This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Appears to Boot Normaly But Nothing Works [Solved]

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi oldman960,

Yes Combofix is still detecting and trying to fix ZeroAccess.

Also – something new. When I open a new tab in Internet Explorer a search page called Funmoods Search opens. My homepage when I first open the browser, however, has not been effected,

Thanks again.

Logs attached.

_____________________________

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{4D25F926-B9FE-4682-BF72-8AB8210D6D75} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{4D25F926-B9FE-4682-BF72-8AB8210D6D75} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}\ not found.
Registry value HKEY_USERS\S-1-5-21-4073680847-1405297832-2471763517-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
========== FILES ==========
< dir C:\Documents and Settings\Amy\Local Settings\Application Data\{71EA6046-8286-4ADC-BF58-501E76626E60}\*.* /s /c >
C:\Documents and Settings\Amy\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Amy\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->FireFox cache emptied: 942688 bytes
->Flash cache emptied: 492 bytes

User: All Users

User: Amy
->Temp folder emptied: 3416498 bytes
->Temporary Internet Files folder emptied: 40596453 bytes
->Java cache emptied: 26213443 bytes
->Flash cache emptied: 186651 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56504 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 3089 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 6604 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 140685517 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 216 bytes

Total Files Cleaned = 202.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 04052013_122918

Files\Folders moved on Reboot…

PendingFileRenameOperations files…

Registry entries deleted on Reboot…

__________________________________________

ComboFix 13-04-05.01 - Amy 04/05/2013 14:18:52.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2921 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
* Resident AV is active
.
.
.
((((((((((((((((((((((((( Files Created from 2013-03-05 to 2013-04-05 )))))))))))))))))))))))))))))))
.
.
2013-03-30 17:21 . 2012-12-14 20:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-03-29 18:18 . 2013-03-29 18:18 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\Sun
2013-03-29 18:15 . 2013-03-29 18:15 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\PCHealth
2013-03-29 17:29 . 2013-03-29 17:28 143872 —-a-w- c:\windows\system32\javacpl.cpl
2013-03-29 17:29 . 2013-03-29 17:28 861088 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-03-29 17:29 . 2013-03-29 17:28 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-29 17:28 . 2013-03-29 17:28 ——– d—–w- c:\program files\Java
2013-03-29 16:43 . 2013-03-29 18:23 ——– d—–w- C:\TDSSKiller_Quarantine
2013-03-28 18:03 . 2008-04-13 18:31 36352 —-a-w- c:\windows\system32\drivers\intelppm.sys
2013-03-28 18:03 . 2008-04-13 18:31 36352 —-a-w- c:\windows\system32\dllcache\intelppm.sys
2013-03-27 20:02 . 2013-03-27 20:02 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2013-03-27 20:00 . 2013-03-27 20:00 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-03-18 16:37 . 2013-03-18 18:09 ——– d—–w- C:\jgh
2013-03-14 14:50 . 2013-03-14 14:50 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\BVRP Software
2013-03-13 20:26 . 2013-03-13 20:26 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2013-03-13 20:12 . 2013-03-13 20:12 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-29 17:28 . 2010-09-22 13:36 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-03-29 17:18 . 2012-06-01 11:51 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-29 17:18 . 2012-02-13 15:40 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-19 19:15 . 2012-04-10 17:30 60920 —-a-w- c:\windows\system32\drivers\cfwids.sys
2013-02-19 19:12 . 2012-04-10 17:20 172416 —-a-w- c:\windows\system32\mfevtps.exe
2013-02-19 19:11 . 2012-04-10 17:30 91640 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2013-02-19 19:11 . 2012-04-10 17:30 10088 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2013-02-19 19:10 . 2012-04-10 17:30 92632 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2013-02-19 19:09 . 2011-10-15 16:16 565888 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2013-02-19 19:09 . 2012-12-17 15:09 84904 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2013-02-19 19:09 . 2012-04-10 17:30 363080 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2013-02-19 19:08 . 2012-04-10 17:30 65928 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2013-02-19 19:08 . 2012-04-10 17:30 235264 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2013-02-19 19:07 . 2011-10-15 16:16 133416 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2013-02-12 00:32 . 2008-09-03 23:47 12928 ——w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2004-08-04 11:00 12928 —-a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-05 20:05 . 2004-08-04 11:00 916480 —-a-w- c:\windows\system32\wininet.dll
2013-02-05 20:05 . 2004-08-04 11:00 43520 ——w- c:\windows\system32\licmgr10.dll
2013-02-05 20:05 . 2004-08-04 11:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-02-05 05:53 . 2004-08-04 11:00 385024 ——w- c:\windows\system32\html.iec
2013-01-26 03:55 . 2004-08-04 11:00 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-01-07 01:19 . 1980-01-01 06:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37 . 1980-01-01 06:00 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-07 14:31 . 2013-03-27 20:00 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-21 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-01-05 98304]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2007-10-30 77824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-10-10 185784]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-02-10 745472]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824]
"Memeo Instant Backup"="c:\program files\Memeo\AutoBackup\MemeoLauncher2.exe" [2010-12-11 136416]
"Seagate Dashboard"="c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe" [2011-11-03 73728]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-01-14 1278064]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\documents and settings\Amy\Start Menu\Programs\Startup\
TrayDay.lnk - c:\program files\TrayDay\TrayDay.exe [2005-1-28 204800]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-1-20 724992]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToMyPC]
2011-11-13 12:53 15216 —-a-w- c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Seagate\\Seagate Dashboard\\HipServAgent\\HipServAgent.exe"=
.
R0 xmasbus;xmasbus;c:\windows\SYSTEM32\DRIVERS\xmasbus.sys [2/4/2005 2:11 PM 140800]
R0 xmasscsi;xmasscsi;c:\windows\SYSTEM32\DRIVERS\xmasscsi.sys [2/4/2005 2:11 PM 5504]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [4/10/2012 1:30 PM 91640]
R2 LxrSII1d;Secure II Driver;c:\windows\SYSTEM32\DRIVERS\LxrSII1d.sys [5/13/2008 2:31 PM 72672]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/10/2012 1:30 PM 167784]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [4/10/2012 1:31 PM 169320]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\SYSTEM32\mfevtps.exe [4/10/2012 1:20 PM 172416]
R2 RapidPortM1;RapidPortM1;c:\windows\SYSTEM32\DRIVERS\CAPM1LP.SYS [2/23/2005 7:04 PM 22912]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [11/3/2011 2:10 PM 8704]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [4/10/2012 1:30 PM 363080]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/17/2012 11:09 AM 84904]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [12/10/2010 9:49 PM 25824]
S3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [4/10/2012 1:30 PM 60920]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [2/5/2013 11:48 AM 235216]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/17/2012 11:09 AM 84904]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [4/10/2012 1:30 PM 92632]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 17:18]
.
2013-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-22 20:34]
.
2005-01-07 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-04 00:12]
.
2013-04-03 c:\windows\Tasks\ReclaimerUpdateFiles_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-04-04 c:\windows\Tasks\ReclaimerUpdateXML_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-04-05 c:\windows\Tasks\RNUpgradeHelperLogonPrompt_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-04-04 c:\windows\Tasks\User_Feed_Synchronization-{9F65D221-A6DA-4935-A0FB-B46D030E6DFB}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page =
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
TCP: DhcpNameServer = [removed] [removed]
DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} - hxxp://www.eomniform.com/OF5/nsplugins/OFMailX.cab
FF - ProfilePath -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-05 14:34
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="4FDA30922D1D3A4A1A518A89786166259F7EDB5C427B6808351193CC975D2AF0366B0F1D0D2
9192344801B1DA40F8878C6AF3B417DB9EAC349444851CFCDD2C520FADA1F447948AE66148D529013
6FAD41FB00C56744F61778843EEBB9CBE595E3A5E2CF484EA8ED9D5A9C1B05ACF5CE1083F2333F7C8
7B3CA5D6961A87C1C5C2B89678E23ABCC46D823758EE164ADC908E54DF9DA09C8B29762B11806445F
7876CB1C5A70DAFB82DBC2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BE
CC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667C038D530D6EB3452A6A0AC4980AC
7933BA7FD869164D679495747435A8FAC96341B3DE98263F27383A1B78105C0A222DC2209BCEE5FCA
1B5F1912D37D708A550DD8E2F2D5E33805417129D6F9D6DDC5C788D9F09E36E97BCC0958BD1B4AAE9
090018327694D560A956A9839D36F5A005FAE07D91E80208B41FBE6C83E01A0F499528FA5547C6822
752F4157BA34C1065B38514688D8A98CAA471C58F33735ED1803CB46EA90DF7BB59A850AF96019EBE
FD89D756A040433356B4207E3738766494751C2AA491235D2D1F4722F285965527A14F63A1BDD524B
1B516982ACA4B4A9B1982B35121BC8384D5A10251AF92F37222965D4783F057A6435970FEF3A24DD1
0ECC7C036DCFAB886F183D7EBB04E79607DA58FBF38B8C19522FD65DE1193F68E275B6390C3DD5573
1F98B7B463104C0F062A9DB57EF066079EDE29EA21BF1044988DC2E76B6878286A8E57CD2B01C8D9F
02EAB857B98A4AF50271D02CEB3E3F93A7A94C89C54991FA9B08E947F18B11FCA5FA18855DE394A6E
CA038D5247EA53D089D34074727FC415B7460EEB3AED2914D7B33531FE1F411C253C95D2D15B86173
FBB61468B2B4AF08EFAF760B67CC0E0BD2789A985713DAAA3130624562EC42464E5E3A2DFE97C0D20
3DCF0609B6E4407AA0A94B71A0AD1E1254B697FCFACC37260E5676F267E9082FAA155F1359BAA7D72
3BE1BE046B64385E2C59C349546FFCC1BC6DD8C3B363F0EAE87ECEA229DDBBDB1705C3753A2891CF9
901CB3D34F000C785006A79721E0CA453295D53E49B25DB5AE530D06ED2E7318E1026A0921BA70918
3AF7EBEEC8D744B67955BD8B47332EF7CFC07B7542C5FDB99A376A27E135E201972943CE1468A41AF
3445DD167EECF13F108E12C75CBF3FC983416A0DD00757D7B792C2CD06969BA050A2D5DA679838860
6CF1EA112F97EF6828231D4D6E2405AA38D61574987589F9DB31CAD4044F6291279DF5DB37AEDAC7F
016B50FFE183BCC89798A994872AA84426D27E457FCE46146DB8B4241C5BFDB44F57029C3BB7D72E6
CA037D5F4EF53D9A6BF6EB4D1B8390AAA7DA54BBAACD2FA54E4B44DF415B0B9888E982573A789C153
A312657FBE8400B0009C5ACF16DAA"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1104)
c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
Completion time: 2013-04-05 14:37:27
ComboFix-quarantined-files.txt 2013-04-05 18:37
ComboFix2.txt 2013-03-29 19:11
ComboFix3.txt 2013-03-28 18:24
ComboFix4.txt 2013-03-18 18:09
ComboFix5.txt 2013-04-05 18:11
.
Pre-Run: 38,520,770,560 bytes free
Post-Run: 38,414,196,736 bytes free
.
- - End Of File - - F1087A89EFD0D4BE72A2751981B1408B
Hi EricDSr,

Next, openOTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
dir "C:\Documents and Settings\Amy\Local Settings\Application Data\{71EA6046-8286-4ADC-BF58-501E76626E60}\*.*" /s /c
C:\Documents and Settings\Amy\Local Settings\Application Data\6o4v7yr6ikfw18072u
C:\Documents and Settings\All Users\Application Data\6o4v7yr6ikfw18072u
C:\Documents and Settings\Amy\Local Settings\Application Data\funmoods-speeddial.crx
C:\Documents and Settings\Amy\Application Data\Funmoods

:Commands
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Next

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Next

  • Download on the desktop RogueKiller (by tigzy)
  • Quit all programs
  • Double Click the desktop icon to start RogueKiller
  • Wait until Prescan has finished …
  • Click on Scan
  • Click the Report button, save the report to your desktop

Please post back with
  • OTL fix log
  • AdwCleaner log
  • RogueKiller log
Is the problem with FunMoods still there?
Hi oldman960,

I appreciate your help.

Computer is running well.

Funmoods problem is gone.

Logs follow.

_____________________________

All processes killed
========== SERVICES/DRIVERS ==========
========== FILES ==========
< dir "C:\Documents and Settings\Amy\Local Settings\Application Data\{71EA6046-8286-4ADC-BF58-501E76626E60}\*.*" /s /c >
C:\Documents and Settings\Amy\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Amy\Desktop\cmd.txt deleted successfully.
C:\Documents and Settings\Amy\Local Settings\Application Data\6o4v7yr6ikfw18072u moved successfully.
C:\Documents and Settings\All Users\Application Data\6o4v7yr6ikfw18072u moved successfully.
C:\Documents and Settings\Amy\Local Settings\Application Data\funmoods-speeddial.crx moved successfully.
C:\Documents and Settings\Amy\Application Data\Funmoods\Funmoods\us\20101003 folder moved successfully.
C:\Documents and Settings\Amy\Application Data\Funmoods\Funmoods\us folder moved successfully.
C:\Documents and Settings\Amy\Application Data\Funmoods\Funmoods folder moved successfully.
C:\Documents and Settings\Amy\Application Data\Funmoods folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Amy
->Temp folder emptied: 195264 bytes
->Temporary Internet Files folder emptied: 5238557 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 826 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 505 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 5.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 04082013_111810

Files\Folders moved on Reboot…

PendingFileRenameOperations files…

Registry entries deleted on Reboot…


________________________________________

# AdwCleaner v2.200 - Logfile created 04/08/2013 at 11:30:22
# Updated 02/04/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Amy - IRWINA
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Amy\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\Tarma Installer
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Viewpoint
Folder Deleted : C:\Documents and Settings\All Users\Application Data\WeCareReminder
Folder Deleted : C:\Documents and Settings\Amy\Application Data\Viewpoint
Folder Deleted : C:\Documents and Settings\Amy\Local Settings\Application Data\PackageAware
Folder Deleted : C:\Documents and Settings\Amy\Local Settings\Application Data\Viewpoint
Folder Deleted : C:\Documents and Settings\LocalService\Local Settings\Application Data\Viewpoint
Folder Deleted : C:\Program Files\Common Files\Viewpoint
Folder Deleted : C:\Program Files\Yontoo

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7327C09-B521-4EDB-8509-7D2660C9EC98}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F8AD5AA5-D966-4667-9DAF-2561D68B2012}
Key Deleted : HKCU\Software\Viewpoint
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4FBBF769-ECEB-420A-B536-133B1D505C36}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\IEHelperv2.5.0.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0E2C3126-DDED-4A58-800E-9AEDE84EA31E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F773BB94-6C19-4643-A570-0E429103D1C3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F8AD5AA5-D966-4667-9DAF-2561D68B2012}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder
Key Deleted : HKLM\SOFTWARE\Classes\IEHelperv250.WeCareReminder.1
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F773BB94-6C19-4643-A570-0E429103D1C3}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B12920CF-BE13-4C09-890D-1B6EFFFE2FBE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E060D9D9-E979-4C2F-A840-BE5150F84AC5}
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Key Deleted : HKLM\Software\Funmoods
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Key Deleted : HKLM\Software\MetaStream
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC5B6CDA-8F90-4740-9A8C-28AC5D3C73FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Viewpoint Manager
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Viewpoint Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Key Deleted : HKLM\Software\Viewpoint
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzutDtDtCtAtBtDyBtB0DtCtDyEzz0AtA0AtN0D0Tzu0CtByDzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1554250186 –> hxxp://www.google.com

*************************

AdwCleaner[S1].txt - [8498 octets] - [08/04/2013 11:30:22]

########## EOF - C:\AdwCleaner[S1].txt - [8558 octets] ##########


________________________________________

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Amy [Admin rights]
Mode : Scan – Date : 04/08/2013 11:50:37
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJPOL] HKLM\[…]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
IRP[IRP_MJ_CREATE] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_CREATE_NAMED_PIPE] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_CLOSE] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_READ] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_WRITE] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_QUERY_INFORMATION] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_SET_INFORMATION] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_QUERY_EA] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_SET_EA] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_FLUSH_BUFFERS] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_QUERY_VOLUME_INFORMATION] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_SET_VOLUME_INFORMATION] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_DIRECTORY_CONTROL] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_FILE_SYSTEM_CONTROL] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_DEVICE_CONTROL] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_SHUTDOWN] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_LOCK_CONTROL] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_CLEANUP] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_CREATE_MAILSLOT] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_QUERY_SECURITY] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_SET_SECURITY] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_POWER] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_SYSTEM_CONTROL] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_DEVICE_CHANGE] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_QUERY_QUOTA] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_SET_QUOTA] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)
IRP[IRP_MJ_PNP] : -> HOOKED ([MAJOR] Unknown @ 0x8AB45BD8)

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD800JD-75JNA0 +++++
— User —
[MBR] 06cfffed04a29a5c0fbbfb278fb9f914
[BSP] 61089aa54da192ccacc263ab131da6b3 : MBR Code unknown
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 62 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 128520 | Size: 73108 Mo
2 - [XXXXXX] UNKNOWN (0xdb) [VISIBLE] Offset (sectors): 149854320 | Size: 3114 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1]_S_04082013_02d1150.txt >>
RKreport[1]_S_04082013_02d1150.txt
Hi EricDSr.


Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it

  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Safe Mode
Hi oldman960,

The computer is still running well

Gmer.txt follows

__________________________________

GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-04-08 20:18:48
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e WDC_WD800JD-75JNA0 rev.05.01C05 74.51GB
Running: jgrigk6t.exe; Driver: C:\DOCUME~1\Amy\LOCALS~1\Temp\awtdrpod.sys


—- System - GMER 2.1 —-

Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xF7B9C200]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xF7B9C214]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF7B9C240]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xF7B9C1EC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF7B9C1C4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF7B9C1D8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xF7B9C22A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xF7B9C26C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xF7B9C256]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject

—- Kernel code sections - GMER 2.1 —-

PAGE ntoskrnl.exe!ZwOpenKey 80572BDF 5 Bytes JMP F7B9C1F0 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateKey 80578ABE 5 Bytes JMP F7B9C204 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetValueKey 8057B4EF 7 Bytes JMP F7B9C25A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 8057BB80 5 Bytes JMP F7B9C1C8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 80596A0F 5 Bytes JMP F7B9C1DC mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 805991EC 7 Bytes JMP F7B9C244 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 8059A5CD 7 Bytes JMP F7B9C218 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetSecurityObject 8059EC29 5 Bytes JMP F7B9C270 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 806568F0 7 Bytes JMP F7B9C22E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
? The system cannot find the path specified. !
init C:\WINDOWS\system32\DRIVERS\mohfilt.sys entry point in "init" section [0xB963E760]

—- User code sections - GMER 2.1 —-

.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[2088] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 62418360 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[2088] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62418460 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)

—- Devices - GMER 2.1 —-

Device \FileSystem\Ntfs \Ntfs 8B01116C

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

Device \FileSystem\Fastfat \FatCdrom 89D100DC

AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device \Driver\Cdrom \Device\CdRom0 8AB45910
Device \FileSystem\Rdbss \Device\FsWrap 89F9C7DC
Device \Driver\Cdrom \Device\CdRom1 8AB45910
Device \Driver\atapi \Device\Ide\IdePort0 8AB45BD8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 8AB45BD8
Device \Driver\atapi \Device\Ide\IdePort1 8AB45BD8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 8AB45BD8
Device \FileSystem\Srv \Device\LanmanServer 8AC440F4

AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8ABAADD4
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8ABAADD4
Device \FileSystem\Npfs \Device\NamedPipe 8AB2845C
Device \FileSystem\Msfs \Device\Mailslot 89F05A44
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 89F70290
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port2Path0Target0Lun0 89F70290
Device \FileSystem\Fastfat \Fat 89D100DC

AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 8ABABFAC
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 8ABABFAC
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 8ABABFAC
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 8ABABFAC
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 8ABABFAC
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs 89DE8954
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- Trace I/O - GMER 2.1 —-

Trace ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8ab45bd8]<< 8ab45bd8
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8af916f0] 8af916f0
Trace 3 CLASSPNP.SYS[f76b7fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x8afabd98] 8afabd98
Trace \Driver\atapi[0x8aff77b0] -> IRP_MJ_CREATE -> 0x8ab45bd8 8ab45bd8

—- Modules - GMER 2.1 —-

Module _________ (FILE NOT FOUND) F745F000-F7477000 (98304 bytes)

—- Registry - GMER 2.1 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG08.00.00.01WORKSTATION 4FDA30922D1D3A4A1A518A89786166259F7EDB5C427B6808351193CC975D2AF0366B0F1D0D291923
44801B1DA40F8878C6AF3B417DB9EAC349444851CFCDD2C520FADA1F447948AE66148D5290136FAD4
1FB00C56744F61778843EEBB9CBE595E3A5E2CF484EA8ED9D5A9C1B05ACF5CE1083F2333F7C87B3CA
5D6961A87C1C5C2B89678E23ABCC46D823758EE164ADC908E54DF9DA09C8B29762B11806445F7876C
B1C5A70DAFB82DBC2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C
FEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667C038D530D6EB3452A6A0AC4980AC7933B
A7FD869164D679495747435A8FAC96341B3DE98263F27383A1B78105C0A222DC2209BCEE5FCA1B5F1
912D37D708A550DD8E2F2D5E33805417129D6F9D6DDC5C788D9F09E36E97BCC0958BD1B4AAE909001
8327694D560A956A9839D36F5A005FAE07D91E80208B41FBE6C83E01A0F499528FA5547C6822752F4
157BA34C1065B38514688D8A98CAA471C58F33735ED1803CB46EA90DF7BB59A850AF96019EBEFD89D
756A040433356B4207E3738766494751C2AA491235D2D1F4722F285965527A14F63A1BDD524B1B516
982ACA4B4A9B1982B35121BC8384D5A10251AF92F37222965D4783F057A6435970FEF3A24DD10ECC7
C036DCFAB886F183D7EBB04E79607DA58FBF38B8C19522FD65DE

—- Disk sectors - GMER 2.1 —-

Disk \Device\Harddisk0\DR0 unknown MBR code

—- EOF - GMER 2.1 —-
Hi EricDSr,

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it. If asked to download Avast's database please do so.

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
Hi oldman960. aswMBR.txt follows and compressed MBR.dat is attached. Thanks. ___________________________________ aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-04-09 08:59:10 —————————– 08:59:10.968 OS Version: Windows 5.1.2600 Service Pack 3 08:59:10.968 Number of processors: 2 586 0x304 08:59:10.968 ComputerName: IRWINA UserName: Amy 08:59:11.500 Initialize success 09:01:31.343 AVAST engine defs: 13040900 09:05:49.218 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e 09:05:49.218 Disk 0 Vendor: WDC_WD800JD-75JNA0 05.01C05 Size: 76293MB BusType: 3 09:05:49.234 Device \Driver\atapi -> MajorFunction 89f62b38 09:05:49.250 Disk 0 MBR read successfully 09:05:49.250 Disk 0 MBR scan 09:05:49.296 Disk 0 unknown MBR code 09:05:49.296 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 62 MB offset 63 09:05:49.312 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 73108 MB offset 128520 09:05:49.343 Disk 0 Partition 3 00 DB CP/M / CTOS MSWIN4.1 3114 MB offset 149854320 09:05:49.359 Disk 0 scanning sectors +156232125 09:05:49.406 Disk 0 scanning C:\WINDOWS\system32\drivers 09:06:02.453 Service scanning 09:06:20.953 Modules scanning 09:06:26.718 Disk 0 trace - called modules: 09:06:26.750 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x89f62b38]<< 09:06:26.750 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8afb4030] 09:06:26.750 3 CLASSPNP.SYS[f76b7fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x8afdbd98] 09:06:26.765 \Driver\atapi[0x8afa47b0] -> IRP_MJ_CREATE -> 0x89f62b38 09:06:27.015 AVAST engine scan C:\WINDOWS 09:06:56.218 AVAST engine scan C:\WINDOWS\system32 09:09:59.281 AVAST engine scan C:\WINDOWS\system32\drivers 09:10:15.984 AVAST engine scan C:\Documents and Settings\Amy 09:46:38.578 AVAST engine scan C:\Documents and Settings\All Users 09:48:10.718 Scan finished successfully 11:10:52.484 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Amy\Desktop\MBR.dat" 11:10:52.484 The log file has been saved successfully to "C:\Documents and Settings\Amy\Desktop\aswMBR.txt"

Attachments:

Hi EricDSr,


Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

I see you have aswMBR on your computer. Please run a scan with it and post the log and attach the mbr.zip that is also produced.


Next

Please rerun aswMBR. Please post the log produced, no need to attach the mbr.dat this time.

Thanks
Thanks oldman960. Log follows: _____________________________ aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-04-10 12:00:04 —————————– 12:00:04.359 OS Version: Windows 5.1.2600 Service Pack 3 12:00:04.359 Number of processors: 2 586 0x304 12:00:04.359 ComputerName: IRWINA UserName: Amy 12:00:04.765 Initialize success 12:00:23.484 AVAST engine defs: 13040900 12:00:45.625 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e 12:00:45.625 Disk 0 Vendor: WDC_WD800JD-75JNA0 05.01C05 Size: 76293MB BusType: 3 12:00:45.796 Disk 0 MBR read successfully 12:00:45.796 Disk 0 MBR scan 12:00:45.875 Disk 0 unknown MBR code 12:00:45.875 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 62 MB offset 63 12:00:45.890 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 73108 MB offset 128520 12:00:45.921 Disk 0 Partition 3 00 DB CP/M / CTOS MSWIN4.1 3114 MB offset 149854320 12:00:45.937 Disk 0 scanning sectors +156232125 12:00:45.984 Disk 0 scanning C:\WINDOWS\system32\drivers 12:00:59.125 Service scanning 12:01:17.609 Modules scanning 12:01:22.765 Disk 0 trace - called modules: 12:01:22.796 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 12:01:22.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8afd48e0] 12:01:22.796 3 CLASSPNP.SYS[f76b7fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x8afd6b00] 12:01:23.312 AVAST engine scan C:\WINDOWS 12:01:53.171 AVAST engine scan C:\WINDOWS\system32 12:05:23.015 AVAST engine scan C:\WINDOWS\system32\drivers 12:05:40.046 AVAST engine scan C:\Documents and Settings\Amy 12:47:57.109 AVAST engine scan C:\Documents and Settings\All Users 12:49:29.046 Scan finished successfully 12:50:47.718 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Amy\Desktop\MBR.dat" 12:50:47.718 The log file has been saved successfully to "C:\Documents and Settings\Amy\Desktop\aswMBR.txt"
Hi EricDSr,


Log looks good. We will re-enable your CD emulator when we are finished.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
Hi oldman960, ESET list follows: ___________________________________ C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58\enemies-names.txt Win32/Adware.AntimalwareDoctor.AE.Gen application C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58\local.ini Win32/Adware.AntimalwareDoctor.AE.Gen application C:\Program Files\DotSpot_2kEI\Installr\1.bin\2kEIPlug.dll Win32/Toolbar.MyWebSearch application C:\Program Files\DotSpot_2kEI\Installr\1.bin\2kEZSETP.dll Win32/Toolbar.MyWebSearch.Q application C:\Program Files\DotSpot_2kEI\Installr\1.bin\NP2kEISb.dll Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\Funmoods\1.5.23.22\escortApp.dll.vir Win32/Toolbar.Funmoods application C:\Qoobox\Quarantine\C\Program Files\Funmoods\1.5.23.22\escortEng.dll.vir Win32/Toolbar.Funmoods application C:\Qoobox\Quarantine\C\Program Files\Funmoods\1.5.23.22\escorTlbr.dll.vir Win32/Toolbar.Funmoods application C:\Qoobox\Quarantine\C\Program Files\Funmoods\1.5.23.22\escortShld.dll.vir Win32/Toolbar.Funmoods application C:\Qoobox\Quarantine\C\Program Files\Funmoods\1.5.23.22\funmoodssrv.exe.vir Win32/Toolbar.Funmoods application C:\Qoobox\Quarantine\C\Program Files\Funmoods\1.5.23.22\bh\escort.dll.vir Win32/Toolbar.Funmoods application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP453\A0197767.dll Win32/Toolbar.Funmoods application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP453\A0197768.dll Win32/Toolbar.Funmoods application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP453\A0197769.dll Win32/Toolbar.Funmoods application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP453\A0197770.dll Win32/Toolbar.Funmoods application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP453\A0197771.dll Win32/Toolbar.Funmoods application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP453\A0197773.exe Win32/Toolbar.Funmoods application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP467\A0242831.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP467\A0242835.dll a variant of Win32/Adware.Yontoo.B application C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP467\A0242882.dll a variant of Win32/Adware.Yontoo.A application
Hi EricDSr,

Most of the detections were items we have already quarantined or old System Restore points. These will be removed when we remove the tools.

Next, openOTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\TDSSKiller_Quarantine
C:\Documents and Settings\Amy\Local Settings\Application Data\{71EA6046-8286-4ADC-BF58-501E76626E60}
C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58
C:\Program Files\DotSpot_2kEI
rmdir C:\WINDOWS\$NtUninstallKB32607$ /c

:Commands
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Next

Let's see if combofix is still detecting Zero Access. Please delete the copy of combofix you have and download a new one from Link 1

If combofix detects Zero Access please note the entire message including any file names that may be mentioned.

Please post back with
  • OTL fix log
  • combofix.txt
Hi oldman960,

Zero Access was still detected.
No files mentioned in the pop-up warning but said it was in the tcp/ip stack.

Computer is running good in spite of the above.

Thanks for your help.

OTL and ComboFix logs follow:

_________________________________

All processes killed
========== SERVICES/DRIVERS ==========
========== FILES ==========
C:\TDSSKiller_Quarantine\29.03.2013_14.17.21\tdlfs0000 folder moved successfully.
C:\TDSSKiller_Quarantine\29.03.2013_14.17.21 folder moved successfully.
C:\TDSSKiller_Quarantine\29.03.2013_12.31.03\mbr0000\tdlfs0000 folder moved successfully.
C:\TDSSKiller_Quarantine\29.03.2013_12.31.03\mbr0000\mbr0000 folder moved successfully.
C:\TDSSKiller_Quarantine\29.03.2013_12.31.03\mbr0000 folder moved successfully.
C:\TDSSKiller_Quarantine\29.03.2013_12.31.03 folder moved successfully.
C:\TDSSKiller_Quarantine folder moved successfully.
File\Folder C:\Documents and Settings\Amy\Local Settings\Application Data\{71EA6046-8286-4ADC-BF58-501E76626E60} not found.
C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58 folder moved successfully.
C:\Program Files\DotSpot_2kEI\Installr\1.bin folder moved successfully.
C:\Program Files\DotSpot_2kEI\Installr folder moved successfully.
C:\Program Files\DotSpot_2kEI folder moved successfully.
< rmdir C:\WINDOWS\$NtUninstallKB32607$ /c >
C:\Documents and Settings\Amy\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Amy\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Amy
->Temp folder emptied: 81226866 bytes
->Temporary Internet Files folder emptied: 158292790 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 1221 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 274163710 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 490.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 04112013_063544

Files\Folders moved on Reboot…

PendingFileRenameOperations files…

Registry entries deleted on Reboot…

_______________________________________________

ComboFix 13-04-10.02 - Amy 04/11/2013 6:56.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2919 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
* Resident AV is active
.
.
.
((((((((((((((((((((((((( Files Created from 2013-03-11 to 2013-04-11 )))))))))))))))))))))))))))))))
.
.
2013-04-10 17:13 . 2013-04-10 17:13 ——– d—–w- c:\program files\ESET
2013-03-30 17:21 . 2012-12-14 20:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-03-29 18:18 . 2013-03-29 18:18 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\Sun
2013-03-29 18:15 . 2013-03-29 18:15 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\PCHealth
2013-03-29 17:29 . 2013-03-29 17:28 143872 —-a-w- c:\windows\system32\javacpl.cpl
2013-03-29 17:29 . 2013-03-29 17:28 861088 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-03-29 17:29 . 2013-03-29 17:28 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-29 17:28 . 2013-03-29 17:28 ——– d—–w- c:\program files\Java
2013-03-28 18:03 . 2008-04-13 18:31 36352 —-a-w- c:\windows\system32\drivers\intelppm.sys
2013-03-28 18:03 . 2008-04-13 18:31 36352 —-a-w- c:\windows\system32\dllcache\intelppm.sys
2013-03-27 20:02 . 2013-03-27 20:02 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2013-03-27 20:00 . 2013-03-27 20:00 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-03-18 16:37 . 2013-03-18 18:09 ——– d—–w- C:\jgh
2013-03-14 14:50 . 2013-03-14 14:50 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\BVRP Software
2013-03-13 20:26 . 2013-03-13 20:26 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2013-03-13 20:12 . 2013-03-13 20:12 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-29 17:28 . 2010-09-22 13:36 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-03-29 17:18 . 2012-06-01 11:51 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-29 17:18 . 2012-02-13 15:40 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-08 08:36 . 2004-08-04 11:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2013-03-07 01:32 . 1980-01-01 06:00 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 00:50 . 1980-01-01 06:00 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-02 02:06 . 2004-08-04 11:00 916480 —-a-w- c:\windows\system32\wininet.dll
2013-03-02 02:06 . 2004-08-04 11:00 43520 ——w- c:\windows\system32\licmgr10.dll
2013-03-02 02:06 . 2004-08-04 11:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:25 . 2004-08-04 11:00 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-03-02 01:08 . 2004-08-04 11:00 385024 ——w- c:\windows\system32\html.iec
2013-02-27 07:56 . 2004-08-04 11:00 2067456 —-a-w- c:\windows\system32\mstscax.dll
2013-02-19 19:15 . 2012-04-10 17:30 60920 —-a-w- c:\windows\system32\drivers\cfwids.sys
2013-02-19 19:12 . 2012-04-10 17:20 172416 —-a-w- c:\windows\system32\mfevtps.exe
2013-02-19 19:11 . 2012-04-10 17:30 91640 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2013-02-19 19:11 . 2012-04-10 17:30 10088 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2013-02-19 19:10 . 2012-04-10 17:30 92632 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2013-02-19 19:09 . 2011-10-15 16:16 565888 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2013-02-19 19:09 . 2012-12-17 15:09 84904 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2013-02-19 19:09 . 2012-04-10 17:30 363080 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2013-02-19 19:08 . 2012-04-10 17:30 65928 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2013-02-19 19:08 . 2012-04-10 17:30 235264 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2013-02-19 19:07 . 2011-10-15 16:16 133416 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2013-02-12 00:32 . 2008-09-03 23:47 12928 ——w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2004-08-04 11:00 12928 —-a-w- c:\windows\system32\drivers\usb8023.sys
2013-01-26 03:55 . 2004-08-04 11:00 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-03-07 14:31 . 2013-03-27 20:00 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-21 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-01-05 98304]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2007-10-30 77824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-10-10 185784]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-02-10 745472]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824]
"Memeo Instant Backup"="c:\program files\Memeo\AutoBackup\MemeoLauncher2.exe" [2010-12-11 136416]
"Seagate Dashboard"="c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe" [2011-11-03 73728]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-01-14 1278064]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\documents and settings\Amy\Start Menu\Programs\Startup\
TrayDay.lnk - c:\program files\TrayDay\TrayDay.exe [2005-1-28 204800]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-1-20 724992]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToMyPC]
2011-11-13 12:53 15216 —-a-w- c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Seagate\\Seagate Dashboard\\HipServAgent\\HipServAgent.exe"=
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [4/10/2012 1:30 PM 91640]
R2 LxrSII1d;Secure II Driver;c:\windows\SYSTEM32\DRIVERS\LxrSII1d.sys [5/13/2008 2:31 PM 72672]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/10/2012 1:30 PM 167784]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [12/10/2010 9:49 PM 25824]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [4/10/2012 1:31 PM 169320]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\SYSTEM32\mfevtps.exe [4/10/2012 1:20 PM 172416]
R2 RapidPortM1;RapidPortM1;c:\windows\SYSTEM32\DRIVERS\CAPM1LP.SYS [2/23/2005 7:04 PM 22912]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [11/3/2011 2:10 PM 8704]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [4/10/2012 1:30 PM 363080]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/17/2012 11:09 AM 84904]
S3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [4/10/2012 1:30 PM 60920]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [2/5/2013 11:48 AM 235216]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/17/2012 11:09 AM 84904]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [4/10/2012 1:30 PM 92632]
S4 xmasbus;xmasbus;c:\windows\SYSTEM32\DRIVERS\xmasbus.sys [2/4/2005 2:11 PM 140800]
S4 xmasscsi;xmasscsi;c:\windows\SYSTEM32\DRIVERS\xmasscsi.sys [2/4/2005 2:11 PM 5504]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 17:18]
.
2013-04-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-22 20:34]
.
2005-01-07 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-04 00:12]
.
2013-04-10 c:\windows\Tasks\ReclaimerUpdateFiles_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-04-10 c:\windows\Tasks\ReclaimerUpdateXML_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-04-11 c:\windows\Tasks\RNUpgradeHelperLogonPrompt_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-04-10 c:\windows\Tasks\User_Feed_Synchronization-{9F65D221-A6DA-4935-A0FB-B46D030E6DFB}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page =
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
TCP: DhcpNameServer = [removed] [removed]
DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} - hxxp://www.eomniform.com/OF5/nsplugins/OFMailX.cab
FF - ProfilePath -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-11 07:12
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="4FDA30922D1D3A4A1A518A89786166259F7EDB5C427B6808351193CC975D2AF0366B0F1D0D2
9192344801B1DA40F8878C6AF3B417DB9EAC349444851CFCDD2C520FADA1F447948AE66148D529013
6FAD41FB00C56744F61778843EEBB9CBE595E3A5E2CF484EA8ED9D5A9C1B05ACF5CE1083F2333F7C8
7B3CA5D6961A87C1C5C2B89678E23ABCC46D823758EE164ADC908E54DF9DA09C8B29762B11806445F
7876CB1C5A70DAFB82DBC2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BE
CC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667C038D530D6EB3452A6A0AC4980AC
7933BA7FD869164D679495747435A8FAC96341B3DE98263F27383A1B78105C0A222DC2209BCEE5FCA
1B5F1912D37D708A550DD8E2F2D5E33805417129D6F9D6DDC5C788D9F09E36E97BCC0958BD1B4AAE9
090018327694D560A956A9839D36F5A005FAE07D91E80208B41FBE6C83E01A0F499528FA5547C6822
752F4157BA34C1065B38514688D8A98CAA471C58F33735ED1803CB46EA90DF7BB59A850AF96019EBE
FD89D756A040433356B4207E3738766494751C2AA491235D2D1F4722F285965527A14F63A1BDD524B
1B516982ACA4B4A9B1982B35121BC8384D5A10251AF92F37222965D4783F057A6435970FEF3A24DD1
0ECC7C036DCFAB886F183D7EBB04E79607DA58FBF38B8C19522FD65DE1193F68E275B6390C3DD5573
1F98B7B463104C0F062A9DB57EF066079EDE29EA21BF1044988DC2E76B6878286A8E57CD2B01C8D9F
02EAB857B98A4AF50271D02CEB3E3F93A7A94C89C54991FA9B08E947F18B11FCA5FA18855DE394A6E
CA038D5247EA53D089D34074727FC415B7460EEB3AED2914D7B33531FE1F411C253C95D2D15B86173
FBB61468B2B4AF08EFAF760B67CC0E0BD2789A985713DAAA3130624562EC42464E5E3A2DFE97C0D20
3DCF0609B6E4407AA0A94B71A0AD1E1254B697FCFACC37260E5676F267E9082FAA155F1359BAA7D72
3BE1BE046B64385E2C59C349546FFCC1BC6DD8C3B363F0EAE87ECEA229DDBBDB1705C3753A2891CF9
901CB3D34F000C785006A79721E0CA453295D53E49B25DB5AE530D06ED2E7318E1026A0921BA70918
3AF7EBEEC8D744B67955BD8B47332EF7CFC07B7542C5FDB99A376A27E135E201972943CE1468A41AF
3445DD167EECF13F108E12C75CBF3FC983416A0DD00757D7B792C2CD06969BA050A2D5DA679838860
6CF1EA112F97EF6828231D4D6E2405AA38D61574987589F9DB31CAD4044F6291279DF5DB37AEDAC7F
016B50FFE183BCC89798A994872AA84426D27E457FCE46146DB8B4241C5BFDB44F57029C3BB7D72E6
CA037D5F4EF53D9A6BF6EB4D1B8390AAA7DA54BBAACD2FA54E4B44DF415B0B9888E982573A789C153
A312657FBE8400B0009C5ACF16DAA"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1076)
c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
Completion time: 2013-04-11 07:16:01
ComboFix-quarantined-files.txt 2013-04-11 11:15
ComboFix2.txt 2013-04-05 18:37
ComboFix3.txt 2013-03-29 19:11
ComboFix4.txt 2013-03-28 18:24
ComboFix5.txt 2013-04-11 10:48
.
Pre-Run: 37,115,568,128 bytes free
Post-Run: 37,101,027,328 bytes free
.
- - End Of File - - 354D7813E6BBF0A6422F57642FB8D199

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI