalSwvUpdater
2013-02-24 17:56:02 ——– d—–w- c:userstacappdatalocalConduit
2013-02-24 17:56:01 ——– d—–w- c:program filesWhiteSmoke_B
2013-02-24 17:55:44 ——– d—–w- c:userstacappdatalocalCRE
2013-02-24 17:55:27 ——– d—–w- c:program filesSearchProtect
2013-02-21 05:30:50 13632 —-a-w- c:windowssystem32driversvddapvdd.dll
2013-02-21 05:30:48 44864 —-a-w- c:windowssystem32sbbd.exe
2013-02-15 22:04:52 208448 —-a-w- c:program filesmozilla firefoxpluginsnppdf32.dll
2013-02-15 22:04:52 208448 —-a-w- c:program filesinternet explorerpluginsnppdf32.dll
2013-02-12 21:15:42 8192 —-a-w- c:windowssystem32E_DCINST.DLL
2013-02-12 21:15:41 95232 —-a-w- c:windowssystem32E_FLBICE.DLL
2013-02-12 21:15:41 95232 —-a-w- c:windowssystem32E_FLBICA.DLL
2013-02-12 21:15:40 81408 —-a-w- c:windowssystem32E_FD4BICE.DLL
2013-02-12 21:15:40 81408 —-a-w- c:windowssystem32E_FD4BICA.DLL
2013-02-11 00:14:39 ——– d—–w- c:program filesRamBooster 2.0
2013-02-11 00:14:34 ——– d-sh–w- c:windowssystem32AI_RecycleBin
2013-02-11 00:14:29 ——– d—–w- c:progra~2Strongvault Online Backup
2013-02-11 00:14:17 ——– d-sh–w- C:AI_RecycleBin
2013-02-11 00:14:00 ——– d—–w- c:userstacappdatalocalCoupon Companion Plugin
2013-02-11 00:13:54 ——– d—–w- c:userstacappdatalocalUpdater21804
2013-02-10 22:09:14 ——– d—–w- c:progra~2Lexmark Universal v2 XL
2013-02-10 22:08:22 206336 —-a-w- c:windowssystem32spoolprtprocsw32x86LMUD1P4C.DLL
2013-02-10 22:08:05 446464 —-a-w- c:windowssystem32lexlog.dll
2013-02-10 22:07:38 ——– d—–w- c:progra~2UD1
2013-02-10 22:06:21 430080 —-a-w- c:windowssystem32LMUD1Pcomc.dll
2013-02-10 22:06:21 204800 —-a-w- c:windowssystem32LMUD1Pinpa.dll
2013-02-10 22:06:21 1077248 —-a-w- c:windowssystem32LMUD1Plang.dll
2013-02-10 22:00:58 184832 —-a-w- c:windowssystem32spoolprtprocsw32x86LMADHQ4C.DLL
2013-02-10 18:10:12 ——– d—–w- c:program filescommon filesEPSON
2013-02-10 18:05:02 ——– d—–w- c:progra~2EPSON
2013-02-09 20:25:12 34304 —-a-w- c:windowssystem32atmlib.dll
2013-02-09 20:25:12 295424 —-a-w- c:windowssystem32atmfd.dll
2013-02-09 20:03:51 46592 —-a-w- c:windowssystem32fpb.rs
2013-02-09 19:59:13 2048 —-a-w- c:windowssystem32tzres.dll
2013-02-09 17:53:47 94112 —-a-w- c:windowssystem32WindowsAccessBridge.dll
.
==================== Find3M ====================
.
2013-03-03 19:29:24 71024 —-a-w- c:windowssystem32FlashPlayerCPLApp.cpl
2013-03-03 19:29:24 691568 —-a-w- c:windowssystem32FlashPlayerApp.exe
2013-02-10 00:35:07 4115232 —-a-w- c:windowssystem32nvcpl.dll
2013-02-10 00:35:07 3010336 —-a-w- c:windowssystem32nvsvc.dll
2013-02-10 00:35:03 634144 —-a-w- c:windowssystem32nvvsvc.exe
2013-02-10 00:35:02 62752 —-a-w- c:windowssystem32nvshext.dll
2013-02-10 00:35:02 223008 —-a-w- c:windowssystem32nvmctray.dll
2013-02-09 17:53:29 861088 —-a-w- c:windowssystem32npdeployJava1.dll
2013-02-09 17:53:29 782240 —-a-w- c:windowssystem32deployJava1.dll
2013-01-30 10:53:21 232336 ——w- c:windowssystem32MpSigStub.exe
2013-01-08 22:11:21 1800704 —-a-w- c:windowssystem32jscript9.dll
2013-01-08 22:03:20 1129472 —-a-w- c:windowssystem32wininet.dll
2013-01-08 22:03:12 1427968 —-a-w- c:windowssystem32inetcpl.cpl
2013-01-08 21:59:02 142848 —-a-w- c:windowssystem32ieUnatt.exe
2013-01-08 21:58:29 420864 —-a-w- c:windowssystem32vbscript.dll
2013-01-08 21:56:23 2382848 —-a-w- c:windowssystem32mshtml.tlb
2012-12-07 12:26:17 308736 —-a-w- c:windowssystem32Wpc.dll
2012-12-07 12:20:43 2576384 —-a-w- c:windowssystem32gameux.dll
.
============= FINISH: 16:44:19.78 ===============

I ran ESET and am no longer getting the message in the action center.
Hi and Welcome!! Shali :)

My name is Robybel.

I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! ;)
Roybel, Thank you for your response. I see that someone kindly condensed my three posts into one. If you read the bottom line it says that ESET seems to have fixed the problem. I'm no longer receiving the message from the Action Center. Thanks again for your help :)
Hi Shali ;)

I'm here :P :lol:

You missing the Attach.txt, please, post it in your next reply, you can find it in the same location of DDS.txt

Next

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

On your next reply please post :
  • Attach.txt
  • aswMBR log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Thank you for your help. Should I do the Quick Scan or scan all of the C drive? I will attempt to attach the "attach" file as a zip.
Hi Shali

Should I do the Quick Scan or scan all of the C drive?

I dont understand :( About aswMBR, just click "Scan" to start the scan
The default scan is a quick scan so that's what I'm doing. Unfortunately, my computer crashed and I got the blue screen :( Am running the scan again.
Robybel, Thanks again for your help :) Here's the log: aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-03-08 14:24:33 —————————– 14:24:33.233 OS Version: Windows 6.1.7601 Service Pack 1 14:24:33.233 Number of processors: 4 586 0x1706 14:24:33.234 ComputerName: SACRED-PLACE UserName: TAC 14:24:34.771 Initialize success 14:24:45.257 AVAST engine defs: 13030800 14:25:02.807 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006d 14:25:02.810 Disk 0 Vendor: ST310003 SD15 Size: 953869MB BusType: 3 14:25:02.819 Disk 0 MBR read successfully 14:25:02.823 Disk 0 MBR scan 14:25:02.828 Disk 0 Windows 7 default MBR code 14:25:02.836 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 14:25:02.871 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476834 MB offset 206848 14:25:02.913 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 476933 MB offset 976762880 14:25:02.941 Disk 0 scanning sectors +1953521664 14:25:03.032 Disk 0 scanning C:\Windows\system32\drivers 14:25:33.232 Service scanning 14:26:00.091 Service MpKsla50f6389 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BD67BCD8-0B72-40B1-ADD1-9114D55FD117}\MpKsla50f6389.sys **LOCKED** 32 14:26:18.754 Modules scanning 14:26:26.212 Disk 0 trace - called modules: 14:26:26.444 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll storport.sys nvstor.sys 14:26:26.451 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86c82030] 14:26:26.458 3 CLASSPNP.SYS[8bced59e] -> nt!IofCallDriver -> [0x86312450] 14:26:26.466 5 ACPI.sys[8b4ae3d4] -> nt!IofCallDriver -> \Device\0000006d[0x86312030] 14:26:27.966 AVAST engine scan C:\Windows 14:26:30.189 AVAST engine scan C:\Windows\system32 14:31:13.366 AVAST engine scan C:\Windows\system32\drivers 14:31:33.354 AVAST engine scan C:\Users\TAC 15:04:02.572 AVAST engine scan C:\ProgramData 15:10:47.719 Scan finished successfully 15:15:39.199 Disk 0 MBR has been saved successfully to "C:\Users\TAC\Desktop\Virus\MBR.dat" 15:15:39.288 The log file has been saved successfully to "C:\Users\TAC\Desktop\Virus\aswMBR.txt"

Attachments:

Hi Shali ;)

AdwCleaner

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

============ Next ==============


[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

On your next reply please post :
  • AdwCleaner[S1].txt
  • JRT.txt

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Here is the logfile from the first tool:

# AdwCleaner v2.114 - Logfile created 03/09/2013 at 06:58:36
# Updated 05/03/2013 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (32 bits)
# User : TAC - SACRED-PLACE
# Boot Mode : Normal
# Running from : C:\Users\TAC\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : WajamUpdater

***** [Files / Folders] *****

File Deleted : C:\END
File Deleted : C:\Program Files\Mozilla Firefox\extensions\[removed]
File Deleted : C:\Users\TAC\AppData\Roaming\Mozilla\Firefox\Profiles\2jquws5c.default\searchplugins\Conduit.xml
Folder Deleted : C:\Program Files\Common Files\Software Update Utility
Folder Deleted : C:\Program Files\SearchProtect
Folder Deleted : C:\Program Files\Wajam
Folder Deleted : C:\Program Files\Yontoo Layers Runtime
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\WeCareReminder
Folder Deleted : C:\Users\TAC\AppData\Local\Conduit
Folder Deleted : C:\Users\TAC\AppData\Local\Coupon Companion Plugin
Folder Deleted : C:\Users\TAC\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Folder Deleted : C:\Users\TAC\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\TAC\AppData\Local\Temp\CT3281024
Folder Deleted : C:\Users\TAC\AppData\Local\Wajam
Folder Deleted : C:\Users\TAC\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\TAC\AppData\LocalLow\Search Settings
Folder Deleted : C:\Users\TAC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
Folder Deleted : C:\Users\TAC\AppData\Roaming\Mozilla\Firefox\Profiles\2jquws5c.default\extensions\{f0e59437-6148-4a98-b0a6-60d557ef57f4}
Folder Deleted : C:\Users\TAC\AppData\Roaming\Mozilla\Firefox\Profiles\2jquws5c.default\extensions\[removed]

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings
Key Deleted : HKCU\Software\GreenTree Applications
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110211181104}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F3FEE66E-E034-436A-86E4-9690573BEE8A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110211181104}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F3FEE66E-E034-436A-86E4-9690573BEE8A}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Wajam
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110211181104}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F3FEE66E-E034-436A-86E4-9690573BEE8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3}
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE}
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1
Key Deleted : HKLM\Software\Description
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211181104}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211181104}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchSettings
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211181104}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3FEE66E-E034-436A-86E4-9690573BEE8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211181104}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1CAE30F47D14B41B5FC8FA53658044
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam
Key Deleted : HKLM\Software\Search Settings
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\Software\Wajam
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{F3FEE66E-E034-436A-86E4-9690573BEE8A}]
Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{F3FEE66E-E034-436A-86E4-9690573BEE8A}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16464

[OK] Registry is clean.

-\\ Mozilla Firefox v5.0 (en-US)

File : C:\Users\TAC\AppData\Roaming\Mozilla\Firefox\Profiles\2jquws5c.default\prefs.js

C:\Users\TAC\AppData\Roaming\Mozilla\Firefox\Profiles\2jquws5c.default\user.js … Deleted !

Deleted : user_pref("extentions.y2layers.installId", "1098dc1a-cb91-4fab-af0e-8da7a9cbb5a3");
Deleted : user_pref("extensions.crossriderapp21804.adsOldValue", -1);

-\\ Google Chrome v25.0.1364.152

File : C:\Users\TAC\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.2920] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?CUI=UN34088370122047754&ctid=CT328[…]

*************************

AdwCleaner[S1].txt - [9230 octets] - [09/03/2013 06:58:36]

########## EOF - C:\AdwCleaner[S1].txt - [9290 octets] ##########


Do I need to shut down Microsoft Security Essentials and Windows Defender in order to run the second tool? Or turn off the firewall? I've disabled all other antivirus programs (I only have SuperAntiSpyWare).
Hi Shali ;)

Do I need to shut down Microsoft Security Essentials and Windows Defender in order to run the second tool?

Yes! Good :thumbup:
I'm not exactly sure how to shut down the Windows programs but I can probably figure it out. I'm getting a message that the JRT appears to be a malicious file.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI