This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32/Small.CA [Solved]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Could use assistance… got the following message in Action Center:

Remove the Win32/Small.CA virus from your PC
This problem was caused by Win32/Small.CA, a known computer virus.
Tap or click to go online to the Microsoft Corporation website to learn about the solution

I have good computer skills, but this one looks intimidating… could use help to remove the threat!

Used DDS as forum asks. Here is the results below:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 15:22:33.25 on Fri 04/05/2013
Internet Explorer: 9.10.9200.16521
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7133.3761 [GMT -4:00]
.
AV: Sophos Anti-Virus *Enabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Sophos Anti-Virus *Enabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxbxcoms.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Lexmark 7100 Series\lxbxmon.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Windows\system32\taskeng.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_6_602_180_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\notepad.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support

\AppleMobileDeviceService.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\System32\MsSpellCheckingFacility.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Family Room\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files

(x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI

RoboForm\RoboForm.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:

\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:

\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:

\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO: HP Network Check Helper: {e76fd755-c1ba-4dcb-9f13-99bd91223ade} - C:\Program Files

(x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck

\HPNetworkCheckPlugin.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber

Systems\AI RoboForm\RoboForm.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [SPMTray] "C:\Program Files (x86)\PC Speed Maximizer\SPMTray.exe"
uRun: [Google Update] "C:\Users\Family Room\AppData\Local\Google\Update

\GoogleUpdate.exe" /c
mRun: [iTunesHelper] c:\program files (x86)\itunes\ituneshelper.exe
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support

\APSDaemon.exe"
mRun: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe"

/DelayServices
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: []
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-

feedback-app?

lic=OQBBAC0AQQAzAFoAOAA4AC0ANgBHAEIASgBLAC0ANgBSAFcARwBBAC0AQQB

NAEgAOQBQAC0AVgBBAFkAVgBIAA"&"inst=NwA2AC0AMQAyADIANAA5ADEAOQA1

ADEANAAtAFgATwAzADYAKwAxAC0ATgAxAEQAKwAxAC0AUABMACsAOQAtAEMA

SQBQACsAMgAtAEQARABUACsAOQAyADIAMAAtAEQARAA5ADAAKwAxAC0AUwBU

ADkAMABBAFAAUAArADEALQBGAFUASQArADIALQBDAEkARAArADEALQBJAEEA

VgBBACsANgA"&"prod=92"&"ver=9.0.894
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &2 Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm

\RoboForm.dll/ComCustomIEMenu.html
IE: &7 Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm

\RoboForm.dll/ComFillForms.html
IE: &8 Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm

\RoboForm.dll/ComSavePass.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard

\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - res://C:\Program Files (x86)\Siber

Systems\AI RoboForm\RoboForm.dll/ComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - res://C:\Program Files (x86)\Siber

Systems\AI RoboForm\RoboForm.dll/ComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - res://C:\Program Files (x86)\Siber Systems\AI

RoboForm\RoboForm.dll/ComShowToolbar.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-

E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-

F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-

5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
LSP: C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll
Trusted Zone: ameritrade.com
Trusted Zone: ameritrade.com\wwws
Trusted Zone: cnet.com\download
Trusted Zone: oneonta.edu\my
Trusted Zone: oneonta.edu\sophos
DPF: Garmin Communicator Plug-In -

hxxps://static.garmincdn.com/gcp/ie/4.0.1.0/GarminAxControl_32.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} -

hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} -

hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} -

hxxps://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
DPF: {3F4AC0C9-3A7D-4115-99B4-2693DE0014AF} -

hxxp://optimum.net/downloads/TNetworkScannerXControl.ocx
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} -

hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.c

ab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -

hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -

hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files

(x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files

(x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:

\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D

/C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:

\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} -

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} -

C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB-X64: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
mRun-x64: [LXBXCATS] rundll32 C:\Windows\system32\spool\DRIVERS

\x64\3\LXBXtime.dll,RunDLLEntry
mRun-x64: [Persistence] c:\windows\system32\igfxpers.exe
mRun-x64: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun-x64: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun-x64: [lxbxmon.exe] c:\program files (x86)\lexmark 7100 series\lxbxmon.exe
mRun-x64: [SmartMenu] c:\program files\hewlett-packard\hp mediasmart\smartmenu.exe

/background
AppInit_DLLs-X64: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD}

- C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 SAVOnAccess;SAVOnAccess;C:\Windows\System32\drivers\savonaccess.sys [2012-8-28

144672]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13

59904]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files

\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 cpuz133;cpuz133;C:\Windows\System32\drivers\cpuz133_x64.sys [2010-7-6 20968]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-3-30

676968]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:

\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:

\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 IntuitUpdateServiceV4;Intuit Update Service v4;C:\Program Files (x86)\Common Files\Intuit

\Update Service v4\IntuitUpdateService.exe [2012-8-23 13672]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows

\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-28 253656]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;C:\Windows\System32\drivers

\bcmwlhigh664.sys [2011-4-19 1254464]
S3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys

[2009-12-10 56344]
S3 HTCAND64;HTC Device Driver;C:\Windows\System32\drivers\ANDROIDUSB.sys [2009-11

-2 33736]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit

Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2012-9-20 30785672]
S3 motccgp;Motorola USB Composite Device Driver;C:\Windows\System32\drivers\motccgp.sys

[2009-6-19 20992]
S3 motccgpfl;MotCcgpFlService;C:\Windows\System32\drivers\motccgpfl.sys [2009-1-29 9216]
S3 MotDev;Motorola Inc. USB Device;C:\Windows\System32\drivers\motodrv.sys [2009-5-8

53632]
S3 motport;Motorola USB Diagnostic Port;C:\Windows\System32\drivers\motport.sys [2009-10-

27 30208]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft

Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers

\rdpvideominiport.sys [2012-10-26 19456]
S3 sdcfilter;sdcfilter;C:\Windows\System32\drivers\sdcfilter.sys [2012-8-28 36640]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-10-26 57856]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-8

-2 51712]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys

[2009-7-13 17920]
S4 SophosBootDriver;SophosBootDriver;C:\Windows\System32\drivers\SophosBootDriver.sys

[2012-8-28 25608]
.
=============== Created Last 30 ================
.
2013-04-05 18:35:13 9311288 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender

\Definition Updates\{A871ADDC-1510-43F3-8174-ED7FF8F911A0}\mpengine.dll
2013-04-05 16:31:16 76232 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender

\Definition Updates\{3A20A2F0-B66D-489A-94F0-545FC85941B3}\offreg.dll
2013-04-05 14:21:08 9311288 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender

\Definition Updates\{3A20A2F0-B66D-489A-94F0-545FC85941B3}\mpengine.dll
2013-03-21 01:47:25 19968 —-a-w- C:\Windows\System32\drivers\usb8023x.sys
2013-03-21 01:47:25 19968 —-a-w- C:\Windows\System32\drivers\usb8023.sys
.
==================== Find3M ====================
.
2013-03-12 21:53:19 73432 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-12 21:53:19 693976 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-03-12 05:10:56 282744 ——w- C:\Windows\System32\MpSigStub.exe
2013-02-12 05:45:24 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45:22 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45:22 308736 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45:22 111104 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48:31 474112 —-a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-02-12 04:48:26 2176512 —-a-w- C:\Windows\apppatch\AcGenral.dll
2013-01-13 21:17:03 9728 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-

shlwapi-l1-1-0.dll
2013-01-13 21:17:02 2560 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-

normaliz-l1-1-0.dll
2013-01-13 21:16:42 10752 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-

advapi32-l1-1-0.dll
2013-01-13 21:12:46 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-

advapi32-l2-1-0.dll
2013-01-13 21:11:21 4096 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-

user32-l1-1-0.dll
2013-01-13 21:11:08 5632 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-ole32

-l1-1-0.dll
2013-01-13 21:11:07 5632 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-

shlwapi-l2-1-0.dll
2013-01-13 21:11:07 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-

version-l1-1-0.dll
2013-01-13 21:11:07 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-

shell32-l1-1-0.dll
2013-01-13 20:35:31 9728 —ha-w- C:\Windows\System32\api-ms-win-downlevel-

shlwapi-l1-1-0.dll
2013-01-13 20:35:31 2560 —ha-w- C:\Windows\System32\api-ms-win-downlevel-

normaliz-l1-1-0.dll
2013-01-13 20:35:18 10752 —ha-w- C:\Windows\System32\api-ms-win-downlevel-

advapi32-l1-1-0.dll
2013-01-13 20:32:07 3584 —ha-w- C:\Windows\System32\api-ms-win-downlevel-

advapi32-l2-1-0.dll
2013-01-13 20:31:48 4096 —ha-w- C:\Windows\System32\api-ms-win-downlevel-user32-

l1-1-0.dll
2013-01-13 20:31:41 5632 —ha-w- C:\Windows\System32\api-ms-win-downlevel-ole32-

l1-1-0.dll
2013-01-13 20:31:40 5632 —ha-w- C:\Windows\System32\api-ms-win-downlevel-

shlwapi-l2-1-0.dll
2013-01-13 20:31:40 3072 —ha-w- C:\Windows\System32\api-ms-win-downlevel-

version-l1-1-0.dll
2013-01-13 20:31:40 3072 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shell32

-l1-1-0.dll
2013-01-13 20:31:00 1247744 —-a-w- C:\Windows\SysWow64\DWrite.dll
2013-01-13 20:22:22 1988096 —-a-w- C:\Windows\SysWow64\d3d10warp.dll
2013-01-13 20:20:31 293376 —-a-w- C:\Windows\SysWow64\dxgi.dll
2013-01-13 20:09:00 249856 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll
2013-01-13 20:08:43 220160 —-a-w- C:\Windows\SysWow64\d3d10core.dll
2013-01-13 20:08:35 1504768 —-a-w- C:\Windows\SysWow64\d3d11.dll
2013-01-13 19:59:04 1643520 —-a-w- C:\Windows\System32\DWrite.dll
2013-01-13 19:58:28 1175552 —-a-w- C:\Windows\System32\FntCache.dll
2013-01-13 19:54:01 604160 —-a-w- C:\Windows\SysWow64\d3d10level9.dll
2013-01-13 19:53:58 207872 —-a-w- C:\Windows\SysWow64\WindowsCodecsExt.dll
2013-01-13 19:53:14 187392 —-a-w- C:\Windows\SysWow64\UIAnimation.dll
2013-01-13 19:51:30 2565120 —-a-w- C:\Windows\System32\d3d10warp.dll
2013-01-13 19:49:17 363008 —-a-w- C:\Windows\System32\dxgi.dll
2013-01-13 19:48:47 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll
2013-01-13 19:46:25 1080832 —-a-w- C:\Windows\SysWow64\d3d10.dll
2013-01-13 19:43:21 1230336 —-a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-01-13 19:38:39 333312 —-a-w- C:\Windows\System32\d3d10_1core.dll
2013-01-13 19:38:32 1887232 —-a-w- C:\Windows\System32\d3d11.dll
2013-01-13 19:38:21 296960 —-a-w- C:\Windows\System32\d3d10core.dll
2013-01-13 19:37:57 3419136 —-a-w- C:\Windows\SysWow64\d2d1.dll
2013-01-13 19:25:04 245248 —-a-w- C:\Windows\System32\WindowsCodecsExt.dll
2013-01-13 19:24:33 648192 —-a-w- C:\Windows\System32\d3d10level9.dll
2013-01-13 19:24:30 221184 —-a-w- C:\Windows\System32\UIAnimation.dll
2013-01-13 19:20:42 194560 —-a-w- C:\Windows\System32\d3d10_1.dll
2013-01-13 19:20:04 1238528 —-a-w- C:\Windows\System32\d3d10.dll
2013-01-13 19:15:40 1424384 —-a-w- C:\Windows\System32\WindowsCodecs.dll
2013-01-13 19:10:36 3928064 —-a-w- C:\Windows\System32\d2d1.dll
2013-01-13 19:02:06 417792 —-a-w- C:\Windows\SysWow64\WMPhoto.dll
2013-01-13 18:34:58 364544 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2013-01-13 18:32:43 465920 —-a-w- C:\Windows\System32\WMPhoto.dll
2013-01-13 18:09:52 522752 —-a-w- C:\Windows\System32\XpsGdiConverter.dll
2013-01-13 17:26:42 1158144 —-a-w- C:\Windows\SysWow64\XpsPrint.dll
2013-01-13 17:05:09 1682432 —-a-w- C:\Windows\System32\XpsPrint.dll
.
============= FINISH: 15:23:32.14 ===============

Also see DDS file that is attached (as per forum instructions)


One last thing… I think this is associated because it occurred around the same timestamp as when I believe the infection happened. See below:

Source
Services and Controller app

Summary
Stopped working

Date
‎4/‎1/‎2013 5:11 PM

Status
Solution available

Description
Faulting Application Path: C:\Windows\System32\services.exe

Problem signature
Problem Event Name: APPCRASH
Application Name: services.exe
Application Version: 6.1.7600.16385
Application Timestamp: 4a5bc10e
Fault Module Name: ntdll.dll
Fault Module Version: 6.1.7601.17725
Fault Module Timestamp: 4ec4aa8e
Exception Code: c0000005
Exception Offset: 0000000000021cca
OS Version: 6.1.7601.2.1.0.768.3
Locale ID: 1033
Additional Information 1: 65d5
Additional Information 2: 65d5e11e3b403a4beaf5cea13462fca9
Additional Information 3: cf43
Additional Information 4: cf43033ca2e685c0646faa7f85c4d1c2

Extra information about the problem
Bucket ID: 53554025

BIG THANKS IN ADVANCE. Frank S.

Attachments:

Hi avayatech,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download ComboFix:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thank you Tom for assisting…

As per your instructions, I have cut-and-pasted the ComboFix.txt document in this reply below:

ComboFix 13-04-08.04 - Family Room 04/09/2013 9:24.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7133.5077 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A}
SP: Sophos Anti-Virus *Disabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\SPL26AA.tmp
c:\programdata\SPL47FF.tmp
c:\programdata\SPLC011.tmp
c:\programdata\SPLC9F5.tmp
c:\users\Family Room\AppData\Roaming\.#
c:\users\Family Room\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows System
c:\users\Family Room\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows System\Online
c:\users\Family Room\Internet Explorer.lnk
.
.
((((((((((((((((((((((((( Files Created from 2013-03-09 to 2013-04-09 )))))))))))))))))))))))))))))))
.
.
2013-04-05 20:08 . 2012-08-21 17:01 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2013-04-05 20:08 . 2013-04-05 20:08 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-04-05 20:08 . 2013-04-05 20:08 ——– d—–w- c:\program files\iTunes
2013-04-05 20:08 . 2013-04-05 20:08 ——– d—–w- c:\program files (x86)\iTunes
2013-04-05 20:08 . 2013-04-05 20:08 ——– d—–w- c:\program files\iPod
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-04-05 20:04 . 2013-04-05 20:04 ——– d—–w- c:\program files (x86)\QuickTime
2013-03-21 01:47 . 2013-02-12 04:12 19968 —-a-w- c:\windows\system32\drivers\usb8023x.sys
2013-03-21 01:47 . 2013-02-12 04:12 19968 —-a-w- c:\windows\system32\drivers\usb8023.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-13 07:08 . 2012-07-07 21:31 72013344 —-a-w- c:\windows\system32\MRT.exe
2013-03-12 21:53 . 2012-03-28 23:06 693976 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-12 21:53 . 2011-05-13 22:40 73432 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-12 05:10 . 2010-07-05 18:36 282744 ——w- c:\windows\system32\MpSigStub.exe
2013-02-12 05:45 . 2013-03-12 22:47 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-12 22:47 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-12 22:47 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 05:45 . 2013-03-12 22:47 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 04:48 . 2013-03-12 22:47 474112 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-12 22:47 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll
2013-01-14 13:48 . 2013-01-14 13:48 10 —-a-w- c:\windows\Fonts\wfonts.key
2013-01-13 21:17 . 2013-02-27 21:16 9728 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 21:17 . 2013-02-27 21:16 2560 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 21:16 . 2013-02-27 21:16 10752 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 21:12 . 2013-02-27 21:16 3584 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:16 4096 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:16 5632 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:16 5632 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:16 3072 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:16 3072 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:35 . 2013-02-27 21:16 9728 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 20:35 . 2013-02-27 21:16 2560 —ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 20:35 . 2013-02-27 21:16 10752 —ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 20:32 . 2013-02-27 21:16 3584 —ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 4096 —ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 5632 —ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 5632 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 3072 —ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 3072 —ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 1247744 —-a-w- c:\windows\SysWow64\DWrite.dll
2013-01-13 20:22 . 2013-02-27 21:16 1988096 —-a-w- c:\windows\SysWow64\d3d10warp.dll
2013-01-13 20:20 . 2013-02-27 21:16 293376 —-a-w- c:\windows\SysWow64\dxgi.dll
2013-01-13 20:09 . 2013-02-27 21:16 249856 —-a-w- c:\windows\SysWow64\d3d10_1core.dll
2013-01-13 20:08 . 2013-02-27 21:16 220160 —-a-w- c:\windows\SysWow64\d3d10core.dll
2013-01-13 20:08 . 2013-02-27 21:16 1504768 —-a-w- c:\windows\SysWow64\d3d11.dll
2013-01-13 19:59 . 2013-02-27 21:16 1643520 —-a-w- c:\windows\system32\DWrite.dll
2013-01-13 19:58 . 2013-02-27 21:16 1175552 —-a-w- c:\windows\system32\FntCache.dll
2013-01-13 19:54 . 2013-02-27 21:16 604160 —-a-w- c:\windows\SysWow64\d3d10level9.dll
2013-01-13 19:53 . 2013-02-27 21:16 207872 —-a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2013-01-13 19:53 . 2013-02-27 21:16 187392 —-a-w- c:\windows\SysWow64\UIAnimation.dll
2013-01-13 19:51 . 2013-02-27 21:16 2565120 —-a-w- c:\windows\system32\d3d10warp.dll
2013-01-13 19:49 . 2013-02-27 21:16 363008 —-a-w- c:\windows\system32\dxgi.dll
2013-01-13 19:48 . 2013-02-27 21:16 161792 —-a-w- c:\windows\SysWow64\d3d10_1.dll
2013-01-13 19:46 . 2013-02-27 21:16 1080832 —-a-w- c:\windows\SysWow64\d3d10.dll
2013-01-13 19:43 . 2013-02-27 21:16 1230336 —-a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-01-13 19:38 . 2013-02-27 21:16 333312 —-a-w- c:\windows\system32\d3d10_1core.dll
2013-01-13 19:38 . 2013-02-27 21:16 1887232 —-a-w- c:\windows\system32\d3d11.dll
2013-01-13 19:38 . 2013-02-27 21:16 296960 —-a-w- c:\windows\system32\d3d10core.dll
2013-01-13 19:37 . 2013-02-27 21:16 3419136 —-a-w- c:\windows\SysWow64\d2d1.dll
2013-01-13 19:25 . 2013-02-27 21:16 245248 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-01-13 19:24 . 2013-02-27 21:16 648192 —-a-w- c:\windows\system32\d3d10level9.dll
2013-01-13 19:24 . 2013-02-27 21:16 221184 —-a-w- c:\windows\system32\UIAnimation.dll
2013-01-13 19:20 . 2013-02-27 21:16 194560 —-a-w- c:\windows\system32\d3d10_1.dll
2013-01-13 19:20 . 2013-02-27 21:16 1238528 —-a-w- c:\windows\system32\d3d10.dll
2013-01-13 19:15 . 2013-02-27 21:16 1424384 —-a-w- c:\windows\system32\WindowsCodecs.dll
2013-01-13 19:10 . 2013-02-27 21:16 3928064 —-a-w- c:\windows\system32\d2d1.dll
2013-01-13 19:02 . 2013-02-27 21:16 417792 —-a-w- c:\windows\SysWow64\WMPhoto.dll
2013-01-13 18:34 . 2013-02-27 21:16 364544 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-01-13 18:32 . 2013-02-27 21:16 465920 —-a-w- c:\windows\system32\WMPhoto.dll
2013-01-13 18:09 . 2013-02-27 21:16 522752 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2013-01-13 17:26 . 2013-02-27 21:16 1158144 —-a-w- c:\windows\SysWow64\XpsPrint.dll
2013-01-13 17:05 . 2013-02-27 21:16 1682432 —-a-w- c:\windows\system32\XpsPrint.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2012-08-28 900160]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...r=9.0.894" [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [2012-12-04 1998400]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [2011-04-19 1254464]
R3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2009-06-19 20992]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2009-01-29 9216]
R3 MotDev;Motorola Inc. USB Device;c:\windows\system32\DRIVERS\motodrv.sys [2009-05-08 53632]
R3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys [2009-10-27 30208]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys [2011-10-01 36640]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-08-02 51712]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-06 1255736]
R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys [2011-08-25 25608]
S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys [2012-04-24 144672]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x64.sys [2010-03-31 20968]
S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2012-08-23 13672]
S2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2012-12-04 216640]
S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [2012-06-15 139840]
S2 Sophos Web Control Service;Sophos Web Control Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [2012-04-24 357400]
S2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2012-12-04 2869824]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-28 21:53]
.
2013-04-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3726542613-2231915011-3630520082-1000Core.job
- c:\users\Family Room\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-25 22:53]
.
2013-04-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3726542613-2231915011-3630520082-1000UA.job
- c:\users\Family Room\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-25 22:53]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXBXCATS"="c:\windows\system32\spool\DRIVERS\x64\3\LXBXtime.dll" [2007-03-22 28672]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-10-16 415256]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-10-16 386584]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-10-16 162328]
"lxbxmon.exe"="c:\program files (x86)\lexmark 7100 series\lxbxmon.exe" [2007-05-11 205744]
"SmartMenu"="c:\program files\hewlett-packard\hp mediasmart\smartmenu.exe" [2009-09-15 610360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: &2 Customize Menu - c:\program files (x86)\Siber Systems\AI RoboForm\RoboForm.dll/ComCustomIEMenu.html
IE: &7 Fill Forms - c:\program files (x86)\Siber Systems\AI RoboForm\RoboForm.dll/ComFillForms.html
IE: &8 Save Forms - c:\program files (x86)\Siber Systems\AI RoboForm\RoboForm.dll/ComSavePass.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
Trusted Zone: ameritrade.com
Trusted Zone: ameritrade.com\wwws
Trusted Zone: cnet.com\download
Trusted Zone: oneonta.edu\my
Trusted Zone: oneonta.edu\sophos
TCP: DhcpNameServer = [removed] [removed]
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.1.0/GarminAxControl_32.CAB
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-SPMTray - c:\program files (x86)\PC Speed Maximizer\SPMTray.exe
Wow6432Node-HKLM-Run- - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3726542613-2231915011-3630520082-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-3726542613-2231915011-3630520082-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Sophos\AutoUpdate\ALsvc.exe
c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
.
**************************************************************************
.
Completion time: 2013-04-09 09:47:02 - machine was rebooted
ComboFix-quarantined-files.txt 2013-04-09 13:46
.
Pre-Run: 855,959,695,360 bytes free
Post-Run: 856,428,355,584 bytes free
.
- - End Of File - - 560EC82CB7E43FF44D9E1F90AC65E530


I wasn't sure if you wanted it attached as well, so please find it attached for your review.

I am awaiting your reply as to how to proceed, thank you again for your help!

Frank S.

Attachments:

That looks good.

Let's run another tool that will do a little tidying up.

AdwCleaner
  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
Tom, Here is text file after AdwCleaner… # AdwCleaner v2.200 - Logfile created 04/09/2013 at 19:12:02 # Updated 02/04/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Family Room - FAMILYROOM-PC # Boot Mode : Normal # Running from : C:\Users\Family Room\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\blekko toolbars Folder Deleted : C:\Users\Family Room\AppData\LocalLow\BabylonToolbar Folder Deleted : C:\Users\Family Room\AppData\Roaming\Babylon ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} Key Deleted : HKLM\Software\Babylon Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\I Want This_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\I Want This_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Deleted : HKLM\SOFTWARE\Software Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com] ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16521 [OK] Registry is clean. -\\ Google Chrome v26.0.1410.43 File : C:\Users\Family Room\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [2116 octets] - [09/04/2013 19:12:02] ########## EOF - C:\AdwCleaner[S1].txt - [2176 octets] ########## Thank you. Awaiting your next post. Frank S.
Great. Let's get an online scan.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!



How do things seem to be running now?
ESET scan results: C:\Program Files (x86)\PDFCreator\message.exe a variant of Win32/InstallCore.A application C:\Users\Family Room\Downloads\FFSetup260.exe a variant of Win32/Bundled.Toolbar.Ask application C:\Users\Family Room\Downloads\CPU-Z Motherboard Identifier Program\cpu-z_1.54-setup-en.exe multiple threats Tom, Besides what was found above and after your careful review of the other logs I've sent/posted, was I infected with Win32/Small.CA or other malicious files? Your feedback would be appreciated. I have only started my PC to run the programs you've directed to prevent any negative activity. When my PC is on, it seems to run fine. When you say it is safe to operate more, I can give provide better feedback. Thanks, Frank S.
avayatech,

Win32/Small.CA is a generic detection. It is very hard to specifically identify. Basically it means that something is doing something that it shouldn't. It can manifest as almost anything but I think the most common is a downloader… that means it invites it's malicious friends to the party (your computer).

In your specific case… I can't say for sure what triggered it. It could have been one of the .tmp files that were deleted or I have seen it in the \AppData\Roaming\.# folder that was deleted… but yours was empty. Another possibility is your cpu-z_1.54-setup-en.exe file that ESET flagged is that "should" be a legitimate file… and wouldn't be flagged, but I see it has been downloaded and it could have been patched.

Other than that… we cleaned off some adware (that should not have triggered the Wins32/Small.CA detection).

Let's remove what ESET flagged.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Program Files (x86)\PDFCreator\message.exe 
    C:\Users\Family Room\Downloads\FFSetup260.exe 
    C:\Users\Family Room\Downloads\CPU-Z Motherboard Identifier Program\cpu-z_1.54-setup-en.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Then give things a little test drive and let me know how things are running.
Tom,

I apologize for the late reply, didn't get an email like I usually do saying that you posted a reply. Anyways, here is the latest ComboFix log with your script file added as instructed:


ComboFix 13-04-11.01 - Family Room 04/12/2013 1:03.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7133.4720 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Family Room\Desktop\CFScript.txt
AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A}
SP: Sophos Anti-Virus *Disabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files (x86)\PDFCreator\message.exe"
"c:\users\Family Room\Downloads\CPU-Z Motherboard Identifier Program\cpu-z_1.54-setup-en.exe"
"c:\users\Family Room\Downloads\FFSetup260.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\PDFCreator\message.exe
c:\users\Family Room\Downloads\CPU-Z Motherboard Identifier Program\cpu-z_1.54-setup-en.exe
c:\users\Family Room\Downloads\FFSetup260.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-03-12 to 2013-04-12 )))))))))))))))))))))))))))))))
.
.
2013-04-12 05:08 . 2013-04-12 05:08 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-04-11 14:57 . 2013-04-11 14:57 76232 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{74CF9A74-0C2D-4EDE-A70F-F5E3A881698E}\offreg.dll
2013-04-10 17:47 . 2013-03-01 03:36 3153408 —-a-w- c:\windows\system32\win32k.sys
2013-04-10 17:47 . 2013-03-02 06:04 1655656 —-a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 17:47 . 2013-01-24 06:01 223752 —-a-w- c:\windows\system32\drivers\fvevol.sys
2013-04-10 17:47 . 2013-03-19 06:04 5550424 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-04-10 17:47 . 2013-03-19 05:46 43520 —-a-w- c:\windows\system32\csrsrv.dll
2013-04-10 17:47 . 2013-03-19 05:04 3968856 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-04-10 17:47 . 2013-03-19 05:04 3913560 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-04-10 17:47 . 2013-03-19 04:47 6656 —-a-w- c:\windows\SysWow64\apisetschema.dll
2013-04-10 17:47 . 2013-03-19 03:06 112640 —-a-w- c:\windows\system32\smss.exe
2013-04-09 13:21 . 2013-03-15 06:28 9311288 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{74CF9A74-0C2D-4EDE-A70F-F5E3A881698E}\mpengine.dll
2013-04-05 20:08 . 2012-08-21 17:01 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2013-04-05 20:08 . 2013-04-05 20:08 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-04-05 20:08 . 2013-04-05 20:08 ——– d—–w- c:\program files\iTunes
2013-04-05 20:08 . 2013-04-05 20:08 ——– d—–w- c:\program files (x86)\iTunes
2013-04-05 20:08 . 2013-04-05 20:08 ——– d—–w- c:\program files\iPod
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-04-05 20:04 . 2013-04-05 20:04 159744 —-a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-04-05 20:04 . 2013-04-05 20:04 ——– d—–w- c:\program files (x86)\QuickTime
2013-03-21 01:47 . 2013-02-12 04:12 19968 —-a-w- c:\windows\system32\drivers\usb8023x.sys
2013-03-21 01:47 . 2013-02-12 04:12 19968 —-a-w- c:\windows\system32\drivers\usb8023.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-11 01:31 . 2012-03-28 23:06 691592 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-04-11 01:31 . 2011-05-13 22:40 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-04-11 01:04 . 2012-07-07 21:31 72702784 —-a-w- c:\windows\system32\MRT.exe
2013-04-04 18:50 . 2012-08-28 16:30 25928 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-03-12 05:10 . 2010-07-05 18:36 282744 ——w- c:\windows\system32\MpSigStub.exe
2013-02-12 05:45 . 2013-03-12 22:47 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-12 22:47 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-12 22:47 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 05:45 . 2013-03-12 22:47 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 04:48 . 2013-03-12 22:47 474112 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-12 22:47 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll
2013-01-14 13:48 . 2013-01-14 13:48 10 —-a-w- c:\windows\Fonts\wfonts.key
2013-01-13 21:17 . 2013-02-27 21:16 9728 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 21:17 . 2013-02-27 21:16 2560 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 21:16 . 2013-02-27 21:16 10752 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 21:12 . 2013-02-27 21:16 3584 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:16 4096 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:16 5632 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:16 5632 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:16 3072 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 21:11 . 2013-02-27 21:16 3072 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:35 . 2013-02-27 21:16 9728 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 20:35 . 2013-02-27 21:16 2560 —ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 20:35 . 2013-02-27 21:16 10752 —ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 20:32 . 2013-02-27 21:16 3584 —ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 4096 —ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 5632 —ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 5632 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 3072 —ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 3072 —ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:31 . 2013-02-27 21:16 1247744 —-a-w- c:\windows\SysWow64\DWrite.dll
2013-01-13 20:22 . 2013-02-27 21:16 1988096 —-a-w- c:\windows\SysWow64\d3d10warp.dll
2013-01-13 20:20 . 2013-02-27 21:16 293376 —-a-w- c:\windows\SysWow64\dxgi.dll
2013-01-13 20:09 . 2013-02-27 21:16 249856 —-a-w- c:\windows\SysWow64\d3d10_1core.dll
2013-01-13 20:08 . 2013-02-27 21:16 220160 —-a-w- c:\windows\SysWow64\d3d10core.dll
2013-01-13 20:08 . 2013-02-27 21:16 1504768 —-a-w- c:\windows\SysWow64\d3d11.dll
2013-01-13 19:59 . 2013-02-27 21:16 1643520 —-a-w- c:\windows\system32\DWrite.dll
2013-01-13 19:58 . 2013-02-27 21:16 1175552 —-a-w- c:\windows\system32\FntCache.dll
2013-01-13 19:54 . 2013-02-27 21:16 604160 —-a-w- c:\windows\SysWow64\d3d10level9.dll
2013-01-13 19:53 . 2013-02-27 21:16 207872 —-a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2013-01-13 19:53 . 2013-02-27 21:16 187392 —-a-w- c:\windows\SysWow64\UIAnimation.dll
2013-01-13 19:51 . 2013-02-27 21:16 2565120 —-a-w- c:\windows\system32\d3d10warp.dll
2013-01-13 19:49 . 2013-02-27 21:16 363008 —-a-w- c:\windows\system32\dxgi.dll
2013-01-13 19:48 . 2013-02-27 21:16 161792 —-a-w- c:\windows\SysWow64\d3d10_1.dll
2013-01-13 19:46 . 2013-02-27 21:16 1080832 —-a-w- c:\windows\SysWow64\d3d10.dll
2013-01-13 19:43 . 2013-02-27 21:16 1230336 —-a-w- c:\windows\SysWow64\WindowsCodecs.dll
2013-01-13 19:38 . 2013-02-27 21:16 333312 —-a-w- c:\windows\system32\d3d10_1core.dll
2013-01-13 19:38 . 2013-02-27 21:16 1887232 —-a-w- c:\windows\system32\d3d11.dll
2013-01-13 19:38 . 2013-02-27 21:16 296960 —-a-w- c:\windows\system32\d3d10core.dll
2013-01-13 19:37 . 2013-02-27 21:16 3419136 —-a-w- c:\windows\SysWow64\d2d1.dll
2013-01-13 19:25 . 2013-02-27 21:16 245248 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-01-13 19:24 . 2013-02-27 21:16 648192 —-a-w- c:\windows\system32\d3d10level9.dll
2013-01-13 19:24 . 2013-02-27 21:16 221184 —-a-w- c:\windows\system32\UIAnimation.dll
2013-01-13 19:20 . 2013-02-27 21:16 194560 —-a-w- c:\windows\system32\d3d10_1.dll
2013-01-13 19:20 . 2013-02-27 21:16 1238528 —-a-w- c:\windows\system32\d3d10.dll
2013-01-13 19:15 . 2013-02-27 21:16 1424384 —-a-w- c:\windows\system32\WindowsCodecs.dll
2013-01-13 19:10 . 2013-02-27 21:16 3928064 —-a-w- c:\windows\system32\d2d1.dll
2013-01-13 19:02 . 2013-02-27 21:16 417792 —-a-w- c:\windows\SysWow64\WMPhoto.dll
2013-01-13 18:34 . 2013-02-27 21:16 364544 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-01-13 18:32 . 2013-02-27 21:16 465920 —-a-w- c:\windows\system32\WMPhoto.dll
2013-01-13 18:09 . 2013-02-27 21:16 522752 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2013-01-13 17:26 . 2013-02-27 21:16 1158144 —-a-w- c:\windows\SysWow64\XpsPrint.dll
2013-01-13 17:05 . 2013-02-27 21:16 1682432 —-a-w- c:\windows\system32\XpsPrint.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2012-08-28 900160]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...r=9.0.894" [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [2012-12-04 1998400]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [2011-04-19 1254464]
R3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2009-06-19 20992]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2009-01-29 9216]
R3 MotDev;Motorola Inc. USB Device;c:\windows\system32\DRIVERS\motodrv.sys [2009-05-08 53632]
R3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys [2009-10-27 30208]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys [2011-10-01 36640]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-08-02 51712]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-06 1255736]
R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys [2011-08-25 25608]
S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys [2012-04-24 144672]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x64.sys [2010-03-31 20968]
S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2012-08-23 13672]
S2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2012-12-04 216640]
S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [2012-06-15 139840]
S2 Sophos Web Control Service;Sophos Web Control Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [2012-04-24 357400]
S2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2012-12-04 2869824]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-28 01:31]
.
2013-04-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3726542613-2231915011-3630520082-1000Core.job
- c:\users\Family Room\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-25 22:53]
.
2013-04-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3726542613-2231915011-3630520082-1000UA.job
- c:\users\Family Room\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-25 22:53]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXBXCATS"="c:\windows\system32\spool\DRIVERS\x64\3\LXBXtime.dll" [2007-03-22 28672]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-10-16 415256]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-10-16 386584]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-10-16 162328]
"lxbxmon.exe"="c:\program files (x86)\lexmark 7100 series\lxbxmon.exe" [2007-05-11 205744]
"SmartMenu"="c:\program files\hewlett-packard\hp mediasmart\smartmenu.exe" [2009-09-15 610360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: &2 Customize Menu - c:\program files (x86)\Siber Systems\AI RoboForm\RoboForm.dll/ComCustomIEMenu.html
IE: &7 Fill Forms - c:\program files (x86)\Siber Systems\AI RoboForm\RoboForm.dll/ComFillForms.html
IE: &8 Save Forms - c:\program files (x86)\Siber Systems\AI RoboForm\RoboForm.dll/ComSavePass.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
LSP: c:\programdata\Sophos\Web Intelligence\swi_ifslsp.dll
Trusted Zone: ameritrade.com
Trusted Zone: ameritrade.com\wwws
Trusted Zone: cnet.com\download
Trusted Zone: oneonta.edu\my
Trusted Zone: oneonta.edu\sophos
TCP: DhcpNameServer = [removed] [removed]
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.1.0/GarminAxControl_32.CAB
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run- - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3726542613-2231915011-3630520082-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-3726542613-2231915011-3630520082-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-04-12 01:10:18
ComboFix-quarantined-files.txt 2013-04-12 05:10
ComboFix2.txt 2013-04-09 13:47
.
Pre-Run: 854,190,227,456 bytes free
Post-Run: 853,955,350,528 bytes free
.
- - End Of File - - 05FBBC059D841B0DAA9EF3C8BAC3993F


My machine appears fine, running well, probably a bit faster than the first time I posted. Sometimes I feel the delay I get now still is from my internet provider.

Please let me know what to do next and again many thanks for helping out.

Frank S.
It is possible to notice a slight delay the first time you go to a website that you often visit. This is because we cleaned out the temp files and some graphics may be stored in temp files so that the website will load slightly faster. Once you have visited the sight the cache file is restored and the next time you visit the slight delay will not occur.

I think you are good to go.


Time for some housekeeping
  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

You can just delete any tools or logs left over.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
ADDITIONAL POST SEE BOTH since your last post… Also, my Sophos Virus Protection program began to detect this in the c:\windows\nircmd.exe I clean it via Sophos, but it keeps coming back. I also tried to delete it via DOS and Windows Explorer with NO luck… permissions issue it appears or resistant to deletion. Could use help with that as a side note. Thanks, Frank S.

ADDITIONAL POST SEE BOTH since your last post…

I don't understand. I only see one post???

c:\windows\nircmd.exe was added by the tools we ran. It should be removed when you do the housekeeping.
Sorry if I confused you about the posts. I had responded by reply and then added another reply mentioning the nircmd.exe, hence double post. I will now do housekeeping as you advised. I would like to ask while I am working on housekeeping what are the best anti virus + malware + other FREE programs you would recommend for me to put on my PC to screen and prevent (other than the education material you advised I read)? Thanks, Frank
If you follow the link I provided, Preventing Malware - Tools and Practices for Safe Computing, you will find information to free programs. My personal synopsis. For Anti-virus I like Microsoft Security Essentials or AVAST!. They are both good. MSSE is probably more "plug and play". Then I would have Malwarebytes installed. If you just use the free version I suggest you run a scan once a week. The paid version does updates and scans automatically and the license is a one time payment for life. Personally, I feel that the windows firewall is sufficient. The article in the link gives you some options for third party firewalls. That is the essentials. From there you can add other programs that are in the article. Do not add them all. Just try one or two.
Tom, I will read through the documents you sent about prevention when I have a chance. Thank you for your help thus far. I do have another problem… my daughter texted me asking me to go to her PC to email her some homework she forgot… Guess what I found? The same Virus that you just helped me with. Can you assist with removal on this case, or should I open a new one? Thanks! Frank S.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI